Corvair CorvairKnowledge Substrate
Governance, roles & how it works

The roles that make an answer trustworthy.

The everyday user reads and asks. Behind them, a set of roles makes those answers trustworthy and the base maintainable: a steward shapes what the base knows, an administrator runs the platform without seeing its content, an auditor verifies after the fact, and a domain partner packages expertise others subscribe to. Access is relationship-based and scoped per base, and each role sees only the surface built for how it works.

Separation of duties

No one role can do everything. That is the point.

The same governance that makes an answer provable also splits the work, so authority is bounded, every action is recorded, and the people who run the platform are not the people who can read what it knows.

person

Application user

Searches, asks, and runs deep research, browses the knowledge bases they are allowed to see, and uploads their own private material to a personal vault. Cannot change the shared base.

account_tree

Knowledge steward

Directs the scanning of internal and external sites, manages the organisation's content, approves recommendations, and directs the agents and reviews their output.

dns

Administrator

Runs the platform and its agents, sets budgets and access, and promotes recipes across environments. Never reads the knowledge content.

policy

Auditor

Verifies decisions after the fact and surfaces disclosure gaps. Reads warrants and coverage, exports for a regulator, and curates nothing.

handshake

Domain partner

Authors and packages licensed domain expertise, trust-scores and versions it, and ships updates that recombine into every subscribing base.

smart_toy

Autonomous agent

Acts through the API within the authority its role is granted, escalating consequential actions, with every action recorded like a person's.

account_tree
Owns what the base knows

Knowledge Steward

The owner-operator of a base. The steward directs the scanning of internal and external sites, manages the organisation's content, approves the recommendations the agents bring, and directs those agents and reviews their output. They own the base's sources, trust tiers, declared scope (what the base is meant to cover, against which gaps are measured), beliefs (its settled positions on contested points), and the recipe. The role is judgement, not labour: the agents stage the work and the steward decides.

radar

Coverage radar

Declared, observed, and available coverage on each dimension, so thin spots are visible before anyone hits them.

hub

Causal claim graph

Claims sized by epistemic gravity (how much rests on a claim, so being wrong about it would cascade through the answers built on it) and coloured by trust, so the load-bearing sources stand out.

inbox

Curation queue

Approve, hold, or re-source what is waiting. Gaps and conflicts arrive with candidate sources already pre-staged.

monitor_heart

Source health & alerts

Which sources have moved, gone dark, or degraded, flagged by validity alerts before coverage rots unnoticed.

rule

Scope & beliefs

Set the declared scope and manage beliefs. Untrust a premise or revise a belief and see the cascade before it commits.

data_object

Recipe inspector

The recipe as code on one side and as a navigable object on the other, the single declaration of what the base is.

preview
Manipulation is direct and preview-first. Drag a dimension, remove a source, untrust a premise, or revise a belief, see the full cascade, then commit or discard as a batch. A topographic view reads the same base as terrain, and changes stream in live.
checkDirect agents, shape sources, tiers, scope, and the recipe checkApprove staged recommendations blockNo change without preview and a warranted entry
In the prototypeSwitch persona to Knowledge steward, open the curation queue, and inspect the recipe.
dns
Runs the platform, never the content

Administrator

The platform owner. The administrator runs the machinery, workers, jobs, agents, budgets, and access, and promotes recipes across environments, but has no path to the knowledge content itself. The console shows what is running and what it costs, with the controls to keep the agents in bounds, never what any base actually knows.

memory

Workers & jobs

The running machinery at a glance. Heavy stages such as discovery and ingestion can run as multiple instances, scaled to load.

toll

Agent limits

Per-agent controls, autonomy levels, and circuit breakers (automatic cut-outs that cap activity the moment it runs hot).

payments

Budgets & cost

Resource consumption and spend, with budgets set per base and per agent so cost stays predictable.

schedule

Schedules & retention

When jobs run, how often, and how long data and logs are kept.

admin_panel_settings

Access & personas

Who can reach which base and in what role. Access is relationship-based and scoped per base.

deployed_code

Environments & promotion

Move a recipe along governed promotion paths, from sandbox to UAT to production, with the right approvals.

visibility_off
The console shows the machinery, never the content. An administrator runs the platform and the agents that work on a base, but cannot read what that base knows. Running the system and reading the knowledge are deliberately different jobs.
checkRun workers, agents, budgets, and access checkPromote recipes across environments blockNo access to knowledge content
In the prototypeSwitch persona to Administrator to see workers, agent circuit breakers, and the environments and promotion paths.
policy
Verifies after the fact

