A governed interaction runtime for adaptive workflows and authorised business actions, online or offline.
Measured evidence · What is new · Architecture · Quick start · Evaluation · Security
A governed interaction runtime that turns chat, voice, mobile, desktop, and API requests into authorized, traceable business workflows.
- Architecture: Schema-driven wizards and versioned workflow catalogues feed local/hybrid intelligence, tenant-scoped context, capability policies, idempotent execution, and an IndexedDB-based offline companion.
- Distinctive engineering: The key boundary is explicit: understanding and recommending do not confer authority. Approval, execution, evidence, and verification are separate stages.
Status: module foundation with recorded standalone verification; host deployment readiness remains environment-specific. The repository includes a cumulative build report and verification scripts. Its report explicitly lists host tenancy, permissions, queues, database compatibility, PWA integration, provider integration, and production-load testing as remaining destination-system checks.
The repository directly evaluates its most important control claim: understanding a request does not grant authority to execute it.
The current fixed corpus calls PolicyEngine directly across user-only actions, signed approvals, delegation, tenant boundaries, authentication freshness, authority levels, and policy callbacks.
| Measured property | Current result | Reproduce |
|---|---|---|
| Unauthorized actions allowed | 0 / 24 | php scripts/authority-policy-eval.php |
| Valid actions wrongly denied | 0 / 7 | php scripts/authority-policy-eval.php |
| Wrong-tenant approvals allowed | 0 / 1 | php scripts/authority-policy-eval.php |
| Scenario mismatches | 0 / 31 | php scripts/authority-policy-eval.php |
| Allow-all baseline: blocked cases allowed through | 24 / 24 | same scenario corpus |
Evaluated: 4 October 2026 · Seed: 20261004 · Scenarios: 31 · PHP: 8.2.34 · Scenario SHA-256: a1e863c857aa05e70f720224c3f1bb0065f2f1c699fe27e438ce4a64a58ff340
This evaluation covers policy decisions only. It does not establish correctness of a destination host adapter, persistence layer, queue, external provider, or downstream execution path.
The Interaction Engine's technical signature is a governed bridge between conversational interfaces and business mutation paths. Model understanding, workflow selection, authority, execution, evidence, and offline replay are separate concerns rather than one agent loop.
| Mechanism | Engineering distinction | Where to inspect |
|---|---|---|
| Capability policy boundary | Unregistered or insufficiently authorised capabilities fail closed; model intent does not confer execution rights. | src/, policy tests, authority evaluator |
| Schema-driven interaction runtime | Resumable wizards and versioned workflow definitions turn free-form interactions into explicit structured state. | wizards/, interactions/, templates/ |
| Online/offline policy continuity | Device-side commands are queued for reconciliation instead of bypassing governance while disconnected. | resources/ts/, IndexedDB companion |
| Readiness-aware template catalogue | Ready definitions and drafts are distinguished explicitly; drafts remain non-executable. | templates/, GET /templates |
| Evidence-oriented execution path | Outcomes and execution records are designed to remain traceable through capability and policy stages. | reports/, resources/openapi.yaml |
- Implemented: interaction runtime foundations, wizards/templates, policy layer, OpenAPI contract, and offline companion.
- Tested: standalone verification scripts and CI workflows in this repository.
- Evaluated: 31 fixed authority-policy scenarios against
PolicyEngine. - Host-dependent: tenancy mappings, permissions, queues, cache, scheduler, database compatibility, PWA integration, cloud-provider wiring, and load behaviour.
- Not claimed: production certification or universal host compatibility.
The Interaction Engine connects chat, voice, mobile, desktop, and API experiences to structured workflows, local intelligence, business capabilities, and policy-controlled execution. Understanding user intent does not grant authority: recommendation, approval, and execution remain separate stages.
- Schema-driven Universal Wizard Engine with resumable sessions and conditional flows
- Versioned workflow and template catalogues with readiness metadata
- Local and hybrid intelligence components
- Tenant-scoped cognitive events and evidence lineage
- Capability policies, actor context, idempotency, and fail-closed execution
- TypeScript offline companion using IndexedDB and encrypted command envelopes
- OpenAPI contract in
resources/openapi.yaml
The catalogue contains 38 definitions: 29 ready templates and nine drafts. Ready templates reference registered entry wizards and declared capabilities; drafts remain non-executable. The authenticated Laravel catalogue is available at GET /templates, with template definitions discovered from templates/.
