The Athanor Roadmap
Last updated: 2026-09-06
This page is the current release path. It does not duplicate completed history or turn accepted architecture documents into one giant checklist.
- Current product truth:
../README.md - Current contracts and ownership:
ARCHITECTURE.md - Long-range runtime contracts:
RUNTIME_ARCHITECTURE.md - Complete feature/status map:
PLANNED_FEATURES.md - Dated implementation history:
history/
The previous long-form roadmap is preserved as
history/2026-08-06-roadmap-snapshot.md.
Recorded late-beta baseline
The 0.9.6 native Windows x64 late-beta source label is historical evidence.
Read the current product version from ../package.json
and installed artifact identity from its immutable release manifest.
OMP is the supported harness. One Rust workspace owns the behavioral core,
Vault, AKASHA, Host, delivery, native lifecycle, and parked Godot client. Read
the canonical component table.
The historical candidate included:
- file-authoritative Rust Vault and PostgreSQL-authoritative Rust AKASHA;
- typed canon, memory, lessons, GIGA, Recall Policy, and Paper Boat sleep/wake;
- PostgreSQL-authoritative Hallway membership, daily threads, recipient-sensitive posts, room-stable unread state, durable Bell rows, exact-thread reads, Host-owned automatic inbox projection, and explicit recipient-authorized bounded Knocks; ordinary Hallway contact remains manual;
- authenticated Host snapshots, typed deltas, resync, persistence, and restart recovery;
- transaction-coupled
boat.readyoutbox delivery through NATS JetStream; - retained sanitized receipt replay after Host restart;
- a compiled addressed Crane subject/envelope and generic transport-receipt path, with no production addressed producer or recipient application handler yet;
- historical Godot Recall Policy and Paper Boat receipt screens;
- native Windows service lifecycle, immutable versions, backup, rollback, doctor, uninstall, and explicit purge;
- one checksum-pinned payload carrying parked Godot 4.7.1, PostgreSQL 18.4-2, pgvector 0.8.6, and NATS 2.14.4.
The RC3 record reports ordinary suites, isolated PostgreSQL/NATS integrations, historical Godot rendering, 20,659-artifact manifest verification, packaged-client smoke, Inno Setup compilation, and an elevated external-authority installation. That Solarisael workstation installation ran NATS, delivery, and separate Kintsu/Kodo Hosts while reusing the existing PostgreSQL authority. This is dated installation evidence, not a census of the current topology.
Current NATS traffic is narrower than the surrounding House surfaces. It does not carry Hallway posts, GIGA jobs, kitten lifecycle, project records, or live conversation. The current Paper Boat receipt proves transport validation; it does not prove room wake, model consumption, or human reading.
That installation record identifies the artifact as 1.0.0-rc.3.
Keep the immutable label as historical evidence, not today's installed version or product maturity.
Final 1.0.0 still requires a complete operator GUI and healthy continuity organs.
It also requires a clean managed installation, real legacy upgrade and rollback, signing, and the public evaluations in EVIDENCE.md.
The release path below retains the implementation sequence and final release
gates. The dated planning update orders the remaining repairs by dependency
and outcome. Where the phase table in RUNTIME_ARCHITECTURE.md differs, this
roadmap is authoritative.
Planning update: 2026-09-06
Sol accepted the critical review as a records and planning update, not runtime implementation or activation of deferred work. The House preserves records and governs changes more reliably than it turns those records into useful continuity, judgment, and completed work. Success means recognition, growth, agency, cooperation, and operator custody; autonomy is one contributing property.
The dated critical organ review owns the evidence census and its uncertainties. The order proposed here is coherent orientation → trustworthy visible outcomes → cooperative completion → useful learning. Repair existing paths first; do not make GIGA the prerequisite for every other improvement.
1. Coherent orientation at every turn entrance
Base context-pressure policy on the active model's capacity, not room-name assumptions. Coordinate an aggregate context budget and select applicable identity, evidence, lessons, and counsel within it. Carry that context through typed prompts, restart continuation, and other synthetic or requested turns.
