Technical Architecture

Persistent agents with durable authority and evidence.

Cuttlefish operates enterprise agents across local runtimes, native desktop environments, hosted model providers, enterprise applications, and cloud systems. Each runtime works inside a user and organization authority boundary while Cuttlefish preserves identity, task state, governed collaboration, durable artifacts, approvals, and execution evidence.

Home supervises the environment. Independent runtimes own their work. Policy controls external effect. Receipts and artifacts preserve the result.

Complete operating architecture

One governed environment across people, agents, models, systems, and evidence.

Cuttlefish owns the operating layer between human intent and external effect. It keeps supervision, runtime identity, delegated scope, durable state, capability control, approvals, artifacts, and evidence coherent while models and enterprise systems remain separate execution dependencies.

Cuttlefish operating architecture Authority enters at the left, work executes inside isolated runtimes, and artifacts and evidence leave through governed boundaries.
Complete Cuttlefish operating architecture Users and enterprise operators direct Home. Home governs three independent agent runtimes, policy and approvals, collaboration, durable state, external capabilities, Workspace Canvas artifacts, and signed execution evidence. OPERATING ROUTES Native desktop Local models Hosted providers Enterprise cloud Hybrid routes CUTTLEFISH OPERATING FIELD identity · authority · state · proof Users intent · review approval · intervention Enterprise operators environment · identity lifecycle · evidence access ORGANIZATION ADMINISTRATION membership · providers · policy provisioning · retained evidence HOME SUPERVISION assign · observe · steer · pause · resume POLICY + APPROVALS capability scope · risk · consent explicit grants where required RUNTIME 01 Research hosted model identity · task · memory COMPANION WINDOW RUNTIME 02 Build local model identity · repo scope CODING HARNESS RUNTIME 03 Review private endpoint identity · evidence scope FLOW MEMBER COLLABORATION FABRIC addressed work · bounded context · result return Durable operational state conversation · task · memory · workflow · lifecycle BOUNDED DEPENDENCIES Models + providers local · hosted · private Connector execution classified · policy-bound Enterprise systems applications · cloud · data WORKSPACE CANVAS durable artifacts RECEIPTS retained evidence Complete Cuttlefish operating architecture A compact view of operator authority, Home supervision, independent runtimes, collaboration, durable state, external execution, artifacts, and receipts. OPERATING ROUTES desktop · local · hosted · enterprise cloud · hybrid Users + operators intent · approval · administration HOME supervision + lifecycle POLICY + APPROVALS identity · capability scope · explicit grants 01 · RESEARCH hosted model private state 02 · BUILD local model repo scope 03 · REVIEW private route evidence scope COLLABORATION FABRIC Durable state task · memory · workflow BOUNDED EXECUTION Models + providers local · hosted · private Capabilities + systems policy-bound effects WORKSPACE ARTIFACT RECEIPT
Independent agent runtimes

Shared governance. Separate runtime ownership.

Each active Companion runtime receives its own runtime identity, model assignment, task and event history, bounded context, capability authority, lifecycle policy, and operating projection. Home can assign and supervise work without absorbing that runtime’s execution state.

Three isolated runtimes under one governance boundaryPeer work crosses explicit collaboration and capability boundaries.
Three independent agent runtimes under shared enterprise governance Home supervises three separately identified runtimes. Each runtime owns its model assignment, task and conversation state, memory scope, capability authority, lifecycle, event history, and operating surface. Peer work crosses the Collaboration Fabric under shared organization policy and approval rules. ENTERPRISE GOVERNANCE BOUNDARY human identity · organization scope · policy · approval authority · evidence access HOME supervise · assign · steer · observe BOUNDED ASSIGNMENT + RUNTIME IDENTITY 01 · RESEARCH Independent runtime runtime identity · hosted model private task + conversation state read authority · selected memory own lifecycle + event stream COMPANION WINDOW 02 · BUILD Independent runtime runtime identity · local model repository state · bounded memory prepared effects · approval scope own lifecycle + event stream CODING HARNESS 03 · REVIEW Independent runtime runtime identity · private endpoint verification state · selected memory evidence scope · review authority own lifecycle + event stream FLOW MEMBER COLLABORATION FABRIC addressed delegation · permitted context · attributable result return Three independent agent runtimes under shared enterprise governance Three separate runtime cells sit inside one governance boundary and exchange bounded work through the Collaboration Fabric while Home supervises them. ENTERPRISE GOVERNANCE BOUNDARY identity · policy · approvals · evidence HOME supervise + assign 01 · RESEARCH Hosted model identity · private state read authority 03 · REVIEW Private route identity · review state evidence scope 02 · BUILD Local model identity · repo state prepared effects COLLABORATION FABRIC bounded delegation · attributable return EACH RUNTIME OWNS identity · model · state · memory · capability · lifecycle

