Bind authority to the operation.
- Deterministic policy and exact-operation authority
- Approval, delegation, budgets and limits
- Tenant binding, idempotency and preflight validation
AUTHORITY · CCP · COMMITSHIELD · AGENT GUARD
Deterministic runtime control and independently verifiable evidence for consequential actions performed by AI agents, humans and software. Assembly orchestration at 1d044a7 pins substrate, forensic cases, Consequence CI, and industry expansion standards.
CONTROL THE CONSEQUENCE. PRESERVE THE EVIDENCE. REPRODUCE THE FAILURE. PROVE THE FIX.
An identity system can establish who is acting. A policy engine can decide whether an operation is permitted. Once a consequential operation crosses the execution boundary, different questions appear.
Authorization establishes permission. HIBS is designed to establish and verify what happened next.
Enterprise identity and PAM can remain upstream. HIBS focuses on the operation, its external effect and the evidence required to resolve what happened—including an honest unresolved state when the evidence cannot support a definitive verdict.
Architecture view, not a claim that every component is production-deployed. Component availability and qualification boundaries are stated in the Library and repository inventory.
Consequence assurance spans the operation lifecycle without pretending uncertainty can always be eliminated.
AUTHORITY · CCP · COMMITSHIELD · AGENT GUARD
WITNESS · PASSPORT · INCIDENT LAB · REPLAY
A timeout does not necessarily mean an operation failed. HIBS treats uncertain execution as a first-class state rather than silently granting permission to try the consequence again.
The implemented hostile vertical slice exercises today’s orchestration boundary. Planned producer bridges are not presented as complete.
Private single-host SQLite/WAL vertical slice. Native and Docker qualification commands exist; no current green CI or real-component end-to-end qualification is claimed here.
Distinct responsibilities and boundaries—not a row of interchangeable products.
HIBS does not need to replace identity, PAM, gateways or policy systems. It uses adapter boundaries and reference integrations around consequential operations.
Identity/PAM, cloud/IAM, agent gateways, MCP, CI/CD, payments, infrastructure and databases are integration categories—not claims that every vendor has a live adapter.
Architectural principles, not claims of uniqueness.
Verification attaches to exact repositories and commits. A README command is not itself a green qualification result.
Not claimed: current green CI, multi-host qualification, production deployment, real CommitShield reservation, or generated Passport/Witness artifacts in the hostile slice. See Technical Due Diligence.
HIBS Labs explores systems where correctness matters after software decides to act: authority, execution, uncertainty, evidence, recovery and replay. The wider Library includes quantitative systems and applied B2B software developed alongside that work.
Nothing has been removed. Core protocols, hostile demonstrations, applied desks, quantitative systems, repositories and technical diligence remain available below. They support the Consequence Assurance identity without each competing as an equal homepage proposition.
The flagship chain binds intent, policy, approval, authority, execution, reconciliation and evidence. HIBS-HORIZON assembly orchestrates the pinned substrate; ambiguous execution is held and reconciled explicitly — not silently retried.
Canonical orchestration repo pinning Store, Replay, CCP, Passport, Stream, CrashStore, qualification harness, and Horizon II adapters. Forensic tier materializes ConsequenceCaseV1 bundles (S09–S16, S20, S25, S27-q3, S29). Consequence CI and forensic export are separate buyer wedges — pick one per pitch. Local forensic-rigorous qualification: 43/43 PASS.
Live GitHub deployment adapter with mode-0600 consumed executor credentials, authority-signed grants, signed approval receipts, host-local file-lock ledger, durable reserved/held/settled/released exposure, restart-safe reconciliation, and Replay-linked incident proof. PossiblyStarted cannot return to retryable.
Records deterministic execution evidence, locates first divergence and applies reproducible drop, timeout, duplicate, delay, reorder and crash fault plans.
Compact Rust append-only engine with checksummed WAL records, immutable segments, tail recovery, corruption detection and stable snapshots.
Portable Rust protocol and offline verifier for who/what ran, artifact, authority, exact operation, consequence, effect and Replay reference. Verdicts are Proven, Diverged or Unresolved; it complements rather than replaces Authority, CCP, Store, Stream, Replay, Sigstore or SLSA.
