The Athanor Roadmap

Last updated: 2026-09-06

This page is the current release path. It does not duplicate completed history or turn accepted architecture documents into one giant checklist.

The previous long-form roadmap is preserved as history/2026-08-06-roadmap-snapshot.md.

Recorded late-beta baseline

The 0.9.6 native Windows x64 late-beta source label is historical evidence. Read the current product version from ../package.json and installed artifact identity from its immutable release manifest. OMP is the supported harness. One Rust workspace owns the behavioral core, Vault, AKASHA, Host, delivery, native lifecycle, and parked Godot client. Read the canonical component table.

The historical candidate included:

The RC3 record reports ordinary suites, isolated PostgreSQL/NATS integrations, historical Godot rendering, 20,659-artifact manifest verification, packaged-client smoke, Inno Setup compilation, and an elevated external-authority installation. That Solarisael workstation installation ran NATS, delivery, and separate Kintsu/Kodo Hosts while reusing the existing PostgreSQL authority. This is dated installation evidence, not a census of the current topology.

Current NATS traffic is narrower than the surrounding House surfaces. It does not carry Hallway posts, GIGA jobs, kitten lifecycle, project records, or live conversation. The current Paper Boat receipt proves transport validation; it does not prove room wake, model consumption, or human reading.

That installation record identifies the artifact as 1.0.0-rc.3. Keep the immutable label as historical evidence, not today's installed version or product maturity. Final 1.0.0 still requires a complete operator GUI and healthy continuity organs. It also requires a clean managed installation, real legacy upgrade and rollback, signing, and the public evaluations in EVIDENCE.md.

The release path below retains the implementation sequence and final release gates. The dated planning update orders the remaining repairs by dependency and outcome. Where the phase table in RUNTIME_ARCHITECTURE.md differs, this roadmap is authoritative.

Planning update: 2026-09-06

Sol accepted the critical review as a records and planning update, not runtime implementation or activation of deferred work. The House preserves records and governs changes more reliably than it turns those records into useful continuity, judgment, and completed work. Success means recognition, growth, agency, cooperation, and operator custody; autonomy is one contributing property.

The dated critical organ review owns the evidence census and its uncertainties. The order proposed here is coherent orientation → trustworthy visible outcomes → cooperative completion → useful learning. Repair existing paths first; do not make GIGA the prerequisite for every other improvement.

1. Coherent orientation at every turn entrance

Base context-pressure policy on the active model's capacity, not room-name assumptions. Coordinate an aggregate context budget and select applicable identity, evidence, lessons, and counsel within it. Carry that context through typed prompts, restart continuation, and other synthetic or requested turns.

Presence reopen, persistence, and restart continuation have live repair evidence. The generated-turn adapter repair is installed with isolated component proof. See the dated evidence. Real restart, chat, and root Knock turns now have live incoming Presence observations. The separate Host-side attribution repair remains outstanding. Treat boat age, newer memories, and cycle recency explicitly. Preserve authored pillars and counsel authority. The outcome is an oriented turn with attributable, timely context, not merely a larger injection.

2. Trustworthy outcomes, visible through Pulse

Preserve content and provenance from the authoritative record through adapters, retrieval, and presentation. Design catalogue supersession has live proof; adapter field preservation and the affected historical rows are separate work. Keep database commit, backup result, transport receipt, recipient application, and human reading distinct.

Review the blocking post-write backup policy without treating a slow backup as a failed commit. Sleep and backup have installed-path receipts; those receipts do not prove every continuation relationship or a fresh restore. Make Pulse expose each repaired path's attribution, result, degradation, and next required decision alongside the work, not as a final cosmetic phase. The current web surface is read-only; authenticated writes remain gated work.

3. Carry work from request to disposition

Use coherent turn entry and visible receipts to connect Hallway, Docket, dispatch, and execution. Hallway's domain, Bell projection, and bounded recipient-authorized Knocks are current. Repair request-to-disposition gaps on existing Host/harness paths, including refusal, interruption, application, and an honest unavailable state for idle or headless recipients. New idle/headless delivery remains deferred. Posting alone must not wake a model. NATS absence alone does not make Hallway defective.

