Platform

Five surfaces.One governed execution boundary.

Keon separates cognition, ingress, execution, truth, and operator visibility into five platform surfaces with strict responsibilities. Platform surfaces are mapped by responsibility, not by sequential pipeline. AI systems can act only through governed authorization.

Cognition
Keon Collective
Owns

Branching cognition, adversarial challenge, and execution candidate generation.

Does not own

Authorization or execution.

Use when

Decisions need temporal branching, multi-agent synthesis, and internal challenge before governed action.

Explore Collective
Execution
Keon Systems Runtime
Owns

Pre-execution authorization, deterministic policy evaluation, governed execution, and receipt emission.

Does not own

Cognition, memory preservation, or operator visibility.

Use when

Any consequential action must be authorized and receipted before effect.

Explore Runtime
Truth
Keon Cortex
Owns

Canonical memory, receipt preservation, lineage, and replayable reconstruction evidence.

Does not own

Authorization or execution decisions.

Use when

Decisions must be provable, reconstructable, and auditable under governed review.

Explore Cortex
Operator Visibility
Keon Control
Owns

Operator observation, state and receipt visibility, lineage access, and governed action initiation.

Does not own

Authorization. Governed actions route through Runtime.

Use when

Operators need a governed cockpit for state visibility and action initiation.

Explore Control
Governed Ingress
MCP Gateway
Owns

Tool ingress governance, tenant and actor identity binding, ingress policy enforcement, and governed envelope preservation.

Does not own

Authorization. Routes into Runtime, which remains the Decide-before-Execute authority.

Use when

MCP-capable agents or external tool calls need governed ingress before reaching the execution boundary.

Explore MCP Gateway
System Relationships

How responsibilities meet.

Collective
produces execution candidates for
Runtime
MCP Gateway
routes governed tool calls into
Runtime
Runtime
emits receipt-backed outcomes to
Cortex
Control
observes and initiates through
Runtime

Surfaces connect through governed message. No request passes through all surfaces by default.

Adoption Paths

Adopt by boundary, not by bundle.

The system can enter through execution or governed ingress. The execution boundary remains mandatory for effects. No deployment requires all five surfaces.

01
Runtime first

Govern effect-bound actions. The execution boundary is the foundation of every deployment.

Explore Runtime
02
MCP Gateway first

Govern MCP-native agents and external tool calls with low client adoption friction. Routes governed tool calls into Runtime.

Explore MCP Gateway
03
Add Cortex

Preserve causal memory, lineage, and reconstructable evidence. Required for provable, auditable deployments.

Explore Cortex
04
Add Collective

Add group intelligence, Temporal Echo planning, adversarial challenge, and synthesis before Runtime.

Cortex is optimized for Collective. Its memory model preserves branch lineage and reconstructable history.

Explore Collective
05
Add Control

Give operators a governed cockpit for state, receipts, lineage visibility, and governed action initiation.

Explore Control
Trust And Federation

Built for zero-trust systems.

Keon operates as a federated, tenant-bound system. Requests entering the governed boundary are attributed, inspected, and routed through policy-bound execution.

Tenant and sub-tenant attribution (parent / reseller aware)
End-to-end identity binding (actor and authority preserved)
Message inspection and taint detection (inbound and outbound)
Encryption in transit and at rest
Zero-trust enforcement across all boundaries
Deployment review depends on engagement scope
Governed Ingress

MCP Gateway brings external tool calls to the governed execution boundary.

MCP Gateway binds tenant and actor identity, enforces ingress policy and scopes, preserves structured governed envelopes, and routes calls into Runtime. Runtime remains the Decide-before-Execute authority.

MCP-capable agents and OpenClaw-style exposed agents enter through the governed ingress boundary.

Authority Boundary

MCP Gateway is an integration surface into Runtime. Runtime holds the Decide-before-Execute authority. Gateway does not replace it.

Explore MCP Gateway →
CAES Alignment

Mapped to CAES primitives.

Deterministic policy evaluation

Pre-execution authorization receipts

Fail-closed enforcement

Append-only causal records

Offline-verifiable evidence

Reference alignment only. No external certification or blanket conformance claim is implied.

Page Contract

Map only. No layer compression.

Purpose

Map the five Keon platform surfaces by strict responsibility.

Primary question

What responsibility does each platform surface own?

Allowed
platform surfacesstrict responsibilitycognition execution truth operator visibility ingress egress separation
Forbidden
canonical plane languagerequired sequential pipeline through all surfacescollapsed doctrine responsibility boundariesproduct lineup marketing