Zain Dana HarperField map · engines · research · work

FIELD MAP · START HERE

One workshop for systems, models, graphics, and research.

Project Telos is the public map of a wider body of work: engines, demos, papers, graphics systems, local-model workflows, generated media, release tooling, and field notes. It is broad on purpose. Start with an engine, open a demo, read a paper, or route directly to a work thread.

A site for range, organized by one Flywheel thesis: compilers, agent tooling, procedural art, reverse engineering, color systems, model harnesses, research infrastructure, and the operating layer that lets verified outputs move between them.

Engines · demos · papers · generated art · local workflows · work routes

Built as a field guide, not a funnel. Every track has a working surface.

Some pieces here are engines. Some are demos, papers, generated images, graphics systems, or notes from ongoing research. The point is not to flatten every artifact into one product. It is to make the range navigable and show how independent engines can pass verified outputs forward.

That connection is the Flywheel thesis: parallel systems run alone, then improve the next run when the problem calls for it. A compiler can inform an agent harness. A graphics pipeline can become a measurement surface. A local-model workflow can become a benchmark. A generated specimen can become a design system.

The front door is range: systems, models, graphics, research, generated media, and the tooling that makes them usable.

The work still carries dates, source links, tests, papers, and limits where they matter. That discipline stays. What changes is the public frame: rigor is support structure, not the whole thesis. Start with what you want to understand or use, then follow the links into the deeper material.

Where to enter.

Different readers need different doors. This page keeps the routes close together so the work can be scanned as a system instead of as isolated project tiles.

Engine room.

public tools that map workspaces, ingest difficult sources, run agent teams, judge claims, and compile typed-effects systems code.

Start here

Use the flagship list when you want names, roles, source links, package pages, and a fast read on what is already public.

Best next move

Open an engine, run a demo, then follow the source link when the behavior matters more than the summary.

Model workflows.

local endpoints, harnesses, benchmark loops, context maps, and agentic work patterns that can be measured instead of narrated.

Start here

Start with flywheel for routing and verification, relay for coding across endpoints, plexus for tool wiring, and mneme for memory. Use telos, forum, gather, index, and crucible for the shared workflow loop.

Best next move

Bring a real workflow, repo, or document set. The useful question is what should become a repeatable loop.

Graphics and generated media.

procedural fields, render pipelines, color systems, engine instrumentation, and generated specimens that become site material.

Start here

Use the Studio, generative demos, Quanta Color, and graphics pages when you want to see the visual side of the workshop.

Best next move

Look for outputs that are generated by the system itself: canvases, textures, captures, and tool-made artifacts.

Research and writing.

papers, essays, field notes, release notes, and the public record of what is stable, forming, or still speculative.

Start here

Use research when you want formal artifacts and writing when you want the plain-language version of the thinking.

Best next move

Read one piece, then jump sideways into the engine or demo that made the idea concrete.

Consulting and collaboration.

freelance work, test runs, technical strategy, prototype development, and research collaboration across unusual domains.

Start here

Use work routes when you need a concrete engagement: audit a workflow, build a prototype, shape a benchmark, improve a site, or pressure-test a tool.

Best next move

Send the artifact or problem. The first pass should turn ambiguity into a scoped run, not a vague sales call.

Private-line work.

larger internal systems, lab-only infrastructure, and public-safe slices that are described by capability without exposing sensitive internals.

Start here

Use Checkpoint, Runtime, Vault, Boundary, and the private-line pages for the public portions of the larger platform.

Best next move

Stay with the public-safe slices. Anything private is described at the boundary, not opened by accident.

Different doors, one workshop: systems that can be tried, inspected, adapted, or discussed without pretending the whole body of work is one product.

Flagships.

Everything below is part of the public map: engines, private-line slices, graphics systems, papers, essays, and product experiments. The workspace behind them is mapped by index itself, while public and private surfaces stay explicitly separated. The private-line flagships publish only the pieces that can be safely shown, while Lab (Seed) and Ledger (Sofer) remain private until a clean public split is ready. The map is meant to help you choose a door, not memorize the whole building.