Auditor

Second and third line. The auditor verifies decisions after the fact and surfaces disclosure gaps, and does not curate. The work is to read, verify, and export: confirm coverage against a framework, inspect the signed trail behind any answer, and hand a regulator a warrant they can check independently.

fact_check

Framework crosswalks

Coverage against a reporting framework, requirement by requirement, surfacing the disclosure gaps that need attention.

verified_user

Validity Warrant trail

Every answer's signed, timestamped warrant as an inspectable, exportable record, ready to hand to a regulator.

alt_route

Conflict map

Where admitted sources disagree, mapped so a reviewer can see and reconcile the tension.

landscape

Validity landscape

How validity holds across the base and over time, replayable as of any date.

download

Export

Export a warrant or a coverage report for inspection outside the system.

lock

Read-only by design

Verify, do not curate. The auditor has no write actions on the base, so the line stays clean.

gavel
The work is to read, verify, and export. Compliance can verify but cannot curate, so the second and third line stay independent of the people who shape the base.
checkRead warrants and framework coverage checkExport for a regulator blockNo curation controls
In the prototypeSwitch persona to Auditor to read a Validity Warrant trail and a framework crosswalk.
handshake
Packages expertise to sell

Domain Partner

The partner-side author who builds, packages, and maintains a licensed domain pack, the authoritative foundation a base can be built on. They produce the pack's named capabilities, reference databases, and how-to guides, trust-score and version it, and ship the periodic updates that keep it current. They work on the pack itself, never on any one institution's live base, and their releases recombine automatically into each subscribing base without disturbing local content.

edit_note

Author the pack

Shape the pack's sources, structure, and trust in a steward-style control room scoped to the pack, not to any subscriber.

widgets

Named capabilities

Ship a prebuilt virtual expert with eight or more named capabilities a subscriber can call from day one.

menu_book

Reference databases & guides

Bundle the licensed reference data and how-to guides that make the expert authoritative in its domain.

new_releases

Trust-score & version

Tier the content and cut a dated release, so every subscriber knows exactly which version they are on.

published_with_changes

Ship updates

Push periodic updates that recombine automatically into each subscribing base, without a redeployment.

shield

Stays off the live base

The partner works on the pack, never on a subscriber's content, so the institution's data and audit trail stay theirs.

paid
Each pack is co-branded and royalty-bearing. For the institution, adding a domain is a licensing decision, not a new deployment; for the partner, every subscriber is a recurring, compounding revenue line. The packaging and subscription model is on the overview's For partners section.
NoteThe partner authoring surface is a separate product. The prototype focuses on the institution side, where packs arrive as ready-to-use virtual experts.
Knowledge as code

Why a base is defined by a recipe.

A base is not configured by hand and left to drift. It is declared by a recipe: a versioned file stating its intent, scope, sources, trust, freshness, access, and curation policy. That one decision is what makes knowledge portable, packageable, and auditable like software.

swap_horiz

Move knowledge between environments

Promote the same recipe from sandbox to UAT to production. Because each environment hydrates from one declaration, what you tested is what you ship, and the promotion is governed and recorded rather than a manual rebuild.

inventory_2

Package expertise from experts

A partner authors a recipe and ships it as a domain pack. Many institutions hydrate the same pack against their own entitlements, so one body of expertise reaches all of them without anyone hand-rebuilding it.

water_drop

Hydration: rebuild from what is reachable

Hydrating a recipe (building the live base by collecting and admitting what the recipe points to) produces a running, governed base and records a manifest of every source collected, every item admitted, and every exclusion with its reason. Hydrate the same recipe in a different environment and you get a compatible base, current as of what that environment can reach.

cached

Reverse-engineering an existing base

A recipe can be derived from a base that already exists, reading its scope, sources, and structure back into a declaration that would reproduce it. This brings an ungoverned base under governance, or forks one whose recipe was never written down.

bolt
Because the recipe is portable, a domain pack can be forked and lifted to a new institution in days rather than quarters, hydrated against the sources available there and current as of that moment.

The separation is the assurance.

A user asks within bounds, a steward shapes under preview-then-commit, an auditor verifies but never curates, an administrator runs the platform but cannot read it, a partner packages expertise without touching a live base, and an agent acts only within the authority it is granted. Every action, by a person or an agent, is recorded.