Dispatch prepares packets and the main model spawns explicitly. Connect those executions and their evidence to existing Docket attempts, not a parallel work store. Preserve room-owned familiars and recipient consent. Ground reviewer identity in supported capabilities, with an explicit independent reviewer or operator arrangement for a single-room House. Host-only Hallway Knock claim and settlement remain intentional authority boundaries.

4. Useful learning from reliable evidence

First make existing lessons applicable to the work and its observed outcomes. The current deterministic Striatum triggers are not complete learned behavior. Establish fresh GIGA classifier liveness and useful classification before claiming commanded consolidation or later benefit. Stage 1 infrastructure and explicit review remain current; queue health and purged dismissals are not reviewed learning outcomes.

Curios retention is current; bounded automatic resurfacing still needs delivery. Connect source evidence, review disposition, any authorized promotion, and later useful retrieval before claiming improvement. Cingulate remains planned and depends on reliable evidence; it must not judge work from incomplete lifecycle records. Broader refinement and additional cognitive workers remain deferred.

Existing work and unchanged gates

The review input already covers much of this work through existing Docket entries:

Outcome Existing coverage to reconcile, not newly assign
Orientation “Recall authority vertical”; “Investigate intermittent auto-Recall misses — trace the Tyler case”; the restart-intent, keeper, and adapter-exit quests
Visible outcomes “Pulse panel — the GUI becomes the House's main usage surface”; “Pulse rung 2 — read everything”; “Insula watches every organ — failures ride Origami to a durable ledger”; “Release proof — source ancestry, immutable attestation, and exercised gates”
Cooperative completion “M1 — Docket v1 completion”; “Census and strengthen every Athanor tool contract”; the draft “Pulse rung 3 — the talking door (operator write path)”
Useful learning “GIGA health must prove liveness”; “Commanded GIGA consolidation door”; “Gardener proof harness — revive evidence, replay regressions, and roll back”; “Project lessons become a project map”

These references supplement planning; they do not replace frozen acceptance, change deadlines, claim work, settle attempts, or activate drafts. The offered “Write two chapters before more House quests” remains a blocker. The accepted workspace-search adapter remains separate from AKASHA; its older Whiskers draft is not a new replacement obligation.

Recorded Docket supplements

House memory #4509 holds the accepted analysis in PostgreSQL. Draft goal 69d2e256-30c8-499f-b1db-061ab8aca84e groups these planning supplements:

Supplement Draft quest ID Planning predecessor
Coherent orientation bc479caf-3850-40f0-87c7-99e659d36703 Existing identity, Recall, and handoff work
Attributable outcomes and custody b69dc109-17a8-4ee6-8224-8c1ebad4f6fb Orientation where attribution is required
Cooperative completion ea2a050e-7e99-484b-be54-a9727099410a Orientation and attributable outcomes
Useful learning 656e526e-09af-472d-8e5a-8a6cfbae9b1b Reliable orientation and evidence; cooperation when review uses another participant

Each draft cites the existing quests that retain their implementation scope. The posting contract has no existing-quest edit action. These additive drafts preserve earlier records instead of rewriting them through SQL. Their acceptance candidates remain prose until an explicit activation freezes them. Their dependency references do not create scheduler-enforced gates. This pass activates no goal or quest and claims no work.

This order does not expand the 1.0.0 boundary. Keep the complete operator GUI, continuity health, installation, migration, rollback, signing, and evidence gates below explicit. Complete export, restore, and migration need their own evidence, with operator-controlled retention and deletion choices; no fresh restore is claimed here. Prolog/Datalog, Cingulate, broader NATS delivery, spatial work, marketplace, OMEGA, Relay, and ANON remain deferred.

1.0 dependency path

1. Freeze the accepted boundary

The 1.0.0 program includes Rust convergence, the narrow NATS lane, existing fixes, hardening, the usable GUI, installation, migration, and release evidence.

