Mechanism
Each adaptation artifact is published into the mesh with a declared capability scope and the credential, attestation, and jurisdictional conditions under which it may be admitted. The conditions enumerate the credentials the consuming agent must hold, the certification and provenance attestations the artifact must currently carry, and the governance authorities under which the artifact may be activated. The artifact is admitted into the catalog through the composite admissibility evaluator against the governance-credentialed authority that admits artifacts into the marketplace.
The same composite admissibility evaluator that performs the governance gate also performs the skill-domain-routing function. Upon evaluating a candidate generation step, the evaluator determines whether that step falls within the capability scope of one or more currently-active adaptation artifacts. Admissibility is evaluated as part of the gate, and capability-scope matching is performed within the same admissibility architecture rather than as a separate routing subsystem. This unifies governance gating and capability routing through one architecture, eliminating the structural separation between governance-gating subsystems and skill-routing subsystems present in prior systems.
Each routing decision is recorded as a lineage event and is consumable by subsequent generation-stage admissibility evaluations. The record carries the candidate generation step evaluated, the active adaptation artifacts considered, the admissibility outcome, the selected routing response, and the governance-credentialed signatures of the evaluation. A reviewer reconstructing a past decision recovers which artifact handled the step, which were outside capability scope, and on what admissibility ground.
When a candidate generation step falls outside the capability scope of all active adaptation artifacts, the evaluator triggers one of a plurality of governance-policy-defined routing responses, including without limitation: activation of a different already-loaded adaptation artifact whose capability scope encompasses the current generation context; confidence-value reduction reflecting generation outside governed competence boundaries, propagating through the confidence governor and producing graduated-actuation mode de-escalation; deferral of the step pending a governed discovery query soliciting a relevant artifact from the marketplace; degraded-mode continuation with stricter admissibility criteria applied to subsequent steps; consultative-mode engagement requesting human-operator or higher-authority-agent input; solicitation of additional observations to reduce uncertainty; or generation-rollback to a prior checkpoint. Each routing decision is lineage-recorded.
Operating Parameters
Credential validity is enforced at evaluation time rather than only at session establishment. An authority credential freshness evaluator produces observations of credential expiration and pre-expiration status, and a revocation-propagation completeness evaluator detects consumers still admitting revoked credentials, so revocation propagates to subsequent admissibility evaluations.
The architecture accommodates disputed admissibility. When governance authorities disagree about whether an artifact is admissible, the evaluation consults the dispute-resolution primitive, and the dispute and its outcome are recorded in lineage. Byzantine-robust evaluation tolerates a bounded fraction of compromised authority signatures, falling through to dispute resolution when the bound is exceeded.
Audit retention follows the deployment domain. The architecture is operable across civilian, commercial, and defense domains, and each routing decision is recorded as a lineage event subject to the same retention, access, and tamper-evidence guarantees as any other operation record. Because the routing record is a lineage event, it supports the same regulatory, legal, and forensic reconstruction the wider mesh provides, so a routing decision can be recovered under the credential and attestation state in force at the time of the decision.
Under sustained denial-of-service conditions, the composite admissibility evaluator applies rate-limiting that throttles high-volume contributors exceeding governance-policy-defined per-source rate envelopes, applies authority-weighted prioritization that processes observations from higher-authority sources before lower-authority sources during admission-queue saturation, and transitions to graduated-response mode producing reduced-throughput operation with elevated thresholds. Per-source rate envelopes are governance-policy-defined.
Under evaluator failure conditions, the routing decision falls through to the governance-policy-defined routing responses. Where admissibility cannot be resolved, the evaluator applies degraded-mode continuation with stricter admissibility criteria, deferral, or consultative-mode engagement rather than admitting an artifact outside its capability scope. Each failure mode and its disposition is recorded in lineage with sufficient granularity to distinguish a routing response driven by absent admissibility from one driven by infrastructural unavailability.
Alternative Embodiments
In one embodiment, the admissibility conditions on an adaptation artifact are expressed as declarative predicates evaluated by the consuming agent's local composite admissibility evaluator. In a second embodiment, the conditions are carried as part of the governed adaptation artifact and validated against governance-credentialed certification observations emitted during the sandbox certification phase. In a third embodiment, certification and authority admission are performed by separate governance-credentialed certifiers and authorities while the consuming agent performs admissibility evaluation locally, decoupling the policy authority from the agent's local trust base so that the agent need not directly trust the artifact producer; this embodiment supports cross-organizational skill federation across the marketplace.
Routing may select a single admissible-and-capable adaptation artifact, or may activate a different already-loaded artifact whose capability scope encompasses the current generation context. Where redundancy or corroboration is required, for instance in safety-critical actuation paths, the routing response may engage corroboration over admitted activations under the wider mesh's corroboration discipline.
