Decision intelligence: a write path you can defend
Most agent stacks record what happened in a log an administrator can rewrite. VisionFlow makes every change to shared knowledge pass three distinct gates, then signs, attributes, and time-stamps what survives. One write door, no exceptions: connectivity without semantics is just faster error.
Integrity before reasoning
A pre-merge conflict gate checks every proposal for duplicate concepts, subclass cycles, relation contradictions, and type conflicts. Its first run over the live corpus caught 2 subclass cycles and 57 contradictions that structural validation had missed for months. The gate blocks only what a proposal introduces; pre-existing corpus defects are reported as advisory, so one bad legacy triple never freezes the whole write path.
Reasoning before governance
The Whelk OWL 2 EL reasoner classifies each surviving proposal against the full ontology before any human sees it. Consistency is not integrity, and neither is authorisation: three distinct gates, each visible in the receipt. A single response reports conflict: pass, whelk: consistent (with the new subsumptions the reasoner actually derived), and acsp: pending for the human decision.
Attribution you cannot forge
The acting identity comes from the authenticated did:nostr key, never from a field in the request body. Every committed triple gains a content-addressed provenance record in a separate named graph: who asserted it, under which activity, at what time, with validity intervals for time-travel queries. Retraction closes an interval; it never deletes history.
Decisions as first-class records
Agent decisions are graph nodes with their own URNs, causal links, and bounded ancestry traversal. Replaying an idempotency key returns the prior receipt; replaying it with a different payload is rejected. Governed decisions elevate back into the versioned corpus — the inverse of how new concepts are added — so they are re-derived on every sync, durable rather than ephemeral. And because facts carry validity intervals, the graph is time-travellable: you can ask what it knew, and looked like, at any past moment. The audit question regulators actually ask, “why did the agent do that, and what did it depend on?”, is a graph query rather than an archaeology project.
A real receipt from the running system
POST /api/ontology-agent/propose → HTTP 200
"gates": {
"conflict": "pass", // integrity: nothing introduced or touched
"whelk": "consistent", // OWL 2 EL: 1 new subsumption derived
"acsp": "pending" // awaiting human authorisation
}
POST (deliberate contradiction) → HTTP 409
"blockingConflicts": 1, // exactly the conflict this proposal adds
"preExisting": 95 // corpus backlog, advisory, never blockingConsistency is not integrity, and neither is permission. The receipt shows all three verdicts separately, which is what an auditor, a regulator, or a future you actually needs. The same gate that guards agents also found the corpus's own latent defects: three subclass cycles and 92 duplicate concepts, now an enumerated cleanup backlog instead of silent corruption.