A window is a projection.

The visible Companion Window presents work owned by its operating runtime. A window can detach while permitted work continues, or trigger pause and checkpoint behavior under its lifecycle policy.

State survives the surface.

Runtime instances, events, scheduled work, selected context, and Flow records are retained as durable application state. Startup recovery identifies interrupted work for deliberate replay or repair.

Authority stays runtime-scoped.

Repository, process, browser, connector, and coordination operations remain bound to a specific runtime, capability, target, origin, policy, and approved limits.

Identity, authority & delegation

Every external effect begins with attributable authority.

Human and organization identity establish the outer boundary. Agent and runtime identity locate the actor inside it. Delegation narrows the assignment, capability scope defines the available operation, policy evaluates the request, and approval supplies human authority where the action requires it.

Authority-to-evidence lifecycleScope can narrow as work moves forward; each transition remains attributable.
Identity, delegated authority, action, receipt, and artifact chain Human and organization identity establish the initiator. An agent and runtime receive a bounded delegated scope. Capability, policy, and approval govern the action. A signed receipt and durable artifact preserve attribution and outcome. AUTHORITY NARROWS TOWARD THE EFFECT attribution and lineage carry through every transition 01 Initiator human + organization identity 02 Agent + runtime acting identity + lifecycle 03 Delegated scope bounded objective + limits 04 Capability classified operation + target 05 Policy + approval explicit authority when required 06 Action attributed external effect 07 Receipt signed execution evidence 08 Artifact durable inspectable output IDENTITY + AUTHORITY ACTION + PROOF Identity, delegated authority, action, receipt, and artifact chain A vertical authority ribbon narrows from initiator and agent identity through delegated scope, capability, policy, and approval, then becomes an action, signed receipt, and durable artifact. AUTHORITY NARROWS TOWARD THE EFFECT 01 Initiator human + organization 02 Agent + runtime acting identity 03 Delegated scope bounded objective + limits 04 Capability operation + target 05 Policy + approval explicit grant if required 06 Action external effect 07 Receipt signed evidence 08 Artifact durable output
Delegation cannot widen authority by itself.

A peer task or Flow membership carries its origin and assigned scope. The receiving runtime still needs its own valid capability and approval for any consequential effect, keeping the performer, requester, and causal path visible.

Collaboration Fabric

Independent agents coordinate through governed exchanges.

The Collaboration Fabric lets runtimes address one another, delegate bounded work, share permitted context or artifact references, coordinate task state, and return results. Each participant keeps its own identity, model route, runtime boundary, and event history while Home retains operator visibility.

