Event Spine
Immutable, tenant-scoped record of every state-changing fact.
- ·Per-aggregate hash chain + global sequence
- ·Merkle batches sealed by service role
- ·Idempotency, concurrency, replay-tested
DECENTRALISED COMMUNITY OS
A community intelligence and governance system for
communities, organisations, ventures, research groups
and digital nations. 10 bounded layers for capability-
based access, member-controlled identity and trust.
The Event Spine is the source of operational truth; every
claim above it can be replayed, verified and challenged.
Each layer has one job, one set of guarantees and a clean seam to the layers above and below. No layer alters another's invariants; no layer bypasses consent / capability checks.
Immutable, tenant-scoped record of every state-changing fact.
Axioms, constitutional versions, amendments, activations.
Members, private profiles, capability grants and revocations.
Purpose-bound grants, receipts, revocations, SAR / export / deletion.
Proposal lifecycle FSM, secret-ballot voting, eligibility, ratification.
Provider-agnostic AI router — suggestion + knowledge, never execution.
Bottom-up pattern & persona shaping across five intelligence pathways: Health & Wellbeing, Psychometrics & Values, Shopping & Retail (+2 reserved). Consented aggregate insights across ventures, wallets, identities.
Approved historical context: claims, evidence, decisions, lessons.
Ingestion gateway, iD Plugin, Wallet Plugin — member-controlled surface.
Measurement specs, meta-cognitive monitoring, drafts (never self-execute).
Every external system is reached through a bounded adapter with an explicit purpose and a hard privacy/capability boundary.
Purpose
Event Spine, projections, RLS policies, security-definer helpers, migrations.
Boundary
Source of truth for operational state. Secrets held server-side; publishable key never touches wallet or admin surfaces.
Purpose
On-chain anchoring of identity registrations, venture deployments and Merkle batch roots.
Boundary
Only hashes and Merkle roots cross the boundary. PII, UIDs and wallet data never leave the off-chain database. Each venture runs its own address space on shared L2.
Purpose
Deliberative reasoning and knowledge retrieval: proposal drafting, ensemble review, meta-review, summarisation and embedding.
Boundary
Reached only through the Cognitive Router. Input scanned for secrets / PII / financial identifiers before dispatch. Outputs are immutable and challengeable. Cannot alter financial permissions or execute transactions. Provider disagreement tracked as a meta-cognitive metric.
Purpose
SSR, server functions and public API routes for webhooks and cron.
Boundary
Server-only environment reads secrets from the platform vault. Node-only APIs avoided; Web-standard fetch, crypto and streams.
Purpose
Provider-agnostic data ingestion for balances, transactions, rewards, assets.
Boundary
No raw card, CVV, password, seed phrase or private key stored. Only hashes + ciphertext. Every action requires explicit member authorisation.
Purpose
Ventures embed the iD Plugin so members carry identity + consent across surfaces.
Boundary
Signed plugin versions with CSP baseline. Configuration cannot alter consent meaning. Trust metrics are read-only for the venture.