DUNIN7 — stack architecture and dependencies — v0.1
Version. 0.1 · Date. 2026-07-28 · Status. Working draft. Components. Loomworks · Stele · Stele Agentic ID · FORAY · GRANTHA · OVA · Loom Protocol (on PROV) · Kaspa anchor. Grounding. The 2026-07-18 agentic-identity inspection (four parallel source-reads of ~/stele, ~/stele-agentic-id, ~/grantha, and the OVA records); the GRANTHA correction of 2026-06 (Decision J1; grant as sole primitive); seed v0.12; today's reach-enforcement arc and CR-2026-157. Verification status. Seat assignments and build states below are as of the 2026-07-18 inspection and are not re-verified today — a Claude Code retrieval is listed at the end for v0.2. Every element carries a state marker; unmarked certainty is the failure mode this document refuses.
Standing correction, in force. GRANTHA holds the authorization seat (Decision J1). OVA is displaced from both authorization and agent identity; GRANTHA consumes it for blind verification; OVA's remaining standalone role is unstated. Seed v0.12's "access-control list established through OVA" predates this and awaits amendment (a v0.13 rider). Today's reach-enforcement arc (scoping note, CR-2026-157, manifest v0.74) used the older OVA naming; its Slice 1 mechanism is grant-shaped and survives; its Slice 2–3 "ACL" framing conflicts with grant-as-sole-primitive and is corrected at their scoping time. A correction note accompanies this document on the record.
State legend, used in every figure: solid border / solid arrow = LIVE (shipped, running) · dashed = COMMITTED (specified or in build, not yet live) · dotted = IN MOTION (direction named, decision open) · terracotta fill = protocol asset · green edge-tab = the seat is occupied today by an interim engine implementation
Figure 1 — The seats: who owns what
The stack by responsibility. Two identity products (humans and agents are deliberately separate systems), one authorization protocol consuming one verification protocol, one notary, one wire layer, one environment. The methodology sits between the protocols and the environment.
Fig 1. Seats per Decision J1 and the 2026-07-18 inspection. Stele and Stele Agentic ID are deliberately separate systems sharing only a neutral stele-core package. The green tab under GRANTHA marks the interim reality: the authorization seat is exercised today by the engine's internal authorizer seam (CR-2026-157), designed to swap to GRANTHA without callers changing.
Figure 2 — Dependency graph: who consumes whom, and how firmly
Consumption edges with their states. Read an arrow as "depends on / consumes."
Fig 2. Two edges carry the whole authorization story: Loomworks calls its own authorizer seam today (live at CR-2026-157), and that seam swaps to GRANTHA without callers changing — the stub's original design intent, now the committed path. The three grey dotted edges are the honest frontier: agent-identity federation, the GRANTHA↔Agentic seams, and the anchor commitment.
Figure 3 — Runtime: one contribution, end to end
The chokepoint story — the reason guarantees live at the substrate. A human's contribution today; an agent's contribution when the federation seam lands.
Fig 3. Every recordable act crosses the same gates in the same order; that is why attestation, origin-marking, and (soon) grant checks are trustworthy — no surface can route around them. The admission step is deliberately human: the machine surfaces and signals, the Operator's people approve.
Figure 4 — Build-state matrix
Component
Seat
Spec state
Build state
Home
Consumed by
Loomworks
Environment
Seed v0.12 (v0.13 riders queued)
LIVE — engine, Operator Layer, record
loomworks-engine · loomworks · loomworks-record
Operators, Companions, verticals
Stele
Identity — humans
Extraction arc records
LIVE — extracted; Phase 7 packaging in flight
~/stele (mounted router in engine)
Loomworks sign-in, onboarding, credentials
Stele Agentic ID
Identity — agents
V2 in draft
V1 FROZEN/tested · V2 IN BUILD · no shared session with Stele; stele-core only