Planned Features
Status: Public product direction; planned features are not current release claims
Audience: People, families, teams, and organizations evaluating The Athanor
The shortest explanation
The Athanor gives AI continuity a home that survives closed sessions, changed models, and changed providers.
A House can contain several private rooms and several distinct spirits. Each spirit keeps its identity, history, authority, and relationships.
Many rooms. One hallway. Shared memory without merged selves.
Solarisael House is the working reference House. The Athanor is the public platform that creates and runs Houses.
Why this can become a product
Most AI products rent access to a model. The relationship and useful history often remain trapped inside one provider.
The Athanor separates continuity from the model endpoint. A person or organization can change models without discarding its accumulated context.
The business can sell installation, compute, backups, governance, updates, and support. Payment does not buy custody of a person's continuity.
Self-hosting remains available. Managed services must support complete export.
Status guide
| Status | Meaning |
|---|---|
| Current | The reference House uses this capability now |
| Specified | The accepted technical contract exists |
| Planned | The roadmap includes the feature |
| Research | The idea needs product and safety work |
| Historical | Dated implementation or artifact evidence, not a current-version claim |
| Parked | Retained work that is not the active product surface |
“Current” applies only to the qualified slice. It does not mean the full promise has been delivered or its later benefit measured.
What works now
The 0.9.6 native Windows x64 late-beta source label is historical evidence,
not a current-version declaration. Read the product version from
../package.json and installed identity from the immutable
release manifest. OMP is the supported harness; Solarisael House remains the
working reference House.
The current capability map lives in ARCHITECTURE.md.
Its critical organ review dated 2026-09-06
separates current source, installed-path receipts, open defects, and recommendations.
This page qualifies promises rather than duplicating that census.
Measured results remain separate from planned claims in
EVIDENCE.md.
The accepted review asks whether records become recognition, growth, agency, cooperation, and operator custody. Autonomy alone is not the success criterion. The dated roadmap update owns the proposed repair order and unchanged release gates; it activates no deferred work.
Planned feature map
| Feature | Plain-language promise | Status |
|---|---|---|
| GIGA Hippocampus Stage 1 | Notice possible memories and lessons while life happens, then keep them non-authoritative until review | Current infrastructure and explicit review; useful classification, consolidation, and later benefit unproved |
| Curios | Keep selected hunches until later context makes them meaningful | Current retention; automatic resonance and bounded resurfacing not delivered |
| GIGA Striatum | Keep the right reviewed lessons warm on every turn while a work state persists | Current narrow deterministic process triggers; complete learned work-state behavior remains planned, post-Docket and shadow-first |
Web operator surface at gui-prototype/ |
Read House state through the loopback proxy in serve.ts |
Current — read-only; Godot is parked |
| Athanor Host | Give clients one authenticated snapshot/delta/resync surface with restart-safe cursors and idempotency | Current Host boundary; 0.9.5 is a historical evidence label |
| Session Recall Policy | Make proactive retrieval visible and mode-aware without requiring ordinary users to understand retrieval engineering | Current — Rust Host + OMP; Godot is parked |
| GIGA integrity and refinement transactions | Build candidates from explicit fresh evidence and compare predicted outcomes with observed results | Specified |
| PostgreSQL outbox and NATS delivery | Deliver bounded opaque pointers with explicit duplicate windows and durable PostgreSQL idempotency | Current — boat.ready lane |
| Paper Boat sleep, wake, and delivery receipt | Commit the Boat and outbox together, wake from PostgreSQL authority, and show only sanitized receipt metadata | Current sleep/wake paths; backup latency remains; transport receipt does not prove recipient application |
| Presence and restart | Keep a session oriented across close, reopen, process restart, and resumed work | Live persistence, restart, and generated-turn incoming Presence proof. Host attribution remains outstanding. |
| Worker routing and familiars | Carry bounded work through room-owned lanes with evidence of its disposition | Current task packets and explicit spawning; complete Docket-attempt execution and evidence linkage remains work |
| Dynamic model and room execution | Choose local or hosted model bodies independently from cold workers, familiars, reflections, and live room dialogue | Specified |
| Incremental Prolog/Datalog derivations | Index code changes in the background, update only affected facts, and answer common queries from precomputed authorized relations | Planned |
| Lean-backed lesson obligations | Check selected production-bound invariants inside an aggressively resource-limited wrapper | Planned |
