Six responsibilities.Authority stays singular.
Keon separates candidate cognition, advisory context, governed entry, authorization, evidentiary truth, and operator control. This is a responsibility map, not a required sequence: Runtime alone decides whether a proposed effect may cross into reality.
Keon Systems Runtime
Runtime evaluates policy before consequence, binds the disposition to evidence, and prevents execution when authorization is denied or incomplete. Other components may inform, preserve, route, or display the work; none inherit this authority.
Runtime authorizes. Runtime denies. Runtime can require governed review.
Inspect Runtime →Policy permits the proposed effect.
Policy blocks the proposed effect.
The effect waits for the required governed review.
Each component keeps one boundary legible.
These components cooperate by contract. They are not interchangeable, and a request does not pass through every component by default.
Keon Collective
- Owns
- Deliberation, challenge, and candidate proposals before governed action.
- Authority stops
- Proposes, never executes. Cognition does not create authority.
- Operator can
- Review the public cognition boundary or request controlled access to deeper material.
Context Fabric
- Owns
- Deterministic assembly of provenance-bound context when source set, query, and policy inputs are pinned.
- Authority stops
- Context remains advisory. It is neither a Decision Receipt nor authorization.
- Operator can
- Inspect source identity, lineage, freshness, and provenance before relying on assembled context.
Keon Cortex
- Owns
- Canonical memory, causal lineage, and evidence for reconstructing governed outcomes.
- Authority stops
- Preserves what can be established. It does not decide or execute.
- Operator can
- Inspect lineage and reconstruct the evidence behind a governed outcome.
MCP Gateway
- Owns
- Governed ingress that preserves tenant, actor, authority, and scope for MCP tool calls.
- Authority stops
- Carries requests to Runtime. It does not evaluate or grant execution authorization.
- Operator can
- Trace how an MCP call enters the governed boundary with identity and scope intact.
Keon Control
- Owns
- Visibility into supported system state, decisions, receipts, lineage, and governed action initiation.
- Authority stops
- Initiated actions still route through Runtime. The interface is not authority.
- Operator can
- Inspect supported governance state and initiate actions through governed entry points.
BrowseAhead informs governance. It does not become governance.
BrowseAhead
In its current bounded form, BrowseAhead inspects supplied untrusted content and produces risk evidence for downstream policy and operator review. Current evidence does not support live URL fetching, and inspection never grants execution authority.
- Input
- Supplied untrusted content
- Output
- Inspection risk evidence
- Authority
- None. Runtime decides effect.
Map here. Trace lifecycle elsewhere.
Use this page to identify ownership. Follow the execution lifecycle in How It Works, then follow the linked public surface for deeper behavior and evidence boundaries.