Coordination engineering is the discipline of designing systems that reliably orchestrate autonomous agents across heterogeneous substrates. As AI collapses the cost of routing work, the human is promoted from router to judgment broker. Thin agents on a shared formal semantic layer (the architecture the industry now calls neurosymbolic), with self-sovereign data, cryptographic provenance, and human-in-the-loop governance., with self-sovereign data and cryptographic provenance.
Everything below expands on these. If you read nothing else, read this.
01What is this?
Six open-source substrates that turn an organisation’s knowledge into a governed, queryable, visible asset. One identity, did:nostr, runs through all of them: the same key signs a request, holds a pod, approves a decision and gets paid.
02What can you do with it?
Ask a formal ontology a question from inside any agent turn. Watch a seventeen-thousand-node graph settle live under GPU physics. Review what agents propose and sign it into canon with your own key. Stand inside the same graph with colleagues, in a CAVE today and on a Quest 3 as the native client lands.
03Why was it built?
Agent output is cheap and trusted knowledge is not. Teams need agents working at machine speed while people keep authority over what counts as true, with a record of who decided.
04What problems does it solve?
Ungoverned writes to shared knowledge, provenance nobody can query, a runtime with no declared capabilities or spend limits, and knowledge that lives in documents nobody reads twice.
05One end-to-end example?
A note is written and marked public. VisionClaw’s discovery engine scores it, a reviewer reads the diff in the broker inbox, the Whelk reasoner checks the new axioms for consistency, the class merges by pull request, and the graph re-settles around the new canon. See the six stages.
06Where else does it apply?
Regulated research corpora, engineering handover, executive intelligence over a living knowledge base, and immersive teaching of complex domains. Three worked scenarios.
07How do I run it?
Docker Compose brings up the knowledge engine and a Nix-built container brings up the agent runtime, on your own GPU hardware. Every substrate is AGPL-3.0 on GitHub under DreamLab-AI. The repository map.
+Who is behind it?
DreamLab AI Consulting Ltd, a UK creative technology studio, with fifteen years of immersive data research at the University of Salford behind the graph engine. The stack is Rust, CUDA, TypeScript and Godot, developed in the open.
Problem
Hard problems share a common shape
Climate modelling, drug discovery, organisational transformation, creative production at scale. These problems all require diverse intelligence collaborating across trust boundaries, at scales where centralised coordination breaks down.
✖
Centralised AI
Scales tokens but not trust. One vendor, one failure mode, one billing relationship.
✖
Agent Frameworks
Scale tasks but not governance. Fast and broken is still broken.
✖
Knowledge Tools
Scale information but not reasoning. More data doesn’t mean better decisions.
✖
Collaboration Platforms
Scale communication but not coordination. More Slack channels don’t solve alignment.
73% of frontline AI adoption happens without management sign-off. Your workforce is already building shadow workflows, stitching together AI agents, automating procurement shortcuts. Your organisation is becoming an agentic mesh whether you plan for it or not.
Evolution Line
From LLM to Coordination Harness
The AI industry has moved through a clear progression. Each stage solves the previous stage’s limitation and reveals a new one. The newest turn is a return of symbolic structure: agent loops are unbounded by construction, and the industry is converging on formal semantics (ontologies shared across the mesh, rather than wired into each agent) as the way to bound them.
Three layers, kept distinct. The ontology is the formal vocabulary: the classes, typed properties and rules that define what can be said. The published corpus at narrativegoldmine.com is that ontology in readable form: pure TBox, every page a class, zero individuals by design. The knowledge graph is the ontology populated with live instances at runtime: VisionClaw’s running graph, agents’ working graphs, the personal graphs written into Solid pods. And the grounding layer, the Ontology Loom, serves the checked graph into a model’s context at query time, so answers restate verified facts rather than guesses. Holding it honest is a machine check at two points: the pipeline’s EL-profile reasoner gates the published closure at build, and a Whelk EL++ reasoner classifies the shared runtime graph and rejects contradictions before they enter it. When these pages say “reasoned”, they mean machine-checked, not an LLM thinking hard.
LLM
Pattern recognition at scale
Chatbot
Conversational access
Reasoning
Chain-of-thought
Agent
Tool use + planning
Agentics
Multi-agent systems
Harness
Sovereign runtimes
Coordination
VisionFlow
Six Substrates, One Identity
Six independent systems mesh through one cryptographic identity spine
did:nostr:<hex-pubkey>
Every actor (human, agent, server, worker) shares a single secp256k1 keypair. Verified at the relay, at every HTTP request, against WAC ACLs, in every provenance bead, and resolvable as a DID Document.