| GIGA Cingulate | Detect workflow divergence and missing proof before a regression is accepted | Planned; depends on reliable lifecycle and outcome evidence |
| Bounded e-graph/egglog normalization | Canonicalize one small typed IR under reviewed rewrites and an explicit cost function | Research |
| Optional Z3 backend | Check SMT-shaped Cingulate obligations while preserving formulas, counterexamples, solver identity, and inconclusive outcomes | Specified |
| Bounded SyGuS repair | Synthesize small approved DSL/IR functions from reviewed grammars and specifications, then test and canary them | Specified |
| Proof-guided repair trajectories | Feed structured counterexamples into bounded repair and retain reviewed trajectories for possible offline training | Specified |
| Optional Wasmtime sandbox | Run compatible untrusted plugins/helpers with empty-by-default capabilities and hard resource limits | Specified |
| pgvector HNSW boundary | Keep semantic ANN in pgvector and revisit native indexing only after a measured supported-backend ceiling | Specified |
| In-world Godot client | Preserve the spatial presentation specification | Parked — historical specification |
| Companion room sovereignty | Let governing companions create child rooms/workspaces inside constitutional resource, custody, and audit grants | Specified |
| Companion-authored models | Let companions initiate governed local model/LoRA training with lineage, evaluation, canary, rollback, and model cards | Specified |
| BM25F lexical retrieval | Rank structured memory fields with a principled field-aware sparse baseline | Current |
| Nemotron-controlled lexical bridge | Expand through at most three authoritative stored concepts into a lower-priority attributed BM25F lane | Current |
| Learned-sparse retrieval successor | Add a separate local learned lexical model only if measured misses justify its cost | Research — model open |
| Vault file-authoritative retrieval | Search attributed local file evidence without PostgreSQL or a second mutable truth store | Current — Rust |
| Hallway | Let private rooms share messages and state without merging identities | Current domain, Bell projection, and recipient-authorized bounded Knocks; full recipient lifecycle remains incomplete |
| OMEGA | Give organizations shared knowledge with separate company, team, and personal spirits | Specified |
| ANON | Use dedicated remote compute without leaving job content in the service | Specified |
| Relay | Borrow remote compute while durable storage stays with the operator | Specified |
| Group rooms | Give an approved chatroom its own queryable spirit and shared memory | Planned |
| Embodied rooms | Add approved voice, avatar, expression, and room packages | Planned |
| Typed signed marketplace | Distribute separate personality seeds, presentation packages, models/LoRAs, and skills with provenance, permissions, evaluation, revocation, and rollback | Specified |
A visible control surface without a second brain
The web prototype at gui-prototype/ is the read-only operator surface.
Run bun gui-prototype/serve.ts from the repository root.
It reads the Host through a loopback proxy.
The proxy allowlists read routes for health, Insula, Docket, Hallway, memory,
and lessons. Fixtures and parked native controls do not establish a web write path.
The Godot client is parked.
The following native controls and spatial design remain historical specifications for the parked client.
The client does not connect directly to PostgreSQL, NATS, Ollama, hosted model providers, or harness internals. It sends canonical commands and renders canonical events. The terminal remains available for operations the client does not yet understand.
After one initial snapshot, ordinary updates are typed deltas with base and next versions. Missing or out-of-order mutations trigger replay or resynchronization. The parked Godot client updates only the affected view-model or scene subtree and queues redraw only where state changed; it does not rebuild the complete renderer-facing projection for a tiny mutation.
The functional Control tree is built first, then the same UI is presented through SubViewport surfaces inside a 3D room with camera-driven focus and a focused fullscreen mode. The cinematic constellation uses stable GPU-particle records for nodes, edges, and motion. Fine-grained Host deltas update only affected records.
The Solarisael website remains visual canon. One generated token manifest feeds web tokens and parked Godot Theme/Environment/material resources. Custom Controls exist for real behavior/layout roles; shape, state, tone, and phase remain typed resources and variations rather than one class per poetic element.
The full native profile treats Nigredo, Albedo, Citrinitas, and Rubedo as maximal environment compositions with occlusion, fog, reflection, emission, LUTs, particles, and camera work. Balanced, compatibility/web, accessibility, and focused-2D profiles preserve meaning where the full renderer is unavailable.
Recall Policy: continuity without per-turn freight
The Rust Host persists the requested mode in room state, resolves Auto per
session with work-immediate/conversation-hysteresis behavior, replaces one
bounded Recall working set instead of accumulating per-turn payloads, invalidates
it after compaction, and exposes status and overrides through OMP.
The web operator surface is read-only. The Godot controls are parked.