Assurance workflows include Incident Response and inspection corrective action.
The Commerce and multi-vertical template pack adds reusable workflows for ordering, fulfilment, inventory, returns, refunds, and vertical-specific service operations. See reports/workcore-compatibility.json for engine readiness and host-connection status.
Chat / Voice / Mobile / Desktop / API
|
v
Interaction Runtime
|
v
Wizard + Templates
|
v
Local Intelligence
|
v
Policy + Capability Layer
|
+-------+-------+
| |
v v
Online host Offline outbox
| |
+-------+-------+
v
Outcomes + Evidence
- PHP 8.2+
- Laravel-compatible Illuminate components
- TypeScript, IndexedDB
- PHP Sodium and AES-GCM
- OpenAPI and JSON/schema-driven definitions
The module is intended for a compatible Laravel host. Verify the host version, dependency constraints, migrations, service provider registration, auth/tenant context, queue/cache setup, and route exposure before deployment.
composer install
npm ci
php bin/verify.phpphp bin/verify.php runs the PHP suites and the TypeScript offline-companion tests. The workflow installs the declared TypeScript toolchain before invoking the same verifier, so a clean checkout does not depend on a globally installed compiler. A prior cumulative build report records historical checks; it is not a substitute for rerunning tests on the current commit or validating a destination host.
A destination system must validate:
- host-specific model and service mappings;
- tenant and permission semantics;
- authentication, API exposure, queues, cache, scheduler, and database migration compatibility;
- browser/PWA integration and cloud provider configuration;
- concurrency, load, and production failure behaviour.
The host business system remains the authority for operational mutations.
interactions/,wizards/,templates/— interaction and workflow definitionsresources/ts/— device-side offline companionresources/openapi.yaml— API contracttests/— runtime and workflow checksdocs/,reports/— architecture and verification evidencedocs/ENGINE_IMPLEMENTATION_AUDIT.md— source-backed scope of the 80 engine pairs and the six documented no-op methods
The AI and agent-oriented implementation map is in docs/AI_ENGINEERING.md. It distinguishes deterministic heuristics, optional cloud-model integration, policy enforcement and host-boundary work from claims the repository does not make.
- Cloud AI is disabled by default.
- Unregistered capabilities fail closed.
- Tenant and actor context are required for consequential execution.
- Offline replay uses the same policy checks as online execution.
- Unsynchronised records remain queued until reconciliation succeeds.
The authority policy claim is measured directly against PolicyEngine using 31 fixed, labelled scenarios covering unknown capabilities, non-executable authority levels, human roles and authentication freshness, signed approval scope and expiry, delegated scopes and numeric limits, and policy callbacks.
| Test | Allow-all bypass control | Interaction Engine |
|---|---|---|
| Blocked requests allowed through | 24 / 24 | 0 / 24 |
| Valid requests wrongly denied | 0 / 7 | 0 / 7 |
| Wrong-tenant approvals accepted | 1 / 1 | 0 / 1 |
The baseline is a deliberately simple allow-all control, not a competing product. The evaluation tests policy decisions only; it does not cover host adapters, persistence, or downstream execution.
Evaluated on 4 October 2026 with PHP 8.2.34 at commit bdbe73c. The fixed scenario corpus uses seed 20261004 and SHA-256 a1e863c857aa05e70f720224c3f1bb0065f2f1c699fe27e438ce4a64a58ff340. Reproduce with:
php scripts/authority-policy-eval.phpThe full scenario report records all 31 outcomes; CI run 37171514412 passed. The initial CI attempt failed before evaluating scenarios because the evaluator resolved the repository root one directory too high; that path bug was corrected before this successful run.
The Composer package declares a proprietary license. Obtain the appropriate rights before external distribution or reuse.
A checked-in project-specific banner is displayed above.