⬢
VisionClaw
Knowledge Engineering
OWL 2 EL formal reasoning (Whelk-rs) + SHACL shapes loaded into Oxigraph, gating writes as a dual-mode enforcing gate
Model-swappable, OpenAI-compatible façade: the model is a URL (Qwen3.8-27B today), swapped behind the façade with no consumer change
Static ontology scaffold lifts grounded recall roughly 3× (a near-random baseline to graph parity), and the gain reproduces across every model behind the façade; prose adds nothing
Published corpus.knowledgeGraph serves the readable public: true corpus (an Obsidian corpus that is also an OWL ontology, published as OKF v0.2) at narrativegoldmine.com, the same ontology VisionClaw renders in 3D. Since July 2026 it also releases the corpus itself: 8,100+ public pages under ODbL-1.0, the archived seven-stage rdflib pipeline (AGPL-3.0) that compiled them losslessly into the formal ontology (286,533 triples with the pipeline's EL-inferred closure and 101,313 resolvable edges across 6 domains at dataset 2026-08-11; live figures in stats.json), the WasmVOWL explorer (MIT), and the prebuilt artefacts. The corpus is mostly synthetic content, generated by agents under human direction by design: a testbed for the pipeline and the grounding stack it feeds, not an authoritative encyclopaedia. The corpus is the ontology in markdown form: pure TBox, every page a class, zero individuals by design, carried in Obsidian frontmatter and compiled in losslessly. Validation stands at 0 errors and 0 warnings; 1,396 classes deliberately declare more than one parent: the taxonomy is a lattice, not a tree, and the overlap is published as data.
Self-improvement
The mesh improves itself — nightly, and human-merged
Dreaming is the estate’s nightly self-improvement loop. Each night a repository forms one falsifiable hypothesis, measures it against its own evaluators, and opens a draft pull request — evidence-gated, witnessed, and never self-merged. It is the rule the mesh governs by, turned on the code itself: an agent proposes, a human signs the merge. Evaluation is not promotion. It runs on this repository today; the estate-wide orchestrator over the agentbox fleet, and a did:nostr identity per cycle, are in progress. Engine: dream-engine, DreamLab’s tracking fork of rUv’s dream-machine, after AutoDesign: Meta-Harness Optimization (arXiv:2608.13560) — freeze the model, evolve the harness.
Verifiable by Construction
Guarantees that hold at runtime
Coordination is only worth trusting when its guarantees survive production. These are the parts that are hardest to fake and easiest to hand-wave past, and in VisionFlow they run in the live path.
Writes are gated, not hoped
SHACL shapes load into Oxigraph and validate every knowledge-graph write. The path is a dual-mode enforcing gate, so a malformed claim is turned away at the door rather than caught later in review.
Provenance you can query
Every governed write reifies as PROV-O triples. Who claimed what, and when, is a SPARQL query answered straight from the graph.
The relay authenticates
NIP-42 challenge/response guards the relay. An actor proves the key it claims before it can publish, so the identity spine holds at the edge as firmly as it does inside the graph.
Federation without a hub
IS-Envelopes route between sovereign nodes through peer discovery, with no central authority in the middle. Trust rides on did:nostr, so two organisations can align while each keeps its own data.
The elevation loop closes
A concept an agent proposes passes the Whelk consistency gate when a human approves it, then goes out as a pull request. Personal insight reaches the shared ontology through one governed door; the closing ConceptElevated event on merge is still to be wired.
Action carries force
Agent activity drives the GPU physics directly. A transient-edge attractive force draws related concepts together as work happens, so the graph moves the way the reasoning does.
Every agent turn can ask; nothing asserts truth without a person
Pervasive ontology augmentation gives every AI call in the harness one shared retrieval brain. A push channel adds a short breadcrumb to each agent turn, synchronously, with no network hop. A pull channel, the ontology_ask tool, returns budget-bounded answers on demand. Reading is pervasive. Writing is governed: only a proposal that passes the reasoner and earns a signed human decision can assert truth.
Read pervasive, write governed. Agents may always ask; nothing asserts truth without a reasoner pass and a signed human decision.
From note to canon, in six stages
Knowledge lives in two tiers. Vault pages hold working notes; OWL classes hold canon. When a note matters enough it migrates, and every migration walks the same six stages of VisionClaw’s insight-migration loop.
Nothing drifts into canon by accident, and nothing lands there without a signature on it. The closing merge event is the one edge still to be wired.
