Platform / Responsibility Map

Six responsibilities.Authority stays singular.

Keon separates candidate cognition, advisory context, governed entry, authorization, evidentiary truth, and operator control. This is a responsibility map, not a required sequence: Runtime alone decides whether a proposed effect may cross into reality.

Authorization before effect

Keon Systems Runtime

Runtime evaluates policy before consequence, binds the disposition to evidence, and prevents execution when authorization is denied or incomplete. Other components may inform, preserve, route, or display the work; none inherit this authority.

Runtime authorizes. Runtime denies. Runtime can require governed review.

Inspect Runtime →
Authorize

Policy permits the proposed effect.

Deny

Policy blocks the proposed effect.

Require review

The effect waits for the required governed review.

Strict Responsibilities

Each component keeps one boundary legible.

These components cooperate by contract. They are not interchangeable, and a request does not pass through every component by default.

02
Candidate cognition

Keon Collective

Review Collective
Owns
Deliberation, challenge, and candidate proposals before governed action.
Authority stops
Proposes, never executes. Cognition does not create authority.
Operator can
Review the public cognition boundary or request controlled access to deeper material.
03
Advisory context

Context Fabric

Review context boundary
Owns
Deterministic assembly of provenance-bound context when source set, query, and policy inputs are pinned.
Authority stops
Context remains advisory. It is neither a Decision Receipt nor authorization.
Operator can
Inspect source identity, lineage, freshness, and provenance before relying on assembled context.
04
Evidentiary truth

Keon Cortex

Review Cortex
Owns
Canonical memory, causal lineage, and evidence for reconstructing governed outcomes.
Authority stops
Preserves what can be established. It does not decide or execute.
Operator can
Inspect lineage and reconstruct the evidence behind a governed outcome.
05
Governed entry

MCP Gateway

Review MCP Gateway
Owns
Governed ingress that preserves tenant, actor, authority, and scope for MCP tool calls.
Authority stops
Carries requests to Runtime. It does not evaluate or grant execution authorization.
Operator can
Trace how an MCP call enters the governed boundary with identity and scope intact.
06
Operator command center

Keon Control

Review Control
Owns
Visibility into supported system state, decisions, receipts, lineage, and governed action initiation.
Authority stops
Initiated actions still route through Runtime. The interface is not authority.
Operator can
Inspect supported governance state and initiate actions through governed entry points.
Bounded Support

BrowseAhead informs governance. It does not become governance.

Supporting capability / inspection evidence

BrowseAhead

In its current bounded form, BrowseAhead inspects supplied untrusted content and produces risk evidence for downstream policy and operator review. Current evidence does not support live URL fetching, and inspection never grants execution authority.

Input
Supplied untrusted content
Output
Inspection risk evidence
Authority
None. Runtime decides effect.
Read The Correct Surface

Map here. Trace lifecycle elsewhere.

Use this page to identify ownership. Follow the execution lifecycle in How It Works, then follow the linked public surface for deeper behavior and evidence boundaries.