Turning Statutory Law into Kinetic Infrastructure
Flow360 is the outward-facing execution muscle of the onePOI.online System of Orchestration (SoO). Positioned as the kinetic router of the platform's Executive Branch, Flow360 is structurally and memory-isolated from the scheduling and authorisation mechanics managed by the Gatekeeper.
Its single, non-negotiable operational mandate is to take a pre-verified, cryptographically unlocked Actuator DAG and map its abstract logical nodes onto physical networks, multi-cloud clusters, and edge hardware with bit-for-bit mathematical certainty. Flow360 is the physical hand that executes the platform's living law at wire-speed across the global estate, ensuring that physical actuation never diverges from constitutional statutes.
Engineered for Institutional Margins.
Adopted for Human Sovereignty.
Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.
How the Tenant Expands Margins
Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.
-
CapEx Pooling & No Single-Tenant Hardware
POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.
-
Zero Interchange & Flat-Fee Clearing
Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.
-
Compliance by Construction
Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.
-
Accelerated Partner Onboarding
Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.
Why the Customer Loves Using It
Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.
-
Nothing Stored to Steal
Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.
-
One Pattern, Everywhere
The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.
-
Delegated Authority, Never Escalated
Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.
-
Payments That Do Not Fail
When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.
Flow360 Runtime Manifest
Kinetic Dispatch & Flow Engine
Core Operational Capabilities
Flow360 executes high-concurrency, deterministic routing across physical and cloud networks under strict cryptographic governance, underpinning the Salient FinTech Innovation Set.
1. Omni-Directional Dispatch
Flow360 manages complex, multi-directional paths. It dispatches idempotent machine instructions to target Packaged Business Capabilities (PBCs) and physical POI Appliances (kiosks, smart lockers, card recyclers) across any network rail.
2. Idempotent Execution
Every instruction dispatched by Flow360 is inherently idempotent. In phygital edge computing, this guarantees commands – such as "dispense cash" or "issue card" – can be safely retried during network partitions without risking double-spend or record duplication.
3. Kernel-Level Circuit Breaking
Enforces non-bypassable policy hooks directly at the operating system socket layer using eBPF (Cilium/Tetragon). If an endpoint registers an error breach, the CSM flips its logical breaker state in under 100 microseconds, isolating the container at the kernel boundary.
4. Canary Deployments & Shadowing
Coordinates programmatic traffic shifting via Pulumi ResourceTransforms, partitioning live transaction streams (e.g. 99% SEPA Instant to stable nodes, 1% to Canary). Supports Request Shadowing, duplicating real payloads to sandboxed enclaves for risk-free sidecar validation.
5. Dual-Offload Encryption Mesh
Enforces mandatory encryption across the estate. The control plane optimises mutual TLS (mTLS) handshakes and KeyMESH identity lookups, while the data plane leverages WireGuard tunnels routed through eBPF sockets to handle bitemporal streams with zero user-space latency.
6. 360-Degree Telemetry Harvesting
Flow360 maintains a continuous feedback loop, capturing high-fidelity execution telemetry (raw "Glyphs") and funnelling it into the MAESTRO framework for real-time auditability and the continuous construction of the platform's Control Flow Knowledge Graph.
The Subsystem Triad of the System of Orchestration (SoO)
Within the SoO, execution is decomposed across three distinct capability blocks with rigid mathematical boundaries, preventing execution logic from ever bypassing or degrading constitutional policy.
The Constitutional Magistrate
The inward-facing security boundary and constitutional checkstop. Intercepts inbound Actuator DAGs, holds them in strict HALT until a signed DRAGON PERMIT is validated, and hydrates the runtime Intent Frame.
- Admission Control: Holds DAGs in HALT until DRAGON PERMIT validation.
- Intent Hydration: Binds runtime to parent Agreement DAG Intent Frame.
- State Validation: Refuses tokens for unmapped topological paths.
The Macro-Orchestration Core
The middle-out macro-orchestration hub. Translates authorised business intent into technical runbooks, decomposing workflows into Stanzas and Strophes while managing Contrary-to-Duty (CTD) Sagas.
- Grammar Decomposition: Decomposes playbooks into Stanzas and Strophes.
- Saga Management: Manages durable sagas and executes automatic CTD reversals.
- State Checkpointing: Commits state before and after every Stanza transition.
The Kinetic Dispatcher
The outward-facing routing and kinetic dispatch engine. Blind to legal reasoning, its mandate is operational: fast, reliable movement of data and commands across the geo-distributed infrastructure grid.
- Omni Dispatch: Dispatches idempotent instructions to PBCs and POI appliances.