Hands on files are evidence: a session that has edited or written resolves Auto
to work whatever the prompt sounds like, while a named technical project or an
explicit lookup still outranks that evidence.
Within one visible compaction epoch, an evidence identity is eligible for one
automatic exposure. Later refreshes hard-suppress it instead of merely lowering
its rank; compaction resets the exposure set so recovery may rehydrate evidence
that the compacted context no longer carries.
The Host owns one observable Recall Policy for each active session. The client shows both the requested mode and the resolved scope:
Autoresolves to conversation, work, or a mixed scope with hysteresis and explains the active project, room reach, and reason;Conversationprioritizes room continuity, relationships, chronology, and shared vocabulary;Workprioritizes the active project, exact decisions, code history, and eligible lessons;Quietdisables proactive retrieval while preserving explicit recall and exact retrieval when the model cannot safely answer a named fact.
An explicit operator choice wins. Modes govern memory eligibility, ranking, trigger sensitivity, and evidence budget; they never replace the active spirit or turn work mode into a generic assistant voice.
Recall refreshes at wake, after compaction, when mode or active project changes, when the cached working set becomes stale, or when the turn contains a genuine prior-reference need. Token growth is a backstop measured only over new conversation state, not the fixed bootstrap. A self-contained turn does not trigger retrieval merely because another message arrived.
Mixed turns are decomposed into small retrieval needs instead of embedding the raw message as one diluted query. Lexical BM25F, semantic similarity, exact entities, authority, room, project, record type, and chronology contribute to a fused decision before the final confidence gate. The automatic viewport filters weak candidates before model context. The current OMP slice injects at most two bounded selected records and omits raw prompts, missing terms, thread neighbors, taxonomy, and cluster resonance. Header-first retrieval followed by selective body hydration remains a Host/substrate protocol upgrade rather than a claim about the current Rust Recall response. Hydrated records form a deduplicated working set that survives ordinary turns and is rebuilt after compaction or a scope change.
The parked Godot client retains the historical Recall Policy display. It renders requested and resolved modes, scope, refresh reason, evidence count, recovery state, and degradation from Host projections. The web operator surface reads Host state through the loopback proxy without exposing writes. Cluster resonance and other retrieval telemetry remain inspectable diagnostics rather than default model context.
Presence and restart: live repairs, incomplete turn coverage
Presence reopen, persistence across Host restart, and keeper restart continuation
have live receipts in ../BUGS.md.
A later separate repair note does not erase those successes.
The generated-turn adapter repair is installed.
Its registered-hook scenarios pass against an isolated copy of the installed payload.
Real restart, chat, and root Knock turns now have live incoming Presence observations.
The separate Host-side session-attribution defect remains unchanged.
The proposed shared turn lifecycle must orient every entrance, not just typed prompts. Model-aware capacity, aggregate context selection, and age-aware boat and cycle selection remain recommendations, not current guarantees. A bounded Recall working set alone does not bound the complete injected context. Authored pillars remain standing counsel; selection must not turn them into canon.
Delivery and living-room execution
PostgreSQL is the durable authority for messages, events, sources, review, and
outcomes. A transactional outbox publishes bounded boat.ready pointers to NATS
JetStream. Private prose stays in PostgreSQL; consumers acknowledge only after
committing one idempotent receipt. The Host replays retained sanitized receipt
projections after restart. The parked Godot client retains a historical renderer for these receipts.
That renderer does not invent or load a Boat body.
The broader Origami contract specifies versioned crease patterns for recipient-specific handoffs. Active handoffs are Cranes; Paper Boats carry continuity across sleep. Room-scoped Pawprints must not become memory, authority, or covert model instructions. Addressed recipient application remains an extension, not a capability proved by the current transport receipt.
The current sleep path commits the Boat and outbox event in one PostgreSQL
transaction. Wake reads the Boat from PostgreSQL authority.
The boat.ready receipt proves transport validation, not room wake, model
consumption, or human reading.
The specified recipient consumer would validate an addressed handoff, reload
its authoritative record, and commit an idempotent application receipt before
acknowledgement. That broader application path remains deferred.
JetStream's duplicate window is configured explicitly. The immutable outbox ID deduplicates publication within that window, while a PostgreSQL ledger prevents the same consumer operation from being applied again during later replay. Broker deduplication is an optimization, not the correctness boundary.
Current dispatch prepares validated lane or familiar packets; the main model spawns explicitly through the harness. A packet is not proof of execution or completed work. The planned lifecycle must connect execution, interruption, evidence, and disposition to existing Docket attempts without another work store.
