Architecture
Three layers. One stable foundation. Agents are replaceable. The core is not.
The Philosophy
Most agent systems make the agent the center of the architecture. steadfaste reverses that relationship.
The agents are replaceable. The foundation is not. Control flows in one direction:
Steward → Constitution → Agent
Workers cannot bypass the Constitution. There are only two doors into the system:
- Workers enter through the Wire
- Surfaces enter through the Core Interface
Both remain behind the same governance boundary.
Layer One: The Constitution
The small, stable Rust core. It owns the parts of the system that must remain dependable:
- Durable state and the tamper-evident Ledger
- Event bus for internal coordination
- Configuration validation (one validated config, no silent env vars)
- Worker supervision and lifecycle control
- Permissions and enforcement
- Verification and graded trust decisions
- The Wire protocol
The Constitution is the system's single writer, single verifier, and single lifecycle authority.
Layer Two: The Wire
The boundary between steadfaste and its workers. A deliberately small, versioned JSON-over-stdio protocol.
The One Rule
Existing workers should keep working.
The protocol is additive-only. New capabilities are introduced without silently breaking old workers.
Any agent that speaks the Wire can become a governed steadfaste worker. For existing coding agents, a delegated CLI adapter and MCP seam provide the integration layer.
Layer Three: The Core Interface
Human-facing applications use a separate stable interface behind the Constitution:
- Web UI
- TUI (terminal interface)
- Messaging gateway (Telegram today, others additively)
- Operator dashboard
- Future clients
The Core Interface exposes governed state, evidence, subscriptions, and lifecycle operations — without giving any surface a path around the Constitution.
System Diagram
steadfaste
┌─────────────────┐
│ CONSTITUTION │
│ State · Ledger │
│ Permissions │
│ Supervision │
│ Verification │
│ Governance │
└────────┬────────┘
│
THE WIRE
stable worker interface
│
┌───────────────┼───────────────┐
│ │ │
Claude Codex Pi
OpenHands Gemini Your Agent
│ │ │
└────── governed workers ───────┘
│
CORE INTERFACE
│
┌───────────────┼───────────────┐
│ │ │
Web UI TUI Messaging
│ │ / Operators
Repository Structure
steadfaste/
core/ Rust — Constitution (Ledger, Wire, Gate, verification)
spec/ Core specification and Covenant vocabulary
worker/ Worker runtime and agent adapters
web/ UI for normal people (Core Interface client)
gateway/ Messaging transports — Telegram, others additively
packaging/ Install / update / uninstall
governance/ The harness policing itself
config/ The one config file (example + schema)
test/ Conformance and system tests
docs/ Architecture, design, research, history
prototype-ts/ is a discarded design reference — do not build on it.
The Covenant
Every action runs under a human Steward who remains accountable for what the system does.
Trust is not requested. It is demonstrated. Actions are recorded. Results are verified. Trust is graded. Failures have consequences.
Explore the specification
The full governing specification lives in the repository at spec/core-spec.md.