Every draft carries its evidence. Every decision carries a name.

Artificer Intelligence Layer

Artificer is the human face of the platform's cognition plane: one context-aware assistant across every capability, designed to draft control narratives, suggest cross-framework mappings, explain posture, and plan convergence. Its reasoning commits to the same evidence spine it reasons about. Nothing it infers becomes evidence until a named human confirms it.

Reasoning held to the record.

Most products bolt a chat window onto a dashboard and call it intelligence. The Redoubt Forge architecture goes the other way: it holds AI to the same discipline it holds infrastructure. The design specifies a cognitive kernel through which every consequential inference passes and commits as a signed, replayable transaction; Artificer is the lens a person holds on that plane. The design has it draft, cross-reference, prioritize, and assemble at machine scale, and write nothing on its own authority. What follows is that specified design.

Context That Follows the Cursor

A compliance question is never generic. "What evidence does this control need?" has a different answer for every system, environment, and framework, and the person asking is usually looking at the exact page where the answer matters. The Artificer design starts there: one context-aware assistant, page aware and scope aware, streaming into a persistent panel across the whole platform rather than living in a separate tab. Opened inside Rampart on a control, it is designed to reason against that control's definition, the active framework, and the evidence already linked. Opened inside Vanguard on a finding, the same assistant reasons about severity and the controls the finding touches. Opened against the Garrison estate, it reasons about what exists and what it maps to. There are no modes to switch and no second product to learn; the context follows the cursor.

What the assistant is allowed to see is itself law, not habit. The observability design binds every captured signal to a declared purpose, and Artificer reads only its own purpose slice; a read outside that slice refuses, by architecture. The architecture states the consequence plainly: Artificer context cannot quietly become ad-hoc analytics. Product telemetry and in-product feedback feed that context under the same purpose binding, so the assistant gets richer without the platform getting nosier. And because Artificer is a lens on the cognition plane rather than a separate brain, everything it composes into an answer is a declared, versioned recipe of graph slices and retrievals, never an opaque window. AI-guided compliance only works when the guide can show where its guidance came from.

Cognition Is State

Ask most AI products how they reached an answer and you get a shrug: the context window is gone, the model version unpinned, the retrieval unlogged. For drafting a birthday email, that is fine. For a system where an assessor's first question is "on what basis?", it is disqualifying. An intelligence layer that cannot answer for itself has no business standing near evidence.

The architecture's answer is a law it names outright: cognition is state. Scratch reasoning is free and leaves no trace; the moment reasoning proposes something consequential, it commits as a reasoning transaction on the platform's signed, append-only event spine. The transaction carries the context recipe consumed, the model and prompt versions applied, the freshness watermark of every input, the taint verdict, and the conclusions with a derived confidence; the full twelve-stage trace, observation through learning, is stored content-addressed beside it. What the platform believes is a projection over those transactions, rebuildable byte for byte and queryable as-of any moment: what was believed at time T, on what basis, and what was done about it. Infrastructure as evidence is the same instinct, applied to thought.

One Thought, One Receipt

Ephemeral reasoning costs nothing; consequence pays. The design commits each consequential inference as exactly one event on the signed spine, with its trace stored beside it and addressed by hash. The cost envelope prices a consequential cognition at roughly one log append. Accountability, at commodity cost.

Beliefs That Age Honestly

A confident answer built on stale facts is worse than no answer; it spends your trust on yesterday's world. Compliance state decays constantly. Evidence expires, infrastructure changes underneath the assessment that describes it, and evidence decay is the quiet failure mode of every static tool.

The design refuses to let the assistant's knowledge rot silently. No belief exists without provenance and a derived confidence, computed from provenance quality, freshness, and derivation chain depth; a static confidence annotation is banned outright. Every belief class declares a freshness horizon, and past that horizon the belief demotes to contested rather than deleting, keeping the expiry in its provenance. A plan that would consume a stale critical input halts and emits a re-observation task for the owning collection controller in Sentinel; the architecture's own words are "never a silent best-guess." Contradiction gets the same honesty: conflicting derivations produce an explicit contested state with resolution machinery, re-observe, quorum, escalate, and never a silent winner. A scheduled consistency sweep walks the belief graph, so a disagreement is noticed before any plan consumes it.

A Threat Model for Thinking

Any assistant that reads customer documents and tool output can be steered by them; that is what prompt injection is. Most products answer with guardrail prompts and output filters, which is to say they ask the model nicely. A platform that stakes authority on a model's good behavior has no answer when the model misbehaves.

This architecture gives the cognition plane a threat model instead. Customer data, tool outputs, and retrieved documents enter as tainted inputs, and taint propagates through context composition and the belief graph. The integrity law is short: tainted input may inform but never authorize. No authority decision derives solely from tainted context, dilution is no bypass, and the commit gate derives the taint verdict inside the kernel rather than trusting the caller's claim. The other half of integrity is supply chain: models, prompts, skills, rules, and retrieval recipes are signed and provenance-verified exactly as the container supply chain is, and an unsigned artifact fails closed at load. The human-in-the-loop boundary is not a review step added at the end; it is enforced at the moment of reasoning itself.

Informs, Never Authorizes

Guardrail prompts ask a model to behave. The design removes the choice: every inbound document and tool output carries taint, and no authority decision may derive solely from tainted context. Prompt injection is defeated structurally, not heuristically, and diluting one poisoned input among clean ones is no bypass.