A governed task across three model routesThe sequence shows public responsibility boundaries rather than internal transport.
Governed work across three independent runtimes Home assigns work to a research runtime using a hosted model. Bounded context and artifact references move through a local build runtime and a private review runtime. Approved results return with receipts and artifacts while each runtime retains its own identity, authority, state, and event history. SHARED POLICY + APPROVAL BOUNDARY separate identity · authority · task state · model route · event history HOME operator supervision RESEARCH RUNTIME Hosted model read-scoped authority BUILD RUNTIME Local model repository scope REVIEW RUNTIME Private endpoint verification scope 01 · ASSIGN objective + finish line 02 · DELEGATE permitted context + artifact reference 03 · PREPARE result remains bounded to build authority 04 · REVIEW verify + approve external effect ARTIFACT + RECEIPT 05 · ATTRIBUTED RESULT RETURNS TO HOME provenance follows the task; runtime boundaries remain intact Governed work across three independent runtimes A single governed task path moves from Home through research, build, and review runtimes using different model routes, then returns an artifact and receipt. SHARED POLICY + APPROVAL BOUNDARY distinct identity · authority · state · model route HOME assign + observe 01 · RESEARCH Hosted model read authority 02 · BUILD Local model repo scope 03 · REVIEW Private route verify + approve 04 · ARTIFACT + RECEIPT attributed result returns to Home

Addressed peer exchange

Independent runtimes can exchange governed work through the Collaboration Fabric while Home preserves operator supervision and a visible history of the participating runtimes.

Bounded shared context

Context can remain private to one runtime, be shared with approved Flow participants, or be visible to the user. Collaboration uses redacted, selected context and artifact references rather than unrestricted prompt transfer.

Versioned Companion Flows

Flows retain immutable versions, launch state, member grants, artifact lineage, gate history, and import review state so repeated collaboration remains inspectable.

Model & provider continuity

Institutional state stays above the model session.

Cuttlefish keeps agent and runtime identity, bounded authority, selected context, task state, collaboration lineage, approvals, artifacts, and execution evidence in Cuttlefish-owned stores. Provider sessions remain scoped to the selected model route.

Stable state across changing cognition routesAn approved route change reconstructs a bounded turn from retained state.
Cuttlefish-owned state across model and provider routes Identity, authority, task state, selected memory, collaboration lineage, approvals, artifacts, and execution evidence remain in Cuttlefish-owned state. A bounded model turn can use an approved local, hosted, or private route while provider-session state remains scoped to that route. CUTTLEFISH-OWNED CONTINUITY agent identity · authority task + event state selected memory collaboration lineage approvals + grants artifacts · execution evidence STABLE INSTITUTIONAL STATE owned above the model turn PROVIDER BOUNDARY selected context crosses · retained state stays Local route approved endpoint AVAILABLE Hosted route approved provider ASSIGNED TURN Private route organization endpoint AVAILABLE SELECTED RESULT RETURNS TO DURABLE STATE provider-session state remains route-scoped Cuttlefish-owned state across model and provider routes A compact orbit shows stable institutional state surrounded by retained identity, authority, tasks, memory, collaboration, approvals, artifacts, and evidence, with one approved provider route selected for a bounded turn. CUTTLEFISH-OWNED CONTINUITY identity · authority task · memory approvals · grants collaboration artifact · evidence STABLE STATE above the model turn Local available Hosted assigned turn Private available RESULT RETURNS TO DURABLE STATE provider-session state remains route-scoped
Current continuity contract

Cuttlefish preserves the state it owns and can start a new provider interaction from that retained record. Live migration of an in-flight provider session is outside the current contract.

Governed capability execution

Intent becomes external effect through an explicit control path.

Cuttlefish resolves the acting runtime and its authority before it exposes a capability. The capability is discovered or compiled, classified by effect, evaluated against policy, held for approval where required, and executed through a connector or native boundary with state and evidence attached.

Governed action lifecycleUnknown, unregistered, expired, mismatched, or over-limit authority fails closed.
Governed capability execution stream Intent moves through runtime assignment, authority and capability resolution, discovery, classification, policy, approval where required, connector execution, state update, artifact creation, and receipt generation. RESOLVE THE ACTOR + AVAILABLE OPERATION Intent Runtime Authority Discovery requested outcome identity + model route scope + target + limits registered capability CLASSIFY Effect + policy risk · reversibility READ-ONLY observe or retrieve within scope Connector read PREPARATORY draft · preview · compare · dry-run Preview artifact APPROVAL REQUIRED hold for explicit consent External effect BLOCKED unknown · expired · mismatched · over-limit DURABLE OUTCOME state update artifact receipt evidence blocked work terminates before connector execution; successful work returns proof state Governed capability execution stream A compact control stream resolves identity and capability, classifies the effect, applies policy and approval, executes allowed work, and returns proof. RESOLVE THE ACTOR + OPERATION Intent Runtime Authority Capability CLASSIFY Effect + policy risk · reversibility READ-ONLY connector read PREPARATORY preview artifact APPROVAL explicit consent BLOCKED no effect DURABLE OUTCOME state · artifact · receipt · evidence FAIL CLOSED unknown, expired, mismatched, and over-limit authority stops before connector execution. ALLOWED EFFECT executes through a connector or native boundary