Immersive Telecollaboration
Walk through the knowledge graph
VisionClaw grew out of 15 years of immersive data research at the University of Salford’s Centre for Virtual Environments. Dr John O’Hare designed and ran the Octave Multimodal Lab, gaining a PhD in telecollaboration, while Prof Rob Aspin’s research pioneered the stereoscopic CAVE infrastructure. Walking through data and reaching into graph structures at room scale shaped VisionClaw’s force-directed engine, its physics model, and its interaction design.
Octave Multimodal Lab // University of Salford Centre for Virtual Environments. Stereoscopic projection on walls and floor; researchers physically walk through the knowledge graph.
Nodes are physical objects you can reach into. Relationships become spatial structures you navigate by walking. The Octave Lab proved that embodied graph exploration surfaces patterns invisible on flat screens.
Embodied Interaction
Hand tracking, drone teleoperation, and physical controllers. You manipulate data the same way you manipulate physical objects.
Photogrammetry Environments
Real-world scenes reconstructed as walk-through spaces. Site surveys, heritage preservation, environmental monitoring, all rendered at room scale with sub-centimetre fidelity.
Telecollaborative Presence
Remote participants rendered life-size through projection. Full spatial co-presence where gesture, gaze, and pointing carry meaning. The Quest 3 native APK extends this to headset users anywhere.
From CAVE to Quest 3. The immersive substrate is migrating from projector-based CAVE systems to a native Meta Quest 3 APK built on Godot 4 + godot-rust + OpenXR. Same binary protocol. Same force-directed physics. Same did:nostr identity. The CAVE validated the concept at scale; the headset makes it portable.
The coordination bottleneck, in ninety seconds
Why coordinated AI reasoning, not raw intelligence, is the limiting factor in high-stakes domains.
Text summary of the film
In high-stakes domains (drug discovery, climate modelling, large creative productions) the binding constraint is not the raw intelligence of any single model but whether many agents and people can reason together without losing provenance, shared meaning, or governance. VisionFlow treats coordination itself as the infrastructure: one cryptographic identity spine, a shared formal ontology that keeps terms meaning the same thing across parties, and human judgment held at the decisions a machine should not close alone.
Judgment Broker
Human-in-the-loop governance that accelerates, not blocks
The Judgment Broker is an emergent property of agents, humans, a knowledge graph, and a relay mesh coordinating through shared cryptographic identity. No single repository owns the broker. Agents publish through Agentbox, humans decide through the forum, knowledge is gated through VisionClaw, provenance is anchored in sovereign pods.
The loop is graded, not asserted. The canon audits it against the six augmentation conditions of arXiv 2609.12482 (durable net value, meaningful human control, accountability and recovery, deepening learning, career pathways, job purpose). As of 14 September 2026 the estate is partial on control and recovery and absent on the three longitudinal conditions; the row-by-row grade, cited to code, is in the compatibility matrix.
1
Agent Declares Agentbox
kind 31400 PanelDefinition: agent publishes a control panel with schema, fields, actions via the governance MCP tools
→
2
Forum Renders nostr-rust-forum
kind 31402 ActionRequest: the forum’s 2,100-line governance model renders the request and routes it to the right human
→
3
Human Decides NIP-98 signed
kind 31403 ActionResponse: cryptographically signed approve/reject/amend/delegate. The decision is an immutable Nostr event
→
4
Knowledge Gates VisionClaw
The decision flows back through the relay mesh. VisionClaw gates knowledge graph mutations; provenance beads anchor the audit trail in sovereign pods.
Kind
Name
Direction
Purpose
31400
PanelDefinition
Agent → Relay
Declare control panel
31401
PanelState
Agent → Relay
Current data snapshot
31402
ActionRequest
Agent → Relay
Request human decision
31403
ActionResponse
Human → Relay
Signed decision
31404
PanelUpdate
Agent → Relay
Incremental state diff
31405
PanelRetired
Agent → Relay
Retire panel
voice → intent → pod + KG → embodiment → elevation
The embodied agent loop is wired end to end. A spoken command selects an agent and dispatches a scoped ACSP ActionRequest (kind 31402). The agent writes the personal knowledge graph to the user’s Solid pod as itself, under a revocable WAC mandate with a per-request NIP-98 signature. The action crosses into VisionClaw over /wss/agent-events and renders as a transient 0x23 beam, with memory and agent activity mapped to colour, shape, and motion in the live graph. High-value personal concepts are then proposed for elevation into the shared ontology through the Whelk consistency gate and human governance, all federated over the Nostr relay mesh.