C++ event/key/value engine with CRC32C WAL, atomic generations, torn-tail recovery, process ownership, snapshots and crash-atomic compaction.
Deterministic event-processing kernel with canonical IDs, partition ordering, crash-consistent checkpoints, poison quarantine and independently verifiable window roots.
Durable reserve, authorize and dispatch lifecycle with PossiblyStarted crash recovery, tenant-bound authentication, idempotency, HTTPS execution, dual evidence chains and offline verification.
Exercises exact-operation authority, durable dispatch fencing, reconciliation-only ambiguity resolution, tamper detection and offline bundle verification. Real CommitShield reservation and Passport/Witness producer artifacts remain release gates.
Review surface for hostile cases, near misses and disputed effects: reconstruct the operation lifecycle, compare evidence roots, inspect divergence and connect deterministic Replay capsules.
Planned hosted layer for receiving portable evidence bundles, witness acknowledgements and Incident Lab review. No canonical repository or production service is currently evidenced.
Hash-chained Consequential Action Proof — parent platform over five commercial packs (Financial, Cyber, Deployment, Agent Payments, Insurance). Publication repo: hibs-hcap; implementation spine: modelgovernor.v01.
Five governors (MG, FG, CG, IG, BG) on governor-spine-core — domain engines under HCAP, not the buyer-facing product label.
Forensic case materialization F1–F12: Track C verticals S09–S11, R12–R16 case nodes, S20 finance_advice guard, S27 insurance/bilateral SchemaOnly, S29 counterfactual. LATEST bundles under evidence/scenarios/.
PR gate + hostile corpus regression index (S16, S28). Buyer wedge A for DevSecOps — deploy duplicate and blast-radius drift caught before merge.
OTel Consequence Profile v0.1, MCP Consequence Guard profiles, CAP draft v0.1, WASM core activation gate. Standards index in assembly docs/standards/.
Nine-section M&A index over the assembly repo: executive, architecture, qualification, evidence, honesty boundaries. data-room-verify.sh before sharing.
Portfolio scanner state that preserves a verified baseline commit while reporting QUALIFICATION_DRIFT when an observed local canonical clone HEAD differs.
Universal integration fabric: transport-neutral integrity contracts, canonical operations, authoritative readback, and deterministic reconciliation evidence. Local Rust proof-pack across 15 phases — CI green on main @ 00258d6.
Fifteen local proof phases tied by hibs-proofpack-core and hibs-proofpack CLI: Evidence · Arrow/ADBC · CCP · CloudEvents · Contract · Connect · Event · Exposure · Identity · Lineage · OTLP · Reconcile · Transport · WASM adapter · explicit NotExercised live-runtime boundary. Artifact: artifacts/hibs-local-proofpack.hibs.
Customer-system observation, consequential write handling, authoritative readback, reconciliation outcomes, schema drift classification, and Q-CONNECT inventory. Sibling repo hibs-connect holds transport-neutral integrity contracts.
Local intake envelopes for REST/OpenAPI, webhooks, gRPC, OTLP, Kafka, NATS, SQL, CDC, files, email, and MCP. Normalizes to canonical operations; blocks unsafe consequential writes and missing readback support.
Local Arrow RecordBatch fixture, ADBC abstract PartitionedResult binding, deterministic scan/material fingerprint, benchmark report evidence.
WASM adapter manifest, read-only default profile, capability gate, wasm32 ABI marker, invocation evidence binding.
Generic reconciliation items, deterministic matching, graph reconciliation, residuals, ambiguity handling, CSV/TSV ingestion, evidence bundles, Q-RECON inventory.
Crystal Commit Protocol: crystallize, horizon, commit-or-strand, mesh blocking, exposure reserve, idempotent replay, local evidence verification, Q-CCP inventory.
All-phases local proof-pack inventory, render, verify, and tamper-negative checks via hibs-proofpack CLI (fixture-report, verify).
OpenAPI/AsyncAPI consequence gate, CloudEvents ingest with HIBS extensions, local OTLP projection, SPIFFE-style identity binding, OpenLineage-style lineage evidence.
Four unified Play bundles plus standalone preservation exports on GitHub. Buyer-operated Docker stacks — not turnkey vendor-of-record. Stripe, SAML, HTTPS and SOC 2 remain separate diligence items unless proved explicitly.
