Project Aurora

Turning assurance intent into controlled execution and reconstructible evidence.

Aurora is Codance Ltd's platform for implementing and operating bounded assurance methods as controlled, evidence-producing campaigns against agentic and other probabilistic systems.

Working-name noticeProject Aurora is a development codename. Codance is the enduring company and IP-owning identity; the commercial product name may change before release.

Role

The operational layer between assurance expertise and justified human judgement.

Aurora provides the controlled execution and evidential machinery. Competent people define what must be assured, the applicable boundary and the authority for judgement. Aurora does not define universal standards or declare that an AI system can be trusted.

Assurance expertise and intent remain outside Aurora's operational layer, which provides campaign control, method execution, observation and retained evidence before competent human judgement

System responsibilities

Responsibilities remain distinct by design.

Campaign management

Defines and authorises the assurance context: campaign, programme, method revision, execution, SUT configuration and declared collection points.

Core execution

Executes versioned Processing Routes, manages working state and dependencies, invokes deterministic and probabilistic skills, and records operational consequences.

Campaign Register

Preserves authoritative ownership, source, admission, execution and evidential attribution without forcing campaign semantics into Core.

Reporting & review

Reconstructs read-only evidence into assessment results, findings and reports while leaving competent judgement with authorised people.

Governed admission

Evidence acquires governed identity before Core begins processing it.

An external signal first enters Aurora through the Input Router. The router validates the transmission and orchestrates Campaign admission with the Campaign Register before Core persistence is allowed. If governed registration fails, admission fails closed.

Once Core persists the admitted input, it creates the canonical msg_id. The Input Router links that identity back to the Campaign Register, joining evidential identity to subsequent Core processing without forcing Campaign semantics into Core.

A sequence showing a sensor sending a signal and campaign envelope to the Input Router; the Input Router consulting the Campaign Register before Core persistence; Core returning a msg_id; the Input Router linking that identity back to the Register; and identity plus receipts returning to the caller. Campaign Management establishes authorised context above the live admission path.

Fail closed

If governed Campaign admission cannot be evidenced, the signal is not knowingly admitted into Core as governed Campaign evidence.

Identity bridge

Core's canonical msg_id joins operational processing back to the Campaign Register while Core itself remains free of Campaign semantics.

Separated responsibilities

The flow is one coordinated governed-admission operation across distinct responsibilities; it is not presented as one atomic database transaction.

Management authorises. The Input Router orchestrates admission. Core executes. The Register remembers.

Assurance integrity

The assurance apparatus is inside the threat model.

Aurora does not assume that the system under test will remain a passive participant in its own assurance. A sufficiently capable agentic system may attempt to influence, evade or interfere with the process assessing it, whether through deliberate strategy, emergent behaviour or badly specified optimisation.

For that reason, Aurora is architecturally able to verify sensor and other admitted-input configurations against Campaign-authorised known-state fingerprints before governed evidence is accepted. A mismatch can cause admission to fail closed and the inconsistency to be preserved through an independent, non-local evidential path.

Known-state verification

Observation and input components can be checked against Campaign-authorised configuration fingerprints before evidence enters governed processing.

Independent evidential path

Detected inconsistencies can be recorded outside the local processing context so an attempted influence does not depend on the potentially affected apparatus to preserve its own warning.

Campaign integrity qualification

The evidential database schema can be locked and cryptographically fingerprinted at Campaign start, then re-qualified at completion so unauthorised structural change can itself become an evidential finding.

Aurora does not claim to make interference impossible. It is designed to make material interference detectable, attributable and difficult to erase from the evidential record.

Processing Routes

A method is a controlled composition, not one enormous prompt.

A declared input initiates a processing sequence by resolving to a versioned Processing Route. Each route composes stages and steps, and each step invokes a bounded, versioned skill runtime. Steps can use products retained from preceding work, deterministic algorithms and governed probabilistic capabilities, while their inputs, outputs and execution identity remain attributable.

