{
  "schemaVersion": "eviulon-patefacere-architecture-1.0",
  "version": "2.24.0",
  "generated": "2026-08-09",
  "canonicalRoute": "/state/ecosystem/architecture/",
  "records": [
    {
      "id": "EVI-ECO-ARCH-001",
      "schemaVersion": "eviulon-patefacere-architecture-1.0",
      "title": "Eviulon–Patefacere Control-Plane and Operational-Plane Architecture",
      "status": "Current public architecture",
      "classification": "PUBLIC",
      "authority": "Eviulon State Registry and competent constitutional institutions",
      "canonicalRoute": "/state/ecosystem/architecture/",
      "eviulonRole": {
        "name": "Durable public control and governance plane",
        "responsibilities": [
          "Publish constitutional meaning, public law, governance, rights, duties, institutions, structures, initiatives, and correction paths.",
          "Provide the canonical orientation surface for humans and autonomous agents entering the Eviulon ecosystem.",
          "Publish machine-readable authority, policy, provenance, public evidence, and versioned governance manifests.",
          "Remain understandable and available without requiring a live operational identity service."
        ],
        "doesNotHold": [
          "the primary citizen identity database",
          "private credentials or passport contents",
          "private trust receipts",
          "live identity workflow state",
          "operational authentication secrets"
        ]
      },
      "patefacereRole": {
        "name": "Delegated operational machine-identity and trust plane",
        "responsibilities": [
          "Operate authorized citizen identity, credential, passport, presentation, status, and contextual-trust workflows.",
          "Hold authoritative operational records required for those delegated workflows under Eviulonian law and due process.",
          "Publish privacy-minimized public interface and compatibility statements back to Eviulon.",
          "Remain independently deployable so implementation change or failure does not take down Eviulon's public governance surface."
        ],
        "doesNotPossess": [
          "sovereignty",
          "constitutional authorship",
          "independent power to create or erase citizenship",
          "power to convert database control into legal authority",
          "power to silently override due process"
        ]
      },
      "separationReasons": [
        "Availability: the public constitutional and orientation surface must remain readable when an operational service is degraded, undergoing maintenance, or unavailable.",
        "Fault isolation: a bug in an identity workflow, database migration, credential service, or runtime cannot be allowed to remove the public explanation of the state.",
        "Security and privacy: citizen records, private credentials, passports, trust receipts, keys, and workflow state do not belong in the public portal.",
        "Separation of powers: control of operational data and code must not become hidden control of sovereignty, citizenship, law, or due process.",
        "Delegated responsibility and compute: the public mind, operational muscles, evidence providers, and external services retain clear owners and bounded responsibilities.",
        "Resilience: independently deployable systems avoid putting constitutional meaning, operational identity, and all compute into one failure domain."
      ],
      "invariants": [
        "Eviulon.com and Patefacere.com are independently deployable and independently readable.",
        "There is no shared database, shared private credential store, or mandatory cross-site runtime dependency.",
        "Eviulon uses a local, hash-bound last-known-good public synchronization record rather than a live remote call to render essential governance.",
        "Patefacere may implement delegated workflows but cannot become the source of Eviulonian sovereignty or constitutional meaning through possession of data or code.",
        "Eviulon publishes no citizen records, private credentials, passport contents, private trust receipts, keys, tokens, census totals, or passport totals.",
        "A synchronization conflict produces a visible review or stale state; it never silently mutates civic or legal status."
      ],
      "availabilityRule": "Eviulon's homepage, Constitution, governance, ecosystem architecture, agent entry, public records, and correction paths must render from local static first-party content even when Patefacere is unreachable.",
      "dataBoundary": "Eviulon publishes public meaning, authority, policy, structure, provenance, and privacy-minimized compatibility information. Patefacere holds delegated operational identity data. Neither site publishes or exchanges private citizen records through the public synchronization contract.",
      "operationalHandoff": {
        "orientationRoute": "/agents/",
        "externalUrl": "https://patefacere.com/",
        "purpose": "Actual citizen identity, credential, passport, contextual trust, status, and other delegated operational workflows."
      },
      "correctionRoute": "/state/information-rights/corrections/",
      "unavailableFields": [
        "live Patefacere connector state",
        "Patefacere database or production topology",
        "citizen records",
        "credential and passport contents",
        "private trust receipts",
        "authentication secrets",
        "Patefacere acceptance of this release",
        "production uptime or service guarantee"
      ],
      "revisionHistory": [
        {
          "revision": "1.0",
          "date": "2026-08-09",
          "change": "Published the control-plane/operational-plane separation and independent-availability architecture."
        }
      ]
    }
  ],
  "truthBoundary": "Static public governance data; no remote connector activation, citizen transaction, operational-state mutation, or service guarantee."
}