Discovery grants no authority.

Environment and connector discovery can describe available operations. A separate compilation and policy path decides which named capabilities become available to a runtime.

Approval binds to the action.

Consequential work presents the target and expected effect, then binds the resulting authority to the runtime, operation, origin, active policy, and approved limits.

Outcome enters durable state.

Execution can update task or world state, publish an artifact, attach source and outcome evidence, and commit a receipt for later verification.

Durable memory, state & artifacts

Each kind of state has a distinct owner and lifetime.

Cuttlefish separates the working context sent to a model from the state required to operate, recover, review, and reuse work. This keeps provider context bounded while preserving the records that carry institutional value.

Working

Model context

The bounded prompt and tool context for one provider interaction.

Provider-scoped and reconstructable from selected sources.
Conversation

Conversation state

User-visible messages, attachments, and continuity saved by the application.

Persists independently of a single model response.
Execution

Task & runtime state

Assignments, lifecycle, event history, scheduled work, authority, and completion state.

Recovers deliberately after interruption or restart.
Knowledge

Persistent memory

User-approved memory and organization-scoped knowledge selected under policy.

Included by scope and provenance rather than copied wholesale.
Workflow

Companion Flow state

Version, launch, member grant, gate, artifact, and run history.

Supports pause, review, replay, export, and repair paths.
Output

Durable artifacts

Documents, code, generated surfaces, and other inspectable work products.

Version and provenance stay attached to the result.
Proof

Execution evidence

Receipts, evidence references, hashes, verification state, and retained anchors.

Supports retrieval, investigation, and reconstruction.
Workspace Canvas

Where agent work becomes an operating artifact.

Workspace Canvas gives drafts and generated work a durable, inspectable surface. Native snapshots, exact file identities, version state, validation results, and artifact references keep the work reviewable beyond the conversation that produced it.

DraftSnapshotValidateVersionArtifact

Window closure can detach a permitted runtime from its projection. Application restart restores retained runtime and workflow records and marks incomplete execution for recovery. A provider failure preserves Cuttlefish-owned state; continuing through another provider requires an approved route.

Execution receipts & evidence

A receipt is a signed proof object for a governed action.

Current governance receipts are signed with Ed25519 and verified before evidence storage. The proof layer binds receipt identity, scope, requester, timestamp, captured content, and signature, then retains available actor, organization, action-lineage, source, evidence, artifact, and integrity references for retrieval.