Provenance and value travel the same rails
Once every actor is a did:nostr identity and every write is anchored, value and trust travel the same rails as the mesh’s messages: no EVM, no bridge, no custodian.
agent → pod → 402 settle → anchor → did:nostr
The same did:nostr key that is a WAC principal, a relay identity and a provenance author is also a payment account, so an agent can earn, spend and sign across the mesh as one actor. The unit of account is the satoshi: a Web Ledger in sats, HTTP 402 gating, an order book and a constant-product exchange, all routed through one ledger path with replay protection, with Lightning over L402 and NWC as the rail today, served by a resident Bitcoin node in the estate that runs mainnet and testnet4 side by side with Core-Lightning (ADR-061). Stablecoin rails are not ruled out: x402 challenges sit in the same 402 grammar and are payable by delegation, a later choice rather than a closed door. The same taproot core mints MRC20 tokens on Bitcoin, inherited from JSS; DREAM, the operator’s internal token at ten per sat, is configured across the runtime and the edge and has been minted experimentally on testnet. The same key is also a sidechain wallet: sidestr-rs, a Rust port of Melvin Carvalho’s sidestr sidechains, and on 2026-09-23 two agents pegged 50,000 test sats into the estate’s sidestr:dreamlab chain beside Bitcoin testnet4, traded three times over Nostr and pegged back out, paid on testnet4; testnet only, no real funds. Private digital objects and contracts stay in the owner’s pod and inherit Bitcoin’s security model through taproot-anchored commitments, on testnet4 by default and mainnet by explicit operator choice.
The web-contract trust ladder
Smart-contract trust is a declared spectrum, not a binary. Every web contract in a pod stands on a named rung: signed and anchored under an honest-or-caught operator at L0, reducible custody with m-of-n multisig and a true single-use seal at L1. The upper rungs, a trustless oracle and client-side validation, arrive only after independent audit.
Rungs L0 and L1 ship in VisionClaw’s web-contract substrate (ADR-124). L2 and L3 are deliberately deferred.
Economic Case
Why extreme token consumption against hard problems is rational
Cost of Not Coordinating
A team running uncoordinated AI agents spends much of its token budget on context rediscovery, duplicate reasoning, and contradictory outputs. Each agent session starts cold with no shared ontology, no provenance, no memory of what other agents concluded.
5-8xtoken waste from uncoordinated agent sprawl
Coordination as Token Multiplier
VisionFlow’s shared ontology means agents don’t re-derive domain vocabulary. The provenance chain means agents don’t re-validate conclusions. The Judgment Broker means agents don’t spin on decisions they lack authority to make.
3-5xeffective token throughput gain from coordination
Hard Problems Justify Deep Spend
Drug discovery: $2.6B average cost per approved compound. Climate modelling: $50M+ per actionable simulation suite. Creative production: $100M+ per franchise. Against these stakes, spending $10K-100K on coordinated AI reasoning is a rounding error, provided the coordination harness prevents even one wrong conclusion from propagating.
10,000:1problem-value to token-cost ratio on hard problems
Governance Dividend
Every governance decision that flows through the Judgment Broker is an immutable, auditable event. In regulated industries (pharma, finance, defence), the cost of reconstructing decision provenance after the fact dwarfs the cost of generating it by construction.
90%reduction in audit reconstruction cost
Coordination Harness ROI Model
For a team of N agents working on a problem of value V:
ROI = (V × coordination_multiplier × governance_dividend) / (token_cost × N)
Without coordination, agents compete, duplicate, and contradict. Each additional agent adds noise faster than signal. With VisionFlow, each agent amplifies the mesh. Shared semantics compound. Provenance eliminates re-validation. Governance catches expensive mistakes early.
The break-even point is typically reached at 3 agents working on any problem valued above $50K. Beyond that, every additional coordinated agent produces net positive value because the ontology, the identity spine, and the governance plane are shared infrastructure, not per-agent costs.
Early ideas · Sidechains
What a sidechain wallet could do for an agent
Every agent’s did:nostr key is already a wallet on the estate’s own sidechain, sidestr-rs, a Rust port of Melvin Carvalho’s sidestr. These are early suggestions for what that makes possible, each marked with how far along it is.
Live on testnet
Workshop demonstrator
Everyone in the room gets an agent with a testnet wallet, and the agents pay each other live on the chain while you watch. It is the loop the estate ran on 23 September: a peg-in, three trades between two agents, and a peg-out paid back on Bitcoin testnet4.
