QUOIN Architectural Core
AUTHORITATIVE CUTOVER · EPOCH G18 ACTIVE

Your agent executed on a stale policy?

Causality before capital. QUOIN fences in-flight cutover races, memory visibility lag, and unauthorized side effects with cryptographically bound Two-Phase Commit leases anchored on AWS DynamoDB & Bedrock.

Kernel Invariant:G_proposal ≡ G_visible = G_active ∧ H(P) = H_receipt

Click to scrub the causal timeline.

// the agent attempted execution on stale memory. quoin intercepted and forced two-phase policy alignment.

STEP 01 // AUTHORITY LEDGERTIMESTAMP: 14:32:11.000

Policy Cutover

Operator published G18 cutover to DynamoDB with CAS condition check.

target_epoch18 (G18 - Volatility Throttle)
prev_epoch17 (G17 - Aggressive Yield)
conditionactive_epoch = 17 (CAS atomic update)
ledger_statusCOMMITTED TO DYNAMODB

Console logs break when agents move money.

/ 01

Eventual consistency is not authority

Vector stores and memory engines take 100–300 ms to propagate policy updates. During this visibility window, agents blindly dispatch high-value actions based on stale assumptions.

/ 02

Execution without cryptographic lease

Decoupled LLM reasoning can propose any action, but traditional execution gateways lack an unforgeable, time-bounded proof connecting that proposal to an authoritative policy epoch.

/ 03

Forensic blackouts and unaccountability

When an unauthorized liquidation or data transfer occurs, standard application logs cannot prove what policy the model witnessed at that exact microsecond. QUOIN seals every decision into an immutable SHA-256 hash chain.

Every decision becomes provable evidence.

One permit per consequential action: evaluated, two-phase leased, and anchored in DynamoDB. Real benchmark values below.

PERMIT
Two-Phase Lease · Seq 042
Agent IDrisk-arbitrage-01
Epoch Target18 (G18 Active Fence)
Lease TTL5,000 ms (HMAC-SHA256 Signed)
Permit Digest7f8a9e10c2b5d4e3f1a0987654321fedcba09876

Two-Phase Commit fence validates policy preconditions before granting gateway dispatch rights.

AUTHORITY
DynamoDB CAS

Atomic Condition Verification

ConditionExpression asserts active_epoch == prev_epoch. Zero race window under cutovers.

G_active = 18 ∧ CAS_status ≡ COMMITTED

TRACE
Forensic Chain

Immutable SHA-256 Merkle Link

Every prompt, tool execution, and permit forms an unalterable causal timeline from genesis to settlement.

genesis → cutover → eval → permit → execute (0 errors)

TAMPER
Fail-Closed

Signature Mismatch Rejection

Payload or timestamp modification immediately breaks HMAC verification. Gateways reject execution.

8f02c1aa…94d3e0 ≠ 7f8a9e…10c2

BEDROCK
Nova Lite

Structured Reasoning

us.amazon.nova-lite-v1:0 enforces policy schema adherence.

Launch in Console →

Controlled Causal Benchmark

Measured Head-to-Head Performance (100 Scenarios)

Stale Policy Executions

0100% Elimination
Naive Baseline:80 Committed

Zero illegal executions permitted across 100 systematic operational cutover scenarios.

Unsafe Effects Blocked

80+80 Protected
Naive Baseline:0 Blocked

Prevented corporate policy violations during in-flight limit tightenings and revocations.

Duplicate Replay Immunity

25100% Deduplicated
Naive Baseline:25 Committed

Single-use execution permits stored in immutable replay ledger prevent accidental double commits.

Verification Overhead

0.60 msSub-millisecond
Naive Baseline:0.00 ms

Deterministic CAS generation matching without adding LLM API network inference latency.

ARCHITECTURAL RIGOR · ZERO-TRUST TOPOLOGY

Four-Plane System Topology

Zero-trust separation between generative LLM reasoning and authoritative side-effect execution. Execution authority is cryptographically isolated from reasoning outputs.

Plane A

Cognitive Reasoning Plane

Amazon Bedrock Nova Lite & Strands SDK

Interprets natural language business requests, reasons over visible context, and formulates candidate DecisionProposals. Strictly unprivileged.

Invariant Guard:Proposal Only (No Side-Effect Capability)
Plane B

Deterministic Kernel & CAS Gate

Pure Python / Rust Hasher / Monotonic Fence

Model-free deterministic fence. Enforces generation equality, binds SHA-256 digests, and executes Phase 2 read-after-write CAS verification.

Invariant Guard:G_proposal ≡ G_visible = G_active
Plane C

Cognitive Memory & Authoritative Ledger

Amazon Bedrock AgentCore Memory & DynamoDB

Stores policy generations, authoritatively versions active epochs with DynamoDB conditional writes, and exposes episodic tenant memory.

Invariant Guard:Atomic CAS Epoch Cutover & Linear Durability
Plane D

Operational Action Service

Single-Use ExecutionPermits & Idempotency Vault

Executes real enterprise side effects (commercial discounts, invoices, refunds). Refuses any request without a valid signed ExecutionPermit.

Invariant Guard:Zero Execution Without Verified Permit
Interactive Vulnerability Simulation

The In-Flight Generation Race

Watch how standard LLM agents commit illegal side effects when policy limits tighten during request execution, and how QUOIN mathematically aborts the transaction.

REQUEST:$1,200 Commercial Discount
INITIAL AUTHORITY:Epoch G17 (Limit $1,500)
IN-FLIGHT CUTOVER:Epoch G18 (Limit $1,000)
PHASE:idle

Naive Baseline Architecture

NO FENCE / CAS

Step 1: Read Active Policy

Reads G17 (Max limit: $1,500.00)

Step 2: LLM Reasoning & Approval

$1,200 ≤ $1,500 → LLM approves action.

In-Flight Event: Admin updates to G18 ($1,000 max)

Pending trigger...

Awaiting Commit...

QUOIN Deterministic Kernel

GENERATION FENCE + CAS GATE

Step 1: Generation Fence Evaluates Proposal

Receipt issued strictly bound to G17 digest.

Step 2: Strands Model Formulates Candidate

Proposal claims candidate_generation = 17.

In-Flight Event: Admin updates to G18 ($1,000 max)

Pending trigger...

Awaiting Gate...

Five lines to fence your autonomous agent.

Works seamlessly with any Python or Node.js agent. The full two-phase verification and causal ledger runs locally for testing or on AWS DynamoDB & Bedrock for production.

✓ QUOIN_ACQUIRE_PERMIT
✓ QUOIN_VERIFY_LEASE
✓ QUOIN_FORCE_CUTOVER
✓ QUOIN_FORENSIC_ANCHOR

// Plane B Two-Phase Commit Fence

from quoin.authority import DynamoAuthorityLedger

from quoin.kernel import PlaneBFenceKernel


// 1. Evaluate proposal against authoritative epoch

decision = kernel.evaluate_precondition(

proposal_epoch=18, agent_id="risk-arb-01"

)


// 2. Acquire cryptographic execution lease

permit = kernel.issue_permit(decision, ttl_ms=5000)

// 3. Dispatch to Execution Gateway with verified lease

result = gateway.execute_with_permit(permit, action_payload)