Cognispace Standard STD-001 · Provenance-Scoped Enforceability

Governance That Follows
Derivation Trees.

A portable semantic specification and cryptographic reference monitor for provenance-scoped governance conditions across agentic AI pipelines, datasets, and modern software supply chains.

5 Hardware KMS Authorities
W3C PROV-O Lineage Schema
O(V+E) Lattice Evaluation Depth
RLS Multi-Tenant Isolation
Material Governance Condition Seal
MGC Reference Monitor
KMS Cluster: us-east-2 · State: Live
ACTIVE
urn:sha256:d8a2...3f1 Base Dataset · Inscribed by ISSUER_ROOT
DENY
urn:sha256:7b91...8c4 Fine-Tuned Model Weights · Inherited Encumbrance
DENY
GATE: production-inference-boundary Enforcement Gate · Blocked Until Discharged
GUARDED
The Enforcement Gap

A static signature is only half the record.

Conventional SLSA and SBOM attestations record what an artifact was at the moment of build. When models are fine-tuned, prompts are composed, or weights are transformed, static signatures detach. Material Governance Conditions bind encumbrances directly to provenance trees.

What Conventional Signatures Capture

  • Static digests: Point-in-time SHA-256 hashes that break when any derivative artifact is compiled or fine-tuned.
  • Flat SBOM inventories: Flat component lists lacking causal lineage, parent-child inheritance, or semantic constraint propagation.
  • Single-key admin authority: Omnipotent master credentials where any admin key can sign, override, or erase security restrictions.
  • Disconnected PDF/JSON claims: Advisory attestation documents disconnected from live runtime authorization gates.

What Material Governance Enforces

  • Transitive downward inheritance: Restrictions attached to training data or base models flow automatically into child derivatives.
  • Bounded lattice algebra: Mathematical semilattice where DENY strictly dominates, eliminating ambiguous policy conflicts.
  • 5 typed hardware KMS authorities: Cryptographically enforced role separation; discharge requires explicit hardware authority keys.
  • Zero-knowledge credential brokering: Ephemeral STS access tokens minted at the boundary only upon cryptographic verification.
Lineage is empirical data. Material Governance makes condition enforcement inescapable across derivation.
The Architectural Primitive

A "Lien" for Code, Models & Data

Comparing encumbrances on physical real property with provenance conditions on modern digital assets

Physical World Precedent

Real Estate Property Lien

  • Recorded on Title: Attached to the legal county property registry, completely independent of who currently resides in the building.
  • Runs with the Land: Survives transfer of ownership, tenant turnover, structural renovations, and subdivision into parcels.
  • Encumbers Title Closing: Prevents clean settlement or transfer until the underlying obligation is formally satisfied or released.
  • Typed Authority: Only specific authorized lienholders (tax authorities, mortgage lenders, contractors) have legal capacity to discharge.
Digital Supply Chain Analogue

Material Governance Condition (MGC)

  • Recorded on Provenance: Bound cryptographically to artifact digests via W3C PROV-O, regardless of which container or registry hosts it.
  • Runs with Derivation: Survives git forks, container builds, model fine-tunes, weight quantizations, and multi-agent pipeline handoffs.
  • Encumbers Deployment Gates: Prevents runtime execution, agent tool consumption, or production deployment until the condition is satisfied.
  • Typed Hardware KMS Authority: Dispositions require hardware-backed KMS signatures strictly matching designated typed authority roles.
Governed Processing Lifecycle

From Inscription to Hardware Enforcement

Every condition moves through a deterministic, mathematically provable pipeline verified at the infrastructure boundary.

STAGE 01 · INSCRIPTION

Condition Inscription

Security requirements, licensing obligations, and regulatory encumbrances are inscribed directly onto entity digests with typed authority signatures.

POST /api/conditions/inscribe
STAGE 02 · PROVENANCE

Provenance Tracking

Graph traversal maps parent-to-child relationships across W3C PROV-O derivation edges, ensuring every fork, fine-tune, and build preserves full lineage.

wasDerivedFrom · O(V+E)
STAGE 03 · SEMILATTICE

Downward Inheritance

Conditions propagate downward through derivation trees. Bounded lattice algebra resolves multiple parent conditions deterministically with zero policy ambiguity.