Presence reopen, persistence, and restart continuation have live repair evidence. The generated-turn adapter repair is installed with isolated component proof. See the dated evidence. Real restart, chat, and root Knock turns now have live incoming Presence observations. The separate Host-side attribution repair remains outstanding. Treat boat age, newer memories, and cycle recency explicitly. Preserve authored pillars and counsel authority. The outcome is an oriented turn with attributable, timely context, not merely a larger injection.
2. Trustworthy outcomes, visible through Pulse
Preserve content and provenance from the authoritative record through adapters, retrieval, and presentation. Design catalogue supersession has live proof; adapter field preservation and the affected historical rows are separate work. Keep database commit, backup result, transport receipt, recipient application, and human reading distinct.
Review the blocking post-write backup policy without treating a slow backup as a failed commit. Sleep and backup have installed-path receipts; those receipts do not prove every continuation relationship or a fresh restore. Make Pulse expose each repaired path's attribution, result, degradation, and next required decision alongside the work, not as a final cosmetic phase. The current web surface is read-only; authenticated writes remain gated work.
3. Carry work from request to disposition
Use coherent turn entry and visible receipts to connect Hallway, Docket, dispatch, and execution. Hallway's domain, Bell projection, and bounded recipient-authorized Knocks are current. Repair request-to-disposition gaps on existing Host/harness paths, including refusal, interruption, application, and an honest unavailable state for idle or headless recipients. New idle/headless delivery remains deferred. Posting alone must not wake a model. NATS absence alone does not make Hallway defective.
Dispatch prepares packets and the main model spawns explicitly. Connect those executions and their evidence to existing Docket attempts, not a parallel work store. Preserve room-owned familiars and recipient consent. Ground reviewer identity in supported capabilities, with an explicit independent reviewer or operator arrangement for a single-room House. Host-only Hallway Knock claim and settlement remain intentional authority boundaries.
4. Useful learning from reliable evidence
First make existing lessons applicable to the work and its observed outcomes. The current deterministic Striatum triggers are not complete learned behavior. Establish fresh GIGA classifier liveness and useful classification before claiming commanded consolidation or later benefit. Stage 1 infrastructure and explicit review remain current; queue health and purged dismissals are not reviewed learning outcomes.
Curios retention is current; bounded automatic resurfacing still needs delivery. Connect source evidence, review disposition, any authorized promotion, and later useful retrieval before claiming improvement. Cingulate remains planned and depends on reliable evidence; it must not judge work from incomplete lifecycle records. Broader refinement and additional cognitive workers remain deferred.
Existing work and unchanged gates
The review input already covers much of this work through existing Docket entries:
| Outcome | Existing coverage to reconcile, not newly assign |
|---|---|
| Orientation | “Recall authority vertical”; “Investigate intermittent auto-Recall misses — trace the Tyler case”; the restart-intent, keeper, and adapter-exit quests |
| Visible outcomes | “Pulse panel — the GUI becomes the House's main usage surface”; “Pulse rung 2 — read everything”; “Insula watches every organ — failures ride Origami to a durable ledger”; “Release proof — source ancestry, immutable attestation, and exercised gates” |
| Cooperative completion | “M1 — Docket v1 completion”; “Census and strengthen every Athanor tool contract”; the draft “Pulse rung 3 — the talking door (operator write path)” |
| Useful learning | “GIGA health must prove liveness”; “Commanded GIGA consolidation door”; “Gardener proof harness — revive evidence, replay regressions, and roll back”; “Project lessons become a project map” |
These references supplement planning; they do not replace frozen acceptance, change deadlines, claim work, settle attempts, or activate drafts. The offered “Write two chapters before more House quests” remains a blocker. The accepted workspace-search adapter remains separate from AKASHA; its older Whiskers draft is not a new replacement obligation.
Recorded Docket supplements
House memory #4509 holds the accepted analysis in PostgreSQL.