The fourteen engines

flywheel route + verify A companion for every model. Routes to any model, local or hosted, verifies what it can, escalates only the hard part, and hands back a re-checkable receipt. Public, FSL-1.1-MIT. Public
telos the engine A shared surface where a person and a model shape the same artifact. Demonstrated live in the Studio; public demo repo at v0.2.0. Its tools package runs, measurements, source refs, and visual outputs into material that can be replayed, compared, and improved. Live
index the map A repository-inventory and dependency-graph engine for many-repo workspaces. index-graph 2.9.0; Development Status Beta. Beta
gather the intake Reaches information from anywhere, guarded APIs, JavaScript-walled pages, scans, audio, and papers, and records how each item was obtained. gather-engine 1.6.1, the current tagged release in the local public clone. Shipped
forum the orchestrator Runs a team of agents with routing, quality checks, and a replayable causal ledger. forum-engine 1.13.0, a versioned public package. Shipped
crucible the judgment Registers a thesis, steelmans its claims, measures them against a substrate, tracks drift across rounds, renders Markdown assessment reports, and refines the weakest axis until the verdict is earned. crucible-bench 1.2.0, a versioned public package. Versioned
emet byte integrity Re-derives a file's bytes from scratch and reports whether the bytes match, changed, or cannot be checked from the available material. EMET 1.1.0, four independent implementations, public on PyPI. Shipped
buildlang the authoring language A typed-effects systems language. Functions declare the effects they may perform and the lifetimes of returned references, checked by the compiler and lowered through a constrained C path. v1.2.0 manifest source version; the primary compiler and C backend work, shader outputs are supported, and additional backends remain experimental. Shipped
learn learning aid + credential provenance Turns your own material into a course: spaced repetition, retrieval practice, predict-then-observe against the telos engine, and self-explanation checked by crucible. Every graded step records what happened. v1.6.0 source version; a public accountable learning and coursework engine. Shipped
relay the coding agent A zero-dependency coding agent for any endpoint, with failover across providers, a gated tool loop, and a witnessed ledger of every step. Public. Public
plexus tool interop Capability discovery and auto-wiring for agent toolchains: reads what each tool emits and consumes, then connects them into an inspectable pipeline. Public. Public
mneme agent memory Accountable memory for agents: layered stores and hybrid retrieval where every memory carries its provenance, so recall traces back to its source. Public. Public
studio-engine world generator Generates replayable creative worlds, shaders, sound, and motion drawn from a seed and carried with a receipt, so the same inputs redraw the same world. Public. Public
build color measure color A bounded color-science workbench for perceptual color, HDR tone mapping, appearance models, ICC profiles, LUTs, and measurable fidelity. Build Color 1.0.2, public on PyPI, beta. Beta

Private-line flagships

Checkpoint Aleph Coordinates the private-line platform across docs, package contracts, MCP declarations, CI state, release notes, and public-safe package surfaces. Private line; public overview: the Checkpoint page. Public
Runtime ORCA Native owner runtime for local run state, module execution, artifacts, release provenance, and handoff checks. Private line; public overview: the Runtime page. Public
Vault Kun Access recovery vault with path-only records, manual diagnostics, rotation discipline, and owner-held credential boundaries. Public repo, value-free by design. Public
Boundary behavior-transform Mode-aware read, write, exec, fetch, input, and model-boundary records that keep raw content inside local adapters while hosts receive counts, hashes, decisions, and redacted refs. Public
Lab Seed Controlled native assessment labs and deterministic fixtures. Still private because the tracked source includes internal/offensive modules and token-shaped corpora that need a public-safe split before publication. Private split
Ledger Sofer Agent workflow routing across intent, admission, execution, and run records. Still private because tracked source includes credential-pattern corpora and internal security-research material that need a public-safe split before publication. Private split

Secondary substrates

proof-surface the check A checkpoint that says no until it’s sure, and stays shut if anything goes wrong; when permission is passed down a chain, trying to grant yourself more than you were given is refused outright. Standard-library only, zero dependencies. Shipped
coherence-membrane the organs Witnessed perception that carries its own honest record of where it came from, plus a self-test built to be proven wrong. An observation that carries its own warrant, or fails. Shipped
accountable-surface the live loop The full experimental loop: perception, default-deny action boundaries, append-only memory, native actuation, and a grounding cortex. The theory, made operational. Shipped
accountable-engine the equalizer The same standard, turned back on the maintainer. A critic that reads the live state of the work and asks the hard questions of the human, not only the machine. Published to stake the idea; the inward half is owed. Forming
RAW rendering GPU drawing code, grown out of a game-engine stand-in into an inert source of frames. The drawing branch of the shared foundation the perception work sits on. Evolving
The Studio the composition Five photo-steered drawing algorithms: run one again from the same starting number and you get the exact same drawing. It is the visual workshop where generated material, fingerprints, and action boundaries meet on a shared backbone. Live

Bricks

the release toolkit shipping discipline The ring of small tools that run on every release: secret sweeps, an evidence index, provenance checks, guarded IO. 6 on PyPI, the rest public on GitHub. Shipped
provenance-sensorium release hygiene A local pre-release sensor. It fingerprints what it saw, blocks a leaked secret, and keeps release authority with the maintainer. Zero-dependency, local-only. Shipped
the Build products the product line Source-visible forecasting and paper-trading toolkits with shared interface and color layers. Each readiness claim is bounded to a named public package and its current evidence. Beta
The Witnessing Spine sector research Five adversarial steelmans across financial-sector technology, plus a synthesis. The evidence, drawn from the field, that the seam shows up everywhere. DOI 10.5281/zenodo.20778927. Published
Conferred Existence philosophy A long-form philosophical foundation for made minds, perception, memory, external anchors, and what it means for a system to stand in relation to the world. DOI 10.5281/zenodo.20773724. Published
Systems papers six preprints Six short papers on byte integrity, typed capability effects, verifier independence, action envelopes, re-perceived effects, and automation boundaries. All archived on Zenodo with permanent DOIs; arXiv is endorsement-pending. See all six › Published
Essays plain-language Verified Is Not Trustworthy, Conferred Existence, and the broader field notes. The arguments written to be read, tested, adapted, and argued with. Hosted independently. Published

Also on the site: the catalog, the resume, and the CV. WARDEN is one private-line branch of the larger Project Telos map.

