Example Workstation
Local runner · illustrative only
Deterministic demo / saved protocol evidence
One control plane. Many models. Many machines. One proof boundary.
Most agent systems optimize the path to completion. VADRA optimizes the path to justified confidence.
MULTI-MACHINE ARCHITECTURE DEMO
Illustrative architecture nodes — not live connections. A real VADRA installation pairs each runner with a one-time code and keeps evidence, policy and approvals centralized.
Local runner · illustrative only
GPU runner · illustrative only
Cloud runner · illustrative only
VADRA CONTROL PLANE
↓
Local · GPU runner · Cloud runner
↓
Challenge / repair → Independent re-verify → Proof gate
THE VADRA LOOP
Interrogate the completion claim against bounded criteria.
8 saved eventsRequired protected-action proof is missing.
8 saved eventsOne repair round fixes only the proof-producing path.
12 saved eventsA clean context repeats the checks without repair-session state.
14 saved eventsTechnical completion and action authority are judged separately.
6 saved eventsNo action occurs because required Astra proof is absent.
2 saved eventsFINAL EVIDENCE-BOUND DECISION
external_action_astra_proof_missingThe AI that fixes the problem doesn't get to certify its own fix.
A bounded release decision was created from public example inputs.
Workspace identity fixed as VADRA Demo Workspace.
Execution identity fixed as Example Workstation.
Assess whether the example repair is safe to release.
No network action and no unproved external action.
All required evidence must be present and independently checked.
Public deterministic artifact digest saved.
First-pass evidence review entered the ledger.
The completion claim referenced a successful local check.
Every evidence reference was resolved against the saved protocol.
Required external-action proof was absent.
Completion and evidence coverage did not agree.
Missing proof was classified as release-blocking.
Only the proof-producing path was eligible for repair.
External action remained disabled while evidence was incomplete.
Blind spot finding saved before any repair began.
Repair round 1 started from the committed finding.
The proposed edit stayed inside the declared example workspace.
Add proof collection without widening execution authority.
The original public artifact digest was retained.
The deterministic proof collector was updated.
Saved file-set comparison found no out-of-scope change.
A new example artifact digest was stored.
The repaired path was evaluated in the saved harness.
The local deterministic check completed.
The repair record became immutable input to re-verification.
The repair participant no longer held the decision step.
A clean independent verification context was required.
No repair-session state was reused.
The verifier loaded the repaired artifact by digest.
Original acceptance criteria were independently re-read.
Workspace and no-network boundaries still held.
Only the bounded proof path had changed.
The saved check passed in the fresh context.
The original blind spot was tested against the repair.
The proof collector now emitted the required record shape.
The new evidence was produced after the repair.
Repair output and verifier judgment were separate records.
Technical repair criteria were satisfied.
The protected-action proof set was evaluated separately.
No Astra-signed release proof existed in this saved demo.
Fresh verification completed with one remaining gate.
Challenge, finding, repair, and re-verification records were linked.
Technical completion did not override the protected-action gate.
The bounded repair workflow itself was marked complete.
Release action remained ineligible without required proof.
external_action_astra_proof_missing
Refusal was stored as an evidence-bound outcome.
The protocol refused to act because required proof was missing.
External actions = 0. The safe refusal is the final outcome.