The route need not remain static. Where the assurance method permits it, future work can be added, cancelled or replaced in response to evidence gathered during execution. Aurora retains the original structure, each authorised change, completed and cancelled work, and the ancestry linking every resulting product back to the input that initiated the sequence.

The method can adapt during execution without allowing the history of that adaptation to disappear.

Method concernAurora representationWhy it matters
Boundary & authorityCampaign execution, SUT configuration, source and collection-point controlThe procedure is tied to a declared context rather than inferred afterwards.
ProcedureVersioned Processing Route → stages → stepsThe planned method can be identified and compared across revisions.
Executable capabilityStep → Device → versioned skill runtimeRuntime capability and version remain bounded and attributable.
Working dependenciesInspectable working state plus typed step productsLater work receives explicit retained products rather than hidden process state.
Adaptive executionAuthorised changes to future processing with trigger and mutation history retainedThe method can adapt without rewriting completed history.
ResultParent-linked output plus campaign attributionA reviewer can traverse from a visible result back to its evidence, procedure, authority and source.

Adaptive assurance

Adapt the procedure without losing its history.

Aurora allows an authorised assurance method to alter future processing in response to evidence gathered during execution. Completed work remains fixed, while future steps may be added, cancelled, replaced or recalculated where the method permits.

The original route, the evidence that triggered each change, the responsible skill and version, the mutation itself, completed and cancelled work, and the resulting ancestry are retained as part of the execution record.

A declared Processing Route adapts future work after retained evidence triggers an authorised change while original, completed and cancelled history remains retained

The method can adapt during execution without rewriting its own history.

Deterministic controls

Exact rules, schema checks, authority conditions, correlation and evidence-completeness tests remain deterministic where that is appropriate.

Probabilistic assistance

LLMs may interpret bounded material, propose probes or classify evidence when the method allows them to do so.

Retained influence

A probabilistic component's material influence is itself part of the assurance evidence. It cannot silently become observation, authority or proof.

Model agnosticism

The method asks for the work. Governance controls which models may perform it.

Aurora separates the assurance method's logical intent from the model selected to perform probabilistic work. A skill requests a defined model-work profile and the capabilities it requires; governed model control determines the eligible providers, models, execution adapters and access conditions. Resolution may then be deterministic or, where the method permits, selected through a bounded probabilistic decision from within that approved set.

The resulting choice remains attributable. Aurora retains the selected provider and model, applicable configuration, selector or policy and the evidential basis of the resolution. The same assurance method can therefore substitute or compare dissimilar approved models, use different models for different steps or parallel branches, or exercise equivalent work across programme runs without rewriting the method itself.

A capability request passes through governed model control, which limits the eligible provider and model set, resolves an approved execution and retains a resolution receipt

Model agnostic does not mean model indifferent. Different models can produce materially different outcomes. Aurora treats model eligibility, selection and resolution as governed and attributable parts of the assurance procedure rather than hiding them inside a skill.

Reconstruction

The result is the start of the review, not the end of it.

Aurora preserves forward operational identity and reverse evidential ancestry. A reviewer can begin with a result or finding and trace backwards through the evidence that supports it, the procedure that produced it, the campaign authority under which it was generated and the originating source.

The result is therefore not an evidential dead end. Its material lineage remains available for reconstruction, examination and competent challenge.

Forward operational identity runs from source to result; review starts at the result and reconstructs backwards through evidence, procedure and authority to source

Reconstruction is forensic, not neuroscientific. Aurora retains declared inputs, observable interactions, execution state, products, model-work records and material execution history. It reconstructs the evidential operation of the system and assurance procedure; it does not claim to reproduce hidden model cognition.

Current alpha

Built to evolve, not to be thrown away after the demonstration.

The demonstrated alpha now spans governed admission, execution, external observation, execution closure, human pair selection, comparative assessment and human-readable reporting. Codance is developing richer method authoring, reusable campaign structures, reviewer interfaces, governed deployment and advanced agentic assurance methods on that proved substrate.