Core Concepts
The model proposes. The runtime decides. Runtime authority explained.
M31A represents a paradigm shift from conventional "agent wrappers". Instead of granting an LLM direct shell execution privileges, M31A embeds the model as an untrusted reasoning component inside a deterministic systems runtime.
Runtime Authority
In ad-hoc agent frameworks, the LLM decides when a task is finished, what commands to run, and what files to touch. When models hallucinate or encounter adversarial injections, catastrophic side effects (deleted databases, exposed credentials, infinite loops) occur.
In M31A, the runtime owns the state machine. The LLM cannot mutate workspace state, spawn child processes, or conclude a mission on its own authority.
The Proposal vs Decision Separation
- • Proposes structured tool calls (JSON)
- • Generates candidate task decompositions
- • Produces candidate source code patches
- • Analyzes diagnostic compiler errors
- • Evaluates actions through 11-stage policy gate
- • Enforces 10-dimensional resource bounds
- • Confines subprocesses via cgroups and rlimits
- • Verifies results against automated tests
- • Commits atomic checkpoints to SQLite
Fail-Closed Governance
Whenever ambiguity arises — whether an ambiguous checkpoint, an unresolved policy ASK in unattended mode, an unverified worktree, or an unrecognized configuration schema — the runtime fails closed. It never guesses, assumes success, or silently bypasses checks.