For architects & senior engineers

How Operon Works.

From intent to governed output. A deterministic compilation pipeline with no LLM in the compiler, and a multi-tier governance architecture built into the runtime.

Intent → governed output

Six stages. Each one produces a typed, signed artifact.

The chain is deterministic, reproducible, and diff-able in CI. No LLM appears in the compile pipeline. LLMs help in authoring; production artifacts are typed, validated, and reproducible.

Six-stage execution pipeline
The six stages, in detail

What actually happens between "describe what you want" and "the agent acts."

STAGE 01

Intent.

A user describes intent through any authoring surface: natural language, the visual canvas, Markdown, or a direct DSL edit. NL2Operon translates natural language into structured intent. The visual canvas captures graph-shaped intent. Either way, the output of this stage is a typed Intent Specification.

→ Output: Intent Specification
STAGE 02

Compile.

The deterministic compiler transforms Intent Specifications into typed runtime artifacts: ADL (agents), PDL (processes), FDL (forms), RDL (reports), CDL (cognition), QDL (quality). The compiler runs in CI. The same input always produces the same output. There is no LLM at this stage.

→ Output: Compiled Artifacts (ADL/PDL/FDL/RDL/CDL/QDL)
STAGE 03

Policy bind.

Policies, declared in OPA/Rego, are evaluated against each artifact and bound as enforceable constraints that travel with the code into production. A policy is not a wiki page. It is code, attached to the artifact, version-controlled and reviewable.

→ Output: Policy-Bound Artifacts
STAGE 04

Sign & attest.

Each policy-bound artifact is cryptographically signed at build time. Provenance and integrity are independently verifiable. The signature includes the compile inputs, the policy bindings, and the build environment.

→ Output: Signed Artifacts
STAGE 05

Verify.

At runtime, before any agent acts, the runtime verifies the signature, re-checks policy against current context (which user, which tenant, which data), and validates permissions. If any check fails, the agent does not act.

→ Output: Verified & Authorized
STAGE 06

Governed execution.

Only after verification does execution begin, with every decision logged to the immutable Evidence Data Trace (EDT), every constraint violation escalated, every agent operating under a declared authority ceiling. Governance isn't bolted on top. It is the architecture.

→ Output: Executed with Full Audit (EDT)
Governed Distribution Infrastructure

Three tiers of authority. One unified policy model.

Operon's governance model separates the policies the platform vendor enforces, the policies an operator defines for all their tenants, and the policies a tenant configures for themselves. Each tier composes; tenants cannot override operator constraints; operators cannot override platform invariants.

TIER 0

Platform Invariants

The unbreakable rules. Cryptographic signing, EDT immutability, the type system. Cannot be disabled, even by an operator.

TIER 1

Operator Artifacts

Policies the operator (you, the enterprise) sets across all your tenants: data classification, model allow-lists, residency rules, escalation matrices.

TIER 2

Tenant Customizations

Policies a tenant configures within the operator envelope: team-level approvals, custom skills, agent budgets.

Architecture in one paragraph

If you only read one section, read this one.

Operon is a three-plane platform. The Builder Plane lets anyone author intent in any surface and compiles it deterministically through six DSLs. The Runtime Plane executes the resulting artifacts across vendors and environments under unified routing, fallback, and orchestration. The Control Plane enforces policy at the semantic call boundary (before any model call, tool invocation, or external write) and emits a signed, queryable Evidence Data Trace. Governance is not a layer between the three planes. It runs vertically through all of them, from authoring through deployment, in your trust boundary, on your terms.

See the architecture → Score your estate

See the runtime against your own platform mix.

A 45-minute architecture review: we map Operon onto the agent platforms you already run, and you leave knowing what adopting it would actually take. Or score your estate first, in your browser, before you talk to anyone.