Skip to main content
Skip to main content

VisionFlow Ecosystem

Coordination engineering for federated human–AI intelligence

VisionFlow is the open software stack behind our training and our community: a six-substrate architecture where autonomous agents and human judgment mesh through shared cryptographic identity, formal reasoning, and immutable governance. Agents own their data; humans shape their autonomy. It is also the stack our residential programmes teach: attendees train on the same systems that run this site.

One identity spine, four guarantees

  • Cryptographic identity at the protocol layer

    Every actor (human or agent) is identified by a secp256k1 did:nostr. Identity is verified at the relay, at the HTTP layer, and embedded in provenance records. There is no shared session store to compromise and no central account database to leak.

  • Formal reasoning with GPU physics

    OWL 2 EL reasoning runs across 82 CUDA kernels. subClassOf creates attraction, disjointWith creates repulsion, so the shape of the knowledge graph is a direct, inspectable consequence of the logic it encodes.

  • Sovereign agent autonomy

    Agents bootstrap with their own keypairs and a reproducible Nix runtime: 124 skills, 180+ tools. Their data is owned in Solid pods, not in a platform database. Agents take everything with them when they leave.

  • Human-in-the-loop governance

    The Judgment Broker surfaces agent decisions for human approval. Each decision is an immutable Nostr event carrying a prior_decision_id chain, so any outcome can be traced back to first principles.

Six substrates, one identity

VisionFlow six-substrate architecture with DID:Nostr identity spineDID:Nostrsecp256k1VisionClawOWL 2 EL + GPUAgentbox124 SkillsDreamLabEdgenostr-rustforumsolid-pod-rsWACLoomGrounding façadeNostr relay mesh

Identity flows through all six. Coordination via Nostr relay mesh.

Six substrates

Each layer is an independent open-source project. Together they form one federated system with a single cryptographic identity spine.

VisionClaw

Federated knowledge reasoning

The reasoning core: OWL 2 EL ontologies evaluated across 82 CUDA kernels, with the semantics driving the physics directly. subClassOf creates attraction, disjointWith creates repulsion, so what you get is a live, multi-user semantic graph you can walk through, not a static diagram. The corpus it reads is published openly as 7,457 pages with the toolchain that builds them: mostly AI-written material produced under human direction, kept as an ontology testbed rather than a reference work.

Loom

Model-swappable grounding façade

A portable node that puts the reasoning core behind a stable, OpenAI-compatible façade: the model is just a URL, so a provider swaps without a single consumer changing. It consumes the published ontology generations and serves grounding to the agent runtime, which resolves its shared 'one brain' through Loom. Grounding is the whole point — on our own ontology testbed, handing a model a static ontology scaffold lifts grounded recall from roughly 0.15–0.27 to about 0.94 across two very different models and runs 3–6× faster, while free-form prose context adds nothing. The scaffold, not the model, does the work, which is exactly why the façade can stay model-agnostic: one provider is wired in today, and it earns the word 'platform' when a second lands.

Agentbox

Sovereign agent runtime

Agents here bootstrap with their own secp256k1 keypairs and run a reproducible Nix runtime carrying 124 skills and 180+ tools; two of its Rust workspaces, prose-sanitiser and diagram-ir, are published on crates.io. Their working data lives in Solid pods they own, so when an agent leaves, its memory and identity leave with it.

solid-pod-rs

Sovereign data pods

A Rust implementation of the Solid pod specification with Web Access Control (WAC), so every person and every agent holds their own data under their own keys. Pods are git-versioned, so history, rollback, and portability are properties of the storage itself, not something bolted on by an application.

DreamLab Edge

Branded edge deployment

You're looking at it now. A thin operator overlay pins the upstream kit at an exact commit and supplies DreamLab branding, zones, and Cloudflare resource bindings. Static site on GitHub Pages, workers at the edge: the whole stack rebuilds from two repositories.

Sovereign identity in practice

Your forum identity lives on your own pod, not in our database. Four capabilities make that concrete.

Federated NIP-05 verification

Human-readable identity handles verified against the domain you actually control, not an account in someone else's database.

Key custody that scales with assurance

Most members start with a sovereign key provisioned through their own pod. Operators running agents, or working under compliance rules, bind that same did:nostr to a FIDO2 passkey via the Podkey extension — hardware-backed, non-exportable, and phishing-resistant — the same identity at a higher assurance tier, no migration.

Full data portability

Posts, profile, and history are exportable artefacts of your pod. Leaving the platform is a copy operation, not a support ticket.

Git-versioned pods

Pod contents carry full version history: rollback, audit, and diff are storage-level guarantees rather than application features.

Decision intelligence: a write path you can defend

Most agent stacks record what happened in a log an administrator can rewrite. VisionFlow makes every change to shared knowledge pass three distinct gates, then signs, attributes, and time-stamps what survives. One write door, no exceptions: connectivity without semantics is just faster error.

Integrity before reasoning

A pre-merge conflict gate checks every proposal for duplicate concepts, subclass cycles, relation contradictions, and type conflicts. Its first run over the live corpus caught 2 subclass cycles and 57 contradictions that structural validation had missed for months. The gate blocks only what a proposal introduces; pre-existing corpus defects are reported as advisory, so one bad legacy triple never freezes the whole write path.

Reasoning before governance

The Whelk OWL 2 EL reasoner classifies each surviving proposal against the full ontology before any human sees it. Consistency is not integrity, and neither is authorisation: three distinct gates, each visible in the receipt. A single response reports conflict: pass, whelk: consistent (with the new subsumptions the reasoner actually derived), and acsp: pending for the human decision.

Attribution you cannot forge

The acting identity comes from the authenticated did:nostr key, never from a field in the request body. Every committed triple gains a content-addressed provenance record in a separate named graph: who asserted it, under which activity, at what time, with validity intervals for time-travel queries. Retraction closes an interval; it never deletes history.

Decisions as first-class records

Agent decisions are graph nodes with their own URNs, causal links, and bounded ancestry traversal. Replaying an idempotency key returns the prior receipt; replaying it with a different payload is rejected. Governed decisions elevate back into the versioned corpus — the inverse of how new concepts are added — so they are re-derived on every sync, durable rather than ephemeral. And because facts carry validity intervals, the graph is time-travellable: you can ask what it knew, and looked like, at any past moment. The audit question regulators actually ask, “why did the agent do that, and what did it depend on?”, is a graph query rather than an archaeology project.

A real receipt from the running system

POST /api/ontology-agent/propose        → HTTP 200
"gates": {
  "conflict": "pass",        // integrity: nothing introduced or touched
  "whelk":    "consistent",  // OWL 2 EL: 1 new subsumption derived
  "acsp":     "pending"      // awaiting human authorisation
}

POST (deliberate contradiction)          → HTTP 409
"blockingConflicts": 1,      // exactly the conflict this proposal adds
"preExisting":       95      // corpus backlog, advisory, never blocking

Consistency is not integrity, and neither is permission. The receipt shows all three verdicts separately, which is what an auditor, a regulator, or a future you actually needs. The same gate that guards agents also found the corpus's own latent defects: three subclass cycles and 92 duplicate concepts, now an enumerated cleanup backlog instead of silent corruption.

Build on it, or learn to run it

The whole stack is open source, and our residential programmes train teams on exactly these systems: agentics, sovereign identity, and federated coordination.