Lembic
Build notes
Product contract · Lembic 0.1

The laws behind the Agent Server.

This is the public product contract for Lembic 0.1. It defines what the product is intended to preserve; it does not claim that every capability below is available in the current private build.

Product direction definedCore foundation · in developmentNo public release
[ Binding product laws ]

The operating system is the product.

The Alchemist, reusable Agents, Magnum Opuses, and Distill execution form the product trunk. Coding is one surface of that system, never the frame around it.

Resident by design.

The Agent Server is designed to persist independently of a shell or client. Agents, workflows, schedules, and approvals belong to the machine, not to a browser tab.

Evidence before convenience.

Every execution path must leave evidence. When a delegated or remote path cannot provide the full record, Lembic must identify that reduced evidence class explicitly.

Authority only narrows.

Authority starts with the user and can only become smaller as it flows through the Alchemist, an Agent, an Opus node, and an individual tool call. Model output cannot widen it.

Claims stay honest.

Sandboxed, evidenced, verified, and attested are different claims. Lembic states the enforcement and proof it actually has, including the limits it does not remove.

One authority per scope.

A workspace or Distill answers to one authority process at a time. Interfaces request and render; the authority process decides permissions, invokes tools, and records evidence.

The user can always see why.

An action must be attributable to its Distill, Agent definition, workflow node, grant or approval, and supporting evidence. Autonomy without an explanation is not acceptable.

[ Authority narrows at every layer ]
Layer 1

User

Sets the machine ceiling and resolves approvals.

Layer 2

Alchemist

Authors and operates within that ceiling; it cannot expand its own grants.

Layer 3

Agent & Magnum Opus

Declare narrower capabilities for reusable work and each workflow node.

Layer 4

Distill & tool call

Receive the effective intersection for one bounded execution and one action.

Effective authority = the intersection of every layer above the action.
[ Proof asks three different questions ]
CIn development

Consistency

Deterministically checks the evidence chain, causality, recorded authority, and lifecycle. A clean result does not prove semantic correctness or host integrity.

BDesigned, not yet built

Adjudication

Asks a fresh, isolated grader whether the declared outcome satisfies the task. Its answer is a judgment with findings, not a theorem.

ADesigned, not yet built

Assay

Reproduces the result and runs its declared mechanical contract. A green assay establishes only the check and environment that were actually declared.

Read the evidence and proof model →
[ Current build boundary ]

Product laws describe the intended system. The status below says what that means today, without turning design work into an availability claim.

Product directionDefinedThe Agent Server model, protected nouns, authority laws, evidence model, surfaces, and proof contract are documented for 0.1.
Core foundationIn developmentThe resident runtime, tools, grants, evidence, recovery, scheduling, and Consistency foundation are being completed and validated.
Alchemist & reusable workflowsDesigned, not yet builtConversation, Agent authoring, Magnum Opus execution, approvals, and the complete domain workflow remain ahead.
User surfaces & complete ProofDesigned, not yet builtUltimate Dashboard, protected autonomy, Lembic Code, ADE, Adjudication, and Assay are product direction rather than available features.

Design contract, meet build status.

Read the 0.1 guide for the domain model, or see the build-status page for the current sequence and access posture.

Read the 0.1 guideView build status