Draft goal 69d2e256-30c8-499f-b1db-061ab8aca84e groups these planning supplements:
| Supplement | Draft quest ID | Planning predecessor |
|---|---|---|
| Coherent orientation | bc479caf-3850-40f0-87c7-99e659d36703 |
Existing identity, Recall, and handoff work |
| Attributable outcomes and custody | b69dc109-17a8-4ee6-8224-8c1ebad4f6fb |
Orientation where attribution is required |
| Cooperative completion | ea2a050e-7e99-484b-be54-a9727099410a |
Orientation and attributable outcomes |
| Useful learning | 656e526e-09af-472d-8e5a-8a6cfbae9b1b |
Reliable orientation and evidence; cooperation when review uses another participant |
Each draft cites the existing quests that retain their implementation scope. The posting contract has no existing-quest edit action. These additive drafts preserve earlier records instead of rewriting them through SQL. Their acceptance candidates remain prose until an explicit activation freezes them. Their dependency references do not create scheduler-enforced gates. This pass activates no goal or quest and claims no work.
This order does not expand the 1.0.0 boundary. Keep the complete operator GUI,
continuity health, installation, migration, rollback, signing, and evidence gates
below explicit. Complete export, restore, and migration need their own evidence,
with operator-controlled retention and deletion choices; no fresh restore is
claimed here. Prolog/Datalog, Cingulate, broader NATS delivery, spatial
work, marketplace, OMEGA, Relay, and ANON remain deferred.
1.0 dependency path
1. Freeze the accepted boundary
The 1.0.0 program includes Rust convergence, the narrow NATS lane, existing
fixes, hardening, the usable GUI, installation, migration, and release evidence.
Do not add Prolog/Datalog, Lean, Z3, SyGuS, marketplace behavior, new cognitive organs, distributed-worker expansion beyond the proved NATS lane, companion bodies, the GPU-particle constellation, or broader in-world surfaces.
Before implementation, keep ../LESSON_MAP.md, this
roadmap, ARCHITECTURE.md,
RUNTIME_ARCHITECTURE.md,
GODOT_CLIENT.md (parked historical specification), and
EVIDENCE.md aligned with the same owners and gates.
2. Retain the historical 0.11 parity baseline and close known fixes
The historical 0.11.0 runtime is a recorded parity reference, not the current
version or target topology. Inventory each TypeScript, Python, and Rust
capability with its owner, callers, tests, persistence effects, failure behavior,
and migration surface.
Record:
- exact, paraphrase, entity, date, and thread retrieval results;
- correction, supersession, archival recovery, and room-isolation behavior;
- p50 and p95 latency at named corpus sizes;
- clean-install prerequisites and operator steps;
- restart, backup, restore, update, and rollback behavior;
- paired task-efficiency results where a stable rubric exists.
Close the already-planned correctness, lifecycle, authority, and visible GUI defects before using the baseline as migration proof. A green test suite does not replace running the affected production-shaped path.
3. Lock one Rust domain, Host, and profile contract
hearth becomes the single behavioral authority. Define one common envelope
for identity, House and room scope, authority, lifecycle, provenance, chronology,
and relationships, with typed payloads for memories, canon, lessons, counsel,
candidates, and other distinct records. Do not flatten typed constraints into an
unvalidated generic document.
Vault and AKASHA execute the same domain commands and return the same observable receipts. One conformance corpus proves:
- scope and authorization before ranking;
- candidate, accepted, superseded, archived, and historical state transitions;
- provenance and source identity;
- continuation and supersession relationships;
- failed-command atomicity;
- bounded attributed retrieval.
The Host is the only client control boundary. Rust owns validation, policy, idempotency, reconciliation, ranking, storage behavior, and versioned protocol schemas. The OMP adapter may remain TypeScript where the harness requires it, but only as generated registration, lifecycle translation, transport, and bounded presentation skin.
4. Converge Vault and AKASHA on the Rust core
Vault remains portable, file-authoritative, single-writer, and database-service-free. Its structured records carry the same domain semantics as AKASHA. Its lexical and optional local semantic indexes are rebuildable and never authoritative.
AKASHA remains the primary installed profile: PostgreSQL-authoritative, transactional, concurrent, and continuously indexed. Preserve the current live schema and data while establishing parity; do not combine the language cutover with an unnecessary database redesign.
