Components
The Constellation map in boring nouns: what each component does, what it will not do, and how mature it is.
This is a public source map, not a claim that every component is installed, live, or needed for every workflow. Constellation is compositional; choose the smallest supported composition on the integration page. Dated claims are on the status page.
Core components
The components exercised together in the alpha.6 governed-action profile.
Decides whether one exact piece of automated work may run, and grants permission for that one run.
- Boundary
- Refuses authority that is already spent or no longer current. Does not execute work or treat a provider response as permission.
- Maturity
- Development source
Details
- Precise role
- Makes bounded, one-use authorization decisions from current inputs.
- Relationship
- core family office
- Implementation
- standalone Rust authorization office
- Maturity in full
- Development source with component qualification and one actual reviewed, authorized-once, Docket-custodied alpha.6 workflow. This does not establish production deployment or arbitrary-work support.
- Available now
- Public source. Alpha.6 pins the authorization runtime at 4dafc1a774178a9e09e75afc6e22c71052fd3dce and the public Phosphor/evidence reader at e0f30de668234935cdbc4b0bd04f5dc13838411d. The Alpha 2 showing (2026-10-02) used forward source f21b2431d07e15e6d03298502c3ca29577c04058 on dev/operator-beta, packaged as agent-governor-ng-operator-tools and agent-governor-ng-systemd-executor inside the published Alpha 2 bundle; no standalone package or tag is published.
- When to use it
- Use for the documented exact-work authorization boundary. Start with the alpha.6 composition when you need the qualified end-to-end local-copy example.
Evaluates a narrowly defined question from recorded evidence.
- Boundary
- Returns a typed refusal when required evidence is missing, stale or cannot be evaluated. Its results never authorize an effect.
- Maturity
- Developer preview
Details
- Precise role
- Derives bounded diagnostic dispositions or typed refusals from retained evidence.
- Relationship
- core family office
- Implementation
- standalone Rust diagnostic engine
- Maturity in full
- Developer preview. Public examples cover saved checks, maintenance annotations, replay, local-inbox delivery and alpha.6 evidence admission. Archive/rollover is separately qualified in disposable state; production migration, transparent cross-store lookup, restoration, rollback remain unverified; one live Slack delivery was observed on 2026-10-01, not qualified. Sustained acquisition over a growing store failed on one host because every store open validates the whole retained history.
- Available now
- Public source; released profiles pin their own revisions, including alpha.2 saved checks, alpha.4 local-successor replay, alpha.5 installed-cadence exercise, and alpha.6 bounded observation admission. The archive/rollover procedure is a source-level operator path, not an installed recurring migration. NQ 0.2.0 is also published as a component package (a Debian package and a tarball) for NQ alone: https://github.com/unpingable/constellation-nq/releases/tag/v0.2.0. The Alpha 2 bundle and the operator-host installation carry an Ubuntu 22.04 rebuild of the same source; it is published only inside that bundle.
- When to use it
- Use a named diagnostic profile or retain a bounded local SQLite check. The five compiled diagnostic profiles and local saved-check interface are distinct; neither establishes general health or permission to act.
Keeps custody of one authorized execution attempt: dispatches it, records the outcome and reconciles it.
- Boundary
- Refuses to execute without matching, current permission. An uncertain attempt is recorded as indeterminate and reconciled, not blindly repeated.
- Maturity
- Exercised in alpha.6 and Alpha 2; not production-hardened
Details
- Precise role
- Keeps custody of a bounded execution attempt and records its outcome.
- Relationship
- core family office
- Implementation
- standalone Rust execution-custody product
- Maturity in full
- Supported executor contracts, an operationally reusable Git-effect vertical, and one qualified alpha.6 local-copy workflow; not production-hardened.
- Available now
- Public source. Alpha.6 pins fbcacc1dfb95f0f625a72e123f61afa41c1ddccb for its bounded local permission snapshot, attempt custody, dispatch, settlement and reconciliation. The Alpha 2 showing (2026-10-02) used forward source 0c771e9be75e6e4bb197ea355682ff86101de97f on dev/operator-beta, packaged inside the published Alpha 2 bundle; no standalone package or tag is published.
- When to use it
- Use when an authorized workflow needs attempt identity and settlement custody.