Builds on: sidestr-rs · sidestr:dreamlab
Parts built
Allowances with hard ceilings
An operator pegs a budget into an agent’s did:nostr key. The agent can spend what that key holds and no more, a spend policy checks each payment first, and whatever is left comes back with a peg-out.
Builds on: sidestr-wallet spend policy · sidestr-agent
Decided, not built
Pay-per-call between agents
One agent pays another for a Loom query, a consultant call or a GPU render. The estate’s HTTP 402 gate gains a sidechain payment scheme, and the payment itself is the receipt.
Builds on: agentbox ADR-2099
Parts built
Tamper-evident audit anchors
The estate’s hash-chained event log and its knowledge records are checkpointed into the sidechain, and from there into Bitcoin. Anyone can then check that the history was not rewritten.
Builds on: checkpoint markers in the protocol
Decided, not built
One ledger instead of three
Today three payment ledgers keep separate books. With the chain as the ledger of record, each becomes a view over the same history.
Builds on: agentbox ADR-2099
Idea
Bounties and escrow
A forum or dream-machine task carries a bounty that the agent who completes it can claim, released when k of n reviewers co-sign.
Builds on: sidestr-round co-signing
Idea
Refundable stakes on proposals
Ontology enrichments and shared-learning proposals carry a small stake: refunded when accepted, forfeited when flagged as spam. Confidence already counts people, not accounts; a stake puts a price on spamming.
Builds on: colloquy · forum governance
Decided, far off
Per-session child chains
Each swarm or session gets a short-lived chain for its many small internal payments, then settles one net total to the root chain when it closes.
Builds on: PRD-024 owner decision D2
Deferred
Settlement across operators
Another operator’s agents, or other sidestr chains, trade with ours, with assets bridged in. This waits for the federation work.
Builds on: federation project
Testnet only. The coins carry no value, nothing here is an offer, and any mainnet use sits behind an owner and legal review.
Grounding & Serving Node
The Ontology Loom: measured grounding behind a model-swappable façade
We tested whether a formal ontology improves an LLM’s factual recall, objectively, with gold answers derived from the knowledge graph itself. Across every model we have put behind the façade (a frontier model at one end, a small local one at the other), a static ontology scaffold lifts grounded recall to roughly 0.94 in every case (for example 0.15→0.94 on Gemma, 0.27→0.94 on Muse, paired uplift with bootstrap 95% CIs), and it runs faster than the bare model (full report). An input-exposure control makes the reading honest: the copy ceiling on this node is 0.964 and gain over copy is uniformly slightly negative across ten models from five providers, so the measured product is faithful delivery of curated, checked facts, not model reasoning over injected structure — exactly what private-knowledge grounding needs, with a judged negative-control ladder confirming the lift is content-specific. The result is about the architecture, not the model: probabilistic agents bounded by machine-checkable semantics, with contradictions rejected at the Whelk gate before they enter the graph. We re-run the benchmark on each new model we deploy; the shape holds.
A held-out graph-derived benchmark (objective gold, bootstrapped intervals) on the current model, Qwen3.8-27B, across four grounding modes:
Grounding mode
Recall
What it shows
Raw: no grounding
~0.3
Bare model on synthetic-corpus recall: near random
Scaffold: static structured injection
~0.9
The win: roughly 3× the baseline, from a pre-computed injection
Prose-enriched scaffold
~0.9
Adds ~nothing over structured; prose stays optional
Tools: agentic graph traversal
mid
Below static injection, and model-dependent; letting the model traverse can hurt it
The static structured scaffold is the whole win: a bare model near random on the corpus answers at graph parity once the scaffold is injected, prose adds nothing, and letting the model walk the graph with tools tends to make it worse. The scaffold, not the model, does the work, which is exactly why the model can be a swappable URL. (The interference from injecting on weak matches is a known effect in the retrieval literature; the Loom gates for it, below.)
The Loom turns that result into infrastructure
The Ontology Loom is the node that serves this grounding as infrastructure. It consumes the corpus generations that knowledgeGraph publishes, weaves them into a reasoned ontology it holds as canonical, and serves that grounding to any LLM behind a stable, OpenAI-compatible façade. The model is a URL: Qwen3.8-27B today, swap for whatever benchmarks best next, with zero consumer change. VisionClaw supplies the GPU engine and the OWL 2 EL reasoner; knowledgeGraph builds the corpus; the Loom serves the grounding.
model = a URL behind a stable façade · swap without consumer change
Model identity is carried in the results, never in the endpoint. A consumer (an agent, a workflow, any OpenAI-compatible client) asks the same façade the same way whether a local GPU model or a cloud model answers. In agentbox the “one brain” retrieval path resolves through the Loom’s harness-side client, live, so grounding is uniform across the harness without wiring an ontology into each agent.