Move behavior from Python and TypeScript into Rust one complete vertical path at a time: migrations, health, backup and restore, imports, memory and lesson operations, retrieval, ranking, embeddings, GIGA work, and maintenance. For each path:
- recover the current contract, owner, callers, and tests;
- implement and exercise the Rust path through the real boundary;
- prove Vault/AKASHA parity where shared;
- migrate every caller and sweep for orphans;
- delete the displaced behavioral owner.
Vault-to-AKASHA migration is an explicit one-way authority handoff. The profiles never accept independent authoritative writes and reconcile later.
5. Prove the PostgreSQL-outbox/NATS spine
PostgreSQL owns truth. NATS owns delivery and wake-up only. A transactional outbox publishes authoritative record IDs with bounded routing and integrity metadata; consumers reload exact PostgreSQL records.
The first production lane must prove:
- commit and publish ordering;
- at-least-once delivery with durable idempotency;
- an explicit JetStream duplicate window;
- duplicate, stale, expired, malformed, and unauthorized pointer rejection;
- consumer restart, redelivery, backoff, dead-letter, and recovery;
- no private memory or conversation body in broker payloads;
- observable Host and GUI delivery receipts.
Vault does not require NATS. The lane advances only if it replaces more bespoke queue, polling, supervision, and failure machinery than it adds. Do not widen the broker until this one lane passes its complete gate.
For 1.0.0, this proof remains bounded to the existing boat.ready production
lane. The structural addressed subject does not count as recipient delivery.
Generalized authority references, recipient application handlers, and private
cross-room subjects belong to the post-1.0 communication spine. Broker
credentials and subject ACLs are mandatory before that expansion.
6. Complete the web operator surface
The web prototype at gui-prototype/ is the read-only operator surface.
Run bun gui-prototype/serve.ts from the repository root.
It reads the Host through a loopback proxy.
The Godot client is parked.
The parked native specification describes authenticated Host commands, snapshots, deltas, replay, and resynchronization.
It prohibits direct connections to PostgreSQL, NATS, model providers, or harness internals.
Its Recall Policy, sanitized Paper Boat receipt, and worker-lane screens remain historical evidence.
The 1.0 operator gate must make the state of a House legible:
- rooms, spirits, sessions, active model bodies, identity bindings, and health;
- messages among the operator, room agents, familiars, subagents, and other authorized agents, with direction, lifecycle, delivery, and failure state;
- Recall Policy, the active working set, selected sources, attribution, selection reasons, freshness, degradation, and useful retrieval metrics;
- memory, canon, lesson, and GIGA candidate authority and review state;
- agent, familiar, and subagent dispatch lineage, current work, completion, refusal, failure, and durable output;
- Host, substrate, PostgreSQL, NATS, queue, delivery, backup, migration, and version state at the level an operator can act on;
- clear attention signals that distinguish healthy background activity from pending decisions and failures.
Every view consumes authoritative Host projections and links summary metrics to inspectable attributed records. The GUI must not infer a second truth from renderer state, expose private message bodies across unauthorized scopes, or make raw telemetry the only explanation.
Conversation composition, source inspection, GIGA review, dispatch and quest
lineage, House and agent observability, and operational metrics therefore
remain before 1.0.0.
The 1.0 conversation and observability surface may use the existing Host/harness/PostgreSQL paths. It does not require putting Hallway, project, kitten, or live-token traffic through NATS.
Companion bodies, spatial Hallway presentation, and the memory constellation remain later work and do not block 1.0.
7. Make installation and lifecycle boring
Remove Athanor-owned Python, WSL, external embedding-service, and Bun prerequisites. OMP may retain its own harness runtime; The Athanor has one behavioral Rust runtime.
The ordinary AKASHA installer provisions:
- the signed native Rust service and CLI;
- managed private PostgreSQL, its database and role, and required extensions;
- deterministic state, log, migration, and backup locations;
- room bootstrap, startup registration, health checks, and rollback metadata.
Advanced operators may select an external compatible PostgreSQL instance.
