INDWEL / SECURITY OPERATIONS
Security Operations
The constitutional law becomes physical here: identity, runtime, data handling, credentials, provider egress, capabilities, Effects, continuity, telemetry, and recovery are bound to the same governed undertaking.
Before cognition
A request reaches cognition only after the system knows which organisation and principal are acting, which Cognitive Contract governs the undertaking, what data may cross the boundary, which provider and venue are permitted, what budget and time envelope apply, and which capabilities can be exposed to the run.
This is familiar enterprise security carried into an unfamiliar execution model. A reasoning system can retrieve, plan, call tools, wait, resume, and seek Effects. Indwel keeps the controls around those powers outside the model so later inference cannot silently enlarge the authority with which the Work began. Each decision narrows the next.
Each decision narrows the next. None is delegated to the model whose execution it governs.
The run begins inside an admitted release, execution envelope, wall-clock and request ceilings, cancellation model, and cost budget.
Organisation, human or workload identity, durable membership, role, delegation, and session authority are resolved before access is exposed.
Rate and abuse controls, classification, DLP, content inspection, malware protection, rights, and quarantine can constrain material before cognition.
Model/provider, execution venue, region, retention posture, outbound destination, and secret policy are admitted independently.
The run receives only allowed tools, operations, targets, and credential references—not ambient account privilege.
The operational boundary
Time and economics participate in authority. A deadline, recurrence, retry, or scheduled wake-up may decide when Work becomes eligible to continue; it cannot mint a new principal, Evidence rule, capability, or Effect grant. Model tokens, acquisition, tools, parallel cognition, artifacts, and human effort can likewise be bounded before execution rather than explained later as billing.
Indwel’s AWS reference implementation places familiar enterprise controls beneath that law. The services are replaceable implementation resources; their constitutional office is stable.
Cognito/JWT, IAM, API Gateway, and Lambda establish principal, workload authority, bounded ingress, and execution.
KMS and Secrets Manager protect cryptographic and credential material; S3 landing, quarantine, vault, and metadata boundaries separate untrusted files from governed Evidence.
GuardDuty Malware Protection for S3, DLP, classification, content inspection, and rights controls can stop or constrain material before cognition.
OpenSearch Serverless and Aurora PostgreSQL/pgvector operate under Collection and Evidence contracts rather than defining evidentiary standing themselves.
Amazon Bedrock can provide governed model execution through declared routes, model and venue admission, egress rules, and invocation authority.
EventBridge clocks, encrypted SQS dead-letter paths, cancellation, idempotency, and durable operation identity preserve Work across delay, retry, and failure.
CloudWatch, CloudTrail, GuardDuty, Security Hub, and AWS Config project operational security state without becoming a shadow store of cognition.
At the point of action
Connecting a system does not hand its credential to the model. OAuth grants, workload identities, database roles, API secrets, and customer-managed credentials remain under the adapter or execution boundary that owns them. Governed connectors, MCP servers, agents, deterministic tools, and Fieldwork receive bounded capability or custody grants; secrets remain behind the execution boundary.
The same system can be an Evidence source in one undertaking and an Effect destination in another. Principal, provider, object, operation, target, budget, and risk can therefore be scoped independently rather than treating “the connector is installed” as permission. Provider egress is governed the same way: technical reachability does not make a model or venue admissible for every act of cognition, and fallback cannot widen the authority already in force.
Tool authorisation answers whether an operation may be attempted. It does not prove the intended business result occurred. Before provider contact, Indwel binds the approved Effect, operation identity, target, and idempotency to the governed act. After contact, the post-condition is observed and reconciled before the undertaking can settle. A 200 OK, queue acceptance, or successful SDK call is therefore not automatically institutional truth.
If a connection fails after an external system may already have committed the change, the truthful state is indeterminate. Indwel reconciles against provider evidence rather than blindly retrying and risking a second Effect.
After contact with the world
Providers fail. Credentials expire. Permissions change. Requests throttle. Events arrive late or twice. External systems accept work before completing it. Indwel preserves those conditions instead of compressing them into a generic AI error.
Retries remain bounded, cancellation can propagate through retrieval, tools, and cognition, and queues or schedulers carry canonical identities and checkpoints rather than reconstructing authority from a message or wake-up event. Duplicate delivery can repeat an attempt; it cannot manufacture a second settled act. Recovery can change availability without changing the law governing the Work.
Telemetry
Operational and governance events can project toward enterprise monitoring in OCSF-oriented or OpenTelemetry-compatible forms, including environments built on Splunk, Elastic, or Microsoft Sentinel.
Prompts, Evidence, connector payloads, model outputs, and secrets remain behind their proper authority and retention boundaries. Security telemetry therefore informs the SOC without becoming an uncontrolled second copy of cognition.
Deployment
A managed Indwel environment, a dedicated estate, or a customer-controlled deployment may place the physical controls differently. The constitutional invariants do not move with them: principal before access; Evidence before reliance; authority before inference and capability; observed Effect before Settlement; receipts throughout.
Operating record
A log may show that an API was called at 10:03. The governed operating record preserves which Work and authority permitted it, which Evidence and route were in force, what operation and target were intended, what post-condition was observed, what remained indeterminate, and what ultimately settled. That distinction is part of security, not an audit afterthought.