A constitutional control plane for AI agents.
arifOS evaluates identity, evidence, authority, risk, and reversibility before an AI agent may execute a consequential action.
It does not execute actions itself. It returns an auditable verdict:
- SEAL — authorized under stated conditions
- HOLD — insufficient evidence or human approval required
- SABAR — proceed cautiously, partial authorization
- VOID — blocked by a constitutional floor
Try the safe demo ·
Connect through MCP ·
The agent that acts is not allowed to certify its own action.
DITEMPA BUKAN DIBERI. Forged, Not Given.
arifOS is a Model Context Protocol server that sits between an AI agent's intent and the action it wants to take. It enforces 13 constitutional floors — non-negotiable rules about truth, reversibility, humility, auditability, and human authority.
When an agent calls arif_init, arifOS binds a session, activates the floors, and routes the agent through a governed loop: observe evidence, think under constraints, dispatch to the right organ, recall governed memory, receive a constitutional verdict, execute (if authorized), and seal the result.
When an agent's evidence is thin, risk is high, or an irreversible action is proposed — arifOS returns HOLD. A HOLD is not a failure. It is a fence.
What arifOS does not do:
- It does not execute actions (A-FORGE executes; arifOS judges).
- It does not wrap an LLM (it governs any agent that speaks MCP).
- It does not replace human judgment (F13 = human veto is final).
arifOS exposes 8 verbs on its public MCP surface. Each verb corresponds to a station in the 000–999 authority ladder.
| Station | Verb | What it does |
|---|---|---|
| 000 | arif_init |
Bind session, activate floors, mint token |
| 111 | arif_observe |
Sense reality — search, fetch, vitals, entropy |
| 333 | arif_think |
Structured reasoning under F2/F7 constraints |
| 444 | arif_route |
Dispatch intent to the correct organ |
| 555 | arif_memory |
Governed recall, store, revise (L1–L6) |
| 666 | arif_judge |
Constitutional verdict: SEAL / HOLD / SABAR / VOID |
| 777 | arif_forge |
Governed execution (post-SEAL, lease-gated) |
| 999 | arif_seal |
Immutable append to VAULT999 ledger |
Canonical stage assignments live in
tools_sot.yaml, sourced fromconstitutional_map.py. If prose and code disagree, code wins.
These are checked on every governed action. They are the physics of the kernel.