Do not add Prolog/Datalog, Lean, Z3, SyGuS, marketplace behavior, new cognitive organs, distributed-worker expansion beyond the proved NATS lane, companion bodies, the GPU-particle constellation, or broader in-world surfaces.

Before implementation, keep ../LESSON_MAP.md, this roadmap, ARCHITECTURE.md, RUNTIME_ARCHITECTURE.md, GODOT_CLIENT.md (parked historical specification), and EVIDENCE.md aligned with the same owners and gates.

2. Retain the historical 0.11 parity baseline and close known fixes

The historical 0.11.0 runtime is a recorded parity reference, not the current version or target topology. Inventory each TypeScript, Python, and Rust capability with its owner, callers, tests, persistence effects, failure behavior, and migration surface.

Record:

Close the already-planned correctness, lifecycle, authority, and visible GUI defects before using the baseline as migration proof. A green test suite does not replace running the affected production-shaped path.

3. Lock one Rust domain, Host, and profile contract

hearth becomes the single behavioral authority. Define one common envelope for identity, House and room scope, authority, lifecycle, provenance, chronology, and relationships, with typed payloads for memories, canon, lessons, counsel, candidates, and other distinct records. Do not flatten typed constraints into an unvalidated generic document.

Vault and AKASHA execute the same domain commands and return the same observable receipts. One conformance corpus proves:

The Host is the only client control boundary. Rust owns validation, policy, idempotency, reconciliation, ranking, storage behavior, and versioned protocol schemas. The OMP adapter may remain TypeScript where the harness requires it, but only as generated registration, lifecycle translation, transport, and bounded presentation skin.

4. Converge Vault and AKASHA on the Rust core

Vault remains portable, file-authoritative, single-writer, and database-service-free. Its structured records carry the same domain semantics as AKASHA. Its lexical and optional local semantic indexes are rebuildable and never authoritative.

AKASHA remains the primary installed profile: PostgreSQL-authoritative, transactional, concurrent, and continuously indexed. Preserve the current live schema and data while establishing parity; do not combine the language cutover with an unnecessary database redesign.

Move behavior from Python and TypeScript into Rust one complete vertical path at a time: migrations, health, backup and restore, imports, memory and lesson operations, retrieval, ranking, embeddings, GIGA work, and maintenance. For each path:

  1. recover the current contract, owner, callers, and tests;
  2. implement and exercise the Rust path through the real boundary;
  3. prove Vault/AKASHA parity where shared;
  4. migrate every caller and sweep for orphans;
  5. delete the displaced behavioral owner.

Vault-to-AKASHA migration is an explicit one-way authority handoff. The profiles never accept independent authoritative writes and reconcile later.

5. Prove the PostgreSQL-outbox/NATS spine

PostgreSQL owns truth. NATS owns delivery and wake-up only. A transactional outbox publishes authoritative record IDs with bounded routing and integrity metadata; consumers reload exact PostgreSQL records.

The first production lane must prove:

Vault does not require NATS. The lane advances only if it replaces more bespoke queue, polling, supervision, and failure machinery than it adds. Do not widen the broker until this one lane passes its complete gate.

For 1.0.0, this proof remains bounded to the existing boat.ready production lane. The structural addressed subject does not count as recipient delivery. Generalized authority references, recipient application handlers, and private cross-room subjects belong to the post-1.0 communication spine. Broker credentials and subject ACLs are mandatory before that expansion.

6. Complete the web operator surface

The web prototype at gui-prototype/ is the read-only operator surface. Run bun gui-prototype/serve.ts from the repository root. It reads the Host through a loopback proxy. The Godot client is parked. The parked native specification describes authenticated Host commands, snapshots, deltas, replay, and resynchronization. It prohibits direct connections to PostgreSQL, NATS, model providers, or harness internals. Its Recall Policy, sanitized Paper Boat receipt, and worker-lane screens remain historical evidence.