RescueOS (revenue ops), Agent Guard (AI ops), TokenShield Platform (FinOps), CommitShield Platform (reserve-before-commit). Each ships app + engine ports, verify-strict gates, and marketplace-style compose bundles from skills-github-pages with standalone GitHub preservation snapshots.
Revenue-operations SaaS: missed-call rescue, recovery funnel, agency console, CRM relay and spend governance. Repo: rescueos-platform.
Commercial AI-ops surface over Rust engines. Canonical in monorepo skills-github-pages/agent-guard; standalone preservation export agent-guard bundles ABCP, TokenShield, Nexus, API Breaker, Ghost Log, RelayMesh and PolicyPack.
OpenAI-compatible spend firewall, rogue-loop freeze, Blake3 audit ledger, Next.js Trust Center. Repo: tokenshield-platform.
Reserve-before-commit spine composing TokenShield spend and ABCP tool boundaries. Repo: commit-shield-platform.
Institutional AI governance gateway: five governors (MG/FG/IG/CG/BG) on governor-spine-core — cost control, model policy, auditability, multi-provider routing. Branch codex/hcap-ccp-publication.
Stdio/SSE sidecar gating MCP tools/call with Blake3 decision ledger. Preservation snapshot: mcp-enclave-shield.
Typed LLM invocation contract and enforcement primitives supporting Agent Guard and governor wedges. Repo: llmcontract.
Multi-site readiness ledger with M365 integration, remediation workflows and regulator-ready exports. Repo: Microsoft-365-native-Martyn-s-Law-readiness-evidence.
On-site contractor verification, field evidence capture and job-completion proof chains. Repos: contractor-gate, hibs-fieldproof, jobproof.
Separately extractable stacks from skills-github-pages, plus Rescue lanes that reuse the same card format. Hardware, live-network and legal boundaries remain visible. File conversion and Cheeky Monkeys are not listed here.
Revenue-operations platform: missed-call rescue, recovery funnel, agency console, CRM relay and spend governance on a buyer-operated stack.
CommercialProduct in skills-github-pages/agent-guard with standalone export agent-guard. Scanner: CANONICAL · RootAdded. Operator surface over Rust engines. Composed hardening completes with Ghost Log BENCH_N=5000; 50k silent bench was the hang.
OpenAI-compatible spend firewall with HTTP 402 fail-closed, rogue-loop freeze, Blake3 audit and a Next.js Trust Center.
Reserve-before-commit spine: TokenShield spend plus ABCP tool boundaries so nothing bills or executes without a successful reserve.
Missed-call, Quote, Gap and inspection lanes plus Rescue Broker. Tenant adapter profiles map customer field aliases, credential state, signed webhooks (x-rescue-signature), diary source and CRM/job rules without a bespoke importer per pilot.
Private-rented-sector compliance and portfolio-readiness platform: CSV/CRM imports, certificate OCR and storage, drift alerts, signed webhooks, heatmap, landlord portal and listing-field exports.
Governance-first licence-obligation engine: email/document ingest, page-cited human approval, full point-in-time SHA-256, append-only stream, audit trail, five-event replay capsule and independently verifiable export bundles.
CONC reconstruction product in the statutory portfolio map. Kept distinct from HIBS hospitality licensing and PRS registration.
Rescue inspection lane: findings, remedial evidence and sign-off for housing and duty-of-care follow-up, using the same detect → one safe action → evidence pattern as Lead Rescue.
Local scrape gate: rustls fetch, robots lane, structural DOM squash and enrichment before LLM ingest, with an optional OpenAI-compatible JSON router.
Intercepts tool calls, tracks execution trees, reserves budget and freezes recursive agent spend before irreversible dispatch.
Un-skippable stdio and SSE sidecar that gates MCP tools/call, masks secrets, and writes a Blake3 decision ledger.
Query shredding, federated MPC mesh, enclave attestation and gateway stitching for confidential multi-vault analytics.
Pressure-weighted routing across CPU, GPU, TPU, ASIC and FPGA queues using pinned-pool staging.
Seals edge telemetry batches into compact signed commitments sized for satellite and constrained IoT uplinks.
Local masked-token PEP and sanctions gate backed by embedded SQLite, with no third-party screening call on the hot path.