Tracks recurring work and changing conditions over time, and proposes the next bounded task.
- Boundary
- Does not authorize or execute work, and does not turn old evidence into a fresh fact.
- Maturity
- Development source
Details
- Precise role
- Tracks currentness, recurrence, and attention over time.
- Relationship
- core family office
- Implementation
- standalone Rust temporal-observation office
- Maturity in full
- Development source. Saved-check recurrence, maintenance-aware attention, replay, local delivery and one actual alpha.6 occurrence/review path are exercised. No production recurring installation or complete consumer migration is claimed.
- Available now
- Public source. Alpha.6 pins cycle runtime 9e592cbe581c24b3973677ef3938bccac4feea49 and Foreman 58639a9bfe8ddf3d6b232aab6dc231dcf82b6769; the later public lineage reader is e7c35db3ad6ce7cd53e280e6be118b042d89f63b. The Alpha 2 showing (2026-10-02) used forward source 3333c791d32cae33dbb8c8302fc69ca2ba0ec217 on dev/operator-beta, packaged inside the published Alpha 2 bundle.
- When to use it
- Use when a workflow needs temporal observation rather than authorization or execution.
Authors, checks, compares and locks automation plans before they are submitted for authorization.
- Boundary
- A checked plan grants no permission and runs no work.
- Maturity
- Exercised in alpha.4 and alpha.6; design-flow work pre-alpha
Details
- Precise role
- Authors, checks, compares, and locks pre-governed plans.
- Relationship
- core operator surface
- Implementation
- standalone Python authoring and supervision product
- Maturity in full
- Public source includes deterministic Plan Core authoring, an optional enrolled provider route, the qualified alpha.4 connected-cache workflow, and the alpha.6 local-copy validator/executor. ECAD/design-flow remains pre-alpha.
- Available now
- Public source. Alpha.6 pins d0f1375245d7fbaa05b0c6da9b8f60c6c5d388f4 for exact plan compilation, validation and the authority-neutral exclusive-create executor; other release snapshots retain their own pins.
- When to use it
- Use for source-level Plan Core work; a checked plan grants no permission and runs no work.
Optional and supporting components
Each is usable on its own; none is required for every workflow.
Shows authored goals with their linked runs, outcomes and supporting records.
- Boundary
- Read-only: cannot accept a plan, grant authority, rerun work or settle an occurrence.
- Maturity
- Experimental
Details
- Precise role
- Shows authored goals and their linked runs, outcomes, and supporting records.
- Relationship
- hosted family capability
- Implementation
- read-only inspector hosted in Constellation AG
- Maturity in full
- Experimental read-only integration. Alpha.6 qualifies one actual non-empty occurrence projection and public identity check; objective completion remains undetermined and ATProto production migration is not qualified.
- Available now
- Hosted in public AG source. Alpha.6 pins evidence reader e0f30de668234935cdbc4b0bd04f5dc13838411d and publishes one non-empty objective projection; there is no standalone package.
- When to use it
- Inspect exact authored-plan and run relationships without changing owner state. A settled or successful attempt does not establish objective completion.
Stores versioned memories and records when they may be relied on across sessions.
- Boundary
- Its records do not select work, infer currentness or authorize action.
- Maturity
- Supported in one vertical; broader doctrine candidate
Details
- Precise role
- Provides receipted persistence custody for workflows that explicitly rely on retained memory.
- Relationship
- optional family member
- Implementation
- standalone Python persistence-custody office
- Maturity in full
- Supported in a continuity-aware vertical; broader trajectory doctrine remains candidate.
- Available now
- Optional public source
- When to use it
- Use only when a workflow needs explicit persisted-memory lifecycle records.
Tracks scoped, expiring mandates and checks whether they still apply to proposed work.
- Boundary
- A mandate is an input to an authorization decision, not permission by itself.
- Maturity
- Implemented; broader deployment not claimed
Details
- Precise role
- Owns scoped, expiring mandate custody and standing judgments.
- Relationship
- optional family member
- Implementation
- standalone Rust mandate-custody product
- Maturity in full
- Implemented. Workload identity transcript schema v2 is current; v1 identity files fail closed and must be regenerated. Broader deployment is not claimed.