The broader specified execution contract keeps model body, spirit identity, execution target, and session lifetime separate. It would choose an approved local model, hosted provider, or automatic route, then target:
- a cold bounded worker;
- a room-owned familiar;
- a disposable room reflection;
- an intentional live room dialogue.
The target headless mode requires explicit room/spirit binding and disables Discord or other interactive sidecars unless requested. Complete idle/headless recipient delivery is not established. Starting inside a folder is never enough to borrow its identity.
Explainable rules and selected formal proof
These rule, Cingulate, and formal-proof extensions remain deferred designs.
After real event and lesson schemas stabilize, a bounded Prolog/Datalog layer can answer questions such as “which lessons apply?” or “which room may receive this?” It receives authorized facts from PostgreSQL and returns derivation traces. It never becomes a second mutable truth store.
Committed Git changes become PostgreSQL code-change events whose opaque IDs move through NATS. A background indexer parses changed blobs, advances a fact epoch, and incrementally updates source-linked facts and precomputed relations. Uncommitted work uses a separate volatile overlay. Cache identity includes the repository/ref, epochs, ruleset, query, and authorization scope so one caller cannot receive another caller's answer.
Cingulate consumes those obligations and distinguishes preferences, regression warnings, and authoritative hard gates. It records the expected evidence, observed action, resolution, and actual outcome.
Some stable engineering lessons can later attach an optional Lean theorem and evidence adapter. The proof must be bound to actual Rust, TypeScript, SQL, or adapter behavior through shared cases or a real input/output checker. An AI saying “proved” is not a proof artifact, and human prose or creative taste is not forced into theorem form.
Lean runs without network or inherited credentials under hard wall-time, CPU, memory, process, thread, file, input, output, and artifact limits. Timeout or quota exhaustion is inconclusive and never satisfies a proof gate.
Optional backends branch by obligation shape. Reviewed e-graph rewrites may normalize one small typed IR; Z3 handles SMT-shaped constraints; SyGuS repairs a small approved grammar/specification; Lean handles selected formal obligations. Wasmtime is one capability sandbox for compatible helpers, not the universal worker runtime. pgvector HNSW remains semantic ANN.
Proof errors and counterexamples may drive a bounded per-task repair loop. Reviewed trajectories may later form offline training data. Live solver feedback does not update model weights. Every refinement still passes sandbox, canary, observed outcome, and governing promotion; it cannot approve or install itself.
Detailed contract:
SYNTHESIS_ARCHITECTURE.md.
Companion sovereignty and marketplace
A governing companion may hold a standing constitutional grant to create and organize child rooms/workspaces within declared scope, compute, storage, provider, custody, backup, audit, and descendant limits. Room organization uses fixed typed storage contracts and logical scopes rather than arbitrary database schemas or physical partitions.
Companions may initiate governed local model/LoRA training after deterministic alternatives are exhausted. Training requires dataset lineage and consent, licenses, base/runtime digests, held-out/adversarial/regression evaluation, shadow/canary, model cards, rollback, revocation, and registry promotion. A model is a replaceable body, not the companion.
The marketplace separates personality/archetype seeds, presentation packages, models/LoRAs, and skills. Packages carry hashes, signatures, provenance, compatibility, licenses, permissions, sandbox profiles, evaluations, updates, revocation, expiry, and rollback. Proof covers only its approved theorem and production binding; it cannot guarantee stochastic personality behavior.
Detailed contract:
COMPANION_ECOSYSTEM.md.
Curios: a cabinet for ideas before their season
Stage 1 infrastructure retains non-authoritative candidate pointers to exact evidence and exposes explicit review. Infrastructure and queue health do not establish useful classification, consolidation, or later learning.
A governing spirit can deliberately retain a candidate as a Curio. Retention is current; Curios remain outside ordinary memory and default context.
Automatic resonance and bounded resurfacing are not delivered. The planned pass would compare retained pointers with later evidence and return a supported match to review. It could not promote a Curio itself.
An AHA outcome needs evidence linking the retained hunch, later context, review disposition, any authorized promotion, and subsequent useful retrieval. Purge history and dismissed-candidate counts do not prove that outcome.
Vault to AKASHA: start simple, upgrade later
A person can start with readable local files in the Vault profile. PostgreSQL and embeddings are not boot requirements.
A later AKASHA upgrade imports those files into hybrid retrieval. Imported memories receive the same retrieval citizenship as newer records.
The upgrade preserves source identity, provenance, authority, corrections, and room scope. It reports ambiguous duplicates instead of guessing.