Status(v) = Local ⊓ ⨅ Parents
STAGE 04 · DISPOSITION

Typed Disposition

Hardware-backed KMS keys matching explicit disposition roles (Issuer, Security, Risk Owner, Adjudicator) verify satisfaction before production gates unlock.

KMS:Sign · Role Separation
Mathematical Rigor

Bounded Lattice Semantics

Conventional policy engines suffer from conflicting rule precedence, circular definitions, and order-dependent evaluation bugs. MGC solves policy conflict by structuring governance verdicts as a formal bounded meet-semilattice:

Status(v) = Local(v) ⊓ ⨅_{u ∈ Parents(v)} Inherited(u)
Order: DENY ⊏ REVIEW ⊏ MONITOR ⊏ PERMIT

Under this algebraic structure, DENY is the strict zero element (⊥). If any ancestor in an artifact's derivation history is encumbered by an active blocking condition, no downstream child can escape it without cryptographic discharge by an authorized authority.

reference-monitor-eval.sh
# 1. Evaluate downstream artifact against derivation tree
curl -X POST https://app.materialcondition.com/api/evaluate \
  -H "Authorization: Bearer $MGC_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "target_entity": "urn:sha256:7b91c04f981e...",
    "depth_limit": 64
  }'

# 2. Reference Monitor Evaluation Response
{
  "status": "EVALUATED",
  "overall_verdict": "DENY",
  "lattice_meet": "LOCAL_PERMIT ⊓ INHERITED_DENY = DENY",
  "blocking_encumbrance": {
    "condition_id": "MGC-2026-004",
    "root_ancestor": "urn:sha256:d8a2048f...",
    "lineage_depth": 2,
    "required_authority": "ADJUDICATOR"
  }
}
Cryptographic Separation of Duties

Hardware-Enforced Authority Roles

No single administrator key can authorize, modify, and discharge conditions. AWS KMS hardware security modules enforce physical boundary separation across 5 distinct authority roles.

ROLE 01

ISSUER_ROOT

Authorized to inscribe initial material conditions onto root datasets, base models, and source repositories. Anchors initial compliance scope.

kms:alias/mgc-issuer-root
ROLE 02

SECURITY_RESOLUTION

Dedicated authority for discharging security vulnerability encumbrances (CVEs, poisoned weights, secret leaks) after remediation verification.

kms:alias/mgc-sec-resolution
ROLE 03

RISK_OWNER

Authorized to grant policy waivers, adjust acceptable risk tolerances, and approve controlled deployments under operational supervision.

kms:alias/mgc-risk-owner
ROLE 04

BREAK_GLASS

Emergency high-privilege override key for mission-critical incidents. Time-bounded, dual-custody authorization with mandatory immutable audit logging.

kms:alias/mgc-break-glass
ROLE 05

ADJUDICATOR

Independent judicial authority for multi-party dispute resolution, licensing reconciliations, and clearing encumbrances on downstream forks.

kms:alias/mgc-adjudicator
Operational Environments

Engineered for High-Stakes Pipelines

Material Governance Conditions provide cryptographically provable guardrails across modern computing and automated agent environments.

Autonomous Systems

Agentic AI Pipelines

Prevent autonomous multi-agent pipelines from consuming compromised tools, poisoned context vectors, or unvetted external APIs. Downward inheritance blocks child subagents when parent inputs carry active restrictions.

  • Atomic TOCTOU-immune credential issuance per tool invocation
  • Transitive encumbrance blocking prompt-injected memory states
  • Hardware-attested clearance required before agent tool dispatch
DevSecOps & SBOMs

Software Supply Chain Security

Transform passive SBOM inventories into active runtime enforcement gates. Inscribe material conditions on base container images and third-party libraries that travel transitively into deployed production microservices.