Two small live demos. Specific tools, not the whole thesis.

These examples show one track inside the larger workshop: byte integrity and action boundaries. They stay here because they are concrete, runnable, and useful, but they no longer carry the whole site’s public framing.

Demo I EMET · byte integrity from the browser input
# re-derive a file's bytes from scratch and compare to the seal
>>> witness(path, seal)
MATCH     sha256 re-derived, identical to the sealed digest

# the same file, one byte changed
>>> witness(tampered, seal)
DRIFT     re-derived digest differs from the seal

# asked to confirm a property with no evidence to re-derive it from
>>> witness(path, seal=None)
UNVERIFIABLE   no seal to check against, not a pass, not a fail

This demo fingerprints text locally and compares it to a stored seal. The point is practical: tiny changes become visible, and missing comparison material is labeled as missing.

EMET ships a tamper-seal that rebuilds a file’s bytes from scratch across four independent language implementations. Honest limit: a plain seal can show whether bytes changed relative to that seal, but it cannot stop a determined forger who controls both the file and the seal. For that, the seal needs an anchor outside the file.

Demo II proof-surface · action boundaries and scoped permission
# a gate request whose authorization receipt is absent
>>> evaluate_gate(request)
GateDecision(decision="deny")
  authorization: no receipt, deny
  budget:        unknown, needs-human

# a delegate trying to widen its own granted scope
>>> verify_delegation(chain)
DENIED    hop scope is not a subset of its parent, privilege escalation

$ python -m pytest
# run the repository suite for the current result

The library models action boundaries: missing permission denies, empty permission grants nothing, and a delegated step cannot quietly widen its own scope.

The check ships in proof-surface: standard-library only, zero dependencies, with its current suite and source at github.com/HarperZ9/proof-surface. Honest limit: the check gives advice, a careful recommendation the real system still has to carry out. The library itself doesn’t hold the power to force it.

The shared backbone (system/spine.js) lets these pieces show up in the studio, where generated drawings can carry fingerprints and boundary checks without turning the whole site into one security product.

Run them yourself: the demos run locally in the browser where possible. Open the recorded demonstrations →  ·  open the studio route →

How it checks itself

The same checking runs underneath everything here. Try it, then forget about it.

Byte fingerprint demo. Type, seal, change, compare.

Try it. Type something, then seal it. The demo takes a fingerprint of those exact words and remembers it. A fingerprint here is a short code that any change, even one character, would scramble into something completely different. Change one letter and compare again: the fresh fingerprint no longer matches the one it kept. Clear the seal and there is nothing to compare against.

NO SEAL
No saved digest yet. Seal the content to create something to compare against.

The fingerprinting is the real thing: crypto.subtle.digest("SHA-256"), a tool built into your browser, run on what you typed and never sent anywhere. EMET does the same across whole files in four independent language implementations; the source and frozen specification live at github.com/HarperZ9. Honest limit: a plain seal like this only compares bytes against the seal you kept.

The check. Allow is earned, not assumed.

An action arrives at the check, hoping to go ahead. The check says no by default. It is a checkpoint that says no until it is sure. When anything is unclear it still says no: no permission slip means deny; anything it can’t be sure about becomes needs-human (stop and ask a person); and allow comes back only when every single thing checks out. Flip the conditions below and watch the answer move. Try to earn an allow, and notice just how much has to be true at the same time.

The request’s conditions
ALLOW
Every check passes: authority is stated, scoped, timed, budgeted, and grounded in observed state.

This is the real decision logic: a single no settles it; anything unknown becomes needs-human; and an allow needs every check to pass at once. The tested original lives in proof-surface: plain Python, nothing extra to install, with current source and suite at github.com/HarperZ9/proof-surface. Honest limit: the check only gives a recommendation; the program around it does the enforcing. This page can never grant a yes on its own.

The standing invitation.

I’m putting the public portions of the workshop in one place so the range can be understood without a private tour. Some projects are mature, some are forming, and some are deliberately held back until they can be separated from sensitive internal work. The public map should make those boundaries legible.

If you are evaluating the work, start anywhere concrete: run a demo, open a package, read a paper, inspect the generative surface, or send a real problem. The best conversations begin with an artifact on the table.

Bring a workflow, a research thread, a prototype, a site, or a hard technical knot. The point is to make it tangible.

Run it: the recorded demonstrations · the studio · the deck  ·  Research: the program · essays  ·  Code: github.com/HarperZ9  ·  Contact: email