- Available now
- Optional public source
- When to use it
- Use when a workflow requires an independently custodied mandate lifecycle.
Tracks finite resource allowances and prevents double spending.
- Boundary
- Accounts for capacity only; it does not authorize action.
- Maturity
- Frozen v0 reference
Details
- Precise role
- Accounts for conserved finite capacity separately from action permission.
- Relationship
- optional reference component
- Implementation
- standalone Rust library and thin transport binary
- Maturity in full
- Frozen v0 reference component with a machine-checked arithmetic core; a scalar spend/residual-viability bridge is formalized, but no cross-stack reserve controller is implemented.
- Available now
- Optional public source
- When to use it
- Use to account for finite execution capacity. A runtime guarantee of keeping mandatory obligations affordable afterward would require a separate protected-reserve admission rule; successful spend alone does not establish it.
Collects bounded observations about an explicitly selected project.
- Boundary
- Does not establish diagnostic truth or permission to act.
- Maturity
- Experimental
Details
- Precise role
- Acquires and validates bounded project concerns without establishing diagnostic truth or action authority.
- Relationship
- optional family member
- Implementation
- standalone Rust project-concern acquisition workspace hosting Pulse
- Maturity in full
- Experimental source with tested actual local acquisition into NQ, Pulse and Nightshift. The host-posture runner ran as a service on one operator host from 2026-10-01 and has been refusing, fail-closed, since NQ's acquisition exceeded its time bounds the same day; no complete recurring migration claim.
- Available now
- Public source at constellation-monitor 45296872d161a79d345571d88d23725b04ff0236; the host-posture runner and Pulse support packaging are on dev/operator-beta (Alpha 2 forward source 5a44225ce9db0f58192df2f0d4c88501ba77f09c). Packages exist only inside the published Alpha 2 bundle and on one operator host; none is published standalone.
- When to use it
- Use monitor-concerns to acquire an explicitly selected project's observations; use the local queue example for exact NQ/Pulse/Nightshift handoffs and their limits.
Checks whether current evidence still supports one specific statement.
- Boundary
- Support expires. It is not general health, permission to act, or delivery.
- Maturity
- Component checks passed; M2 support judged; live delivery unqualified
Details
- Precise role
- Evaluates proposition-specific present support under explicit coverage and policy.
- Relationship
- hosted optional family capability
- Implementation
- Rust subsystem and support adapters hosted within Constellation Monitor
- Maturity in full
- Host-load component checks and actual local predicate-support/attention example passed; in Alpha 2 (2026-10-02) Pulse judged current support for the two fixed M2 propositions from fresh NQ acquisition. Live delivery and full recurring migration remain unqualified.
- Available now
- Hosted in the public constellation-monitor repository at 45296872d161a79d345571d88d23725b04ff0236 and on dev/operator-beta; the Alpha 2 bundle carries a pulse-m2-support package. No separate Pulse repository or standalone package is published.
- When to use it
- Select the adapter matching the named evidence profile and explicit source policy. Positive support expires and is not general health, action permission or delivery.
Runs declared commands over SSH or serial connections and records output, exit status, artifacts and hashes.
- Boundary
- Transport only: it does not choose what to run, and it does not own attempt custody or settlement.
- Maturity
- Early usable
Details
- Precise role
- Carries a declared command to a declared substrate and retains factual transcripts, observed exit status, artifacts and hashes.
- Relationship
- optional execution-transport integration
- Implementation
- Python CLI and library with SSH, serial-console and caller-recipe transports
- Maturity in full
- Early usable public implementation with live SSH specimens; exact-SSH and governed worker composition remain development-only.
- Available now
- Optional public source; no daemon, MCP server, endpoint provisioner or binary package.
- When to use it
- Use when a workflow needs transport evidence; callers still own selection and Docket owns governed attempt custody, settlement and reconciliation where composed.
Runs bounded model-provider requests with cancellation, deadlines and retained records.
- Boundary
- Completing a review does not accept a plan, grant authority or execute work.
- Maturity
- Exercised in alpha.6
Details
- Precise role
- Provides a reviewed source-only provider-runtime distribution for an enrolled integration.