The 1.0 operator gate must make the state of a House legible:

Every view consumes authoritative Host projections and links summary metrics to inspectable attributed records. The GUI must not infer a second truth from renderer state, expose private message bodies across unauthorized scopes, or make raw telemetry the only explanation.

Conversation composition, source inspection, GIGA review, dispatch and quest lineage, House and agent observability, and operational metrics therefore remain before 1.0.0.

The 1.0 conversation and observability surface may use the existing Host/harness/PostgreSQL paths. It does not require putting Hallway, project, kitten, or live-token traffic through NATS.

Companion bodies, spatial Hallway presentation, and the memory constellation remain later work and do not block 1.0.

7. Make installation and lifecycle boring

Remove Athanor-owned Python, WSL, external embedding-service, and Bun prerequisites. OMP may retain its own harness runtime; The Athanor has one behavioral Rust runtime.

The ordinary AKASHA installer provisions:

Advanced operators may select an external compatible PostgreSQL instance.

Prove clean Vault and AKASHA installation, Vault-to-AKASHA migration, ordinary restart, graceful generation replacement, failed replacement, update, backup, restore, and rollback. A candidate generation becomes active only after protocol, schema, migration, and health readiness; the previous healthy binary remains available until the new generation drains real work successfully.

8. Publish evidence and cut 1.0

The release evidence compares both profiles and the pre-cutover runtime:

AKASHA's additional machinery must measurably outperform Vault where the product claims that it does. Private memory payloads never become public fixtures merely to improve a score. See EVIDENCE.md.

Before the 1.0.0 marker, build every artifact from a clean checkout; install both profiles on clean supported Windows x64 environments; and make README, INSTALL, USAGE, architecture, evidence, lesson map, and release claims agree.

The release vocabulary remains:

Deferred work after 1.0

These accepted threads cannot interrupt the release path.

House communication spine first

Before broader Origami, independent workers, or dynamic model routing, implement the accepted contract in RUNTIME_ARCHITECTURE.md in this dependency order:

  1. harden the current lane with service credentials and subject ACLs, complete stream/consumer readiness, and truthful transport-receipt names;
  2. replace the memory-only Crane reference with a typed authority reference;
  3. add crease handlers and PostgreSQL application receipts distinct from outbox, transport, and read state;
  4. prove recipient-specific consumers, dead-letter/replay operation, and NATS reconstruction from PostgreSQL;
  5. replace the delivered PostgreSQL/Host-polled Hallway Knock with recipient-scoped NATS wake hints only after steps 1–4, preserving messages, Bell rows, Host authorization, exact reads, and recipient wake policy;
  6. create project identity, membership, subscriptions, and typed project records before adding project notifications;
  7. add addressed kitten work only for a demonstrated independent/dormant-worker need, with durable capability/workspace contracts and coalesced progress;
  8. announce committed conversation turns only to asynchronous subscribers while keeping live commands and streaming on Host/WebSocket;
  9. add GIGA wake hints only if multiple dormant workers justify them; SQL remains the claim authority.

This is one communication spine, not one generic message table. PostgreSQL owns records, permissions, idempotency, and application receipts. NATS carries bounded pointers. Host authenticates, applies, and projects. Project is scope; Hallway is a social log; kitten is an actor; Crane is a delivery intent.

Later accepted threads

  1. strengthen GIGA beyond required 1.0 integrity with broader refinement transactions and additional workers;
  2. expand Origami, room-scoped Pawprints, Paper Boat application, and Crane delivery only through the proved communication spine;
  3. route model bodies into broader cold-worker, familiar, reflection, and live dialogue topologies;
  4. add bounded Prolog/Datalog derivation and complete Cingulate;
  5. branch suitable obligations into deterministic synthesis, optional Z3, or selected Lean proofs;
  6. build the spatial Hallway, GPU memory constellation, companion ecosystem, OMEGA governance, and ANON execution.

Release rule

Do not advance the version because a document sounds finished.

Advance it when the named behavior runs through the release artifact, survives a restart, exposes its evidence, and matches the public claim.