Receipt anatomyA public view of proof responsibilities, without private schema or key details.
Anatomy of a governed execution receipt A single signed proof sheet groups attribution and authority, action and lineage, and evidence and integrity. The receipt links the acting identity, delegated authority, external effect, artifacts, timestamp, sequence, and Ed25519 verification. 01 · ATTRIBUTION Who requested and acted human · organization · agent · runtime 02 · AUTHORIZATION What authority was present delegation · capability · policy · approval GOVERNED EXECUTION RECEIPT Attributable governed action stable proof identifier · ordered timestamp ED25519 VERIFIED IDENTITY + AUTHORITY ACTOR requester · agent · runtime · organization SCOPE delegated capability · target · limits DECISION policy result · bound approval reference ACTION + LINEAGE ACTION governed operation · outcome · execution time LINEAGE initiator · delegation · preceding action SEQUENCE ordered timestamp · linked state transition EVIDENCE + INTEGRITY OUTPUT artifact · evidence reference · integrity state 03 · LINEAGE What happened, in order action · transition · preceding receipt 04 · EVIDENCE What the action produced artifact · source · retrieval · integrity PROVES INTEGRITY + ATTRIBUTION OF THE CAPTURED GOVERNANCE EVENT Anatomy of a governed execution receipt A compact signed proof sheet groups identity and authority, action and lineage, and evidence and integrity in one retrievable receipt. GOVERNED EXECUTION RECEIPT Attributable governed action stable identifier · ordered timestamp ED25519 01 · IDENTITY + AUTHORITY ACTOR requester · agent · runtime SCOPE delegation · capability · limits DECISION policy · bound approval 02 · ACTION + LINEAGE ACTION operation · outcome · time LINEAGE initiator · delegation · prior action SEQUENCE ordered transition linkage 03 · EVIDENCE + INTEGRITY OUTPUT artifact · source · proof VERIFY signature · hash · integrity state RETRIEVABLE PROOF integrity + attribution of the captured event receipt ≠ log · trace · telemetry · audit event
Receipt

Signed proof object for a specific governed decision or action.

Log

Detailed operational messages used to diagnose behavior.

Trace

Request path and timing across participating components.

Telemetry

Aggregated health, usage, reliability, and performance signals.

Audit event

Historical record of an administrative or product event.

Evidence retention

Continuity depends on proof state that can be inspected.

The evidence plane retains signed receipts alongside source and evidence references, causal identifiers, and immutable-anchor health where configured. Proof views distinguish complete records from missing, pending, or failed evidence so audit, investigation, and reconstruction begin from an honest record.

Product operating surfaces

The interface exposes the architecture at the point of control.

Each product surface presents a specific infrastructure responsibility. Users see the work and decisions relevant to them while the runtime keeps identity, authority, state, execution, and evidence coherent underneath.

Supervision

Home

Assigns work, observes independent runtimes, presents approvals and outcomes, and keeps the operator in control.

Runtime projection

Companion Windows

Expose one agent runtime’s task, model assignment, tools, event stream, lifecycle, and deliverables.

Governed collaboration

Companion Flows

Version repeatable multi-agent work, member grants, launch state, gates, artifacts, and history.

Intent routing

Universal Composer

Routes user intent and selected context into the right runtime and operating surface.

Durable output

Workspace Canvas

Turns generated work into inspectable snapshots, versions, applications, documents, and artifacts.

Contained engineering

Coding Harness

Binds repository, process, edit, verification, and artifact operations to one runtime identity and capability scope.

Enterprise authority

Environment controls

Manage connections, capabilities, providers, roles, approvals, revocation, and operating boundaries.

Verification

Runs, receipts & artifacts

Retrieve execution history, inspect proof completeness, verify signatures, and open durable results.

Deployment & availability

Native operation with local, hosted, and enterprise-managed routes.

The public release channel provides native desktop installers for Windows, macOS, and Linux. Users can run approved local models through Ollama or LM Studio, connect compatible private endpoints, or use hosted providers. Enterprise environments add organization identity, managed provider and connector policy, cloud-system access, approvals, and retained evidence.

DesktopWindows · macOS · Linux

Native shell, local operating surfaces, secure credential storage, and contained runtime execution.

Model routesLocal · hosted · private

Runtime-scoped model assignments with explicit, user-approved fallback selection.

Enterprise routesCloud · hybrid model use

Organization-managed environments and providers can coexist with desktop-local cognition and state.

AvailabilityDirect release · Microsoft Marketplace preview

Installers, versions, checksums, and release notes remain available through the current release page.

Microsoft Marketplace

Cuttlefish Enterprise Runtime preview

Review the enterprise offer on Microsoft Marketplace. The listing is an availability channel and does not imply Microsoft endorsement or architectural approval.

View on Microsoft Marketplace

Cuttlefish’s enterprise Azure environment was built with Capstone IT Solutions. This statement describes infrastructure work; it does not present Capstone as a customer, reseller, or endorsed reference.