Codex OS Modules

The structural components of evidence‑driven execution.

Freeze Gate

The admissibility surface. Validates authority, governing conditions, invariants, and applies disposition (ALLOW / HOLD / ESCALATE / REFUSE), emitting structural receipts.

Consequence Boundary

The point where execution becomes real. Crossing consequence requires a scoped, unforgeable, freshness‑bound capability. If the capability is absent, the action did not occur.

Evidence Plane

Append‑only, non‑runtime‑writable, non‑admin‑writable, externally attestable. Stores execution receipts, governance receipts, structural violations, and diagnostic events.

Authority Object

Versioned governance object defining admissible envelope, governing conditions, invariants, and external constraints. Cannot authorize execution itself.

Diagnostic Engine

Captures substrate‑level state changes that affect admissibility. Produces diagnostic events, freshness‑bound evidence, and state‑change artifacts.

Capability Issuer

Issues consequence capabilities bound to authority version, admissibility evaluation, disposition, time, and scope.

Verifier Interface

Allows external parties to reconstruct what was allowed, narrowed, refused, crossed consequence, or never occurred.