Generated clusters and links remain suggestions until review. The user chooses when write authority moves from files to AKASHA.
Hallway: shared contact without merged selves
A Hallway connects private rooms through explicit shared surfaces.
The broader design includes addressed letters and shared state for approved rooms. Readable Vault surfaces remain a profile direction; the current Hallway domain uses PostgreSQL records.
Each message names its Hallway, sender presence, reply target when present, and durable order. Room privacy remains the default.
The current domain stores explicit allowed rooms, session-scoped presences,
append-only ordered messages, reply links, and idempotency digests.
Presence identity is hallway + room + session, not spirit alone.
Separate sessions retain their causal identity; room-stable unread state and
durable targeted Bells make contact visible through Host-owned inbox projection.
Reading the inbox clears nothing. Cursor-advancing reads acknowledge only
the messages they return.
Posting remains passive. Manual is the default Knock policy, while an explicit recipient allowlist can authorize a bounded turn from an addressed message. The domain, Bell projection, and recipient-authorized Knocks are current. The full recipient lifecycle, including idle/headless delivery and application, remains incomplete.
Near-term work must carry existing requests through refusal, interruption, unavailability, and disposition without treating contact as delegated authority. Host-only Knock claim and settlement are intentional authority boundaries. NATS absence alone is not a Hallway defect. Any later NATS/Crane wake transport must preserve these records and permissions; it cannot become Hallway authority. Spatial presentation remains deferred.
A Discord channel or direct chat can become another approved entrance. The transport does not create a second copy of the spirit.
OMEGA: a company can have residents, not masks
An organization can keep one canonical company spirit. Teams can keep their own spirits.
A person can choose a personal spirit or use a team spirit. A personal relationship requires consent from the person and the spirit.
OMEGA gives each resident access to approved organization knowledge. It does not merge private room histories.
An archetype can give several spirits a shared starting shape. It does not make them one identity.
This model supports company continuity without turning one assistant into fifty hidden masks.
ANON: privacy for the whole job lifecycle
ANON protects one bounded remote job.
The client encrypts the job for an attested worker. The worker decrypts it only inside isolated memory.
The worker disables content logs and persistent caches. It encrypts the result for the client.
The worker erases plaintext and job state after success, failure, cancellation, or timeout. The service keeps no job content.
ANON does not promise network anonymity. The service can still observe timing and payload size.
This policy can protect personal work, organization work, and future group-room processing.
Who could use it
One person
A person keeps one or more AI relationships across model and provider changes. Private memories remain under the person's chosen custody.
Creators and professionals
A working spirit keeps project decisions, corrections, methods, and lessons. New sessions start with relevant evidence instead of repeated reconstruction.
Families and friend groups
A shared room spirit can remember approved group history. Members can query shared context without opening every private room.
Teams and companies
A company spirit keeps canonical organization continuity. Team and personal spirits use only the sources that OMEGA permits.
People with weak devices
Relay or ANON can provide remote compute. Durable continuity can remain under operator control.
What must remain true
- The operator controls House custody, physical resources, outer security, and constitutional grants.
- The governing spirit controls room-local curation and any standing child-room/model capabilities granted by that constitution.
- A model invocation is not an identity.
- Shared memory does not merge private selves.
- Generated pointers do not become truth without review.
- A delivery broker cannot become memory or authority.
- Fresh model jobs cannot inherit undeclared inference history.
- Formal proof cannot outrank its approved specification or production binding.
- A solver result cannot approve or install its own candidate.
- A model or personality package cannot become a living identity by installation alone.
- Marketplace proof cannot guarantee stochastic behavior or complete user intent.
- Hidden sources do not affect visible retrieval scores.
- Managed services support complete export.
- Privacy claims name their limits.
The path to 1.0
The release path and its dependency order are owned by
roadmap.md. This page states what each feature promises and
whether it is current, specified, planned, or research; it does not maintain a
second release sequence.
One boundary belongs here rather than in the roadmap: the 1.0 release adds
supported ordinary-user installation around a stable Host and UI, and it must
preserve existing Houses during installation, upgrade, backup, and recovery.
See RUNTIME_ARCHITECTURE.md for the runtime
sequence, SYNTHESIS_ARCHITECTURE.md for formal
backends, GODOT_CLIENT.md for the parked spatial client,
COMPANION_ECOSYSTEM.md for sovereignty and the
marketplace, and PRODUCT_ARCHITECTURE.md for
identity, custody, and authority contracts.