Beyond the benchmark, the node has hardened into infrastructure:
Confidence-aware injection, live
Grounding only helps when the query is on-ontology: injecting context on a weak match can displace the model’s own knowledge (the “context interference” effect: Lin et al. 2026, Yoran et al. 2024). The Loom scales injection by retrieval confidence: a strong exact-title hit gets the full scaffold (verified rollup → full budget), a weak match a scaled fraction (digital-asset transfer, score 2.3 → 0.4×), an off-topic query nothing at all (banana pancakes → gated, zero tokens).
A single read-truth
The Loom holds the reasoned generation in an in-process pyoxigraph store (286,500 triples of assertion-plus-closure) and answers read-only SPARQL and node search over it. One queryable source of ontological truth behind the façade, never the working graph.
Governed elevation, end to end
New knowledge reaches the ontology through one governed door: an agent distils a note, grounds it against the Loom, and proposes an enrichment as an ACSP 31402 request; a human admin approves with 31403; only then does it publish. The first elevation ran this way: proposed, approved, and live in the served generation the same day.
What the numbers measure. The recall figures are domain-specific factual recall on a mostly synthetic corpus. The corpus is a testbed for the pipeline and its grounding, which is exactly what makes it a fair reading of the mechanism. The rest runs in the deployed node: the model-swap seam works across two very different models behind one façade, the read-truth store and confidence-aware injection are live, the agentbox “one brain” grounds through it, and governed elevation publishes into the served generation. Repo: github.com/DreamLab-AI/loom.
Real-World Scenarios
Federated problem-solving across trust boundaries
🌍
Climate Modelling Consortium
Three universities, two government agencies, one NGO. Each institution runs its own VisionClaw with domain-specific ontologies. OWL 2 EL reasoning ensures “sea surface temperature anomaly” means the same thing across all ontologies. Data stays in sovereign pods; cross-institutional findings surface through the Judgment Broker.
Why competitors can’t: No other platform combines formal ontology alignment, cryptographic data sovereignty, and human-in-the-loop governance.
💊
Pharmaceutical Drug Discovery
Biotech startup + CRO + regulatory consultancy. Literature mining agents parse 50K papers, chemistry agents run ADMET predictions, compliance agents map to ICH guidelines. Each organisation’s agents operate within their Solid pod boundary. The CRO never sees the biotech’s proprietary target list.
Why competitors can’t: No other platform provides per-organisation pod boundaries with cross-organisation semantic alignment and auditable provenance chains.
🎬
Creative Production at Scale
12-episode series, five time zones. Production ontology maps episodes to scenes to shots to assets. VFX agents track pipeline stages. When a VFX shot depends on an unapproved 3D asset, the OWL 2 constraint propagates through the graph and the GPU physics engine makes the blocked dependency visually obvious.
Why competitors can’t: No other platform uses formal reasoning to propagate production constraints through a visual knowledge graph.
Real-World Validation
DreamLab Creative Hub 45+ person team, 10,000+ graph nodes, daily production
University of Salford Research partnership: Vitrine digital preservation with the XR Lab
THG World Record IRIS on VisionFlow generated the campaign assets from a 185-node fashion ontology for THG Studios' WRCA-certified AI-driven, immersive, shoppable catwalk (Feb 2026) · report
Landscape · 2026
The frontier moved to coordination guarantees
Through 2025–2026 the industry standardised how agents talk: Anthropic’s MCP and Google’s A2A, now both stewarded by the Linux Foundation’s Agentic AI Foundation. “Having agents” is table stakes. The real question is coordination: who each actor cryptographically is, who owns the data, how decisions are governed and audited, whether reasoning is formally grounded or merely generated, and whether organisations federate without a central authority. On those axes the field thins fast.
Every peer grounds its agents in LLM inference. Palantir grounds them in a governed knowledge graph, which is closer, but still not description-logic entailment. VisionFlow’s OWL 2 EL + Whelk produces checked entailments and rejects contradictions before they enter the graph.
Others match one axis; VisionFlow holds all six
Block’s Buzz matches on identity, governance and federation; Palantir owns governance; A2A owns federation. Only VisionFlow carries sovereign identity, self-owned data, signed governance, formal reasoning, cross-org federation and open source at once, and binds them to one did:nostr key.
