# AI execution architecture

Deterministic programs first, single agents first; only complex tasks add specialist roles and multi-model collaboration. Permissions are checked before a call and evidence after the run.

> Document ID: MYRILUM-DOC-ARCH-005
> Document type: concept
> Product: NOT_APPLICABLE
> Version: 0.1.0
> Region: GLOBAL
> Visibility: PUBLIC
> Publication: PUBLISHED_GLOBAL
> Content maturity: VALIDATED
> Governance: APPROVED
> Capability state: IN_DEVELOPMENT
> Availability: NOT_AVAILABLE
> Authorization: PUBLIC_INFORMATION
> Freshness: CURRENT
> Safety class: INFORMATIONAL
> Owner: Web3Capital Documentation Steward
> Approvers (assignment only; not approval evidence): Stephen
> Canonical authority: SRC-ARCHITECTURE-ATLAS-V2-2
> Source commit: 882487dec08bc4ca204510e166217478fa8f68ec
> Content digest: 9612de086c7746d168415889f77e4329d86268ac311ffa3296ea5c129be7751e
> Effective: NOT_SET
> Expires: NOT_SET
> Last verified: 2026-09-23
> Review due: 2026-10-23
> Command authority: NONE
> Canonical URL: /en/architecture/ai-execution

<a id="overview"></a>

## What this map shows

![AI execution architecture diagram (A05)](/figures/atlas-v2-2/A05.png)

*MYRILUM architecture map v2.2 · A05 (public edition). Labels are in Chinese; every element is listed in English below. Select the diagram to open it at full size.*

This is MYRILUM's target architecture. It does not mean everything on the map is live; whether a capability can be used today is stated in “Current availability”.

Deterministic programs first, single agents first; only complex tasks add specialist roles and multi-model collaboration.

Permissions are checked before a capability is called and evidence after the run ends; a model can claim neither for itself.

<a id="part-1"></a>

## Execution inputs and boundaries

| Field | Value |
|---|---|
| Work order | Input references, output standards, task version and dependencies |
| Scoped authorization | Tool allowlist, data permissions, recipients and validity period |
| Budget and time | Reserved credits, call limits and deadline |
| Check contract | Artifact format, evidence requirements, and failure and stop conditions |

> **Not one super-brain** — Scheduling, permissions, budgets, ledgers and state recovery cannot rest on a single master prompt or chat context.

<a id="part-2"></a>

## Processes and run instances

| Field | Value |
|---|---|
| Workflow | Deterministic steps, branches, waits and recovery |
| Agent definition | Role, skills, model policy and version |
| Agent runtime | State, context, leases, attempts and checkpoints |
| Professional human task | A clear task sheet, deadline, handoff and acceptance |

> **Definitions and runs are separate** — One agent definition can run many times, and one model can serve different agents; every run must be traceable on its own.

<a id="part-3"></a>

## Capabilities through unified gateways

| Field | Value |
|---|---|
| Model gateway and routing | Weighs quality, cost and latency among permitted candidates |
| Tool gateway | Parameter contracts, authorization, idempotency and side-effect control |
| Controlled knowledge and memory | Scoped at recall; permissions are checked again before returning |
| Remote execution adapters | API / MCP / A2A; a protocol never replaces the business contract |

> **Models and tools are replaceable** — Providers connect through adapters; switching remains bound by data, region, budget and authorization.

<a id="part-4"></a>

## Results enter the business loop

| Field | Value |
|---|---|
| Call and usage receipts | Provider request identifiers, versions, resource amounts and exceptions |
| Candidate results | Content, data, files and source references |
| Verification and risk checks | Failures go back for revision; major uncertainty goes to a person |
| Controlled state commit | Domain rules commit; models never write official facts directly |

> **No partnership claims** — This map fixes no specific model, cloud or payment vendor; a component on the map is not necessarily integrated, authorized or live.

<a id="source"></a>

## Source

This page follows A05 of the MYRILUM architecture map v2.2 (public edition: restricted products and internal open items are left out).

---

This document is read-only, grants no command authority, and does not authorize deployment, payment, provider modification, or any other real-world action.
