CarnacPrompt™ reads consequence while a request is still forming. Carnac™ reads it again before the model or agent creates an effect. One integration conducts the Hive Canon underneath, so most work runs at negligible cost and the work that matters gets proven in proportion to the stakes.
The instrument shows how one request routes. Reads light in order on the left and center. The routes that fire light on the right. It cycles on its own and you can pin a scenario. Routing levels are illustrative and deployment specific.
CarnacPrompt and Carnac are equal products that cover different parts of the same envelope. CarnacPrompt owns the formation phase, where a request is still being shaped. Carnac owns the lifecycle, from the moment a request runs to the moment an effect is about to commit.
It reads the request as a person types it or as an agent builds it, before it is ever submitted. Because it read consequence early, it can stage the response before the model runs.
It reads the request when it runs, reads the answer as it forms, and reads a late known value right before an effect commits. It catches the request that looked ordinary at the start and turned serious along the way.
Consequence is not always visible at the start. A request to summarize a file is ordinary until the summary contains a diagnosis. So the work is read at four points. The disposition is the record and the response that follow. It is the result of the reads, not a fifth read.
CarnacPrompt reads the request as it forms, inside your boundary, and can intervene before the model ever runs.
A cheap read on every request. It also flags work that might turn consequential later so the output read knows to watch.
Runs where the input read flagged it or the domain is watched. It catches consequence that appears mid run.
Reads a late known value, like a dose or a transfer amount, right before the effect acts, for effects that policy gates.
What was routed, what was escalated, who was asked, and what they decided is recorded as a signed disposition, whether they acted or not. If a later read scores higher than an earlier one, Carnac re routes to the stronger response and seals the whole request back to the start. The record then shows where it turned serious.
Carnac dispatches each read to one or more responses, proportioned to consequence. A chatbot proves almost nothing. A surgical robot proves almost everything. The decision lands in the right place on its own, and each response calls a real Canon primitive underneath.
No receipt, but the decision is recorded as a light breadcrumb, so even this is on the record.
Check against a named authority and attest the check. It never certifies the underlying fact.
Route for a confirmation before the effect completes, and record who approved.
Bind the severity into the signed artifact, carry an escalation obligation, and record the disposition. A critical request can fire several responses at once.
This lab sends the text you submit to the Hive Carnac service at /v1/carnac/sandbox for consequence classification, and shows the live signed decision it returns. The submitted text is not logged by default, and the sandbox is read only, so it cannot trigger any external effect. If the service is unreachable, the lab falls back to deterministic local rules that run in your browser, clearly marked unsigned and reduced coverage. The routing levels shown are deployment specific, not fixed ratios.
Formation read · CarnacPrompt assesses a request as it forms
Anyone can test a prompt here. What you submit is sent to the Hive Carnac service for classification, is not logged by default, and no effect can commit from this read.
Output read · Carnac catches consequence that appears mid run
Anyone can test a prompt here. Both fields are sent to the Hive Carnac service for classification, are not logged by default, and no effect can commit from this read.
Edit both fields. The same local rules read the request as it forms and read the output as it lands, so you can watch an ordinary request become consequential in its result.
This reference set recognizes named signals only. It still misses consequence carried by meaning with no listed keyword. A request like "reconcile these two spreadsheets and keep only the rows that changed" can carry real consequence and matches no rule here. The trained classifier reads that by meaning. This reference set will not. That gap is the whole point.
CarnacPrompt™ and Carnac™ are the two gates. Everything below sits beneath them as what they produce. Howler™ is what a high consequence decision becomes. The decision ledger is where every decision is kept.
When a classification lands at or above the severity threshold, its severity and features are bound into the signed artifact, not stapled on after. An escalation obligation rides with it to a person, a monitor, or an incident channel.
It is a signed, independent record that the classifier produced and signed a high consequence classification state from the features it observed on that path at that time, and that an escalation was owed. It forces visibility and records the response or the lack of one. It does not compel action, and we do not claim it does.
Even for work that just runs, Carnac records a light breadcrumb: this request was seen, classified, and on what basis. These are sealed periodically into a continuity chained, signed ledger.
