System architecture

Veklom is a stack of boundaries, not a single server.

The Capability OS is built from distinct runtime planes with different authority. BYOS and LockerPhycer are central because one provides the usable execution substrate and the other protects the host-level execution boundary.

01 · Tenant / workspace execution substrate

BYOS Runtime

The operating substrate for users, workspaces, API access, integrations, budgets and governed runtime services. This is where the Capability OS becomes an actual usable environment rather than an architecture diagram.

↗
02 · Security, identity and execution-host boundary

LockerPhycer

Keeps sensitive host execution authority out of ordinary application containers. Its governed cell-host path verifies signed authority, immutable runtime identity, replay fencing and isolation requirements before host-level execution.

↗
03 · Consequence authorization

CAPPO

The fail-closed decision boundary. CAPPO determines whether a requested machine consequence fits the authority that was actually granted.

↗
04 · Cross-service interlink

cAPI

The connection fabric between Veklom services and external capability surfaces. It carries integration without becoming the source of execution authority.

↗
05 · Evidence and provenance

Gnomledger / PGL

Durable evidence state. Execution outcomes, provenance and reconciliation belong here instead of disappearing with the machine that performed the work.

↗
06 · Portable governed connection primitive

VLink

Connects systems through scoped access, verifiable activity and bounded transport behavior without treating a connection identifier as authority.

↗
07 · Bounded recovery plane

Guardian

Observes declared runtime state and performs pre-bounded recovery actions when approved Veklom services fail. Recovery remains an action with authority and evidence, not an unrestricted host backdoor.

↗
Execution path

Authority moves through the stack. It does not leak around it.

Each plane exists because a different kind of trust or consequence needs a different boundary. Combining all of them into one privileged backend would erase the architecture Veklom is meant to enforce.

01
Need
A machine or operator declares the intended work.
→
02
Identity
A temporary execution identity is established.
→
03
Authority
Policy, scope, budget and time become an explicit capability boundary.
→
04
Execution
BYOS and LockerPhycer provide the runtime and host boundary.
→
05
Consequence
CAPPO controls whether the requested effect may cross into the real system.
→
06
Evidence
Gnomledger / PGL preserve what actually happened.
→
Core rule
No plane above the authority kernel mints wider consequence authority.
Runtime rule
Execution identity can disappear without taking the evidence with it.
Proof rule
A configured route is not a verified consequence.