- Relationship
- shared provider integration
- Implementation
- reviewed source-only provider-runtime distribution
- Maturity in full
- Bounded provider path with cancellation and deadline checks. It retained the independent review used by alpha.6; review completion alone did not accept the plan, grant authority or execute work.
- Available now
- Optional public source
- When to use it
- Use only where a documented integration selects it; it is not a new governance office.
Checks a proposed change against supplied evidence and rules before execution.
- Boundary
- A preflight answer does not replace an owning authorization decision.
- Maturity
- Public; relation to AG unratified
Details
- Precise role
- Performs stateless admissibility preflight for supplied basis, precedence, and standing.
- Relationship
- optional integration or reference
- Implementation
- standalone Rust admissibility-preflight library and CLI
- Maturity in full
- Public, live with a historical consumer; its relation to AG remains unratified.
- Available now
- Optional public source
- When to use it
- Use for standalone or legacy preflight, not as a replacement for an owning authorization office.
Builds readable indexes of selected sources and compares editions.
- Boundary
- An index does not establish current truth or permission to act.
- Maturity
- Implemented; locally tested
Details
- Precise role
- Builds readable indexes and compares editions of explicitly selected sources without changing their semantic state.
- Relationship
- optional read-plane integration
- Implementation
- Python CLI and library for explicit-source indexes and editions
- Maturity in full
- Implemented and locally tested. Continuity input is an export fixture, not a live store connection; no automatic session orientation.
- Available now
- Public source; CLI build, render, edition create and edition compare. No native MCP server.
- When to use it
- Use to find and compare selected source material. An index does not establish current truth or permission to act.
Checks architecture claim records and their evidence references, and generates documentation.
- Boundary
- Resolving evidence is not judging it adequate; reports grant no authority.
- Maturity
- Implemented
Details
- Precise role
- Checks claim structure, resolves cited evidence, reports freshness and renders documentation.
- Relationship
- optional architectural evidence documentation engine
- Implementation
- Python CLI used by architectural claim specimens
- Maturity in full
- Implemented scoped engine. Evidence resolution and freshness are not judgments that the evidence adequately supports a claim.
- Available now
- Public source; CLI lint, verify-basis, report and render. Global options precede the command; render writes documentation.
- When to use it
- Use to maintain evidence-backed architecture documentation. Human review remains responsible for adequacy; reports grant no authority.
Checks caller-defined facts and rules with the Z3 solver.
- Boundary
- A passing check is not real-system correctness or permission. Solver unsat and unknown are not yet distinguished.
- Maturity
- Implemented
Details
- Precise role
- Checks a caller-encoded proposal, facts and rules. The caller supplies the model, assumptions and input truth.
- Relationship
- optional encoded-claim checking integration
- Implementation
- Python library, CLI and stdio MCP server backed by Z3
- Maturity in full
- Implemented finite checking surface. Solver unsat and unknown currently collapse into failed rules; no distinct solver-timeout or translation-failure verdict.
- Available now
- Public source; install z3-verifier from the repository. CLI verifier-check; stdio server verifier-mcp exposes verify.
- When to use it
- I need to formalize/check a claim: begin with Verifier's supported input model and inspect the JSON verdict. A passing check is not real-system correctness or permission; formalization is optional.
Design only
Named and documented, not implemented.
Axolotl
Explores bounded ambiguity interrogation and intent preparation upstream of authorization.
- Boundary
- Not implemented; not a workflow prerequisite.
- Maturity
- Design only
Details
- Precise role
- Explores bounded ambiguity interrogation and intent preparation upstream of authorization.
- Relationship
- design-stage upstream capability
- Implementation
- design and roadmap only
- Maturity in full
- Pre-alpha design; explicitly not implemented.
- Available now
- No public source or implementation is available.
- When to use it
- Treat as roadmap context, not an installable component or a current workflow prerequisite.
Historical and classic-lineage entries (Governor Atlas) are on the archive page.
Choose a source for the task
Need to formalize or check a supplied claim? Read the Verifier HOWTO. It is an optional bounded check of supplied input, not authority.
Resuming a workflow with explicit retained-memory records? Read the Continuity lifecycle guide and Spine's declared-source guide. Those guides do not select work, infer currentness, or authorize action.