The admissibility conditions on an artifact admit several expression variants. The architecture is agnostic to the expression language so long as the evaluation is deterministic, governance-credentialed, and version-bound through the artifact's version-lineage chain. An artifact progresses through publication, certification, active-consumption, version-revision, deprecation, and retirement, and the active version admitted by a consuming agent is governed by the deprecation and transition-window policies in force.
In a further embodiment, the certification phase performs sandbox evaluation before active consumption, so that governance-credentialed certifiers emit governed certification observations against which later admissibility evaluations are checked. In a still further embodiment, admissibility evaluation is performed by the consuming agent's local composite admissibility evaluator, while certification and authority admission are performed by separate governance-credentialed certifiers and authorities, decoupling the policy authority from the consuming agent's local trust base so that the agent need not directly trust the artifact producer. This embodiment supports cross-organizational skill federation across the marketplace.
Composition
Admissibility-driven routing composes with the wider mesh architecture along several axes. Cross-jurisdictional admissibility is supported because the artifact's jurisdictional conditions are evaluated against the operating cell's jurisdictional state, supporting multi-authority admissibility with cross-jurisdictional co-existence. Byzantine-robust evaluation tolerates a bounded fraction of compromised authority signatures and falls through to dispute resolution when the bound is exceeded. Dispute mechanism integration is supported because each routing decision produces a lineage record that a disputing party can cite without out-of-band evidence.
The routing function composes with the artifact publication and lifecycle mechanism in that admissibility is evaluated against the same governance-credentialed authority that admits artifacts into the marketplace, removing a class of split-trust failures. It composes with credential issuance in that credential freshness and revocation are evaluated at evaluation time. It composes with lineage-recorded provenance in that the routing record is itself a lineage event subject to the same retention, access, and tamper-evidence guarantees as any other operation record.
Composition with deactivation events is supported in that a deactivation observation narrows which artifacts remain admissible. Composition with environmental conditions is supported in that an observation that an operating cell is degraded propagates into the admissibility evaluation, demoting artifacts out of the admissible set or driving the governance-policy-defined routing responses when no artifact is admissible. Because the routing decision is itself lineage-recorded and consumable by subsequent generation-stage admissibility evaluations, a change in operating condition re-evaluates any in-flight routing that has not yet committed to an artifact activation.
Prior-Art Distinction
Prior systems maintain a structural separation between governance-gating subsystems and skill-routing subsystems. A capability-routing subsystem answers whether a skill can handle the request, while a separate governance or policy subsystem decides whether the request is permitted, the two operating as distinct stages. The present architecture produces a unified treatment of governance and capability-routing decisions through the same composite admissibility evaluator, so that the question of whether a candidate generation step falls within the capability scope of an active adaptation artifact is answered as part of the same admissibility evaluation that governs the step.
The distinction is structural rather than configurational. Where governance gating sits beside capability routing as a separate subsystem, it is subject to bypass when misconfigured, omitted, or evaluated against stale state. The present architecture eliminates that separation: capability routing is performed within the admissibility architecture, and the result is a property of the composite admissibility evaluator rather than of any deployment configuration.
A second distinction concerns the evidentiary footprint of a routing decision. Each routing decision is lineage-recorded and is consumable by subsequent generation-stage admissibility evaluations. The record carries the candidate generation step, the active adaptation artifacts considered, the admissibility outcome, and the selected routing response, producing an evidentiary footprint sufficient to reconstruct the decision from the record. A party challenging a decision cites the record rather than relying on operator memory or out-of-band log fragments.
Disclosure Scope
This material is disclosed in U.S. Provisional Application No. 64/049,409. The disclosure covers the admissibility-gate-as-router mechanism, the composite admissibility evaluator performing a unified governance gate and skill-domain-routing function, the plurality of governance-policy-defined routing responses, and the lineage recording of each routing decision for consumption by subsequent generation-stage admissibility evaluations. Defense adaptation operations and civilian adaptation operations are within scope, as are commercial deployments that operate under the architecture's governance regime. The scope further extends to federated marketplaces across multiple authorities and to long-horizon retention of routing decisions sufficient to support forensic reconstruction of past artifact activations under the credential and attestation state in force at the time of the activation.
The disclosure does not bind to any particular admissibility-condition expression language, signature primitive, attestation scheme, or transport substrate, provided the structural invariants are preserved: that governance and capability-routing are decided through the same composite admissibility evaluator, that each routing decision is recorded in lineage, and that credential and attestation validity are evaluated at evaluation time. Variants employing post-quantum signatures and distributed-ledger lineage substrates are within scope, as are variants employing alternative dispute-resolution primitives. The scope further encompasses use of admissibility-driven routing as a substrate for downstream governance properties, corroboration constraints over admitted artifact activations, dispute mechanisms over routing decisions, and revocation propagation through prior routing records, under the same composition discipline by which the evaluator composes with the wider mesh.