Drafts at Machine Scale

Narrative writing is the grind of compliance: hundreds of controls, each needing an implementation description that matches the actual system, multiplied by every framework in scope. Teams cope with templates, and templates produce prose that reads plausibly and describes nothing. The narrative drifts from the system it claims to describe the day after it is written.

In this design, Artificer drafts and Rampart holds the record. A control narrative is a managed document in Rampart's document machine, computed from living data rather than typed into a binder; when posture or a narrative input changes, the document is marked stale with its cause named and regeneration is queued. Gap analysis is Artificer's other standing draft: the delta between declared frameworks and computed posture, cross-referenced so one fix surfaces everywhere it counts rather than being rediscovered per framework. That rediscovery is the overhead multi-framework programs know well. Cross-framework coverage itself belongs to Rampart's mapping engine, which the design holds to five strategies: native, via NIST 800-53, via NIST CSF, crosswalk, and AI-suggested. A model-suggested mapping enters a confirmation queue, and its record carries a human-confirmed flag. Suggestion and satisfaction are different states.

Assembled deliverables follow the same rule. The design regenerates system security plans and managed documents from living data, with full content lifecycle and versioning, and holds posture exportable as a machine-verifiable attestation a third party can check cryptographically: OSCAL-native, selectively shareable, and exchanged through Alliance as proof rather than paperwork. What reaches an assessor is computed from current state, and every generated artifact traces to the evidence it drew on and the human who confirmed it.

Suggested Is Not Satisfied

A model-suggested mapping is a hypothesis, not a fact. In the Rampart design it waits in a confirmation queue, and the platform's own gauges treat the AI-suggested share as queue depth, not coverage. Machine scale does the cross-referencing. A named person does the counting.

The Convergence Plan

The most useful question a platform can answer is the one most tools dodge: what should we work on next? A sorted findings list is not an answer. Raw severity ignores what an action buys across frameworks, what blocks what, and which gaps a machine can close without you. Prioritization is why the authorization bottleneck exists: the work is not unknown, it is unordered.

Convergence plans are named in Artificer's charter row as its core work. Desired state is declared as frameworks, overlays, and defenses; current posture is computed; the plan is the diff. The design that seeded this capability classifies each gap by reconciliation tier: automated, where the platform converges on its own rails; AI-assisted, where a draft is prepared and a person confirms; human-required, where judgment is the control. In the current architecture that tier is derived from impact, reversibility, confidence, and actor trust, never hand-assigned, and an irreversible action can never derive to the automated tier. Priorities and dependency chains order the plan, and the items that need a person land in front of the right one through Citadel's action queue.

Behavior Change Is Deployment

Teams distrust AI features for a mundane reason: the ground shifts. A silent model upgrade changes conclusions, a prompt tweak changes judgment, and nobody can say what changed, when, or under whose authority. In compliance work that is not an annoyance. It is a provenance failure.

The design versions the platform's behavior the way it versions code. Prompts, skills, rules, and policies are the engineering DNA: signed, versioned data on the substrate, shared by every actor, and distributed as signed, provenance-verified genome packages through Armory. A behavior change is a deployment: proposed, shadow-evaluated, staged, promoted, with rollback armed and no learned behavior live on arrival. Promotion evidence includes counterfactual replay, where a candidate faculty is replayed against committed reasoning history and the resulting diff report says exactly where it would have disagreed. Verification is itself cognition: scheduled verifiers re-derive earlier conclusions and commit their results as new transactions citing the original, and divergence contests the belief rather than overwriting it.

No Model Is Load-Bearing by Identity

A model swap in this architecture is a genome deployment: contract-tested against the behavior it replaces, canaried, rollback armed. The standing law is blunt: no model is load-bearing by identity, only by verified behavior. The platform is designed to outlive its own AI substrate.

Authority Stays Human

The assistant's designed tool surface is three verbs: query reads, act proposes a write, visualize renders. Reads are free; every act previews before anything persists. Confirmation is not a UX flourish; it is where authority lives. The reconciliation model behind it is explicit: per-action approval is the floor of human authority, not the whole of it. An organization can pre-approve a class of low-risk actions at policy-declaration time, under confidence thresholds it sets; that autonomy is earned from verified outcomes, measured, and always revocable. Earned trust decays by default: an authority grade survives its window only on fresh verified outcomes and steps down automatically without them.

Some acts never delegate. Risk acceptance and control N/A justification are Tier 3 by architecture: in the Rampart design they refuse without a live human step-up ceremony, and the architecture admits no automatic path. Escalations carry liveness expectations, and on breach the design halts pending consequential actions rather than proceeding; in the architecture's words, silence is never consent, and an empty chair never approves. Every state change binds to exactly one actor with an accountability chain that resolves to a responsible human, which is why an assessor working through Alliance can trace any generated artifact to the person who confirmed it, the evidence it drew on, and the transaction that produced it.

Propose. Confirm. Persist.

The market is crowded with agents that act first and explain later. This design inverts that: reasoning commits with its receipts, writes are proposed and previewed, and the charter holds the line in one sentence: nothing a model infers counts as evidence until a named human confirms it. Compliance is hard, and no assistant makes it otherwise. The honest role for AI in a compliance control plane is to carry the mechanical load at machine scale and hand judgment, with full context, to the person who owns it.