VISM separates decision, authority, effect and verification responsibilities. The architecture is designed to ensure that a model output cannot become a production credential or an unverified tool receipt become a success verdict.
Trust boundaries
The control plane coordinates a transition. The execution plane operates in the customer environment through structured APIs. The reasoning inspector consumes a filtered read-only evidence bundle. Write credentials stay behind a narrow effect broker/adapter boundary—not with the agent, model or generic worker.
Module contracts
| Module | Bounded responsibility | Important limitation |
|---|---|---|
| Gateway | Authenticate, validate typed proposals and capture idempotency context. | Does not mutate production. |
| Inspector | Find missing evidence, risks and contradictions in a scoped bundle. | Advisory; no credential or decision authority. |
| Policy | Evaluate final plan and live context deterministically. | Error or timeout never defaults to a permit. |
| Planner | Create an immutable manifest with pinned targets, payloads, constraints and recovery branches. | Final plan is rechecked by policy. |
| Approval | Bind a human assertion to the plan hash and scope. | Cannot turn a hard DENY into allow. |
| Effect broker | Validate one-use permits and send exact typed API effects. | No broad worker credential is exposed. |
| Verification | Evaluate independent evidence and return PASS/FAIL/UNKNOWN. | Does not self-report PASS from model text. |
Shared contracts
Every object includes a schema version, tenant, environment, correlation ID, actor and timestamp. Resource identity includes provider/account/region/cluster/namespace/kind/UID; a reused name is not treated as the same resource. A PlanManifest pins parent state digest, targets, preconditions, step DAG, exact payloads, policy and verification digests, recovery branches and expiry.
Transaction and effect boundary
The coordinator records intent and reservations durably before effect. The broker revalidates current approval, policy, ownership, target UID and live preconditions at the write boundary. Cloud effects are not atomic with a control database; a lost response after a write enters RECONCILING, then relies on provider state and independent verification rather than blind retry.
MEDIATION REQUIREMENT
The guarantee applies only where VISM controls the relevant write path. Unmanaged administrator keys, SSH paths, pipeline tokens or competing controllers create a coverage gap that must remain visible.