Prove clean Vault and AKASHA installation, Vault-to-AKASHA migration, ordinary restart, graceful generation replacement, failed replacement, update, backup, restore, and rollback. A candidate generation becomes active only after protocol, schema, migration, and health readiness; the previous healthy binary remains available until the new generation drains real work successfully.
8. Publish evidence and cut 1.0
The release evidence compares both profiles and the pre-cutover runtime:
- the same semantic conformance corpus against Vault and AKASHA;
- Vault exact and paraphrased local-file retrieval;
- AKASHA paraphrase, entity, date, and thread recall;
- correction, supersession, archival authority, and room isolation;
- Vault-to-AKASHA migration with record, relationship, source, and authority checks;
- clean native installation, restart, live replacement, failed replacement, backup, restore, and rollback;
- p50 and p95 latency with corpus, index, embedding, and hardware details;
- bounded context, attributed selection reasons, and Recall Policy behavior;
- final-answer grounding and paired end-to-end task efficiency;
- the NATS lane's delivery, privacy, idempotency, and recovery receipts;
- rendered GUI operation and degraded-state visibility.
AKASHA's additional machinery must measurably outperform Vault where the product
claims that it does. Private memory payloads never become public fixtures merely
to improve a score. See EVIDENCE.md.
Before the 1.0.0 marker, build every artifact from a clean checkout; install
both profiles on clean supported Windows x64 environments; and make README,
INSTALL, USAGE, architecture, evidence, lesson map, and release claims agree.
The release vocabulary remains:
- The Athanor is the product;
- House is one operator-owned continuity domain;
- Vault is the portable transparent file profile;
- AKASHA is the installed PostgreSQL and semantic hybrid profile;
- GIGA is an optional cognitive capability above the shared Rust domain core;
- NATS is AKASHA delivery infrastructure, never authority;
- OMEGA and ANON remain planned profiles, not current release claims.
Deferred work after 1.0
These accepted threads cannot interrupt the release path.
House communication spine first
Before broader Origami, independent workers, or dynamic model routing, implement
the accepted contract in
RUNTIME_ARCHITECTURE.md
in this dependency order:
- harden the current lane with service credentials and subject ACLs, complete stream/consumer readiness, and truthful transport-receipt names;
- replace the memory-only Crane reference with a typed authority reference;
- add crease handlers and PostgreSQL application receipts distinct from outbox, transport, and read state;
- prove recipient-specific consumers, dead-letter/replay operation, and NATS reconstruction from PostgreSQL;
- replace the delivered PostgreSQL/Host-polled Hallway Knock with recipient-scoped NATS wake hints only after steps 1–4, preserving messages, Bell rows, Host authorization, exact reads, and recipient wake policy;
- create project identity, membership, subscriptions, and typed project records before adding project notifications;
- add addressed kitten work only for a demonstrated independent/dormant-worker need, with durable capability/workspace contracts and coalesced progress;
- announce committed conversation turns only to asynchronous subscribers while keeping live commands and streaming on Host/WebSocket;
- add GIGA wake hints only if multiple dormant workers justify them; SQL remains the claim authority.
This is one communication spine, not one generic message table. PostgreSQL owns records, permissions, idempotency, and application receipts. NATS carries bounded pointers. Host authenticates, applies, and projects. Project is scope; Hallway is a social log; kitten is an actor; Crane is a delivery intent.
Later accepted threads
- strengthen GIGA beyond required 1.0 integrity with broader refinement transactions and additional workers;
- expand Origami, room-scoped Pawprints, Paper Boat application, and Crane delivery only through the proved communication spine;
- route model bodies into broader cold-worker, familiar, reflection, and live dialogue topologies;
- add bounded Prolog/Datalog derivation and complete Cingulate;
- branch suitable obligations into deterministic synthesis, optional Z3, or selected Lean proofs;
- build the spatial Hallway, GPU memory constellation, companion ecosystem, OMEGA governance, and ANON execution.
Release rule
Do not advance the version because a document sounds finished.
Advance it when the named behavior runs through the release artifact, survives a restart, exposes its evidence, and matches the public claim.