Zero-dependency circuit breaker with three-strike trip, half-open recovery and TTL LRU fallback routing.
Append-only Blake3 hash-chain ledger that detects edit, deletion or insertion and can trigger local lockdown hooks. Standalone bench default remains 50k; composed Agent Guard passes BENCH_N=5000 and prints append progress so the gate is not silent.
Lock-before-squeeze reference hot path that serves duplicate agent state fetches from a 64-byte context crystal.
Signed event intake, tenant isolation, idempotency, retry, dead-letter and replay proof for CRM, SMS and recovery connectors.
Tenant policy registry for allow, deny, require-approval and shadow/live enforcement across agents, MCP, spend and Rescue send modes.
Origin: Harvested Intelligent Betting Systems. HIBS-Bet, Racing, football intelligence and Harvested quant research — each with its own repository, evidence boundary and operating status. No profitability or live-money-readiness claim is made.
Football betting engine and prediction stack. Repo: hibs-bet — actively updated. Public pilots were taken offline Aug 2026; repository and capture evidence remain the diligence surface.
Racing vertical: docker compose stack, inst_workflow catalog, EQUIBET research lanes. Repo: hibs-bet-racing.
Football research and intelligence surfaces. Repos: football-app, football-intelligence-platform.
Self-hosted B2B quant desk: hash-chained Postgres ledger, interchangeable feeds, evidence promotion (shadow → paper → micro → live) and a native operator UI. Repo: harvested-intelligent-betting-system.
Cross-domain probability, pricing, risk, execution, settlement, replay and audit foundation with racing as the reference vertical.
Harvested trading scanner path: scheduled depth polls, recon-gated scan cycle, profile-only or shadow eval, JSONL audit trail. The same fail-closed pattern as Axiom ENFORCE gates — scan is not place-order.
The skills-github-pages source portfolio packages 15 separately extractable stacks plus four unified SaaS platforms. This website is the static export of that catalogue.
Full private GitHub org inventory for mc8h7dxz6t-ui as of 2026-09-07. Preservation snapshots are labeled; qualification claims attach to named commits in each repo, not this table alone.
| Repository | Surface | Status |
|---|---|---|
| hibs-standalone-control-plane | HIBS-HORIZON assembly · forensic tier · data room | PRIVATE · 1d044a7 |
| hibs-labs-rust.consequence-control-plane | CCP · GitHub adapter · MCP guard · OTel | PRIVATE · f1ffe2e |
| hibs-labs-rust.replay | Deterministic replay + fault plans | PRIVATE |
| hibs-labs-rust.store | Append-only durable store | PRIVATE |
| hibs-labs-cpp.crashstore | C++ crash-recovery store | PRIVATE |
| hibs-stream | Deterministic event runtime | PRIVATE |
| ui-hibs-execution-passport | Portable execution proof · v0.1 | PRIVATE |
| ui-hibs-labs.hostile-execution-demo | Consequence Assurance hostile slice | PRIVATE · QUALIFIED SLICE |
| hibs-authority | Authority preservation snapshot | PRIVATE |
| CONTROL-SUBSTRATE-QUALIFICATION | Qualification harness | PRIVATE |
| evidence-incident-lab | Incident lab evidence | PRIVATE |
| hibs-connect | Transport-neutral integrity contracts · SourceEnvelope · Q-CONNECT | PRIVATE · INTEGRITY CORE |
| hibs-connect-reconcile | 15-phase local proofpack · Connect/Reconcile/Transport/ADBC/WASM | PRIVATE · 00258d6 · CI PASS |
| contractor-gate | On-site contractor verification | PRIVATE · RUST |
| hibs-fieldproof | Field evidence capture | PRIVATE |
| Repository | Surface | Status |
|---|---|---|
| hibs-hcap | HCAP publication index · 5 commercial packs · CCP Q001-Q010 | PRIVATE · afb5ae8 · PIN 486a0f49 |
