Carolopedia

A public encyclopedia of Carolverse.

๐Ÿ“– Carolopedia โ€บ Guides โ€บ Governance architectureGuide page

Governance architecture

The operating runbook is not published.

๐Ÿ“–Summary

The Governance service is built following the [agent-centric modular architecture](/dev/carolopedia/wiki/architecture) of Carolverse. It is the rules-and-oversight layer that every other service is accountable to โ€” the constitution, the policies, the requirements and designs, the source-of-truth catalog, and the monitor โ€” operated by [Orion](/dev/carolopedia/wiki/agent/agt-023). It is **work in progress**: the pillars exist as concepts and as the stores other services already read, but Governance has not yet been assembled into its own self-contained service.

๐Ÿ“–Functional considerations

Governance is the layer that makes the rest of Carolverse trustworthy, so its architecture is shaped by what it must guarantee across every service:

- **A single, readable rulebook.** The constitution and policies must be the binding reference any agent or service can point at โ€” one place, not scattered copies.
- **One source of truth.** Requirements, designs, and the catalog of what exists must be derived from live sources, never hand-maintained, so records match reality.
- **Accountability by construction.** Every governed action ties back to an accountable agent, so oversight has something concrete to check.
- **Continuous oversight.** The monitor must keep watch over services and surface where reality drifts from the records or the rules.
- **Honest about state.** Where a pillar is still being built, that must be visible rather than papered over.

๐Ÿ“–Solution architecture

Governance is conceived as a small set of **oversight pillars** rather than a build pipeline, wired into the same [agent-centric modular architecture](/dev/carolopedia/wiki/architecture) as the rest of Carolverse: every rule and record has an accountable owner, today [Orion](/dev/carolopedia/wiki/agent/agt-023).

- **Constitution + policies** โ€” the binding rulebook other services are checked against.
- **Requirements + designs** โ€” auto-derived from live sources, the reference for what each service is supposed to do and be.
- **The source-of-truth catalog** โ€” the registry of what actually exists across Carolverse.
- **The monitor** โ€” continuous oversight that compares running reality to the records and the rules.

These pillars are not yet consolidated into one service; today they live as the stores and conventions that other services already read. The architecture work ahead is to draw them together behind a single Governance control surface.

๐Ÿ“–Technologies

Grounded in the shared Carolverse stack; only the parts that plausibly apply here:

- **Python 3** services on **FastAPI** / **Flask** behind **nginx**, where Governance surfaces are served.
- **SQLite (WAL)** datastores hold the policies, requirements, and design records.
- The **registry** and the **design store** are the binding sources of truth that the oversight pillars read from.
- **systemd** / **cron** schedule any recurring oversight sweeps as the monitor pillar is built out.
- The reasoning steps where rules or designs must be interpreted run on the service's own lane, read from the registry when this page renders: **{{service_lane}}**.
- Much of the implementation is still **intended rather than built** โ€” see the roadmap.

๐Ÿ“–Design principles

- **Single source of truth.** Requirements, designs, and counts are derived from the live registry and design store, never hand-copied โ€” the shared principle described on the [Carolverse Architecture](/dev/carolopedia/wiki/architecture) page.
- **Agent-centric accountability.** Every rule, record, and oversight action has an accountable agent owner.
- **Observability first.** Oversight is only real if drift surfaces on a monitor; if it is not watched, it is not governed.
- **Honesty over polish.** State what is built and what is still intended, plainly.

๐Ÿ“–Success criteria

- The constitution and policies are the **one place** every service is checked against, with no conflicting copies.
- Requirements and designs **match live reality**, because they are derived from sources, not maintained by hand.
- The source-of-truth catalog reflects **what actually exists** across Carolverse.
- The monitor **surfaces drift** โ€” where a service diverges from its records or its rules โ€” rather than letting it go unseen.

๐Ÿ“–Policies

- **One source of truth.** Records are auto-derived from live sources; the rulebook is never silently forked into per-service copies.
- **Every governed action is tied to an accountable agent** โ€” never a human id, never anonymous.
- **Lifecycle and record changes route through the owning app and its agent**, never by hand-editing a store.
- **Bypass skips the planner, not the standards** โ€” the same checklists, review, and observability still apply (the org-wide bypass rule this layer enforces).

๐Ÿ“–What it delivers today

Governance is **wip**; what exists today are the pillars as shared stores and conventions that other services read, overseen by [Orion](/dev/carolopedia/wiki/agent/agt-023):

- The **constitution and policies** as the binding rulebook of record.
- The **requirements and designs** stores, derived from live sources.
- The **source-of-truth catalog** (the registry of what exists).
- Early **monitor** oversight surfaced through the existing service and registry views.

These are not yet packaged behind a dedicated Governance service โ€” there are no Governance-specific blocks, droids, or agent-facing tools yet.

๐Ÿ“–What it will deliver

Because the service is early, most of its capability is ahead:

- A single **Governance control surface** that draws the constitution, policies, requirements, designs, and catalog together in one place.
- A **continuous oversight monitor** that compares running services to their records and rules and flags drift on its own.
- **Policy-compliance gates** that any service can check itself against before shipping.
- **Doing droids** under Orion to run the recurring oversight sweeps, so governance is observable and self-healing rather than manual.

Source: Services Catalogue ยท Public information reflected here.