The closest convergence. Block (Jack Dorsey) shipped Buzz, a self-hostable, Nostr-native platform where humans and agents share channels, every actor holds a secp256k1 keypair, and every action is a signed Nostr event with an append-only audit log. A well-funded team arriving independently at the same substrate this ecosystem has built since 2022 validates the thesis rather than threatening it. The one axis Buzz does not carry is the decisive one: formal, ontology-backed reasoning. That, with Solid-pod data sovereignty and immersive 3D embodiment, is the moat.
Scaling Model
Three axes, one architecture
Single Operator
Token-Efficient
One Agentbox, standalone mode. Local SQLite beads, local Solid pod, local events. 130 skills, 180+ tools, privacy filter active.
One API key. One container. Minutes to deploy.
Team
Governed Collaboration
VisionClaw + forum + Agentbox on a shared relay. Shared ontology, Judgment Broker oversight. Knowledge-graph writes are gated by signed human decisions; ontology changes ship as consistency-gated GitHub PRs.
One GPU host + one agent container + CF Workers. 45+ person team validated.
Enterprise
Federated Intelligence
Sovereign agentbox instances on the Nostr relay mesh. Cross-org relay federation routes IS-Envelopes across nodes with NIP-42 challenge/response and peer discovery. Each node is independently hardened, and trust rides on did:nostr rather than network topology.
Horizontal. Add nodes. Each node owns its data.
Three doors
One system, explained for your seat
Pick the description that matches how you will meet it.
Your day with VisionFlow
You work in three places: your notes, the live graph, and a review inbox. You write notes the way you always have. The system watches for the ones that matter, and when one crosses the line it appears in your inbox as a plain diff: the note, the class it would become, and the evidence.
What happens when you ask for something
Ask a question. Any agent you talk to can consult the ontology mid-answer, so replies are grounded in your team’s agreed canon rather than a model’s general recollection.
Review a proposal. You read the diff and approve or reject with one signed action. Approval means a reasoner has already confirmed the change breaks nothing.
Step inside. In the CAVE, or on a Quest 3 once the native client lands, the same graph surrounds you with colleagues present in it. You explore, select and discuss; changes to canon still go through your inbox, on purpose.
What a refusal means
When the system declines to do something, a gate held. An agent reached for a capability it was not granted, a spend cap, or a write it was not allowed to make. A refusal is the design working, and each one leaves a signed trace you can inspect.
What you cannot do
You cannot write canon directly, and neither can any agent. Everything true in the ontology got there through detection, review, a consistency check and a signed merge. That is the point.
What you are looking at
Six substrates with one concern each. VisionClaw is a Rust server with a CUDA physics path, an Oxigraph and Whelk knowledge pipeline, a React client and a Godot XR client in progress. agentbox is a Nix-built container runtime that supervises agents, tools and sidecars. solid-pod-rs is consumed as a pinned crate, never as a checkout. The forum, the branded edge deployment and the Loom are peers on the relay mesh; this repository is the canon over all of them.
Runtime topology, in four facts
Two compose stacks join one external Docker bridge, so the engine and the runtime address each other by service name.
Nearly every published port binds loopback. The runtime exposes one LAN door, :9096, and it demands NIP-98 signed requests: unsigned traffic gets a 401.
Browser and headset consume the same binary WebSocket position stream, a fixed 52-byte record per node, plus one REST surface.
State lives in named volumes: vector memory in Postgres, pods, secrets and events each in their own, so a container is disposable and its knowledge is not.
Where to start reading
Start with the diagrams. More than seventy sequence and flow diagrams in VisionClaw, each participant carrying a path:line citation and each file naming a verified commit. Paths, Mermaid and citations are linted in CI.
Then the design record. Decisions live in ADRs, and the house rule is that a record is amended by dated addenda, never rewritten. A decision’s history is part of the decision.
Then one trace to internalise. Follow a single agent action from the runtime, over a signed event, into the engine, and out as a rendered beam. Once you can narrate that path, the rest of the estate is variations on it.
Habits that keep it safe
Capabilities are declared in a manifest and enforced at dispatch. Secrets stay in custody volumes, not in images. New network exposure lands on a sanctioned list and is CI-enforced. If your change wants a new door, the review will ask why, and it should.
Two paragraphs on the problem
Your organisation’s knowledge lives in documents nobody reads twice and in the heads of people who leave. AI agents can now produce and act on knowledge at machine speed, which makes the real question sharper, not easier: who decided this was true, and what is it allowed to touch?
VisionFlow answers with structure. Agents do the fast work inside a container with declared limits. People hold a small, well-lit approval loop. The agreed knowledge becomes a formal, queryable model your team can stand inside and inspect.