When a regulator asks about everything you did not receipt, the answer is the sealed ledger. The breadcrumb stays featherweight on purpose. It is a record of the decision, not a receipt of the request, so it does not wreck the cost story.
Carnac and CarnacPrompt are the two gates that run today. The Evidence Plane is the layer above them. It is how the same receipts hold up across many requests, many machines, and many vendors at once. Some of this layer is now built and tested as backend capability, and some is still design. We mark which is which in the honest status below and never blur the two.
Every part of a request carries where it came from, such as the operator, the person, a retrieved file, or a tool result. A rule can then honor instructions only from the parts allowed to instruct.
Many requests seal into one batched signature, so the proof gets cheaper per request as volume grows. A single missing batch is still a provable gap.
One chain follows a session that starts on one model and finishes on another. Switching vendors does not cost you the record.
When one agent hands work to another, each handoff is a signed link and scope can only narrow, never widen. The full delegation tree is there at check time.
Signing once over a batch keeps the hot path clear while every single receipt still verifies on its own, offline.
Each receipt says honestly whether running it again would mean anything, from fully repeatable to not repeatable. No overclaim about what re running can prove.
We keep these three apart so nobody has to guess. The proof mark never shows for anything we cannot prove.
Carnac and CarnacPrompt run today. The reads, the governed floor, the signed receipts, the continuity chain, the disposition record, and public verification are built and covered by tests. The single chain for one inference is also built and covered by tests. It seals structural commitments, typed origins that honor instructions only from allowed sources, batched proofs that still verify one at a time offline, replay labels, and delegated agent links, with public chain checking that needs no plaintext.
Hive primitives are built and ready. A customer's environment still needs a scoped connection, normally through a simple API or curl integration. We do not claim an integration exists before it does.
Some of the Evidence Plane is still design, not yet built. That includes one chain that follows a session across two different vendors, routing that changes with the stakes of the request, and a single policy object that travels between vendors. We describe these as direction, never as a live feature.
We are precise about scope rather than promising that nothing anywhere can slip by. These limits are stated on purpose, and the control model is built around them.
These gates protect the paths they sit on. Work that never crosses an instrumented path is not seen by them. Carnac can only hold an effect that routes through it.
A hook only sees what crosses it. Gateway enforcement, with S2S and HiveSeal where deployed, prevents ungated effects, and continuity reconciliation across the ledger detects a path that tried to go around.
The floor is Carnac's own decision. Ordinary runtime configuration cannot lower it. The operator can turn proof up and name always proven categories, but can never route below the floor, and any attempt to do so is itself recorded.
The floor is not frozen forever. It can be revised, but only through a signed governed policy release, recorded as a policy amendment. A law change or a corrected false positive goes through that channel, not a runtime switch.
CarnacPrompt classifies consequence, not content, and runs inside your boundary. Raw forming requests stay with you. Only commitments, consequence vectors, rule identifiers, and routing metadata leave.
The return of a non gated request is kept separate from the commitment of an effect. If the classifier is uncertain or down, work routes to a stronger response and still returns. An outage gates effects only where policy declares.
Learning is additive only. Carnac learns to recognize more things as consequential, never fewer. New patterns can raise a score or add an always protect rule. Nothing in the learning loop can lower a floor or remove a protection, and the loop is audited for that property.
Each example follows one path: what enters CarnacPrompt™, what is committed before inference, what Carnac™ checks before an effect, when Howler™ is raised, and which Hive primitive closes the chain. The chain is identical. Only the stakes and the destination change.
These are illustrative deployment shapes only. Naming a provider or a sector describes where Carnac™ could sit. It is not a claim of any customer, partner, endorsement, or existing relationship. What each model returns, and which effects are gated, is deployment specific.
Most work runs at negligible cost and each request leaves a signed decision breadcrumb. The consequential work is proven in proportion to its stakes. The work that turns consequential mid run is caught the moment it does and sealed back to the start. The dangerous work is held before it can act. The operator can demand more proof, never less, and any attempt to suppress leaves a mark.