THE ARCHITECTURE
One execution path. Several explicit owners.
- Ares owns
- Governed final context materialization, staged runtime release construction, local runtime selection, and bounded projections from policy, memory, and graph-obligation owners.
- Recursive Agent owns
- Managed physical admission, cumulative budgets, queue/lane accounting, cancellation fencing, native provider-egress bindings, receipt chains, and typed submit/status/verify paths.
- What stays external
- Policy basis, semantic-memory authority, and Agent Graph obligation semantics remain owned by their declared systems. Ares carries bounded evidence and references; it does not mint their authority.
- Why this matters
- A model call can be tied to the exact rendered request, source revision, context digest, policy basis, graph obligation, route class, provider identity, model, token budget, and expiry without using those bindings as a substitute for authorization.