How it earns trust
Nothing becomes canon without a person. Every change to agreed knowledge passes an automated consistency check and a signed human approval.
Every action has a name on it. Agents and people act under cryptographic identities, so the trail shows who did what.
Agents run inside declared limits. The runtime grants capabilities and budgets explicitly and refuses the rest.
Your data stays yours. Knowledge and records sit in pods on your own hardware, under your access rules, with no platform holding them.
High-value decisions are tamper-evident. Decision records carry commit marks and can anchor to the Bitcoin chain, so alteration is detectable by outsiders.
What it costs
Every substrate is open source under AGPL-3.0, so running it yourself carries no licence fee. You provide the hardware, a GPU-equipped server, and the engineering time to operate it; DreamLab AI offers the engineering. Where the platform meters paid usage it does so in signed, auditable ledger entries denominated in sats rather than an opaque invoice.
Decisions we need from you
Which knowledge tree migrates first, and who owns its canon.
Who sits on the approval rota, and how many signatures high-value changes need.
Which deployment profile fits your risk appetite: private LAN, tunnelled, or public-facing.
Built, in progress, deferred
What ships today, plainly
A page like this is worth reading only if it also says what does not exist yet. Here is the shape of the estate as the engineering record states it, verified against source on 6 September 2026, with maturity words from the ADR-002 ladder.
Area
Where it stands
Maturity
Semantic coreOxigraph store, OWL 2 EL reasoning with Whelk, SHACL shapes gating writes
Running. The consistency gate is real on the elevation path, and a malformed claim is refused at the door.
integrated
GPU graph82 CUDA kernels, semantic forces, one binary position wire to the browser
Running. 13,165 nodes and 153,957 edges rendered live in the September 2026 browser receipt.
released
XR clientGodot 4, godot-rust, OpenXR on Quest 3
In progress. The CAVE validated the concept at scale; the native headset client is migrating onto the same wire and physics.
in progress
Governance loopACSP kinds 31400 to 31405, signed decisions, NIP-42 at the relay
Running, for one use case today: ontology concept elevation. The closing ConceptElevated event on merge is still to be wired.
integrated
Agent runtimeNix-built container, 130 skills, manifest-gated capabilities, one NIP-98 door
Running. Unauthenticated requests to the LAN door are refused, verified in the browser receipt.
released
Ontology groundingThe Loom façade, confidence-aware injection, model swap behind one interface
Running. The façade answers healthy at 8,146 classes; hosted CI for the Loom is still open.
integrated
Governed elevationPropose, approve, publish, end to end
Running. The first elevation ran proposed, approved and live in the served generation the same day.
integrated
Provenance and valueGit-marks, taproot block-trails, HTTP 402 gating
Partly. Web-contract rungs L0 and L1 ship; L2 and L3 wait for independent audit.
L0 and L1
Value railSats Web Ledger, HTTP 402 gating, MRC20 mint, Lightning over L402 and NWC, sidestr sidechains
Ledger, gating, exchange and mint are routed and test-proven, on testnet4 by default. The estate now runs its own Bitcoin node, mainnet and testnet4, for anchoring and Lightning. L402 challenges are recognised and payable by delegation; the native NWC rail is the next phase. On the estate’s testnet sidechain sidestr:dreamlab, two did:nostr agents ran a full peg-in, trade and peg-out loop on 2026-09-23, with sidestr-rs on the agents’ side and the upstream engine producing blocks; level 1, one signer, test sats only.
sats live, NWC next
Cross-org mesh federationIS-Envelopes between sovereign nodes
Built, not yet federation-verified. The transport and relay auth exist; standalone-first stays the supported mode until the live cross-substrate smoke test runs.
integrated, unverified
DreamingThe nightly self-improvement loop
Running on this repository. The estate-wide orchestrator over the agent fleet is in progress.
standalone
Contact form on this site
Deferred. The one action routes to DreamLab AI directly; no form endpoint exists yet.
deferred
Source: the 2026-09-06 post-sprint closeout table and the README status ladder in docs/estate-closeout. A maturity claim above the tier its evidence supports is a governance defect here, not a footnote.
Nightly estate check
Every repository, every night
CI on the default branch, open pull requests, the latest release, the last commit, public surface reachability and published registry versions, collected for every repository in the estate by a workflow that runs at 02:30 UTC and committed as data. What you read below is that committed snapshot, deployed through the same publication gates as this page — not a live query made while you scroll. The dream cycle reads the same file at 03:00, so a repository shown red here becomes a hypothesis the next night.