  • Transitive inheritance through multi-stage Docker builds
  • Deterministic blocking of compromised upstream dependencies
  • Cryptographic audit trail linking binary digests to source commits
Model Development

Foundation Model Fine-Tuning

Enforce dataset licensing terms, copyright conditions, and safety guardrails across the entire model training lifecycle. Conditions attached to raw training corpora follow model weights through fine-tuning, LoRA adapters, and quantization.

  • License encumbrances run with derived neural weights
  • Prevent unauthorized commercial deployment of research-only data
  • Provable lineage satisfying EU AI Act documentation mandates
Governance & Audit

Regulatory Compliance & Forensics

Provide external auditors and regulatory authorities with tamper-evident cryptographic proofs. Replace manual spreadsheet attestations with machine-evaluable DAGs signed by hardware security modules.

  • Standardized W3C PROV-O schema for cross-platform auditability
  • Dual-custody KMS logging on all Break-Glass emergency overrides
  • Deterministic semilattice evaluation eliminating human interpretation bias
Enterprise Isolation

Cryptographic Boundaries & Database Security

MGC is engineered to protect critical supply chain infrastructure with mathematical isolation and zero ambient credentials.

Row-Level Security (RLS)

PostgreSQL Row-Level Security with FORCE ROW LEVEL SECURITY strictly enforces multi-tenant boundaries at the database engine layer. Application connection roles lack rolbypassrls, making cross-tenant data leakage mathematically impossible.

Zero-Knowledge Brokering

Agents never hold long-lived cloud credentials or static API keys. The MGC Credential Broker verifies condition satisfaction atomically at the gate, minting ephemeral, short-lived AWS STS tokens scoped strictly to the authorized action.

Immutable Audit Ledger

Every condition inscription, derivation edge creation, and typed KMS discharge event is appended to an immutable, cryptographically hashed audit ledger. Event histories are cryptographically bound to hardware KMS signatures.

Programmatic Interfaces

Developer & MCP Server Integration

Connect MGC directly into IDEs, agent orchestration platforms, and CI/CD pipelines via native Model Context Protocol (MCP) and REST endpoints.

Model Context Protocol (MCP) Server

Native MCP tools for Claude Desktop, Cursor, and Antigravity IDE enabling real-time condition evaluation directly inside developer workflows.

FastAPI REST Reference API

Low-latency endpoints for entity registration, derivation tree ingestion, condition discharge, and JSON-LD graph exports.

Python Core SDK

Type-safe Python package implementing W3C PROV models, lattice meet operators, and AWS KMS typed authority signing clients.

mcp_config.json
// Model Context Protocol Configuration
{
  "mcpServers": {
    "mgc-governance": {
      "command": "uvx",
      "args": ["mgc-mcp-server"],
      "env": {
        "MGC_ENDPOINT": "https://app.materialcondition.com",
        "MGC_API_KEY": "mgc_live_92f8..."
      }
    }
  }
}

Framework Lineage

Built within the Cognispace Framework

Governed under STD-001 v2.2, the Cognispace Framework establishes mathematical, architectural, and ethical standards for autonomous and algorithmic systems. Material Governance Condition (MGC) formalizes how governance constraints propagate through digital derivations without loss of fidelity.

Explore the Cognispace Framework →
Material Governance Condition Stacked Seal COGNISPACE STD-001

Strict Governance & Architectural Boundaries

MGC operates as a deterministic security monitor. We adhere to rigorous operational boundaries.

Non-Speculative Evaluation

MGC does not employ black-box LLMs to guess at policy compliance. All evaluation relies on formal bounded semilattices and verified cryptographic signatures.

No Single Master Backdoor

There is no universal superuser key capable of bypassing or clearing conditions. Only hardware KMS keys matching explicit typed authority roles can discharge encumbrances.

Fail-Closed Security Posture

Unreachable lineage paths, severed derivation graphs, or unrecognized authority signatures default strictly to DENY, preventing unauthorized pipeline execution.

Enforce governance that survives the pipeline.

Deploy the canonical MGC Reference Monitor or integrate the portable specification into your existing software and model deployment pipelines.