- Idempotent Action: Guarantees safe retries during network partitions.
- Telemetry Harvesting: Funnels execution Glyphs into MAESTRO for auditability.
The 7-Step Lockstep Execution Handshake
This triad operates through a strict, non-repudiable 7-step handshake that guarantees Substantiated Integrity:
1. Intercept & Validate: The Gatekeeper catches the execution request, halts it, and waits for the DRAGON warrant.
2. Bind & Unlock: Upon warrant validation, the Gatekeeper hydrates the token and passes it to the Conductor.
3. Orchestrate: The Conductor manages the workflow sequencing and saga integrity.
4. Route & Actuate: Flow360 handles the kinetic dispatch, navigating the network to hit the physical edge endpoint.
5. Attest: Flow360 returns the signed evidence of the action (the Glyph), which the Gatekeeper seals into a Lawful Act Hyperedge (LAHE).
6. Commit: The LAHE is written to the immutable bitemporal ledger, closing the transaction loop.
Mitigating Core Failure Modes Across the Grid
By combining kernel-level eBPF filters, hardware attestation, and fail-closed state machines, Flow360 and the SoO triad defeat critical distributed attack vectors.
OWASP LLM06 (Excessive Agency)
Zero Executive Agency
AI models in the System of Intelligence have zero executive authority. They can only formulate non-binding Proposed Intent claims. Flow360 is physically blocked from executing unapproved calls via eBPF/XDP kernel hooks, which remain closed until Gatekeeper validates an authoritative PERMIT signed by DRAGON.
OWASP LLM03 (Supply Chain Integrity)
cATO & Dynamic PBOM
Continuous Authority to Operate (cATO) tracks dependencies via the PBOM (SBOM/HBOM/DBOM/MBOM). If a vulnerability is announced, the Event Mesh alerts Gatekeeper, which instantly invalidates the asset in cache, severs communication rails in under 100 microseconds, and refuses execution.
Network Degradation & WAN Blackout
Constitutional Island Mode
During network partition, POI Appliances enter Constitutional Island Mode. Edge orchestrators evaluate cached local Agreement DAG rules. If local evidence is insufficient to clear deontic constraints, Gatekeeper refuses execution tokens, and Flow360 blocks mechatronic relays, locking assets in a fail-closed state.
Catastrophic Tamper & Hardware Intrusion
Dynamic Bus-Impedance Defense
Motherboard trace monitoring detects physical probe attachments or voltage glitches in microseconds. Flow360 immediately triggers hardware zeroization relays (clearing SRAM keys) and mechanically locks peripheral cash cassettes while the Gatekeeper writes the terminal event receipt.
Deep Technical: Pulumi ESC ResourceTransforms & eBPF Socket-Level Filtering
Deep Technical: Pulumi ESC ResourceTransforms & eBPF Socket-Level Filtering
Flow360 translates abstract Actuator DAG definitions into concrete cloud infrastructure and edge networking configs using Pulumi ESC (Environments, Secrets & Configuration) and ResourceTransforms.
At the kernel level, Flow360 attaches eBPF programs (via Cilium and Tetragon) directly to socket ingress/egress layers. If an execution token's Policy Hash is missing or invalidated, kernel-level packet drops occur at line rate with zero user-space processing overhead.
Deep Technical: Hardware-Offloaded CEN XFS4IoT & NEXO Peripherals
Deep Technical: Hardware-Offloaded CEN XFS4IoT & NEXO Peripherals
For physical edge appliances (smart ATMs, cash recyclers, and locker banks), Flow360 interfaces with hardware peripherals using standardised CEN XFS4IoT and NEXO protocols over encrypted TLS channels.
Every hardware command is wrapped in an idempotent transaction frame. If power drops or network connections fail during card dispensing or cash transport, the peripheral controller automatically reports its physical state upon reboot, allowing Flow360 and the Conductor to execute Contrary-to-Duty reconciliations without ledger drift.
Deep Science: Glyph Telemetry Serialisation & LAHE Ledger Mathematics
Deep Science: Glyph Telemetry Serialisation & LAHE Ledger Mathematics
Flow360 captures physical and digital execution proofs as cryptographic Glyphs (\(\mathcal{G}\)), composed of high-resolution execution timestamps, enclave attestation signatures, state root hashes, and syscall traces:
The Gatekeeper verifies that \(\mathcal{G}\) strictly complies with the original DRAGON Lawful Warrant (\(\text{Warrant}_{\text{DRAGON}}\)) and Policy Hash (\(\mathcal{PH}\)), sealing them into an immutable Lawful Act Hyperedge (LAHE) committed to the bitemporal ledger: