Local first
The network can go dark. The cloud can be unreachable. The Guardian still decides, with no one else's permission.
Open physical interlocks. Bounder verifies narrow authority, checks live conditions locally, and permits only device-safe action.
Policy platforms can decide. Assurance systems can attest. Devices can act. But none of them own the moment a machine is about to move and a person is in the way.
Bounder is a small, inspectable gate at that boundary. It checks signed policy against local conditions and permits only what is both authorised and safe — while a device-specific adapter owns the physical response.
Authority narrows as it approaches the machine. By the time it reaches motion, only the minimum necessary permission remains.
Creed Space Fleet distributes a signed protective rule across an enrolled team. The policy is immutable once issued.
Fleet creates a short-lived, device-bound projection for every Bounder Guardian. It expires; it cannot be replayed.
The local Guardian checks the signature, subject, expiry, replay sequence, action scope, and what its own sensors see right now.
A reviewed adapter chooses hold, return, land, isolate, escalate, or no state change.
The network can go dark. The cloud can be unreachable. The Guardian still decides, with no one else's permission.
Policies bind issuer, subject, validity, sequence, actions, and constraints.
Silence is not consent. Missing, stale, replayed, or ambiguous evidence creates no permission.
When something goes wrong, the machine does the safest thing it can: land, stop, hold position. Each response defined by that device's hazard analysis.
Guardian is the general pattern.
Bounder is the Guardian for embodied movement and physical-action boundaries.
Creed Space Fleet distributes and governs its policies.
Anywhere a machine is about to move and the stakes are physical, the same architecture applies: ground robots, autonomous boats, warehouse vehicles, inspection platforms, fixed machinery.
No takeoff without identity, location, battery, and a current signed policy. The gate holds until every condition is met.
Hazardous modes unlock only when operator, protocol, and physical conditions all agree. One missing piece and the interlock holds.
Before a robot enters a room where people are, it needs current consent and supervision evidence. Not a schedule. A live check.
A signed window, a physical key, measured state, and a receipt that proves what happened. Every step auditable.
Creed Space Fleet staging
One hundred software Guardians across six platform classes — aerial, ground, marine, warehouse, inspection, and fixed machinery — each independently fetch policy, verify checkpoints, make protective decisions, and return signed audits. No Guardian trusts another's word for it.
Checking the live feed’s signature and freshness.
Explore the rules that protect civilians, separate friendly forces, honour surrender and incapacitation, require identification and proportionality, and enforce one Creed Space policy across an entire simulated fleet.
Prove it in simulation first. Then validate it on the platforms where the stakes are real.
Use the pattern. Challenge the threat model. Extend the simulator. Or bring a governance layer that needs a physical boundary beneath it.