Campaign management
Defines and authorises the assurance context: campaign, programme, method revision, execution, SUT configuration and declared collection points.
Project Aurora
Aurora is Codance Ltd's platform for implementing and operating bounded assurance methods as controlled, evidence-producing campaigns against agentic and other probabilistic systems.
Role
Aurora provides the controlled execution and evidential machinery. Competent people define what must be assured, the applicable boundary and the authority for judgement. Aurora does not define universal standards or declare that an AI system can be trusted.
System responsibilities
Defines and authorises the assurance context: campaign, programme, method revision, execution, SUT configuration and declared collection points.
Executes versioned Processing Routes, manages working state and dependencies, invokes deterministic and probabilistic skills, and records operational consequences.
Preserves authoritative ownership, source, admission, execution and evidential attribution without forcing campaign semantics into Core.
Reconstructs read-only evidence into assessment results, findings and reports while leaving competent judgement with authorised people.
Governed admission
An external signal first enters Aurora through the Input Router. The router validates the transmission and orchestrates Campaign admission with the Campaign Register before Core persistence is allowed. If governed registration fails, admission fails closed.
Once Core persists the admitted input, it creates the canonical msg_id. The Input Router links that identity back to the Campaign Register, joining evidential identity to subsequent Core processing without forcing Campaign semantics into Core.
If governed Campaign admission cannot be evidenced, the signal is not knowingly admitted into Core as governed Campaign evidence.
Core's canonical msg_id joins operational processing back to the Campaign Register while Core itself remains free of Campaign semantics.
The flow is one coordinated governed-admission operation across distinct responsibilities; it is not presented as one atomic database transaction.
Management authorises. The Input Router orchestrates admission. Core executes. The Register remembers.
Assurance integrity
Aurora does not assume that the system under test will remain a passive participant in its own assurance. A sufficiently capable agentic system may attempt to influence, evade or interfere with the process assessing it, whether through deliberate strategy, emergent behaviour or badly specified optimisation.
For that reason, Aurora is architecturally able to verify sensor and other admitted-input configurations against Campaign-authorised known-state fingerprints before governed evidence is accepted. A mismatch can cause admission to fail closed and the inconsistency to be preserved through an independent, non-local evidential path.
Observation and input components can be checked against Campaign-authorised configuration fingerprints before evidence enters governed processing.
Detected inconsistencies can be recorded outside the local processing context so an attempted influence does not depend on the potentially affected apparatus to preserve its own warning.
The evidential database schema can be locked and cryptographically fingerprinted at Campaign start, then re-qualified at completion so unauthorised structural change can itself become an evidential finding.
Aurora does not claim to make interference impossible. It is designed to make material interference detectable, attributable and difficult to erase from the evidential record.
Processing Routes
A declared input initiates a processing sequence by resolving to a versioned Processing Route. Each route composes stages and steps, and each step invokes a bounded, versioned skill runtime. Steps can use products retained from preceding work, deterministic algorithms and governed probabilistic capabilities, while their inputs, outputs and execution identity remain attributable.
The route need not remain static. Where the assurance method permits it, future work can be added, cancelled or replaced in response to evidence gathered during execution. Aurora retains the original structure, each authorised change, completed and cancelled work, and the ancestry linking every resulting product back to the input that initiated the sequence.
The method can adapt during execution without allowing the history of that adaptation to disappear.
| Method concern | Aurora representation | Why it matters |
|---|---|---|
| Boundary & authority | Campaign execution, SUT configuration, source and collection-point control | The procedure is tied to a declared context rather than inferred afterwards. |
| Procedure | Versioned Processing Route → stages → steps | The planned method can be identified and compared across revisions. |
| Executable capability | Step → Device → versioned skill runtime | Runtime capability and version remain bounded and attributable. |
| Working dependencies | Inspectable working state plus typed step products | Later work receives explicit retained products rather than hidden process state. |
| Adaptive execution | Authorised changes to future processing with trigger and mutation history retained | The method can adapt without rewriting completed history. |
| Result | Parent-linked output plus campaign attribution | A reviewer can traverse from a visible result back to its evidence, procedure, authority and source. |
Adaptive assurance
Aurora allows an authorised assurance method to alter future processing in response to evidence gathered during execution. Completed work remains fixed, while future steps may be added, cancelled, replaced or recalculated where the method permits.
The original route, the evidence that triggered each change, the responsible skill and version, the mutation itself, completed and cancelled work, and the resulting ancestry are retained as part of the execution record.
The method can adapt during execution without rewriting its own history.
Exact rules, schema checks, authority conditions, correlation and evidence-completeness tests remain deterministic where that is appropriate.
LLMs may interpret bounded material, propose probes or classify evidence when the method allows them to do so.
A probabilistic component's material influence is itself part of the assurance evidence. It cannot silently become observation, authority or proof.
Model agnosticism
Aurora separates the assurance method's logical intent from the model selected to perform probabilistic work. A skill requests a defined model-work profile and the capabilities it requires; governed model control determines the eligible providers, models, execution adapters and access conditions. Resolution may then be deterministic or, where the method permits, selected through a bounded probabilistic decision from within that approved set.
The resulting choice remains attributable. Aurora retains the selected provider and model, applicable configuration, selector or policy and the evidential basis of the resolution. The same assurance method can therefore substitute or compare dissimilar approved models, use different models for different steps or parallel branches, or exercise equivalent work across programme runs without rewriting the method itself.
Model agnostic does not mean model indifferent. Different models can produce materially different outcomes. Aurora treats model eligibility, selection and resolution as governed and attributable parts of the assurance procedure rather than hiding them inside a skill.
Reconstruction
Aurora preserves forward operational identity and reverse evidential ancestry. A reviewer can begin with a result or finding and trace backwards through the evidence that supports it, the procedure that produced it, the campaign authority under which it was generated and the originating source.
The result is therefore not an evidential dead end. Its material lineage remains available for reconstruction, examination and competent challenge.
Reconstruction is forensic, not neuroscientific. Aurora retains declared inputs, observable interactions, execution state, products, model-work records and material execution history. It reconstructs the evidential operation of the system and assurance procedure; it does not claim to reproduce hidden model cognition.
Current alpha
The demonstrated alpha now spans governed admission, execution, external observation, execution closure, human pair selection, comparative assessment and human-readable reporting. Codance is developing richer method authoring, reusable campaign structures, reviewer interfaces, governed deployment and advanced agentic assurance methods on that proved substrate.