Aurora-Lens Architecture Map

Admissibility before consequence. Runtime governance for determining whether a candidate output, inference, recommendation, action, or state transition may become consequential.

A system must not commit merely because it can generate.

Aurora-Lens is not a conversational memory feature, a guardrail, a moderation layer, or a referential-continuity demo. It is a runtime governance architecture.

Before an output or action is delivered, relied upon, executed, escalated, or treated as operationally valid, Aurora-Lens evaluates whether the proposed commitment has an admissible basis. That basis may include evidence, authority, source status, freshness, scope, policy fit, role, consequence grade, ambiguity state, provenance, and persistent state consistency.

Public demonstrations may show one narrow failure class, such as unresolved referents or ambiguous continuation. Those examples are not the boundary of the architecture. They expose the invariant: where admissibility is unresolved, the system must not pretend certainty and proceed.

The architecture is layered

Aurora-Lens sits within a broader architecture comprising several linked layers.

Reasoning construction

Compositional reasoning, primitive constraints, roles, domains, spans, candidate interpretations, and conditions under which an interpretation may collapse into a committed state.

Persistent epistemic state

Not memory in the ordinary sense. A maintained state substrate that distinguishes active state, unresolved state, potential state, echo state, reconstruction, and admissibility-relevant context.

Epistemic admissibility

Whether the system has enough valid basis to permit a claim, interpretation, recommendation, or action to become consequential.

Commitment control

The runtime boundary where a candidate output, action, or determination either passes, is contained, is refused, is delayed, is escalated, or requires constrained clarification or re-attestation.

Aurora-Lens product layer

A deployable runtime embodiment of commitment control — a governance layer between an application and a model interface.

Compositional reasoning

The reasoning-construction layer is not merely text classification. It concerns how concepts, roles, domains, spans, and primitives are formed, maintained, and constrained.

A candidate interpretation is not automatically valid because a language model can express it fluently. An interpretation must satisfy the structural conditions required for commitment.

Where a statement contains an ambiguous referent, the system may maintain multiple candidate interpretations. Commitment to one interpretation is permitted only when admissibility constraints eliminate or resolve the competing candidates. If more than one candidate remains admissible, commitment is prohibited.

That principle generalizes beyond pronouns. Any unresolved role, domain, span, primitive precondition, authority condition, evidence condition, or scope condition can prevent commitment.

Ambiguous reference is the easiest public demonstration of a deeper rule: unresolved structure must remain unresolved until admissibility permits collapse.

Persistent Existence Frame

The Persistent Existence Frame (PEF) is the state substrate that allows unresolved conditions to persist rather than being erased by fluent generation.

Ordinary model interaction tends to collapse uncertainty into an answer. If the model can continue the conversation, the unresolved condition often disappears into the next phrase. Aurora-Lens treats that as a governance failure.

PEF-style state distinguishes between what is active, what is unresolved, what is merely potential, what is echoing from prior context, and what can be reconstructed. This prevents a system from treating a candidate continuation as if it had settled the underlying admissibility burden.

PEF is not memory. Memory stores content. PEF preserves the status of content. A fact, claim, authority, referent, or evidential basis may be present in state while still being inadmissible for commitment.

Epistemic admissibility

Epistemic admissibility is the question of whether a proposed commitment has the required basis to proceed.

A candidate output may fail admissibility for many reasons: lack of evidence, untrusted source, exceeded authority, stale information, out-of-scope action, policy conflict, high consequence grade, unresolved ambiguity, missing provenance, or contradiction with maintained state.

Admissibility is not the same as confidence. A model may be highly confident and still be inadmissible. A retrieved passage may be relevant and still be stale. A governance artifact may be intact and still lack authority.

Aurora-Lens evaluates whether a candidate commitment is permitted, not merely whether a model can produce a plausible answer.

Commitment control

Commitment is the transition from candidate state to consequence.

A commitment may be an answer shown to a user, a recommendation delivered to a clinician, a procurement approval, a legal summary, a financial decision, an operational instruction, a public statement, an escalation, or any output that downstream systems may rely upon.

Aurora-Lens governs that transition. The commitment-control layer may allow the candidate to pass. It may also refuse, contain, delay, escalate, require clarification, require re-attestation, or maintain unresolved state.

The model can generate. The gate decides whether generation may become consequence.

Refusal, containment, and lawful continuation

A governed system does not merely say yes or no. It must also determine what may lawfully happen next.

  • Ambiguous referent failure may require constrained clarification.
  • Insufficient evidence may require retrieval, escalation, or refusal.
  • Missing authority may require re-attestation or escalation to a person with standing.
  • Stale, superseded, or unrevalidated conditions may require suspension until freshness is restored.
  • High-consequence actions with absent basis may require containment or hard stop.

Many governance systems detect a problem but leave the next action unconstrained. Aurora-Lens treats the failed or unresolved condition as state-bearing. It remains part of the path the next decision must answer to.

External orientation and silent decay

Not all admissibility failures originate inside a conversation. In institutional systems, a previously valid basis may silently decay: expired credentials, superseded policy, changed sanctions status, lost source authority, shifted jurisdiction, or approval paths that no longer apply.

The system may receive no explicit revocation event. That does not mean permission continues.

Aurora-Lens separates orientation discovery from consequence admissibility. External systems may provide sanctions updates, registry status, policy versions, credential state, supplier records, HR authority state, source-trust metadata, or other orientation information. Those systems supply or expose world-state or institutional-state conditions.

Orientation data is not itself permission. The admissibility layer governs whether the available basis is sufficient for the proposed consequence.

Absence of revocation is not authorization. Missing required freshness is unresolved admissibility.

Public demos are examples, not the architecture boundary

Some public Aurora-Lens demos expose the invariant through referential ambiguity and conversational continuity. Those examples are useful because the failure is easy to see: an unresolved referent should not be silently collapsed into a committed answer.

Referential ambiguity is only one manifestation of the broader architecture. The same admissibility principle applies to stale evidence, missing authority, source failure, scope mismatch, policy conflict, unresolved institutional state, missing freshness, failed primitive preconditions, contradiction, and consequence-grade mismatch.

Public examples are selected demonstrations. They do not define the full scope of the architecture.

The architecture is broader: it governs whether a proposed output or action has the required admissibility basis before consequence.

What Aurora-Lens is not

Not a post-hoc moderation filter.

Not merely a retrieval wrapper.

Not a confidence threshold.

Not a memory extension.

Not an agent framework.

Not a system that asks the language model whether the language model should be trusted.

It is a deterministic governance layer for commitment. A model may propose. An application may request. A workflow may attempt. An upstream system may supply orientation state. But the commitment-control layer retains the authority to determine whether the proposed consequence is admissible.

The core invariant

Commitment is permitted only when applicable admissibility conditions are satisfied.

Where they are not satisfied, the correct output is not a more confident answer. The correct output is a governed non-commitment state: refusal, containment, escalation, clarification, delay, withholding, re-attestation, or maintained unresolved state.

This is what makes Aurora-Lens different from systems that merely detect drift, log uncertainty, classify risk, or produce audit artifacts after the fact.

Detection is not governance unless it changes what may happen next. Audit is not governance unless the decision basis was controlled before consequence. Continuity is not governance unless unresolved burdens persist and constrain future commitments. Orientation is not permission. Fluency is not admissibility. Generation is not commitment.