| modelgovernor.v01 | Governor spine MG/FG/IG/CG/BG · implementation modules | PRIVATE · 486a0f49 · DOCKER PASS |
| agent-guard-llm | Agent Guard LLM engine snapshot | PRIVATE |
| agent-guard-soak | Agent Guard soak tests snapshot | PRIVATE |
| llmcontract | LLM invocation contract snapshot | PRIVATE |
| Repository | Surface | Status |
|---|---|---|
| rescueos-platform | Play 1 · revenue-ops SaaS | PRIVATE · SNAPSHOT |
| agent-guard | Play 2 · AI-ops SaaS · ABCP + TokenShield + Nexus bundle | PRIVATE · c0ec35b · PIN d0bf285 |
| tokenshield-platform | Play 3 · LLM spend firewall SaaS | PRIVATE · SNAPSHOT |
| commit-shield-platform | Play 4 · reserve-before-commit SaaS | PRIVATE · SNAPSHOT |
| tokenshield | TokenShield engine snapshot | PRIVATE · MIT |
| tokenshield-governance | TokenShield governance UI | PRIVATE · MIT |
| commit-shield | CommitShield engine snapshot | PRIVATE |
| mcp-enclave-shield | MCP sidecar gate snapshot | PRIVATE · MIT |
| skills-github-pages | HIBS Edge monorepo + this site · evidence index branch | PRIVATE · MIT · e946bf9 |
| Repository | Surface | Status |
|---|---|---|
| lead-rescue-engine | Missed-call + Rescue lanes | PRIVATE · MIT |
| licence-duty | Multi-site licence-obligation evidence · hospitality | PRIVATE · 32b6034 · SNAPSHOT |
| prs-ready | PRS registration · portfolio readiness | PRIVATE · c9e20c1 · SNAPSHOT |
| landlord-duty | Housing inspection · remedial evidence lane | PRIVATE · 340388d · SNAPSHOT |
| credit-duty | CONC reconstruction · port 8081 | PRIVATE · SNAPSHOT |
| jobproof | Job completion proof chain | PRIVATE · SNAPSHOT |
| rtw-chain | Right-to-work evidence chain | PRIVATE |
| scrap-gate | Scrape gate snapshot | PRIVATE · SNAPSHOT |
| ldpe-engine | LDPE DOM enrichment | PRIVATE · MIT |
| relaymesh | Event relay snapshot | PRIVATE · SNAPSHOT |
| policypack-studio | Policy pack registry snapshot | PRIVATE · SNAPSHOT |
| Microsoft-365-native-Martyn-s-Law-readiness-evidence | Martyn's Law M365 readiness ledger | PRIVATE |
| deterministic-csv-reconciliation-cli-harbor | CSV reconciliation CLI | PRIVATE |
| Repository | Surface | Status |
|---|---|---|
| -ui-api-breaker-sentry | API Failure Sentry · circuit breaker | PRIVATE · MIT · ALPHA |
| -ui-nexus-context-sentry | Nexus context dedupe | PRIVATE · MIT |
| -ui-ghostlog-secure-chain | Ghost Log tamper-evident chain | PRIVATE · MIT |
| -ui-agent-boundary-control-plane | Agent spend freeze gate | PRIVATE · MIT |
| -ui-apep-secure-plane | APEP confidential analytics | PRIVATE · MIT |
| -ui-hcg-silicon-gateway | HCG silicon workload router | PRIVATE · MIT |
| -ui-zk-telemetry-control-plane | ZK telemetry commitments | PRIVATE · MIT |
| -ui-sovereign-compliance-bridge | Local AML / PEP gate | PRIVATE · MIT |
| Repository | Surface | Status |
|---|---|---|
| hibs-bet | Football betting engine | PRIVATE · ACTIVE |
| hibs-bet-racing | Racing vertical | PRIVATE |
| football-app | Football research app | PRIVATE |
| football-intelligence-platform | Football intelligence snapshot | PRIVATE · SNAPSHOT |
| harvested-intelligent-betting-system | Harvested B2B quant desk | PRIVATE · SHADOW DEFAULT |
| axiom-standard | Rust quant foundation · paper mode | PRIVATE |
| hibs-quantitative-labs.github.io | Quant labs Pages site | PRIVATE · MIT |
Statutory desks licence-duty, prs-ready and landlord-duty are preserved on this org; canonical development remains on Cursor-origin remotes — see Commercial Automation. Cheeky Monkeys and the any-file converter remain outside this inventory. Aug 2026: hibs-bet public pilots offline; captures on this site. Deploy from skills-github-pages/landing via landing/deploy/bootstrap-remote.sh.