FortEmerald, layer by layer.

Eight connected layers govern runtime health, identity and authority, protected context, AI routing, execution, evidence, cryptographic protection and integration across cloud, customer and edge environments.

One request can cross identity, data, intelligence, approval and execution systems.

An operator, service or AI request may cross enterprise identity, customer data, a model provider, an approval workflow, a software interface and a connected machine. Without a shared control path, each system records only part of who acted, what was disclosed, which policy applied and what happened.

FortEmerald keeps the complete operation connected.

A tenant-bound request reference links identity, permitted context, the approved processing route, action authority, destination delivery and reported result. Each layer owns one responsibility while contributing to the same evidence trail.

Identity and authority
Sapphire evaluates disclosure and action separately using the current principal, purpose, target, posture, policy and approval state.
Context and processing
Emerald creates the permitted information capsule; Opal selects and records an approved processing route when the task requires one.
Operation and integration
Titanium forms one bounded operation; Copper translates it at the destination boundary and returns native state and results.
Runtime, trust and evidence
Silicon operates the route, Alloy protects its identities and artifacts, and Amber records each material checkpoint.

Silicon

Platform runtime

Runs FortEmerald across managed cloud, customer cloud, on-premises, edge and isolated environments. It keeps version, placement, dependency health and recovery state available to every control decision.

Evaluate the environment

Evaluates the deployment profile, isolation tier, runtime requirements, compatibility, capacity, latency and approved maintenance window before a workload or service is admitted.

Admit an approved release

Matches software version, deployment profile and compatibility requirements to an eligible runtime cell.

Observe the complete route

Combines health from control services, queues, storage, model endpoints and edge connections into the operating posture of the route.

Recover within policy

Pauses an unhealthy rollout and coordinates recovery or rollback through the deployment runtime while reporting the route as degraded or unavailable.

Desired stateApproved release + deployment profile
Managed cellCustomer cellEdge cellIsolated cell
Health gateready · degraded · rollback · recovery
Placement, version and health remain visible to the policy and evidence domains throughout a request.

Works withSapphire, Opal and Titanium use runtime posture. Amber records rollout and recovery, while Alloy protects releases and workload identities.

Sapphire

Identity and authority

Determines who or what is making a request, which tenant and scope apply, and the authority available for one purpose. Permission to access context and permission to perform an action are evaluated separately.

Bind the principal

Separates initiator, acting service or agent, delegator, owner and approver, then binds them to tenant and compartment scope.

Build the decision context

Combines purpose, target, action, relationships, time, location, risk, posture, parent authority and evidence freshness.

Intersect every policy

Applies role, attribute, relationship and safety rules together. Applicable restrictions narrow authority and required obligations accumulate.

Issue bounded authority

Returns a versioned decision and, when permitted, a short-lived capability bound to the requester, target, purpose and action.

PrincipalPurposeTargetPostureApproval
Policy intersectionIdentity + attributes + relationships + risk
Disclosure rulesRequired obligationsBounded capability
The same request returns for a second decision when an interpretation or AI proposal becomes a specific action.

Works withCopper target state and Silicon posture inform policy. Disclosure rules go to Emerald, route limits to Opal, and action authority to Titanium. Amber records each decision.

Emerald

Protected context

Builds the minimum information package needed for one task. Approved fields, transformations, audience, purpose and expiry remain attached while broader records stay in their source systems.

Resolve approved sources

Uses the disclosure decision to identify the allowed records, snapshots, fields and source-system references for the task.

Apply data boundaries

Enforces tenant, compartment, row, field, classification, purpose and audience limits before disclosure.

Minimize and transform

Redacts, tokenizes or replaces protected identifiers with opaque references and excludes reusable credentials.

Bind and expire

Packages the approved content with recipient, purpose, handling rules, digest, expiry and a separate disclosure receipt.

Source recordtower IDsensor faultweathertechnician namecustomer record IDoperating limits
filterredactbind
Expiring capsuleFault + conditions + approved limitsAudience · purpose · digest · expiry
Withheld fields are excluded from the capsule. The evidence record receives a disclosure receipt and content digest by default.

Works withSapphire supplies disclosure rules and Copper can supply current machine state. The capsule goes to Opal or a deterministic consumer; Amber receives the disclosure record and Alloy protects the artifact.

Opal

Governed intelligence

Selects the approved AI model, agent or deterministic service allowed to process a task and the environment in which it may run. Its output remains a proposal until consequential action is authorized.

Find eligible releases

Filters the approved catalogue by task capability, classification, contract, geography, provider handling terms and endpoint health.

Select the environment

Balances locality, sovereignty, latency, availability and cost inside the restrictions already attached to the request.

Invoke under external limits

Applies token, spend, time, recursion, delegation and tool-use limits outside the model’s own instructions.

Validate the return

Checks response schema, actual route identity, release, endpoint and usage while preserving the output as untrusted input to the next decision.

ClassificationResidencyRetentionLatencyCostHealth
External modeleligible
Private modelselected
Deterministic serviceeligible
Validated returnInterpretation or typed proposalRoute + release + endpoint + usage
The intelligence step is conditional. Direct operations continue through the request contract from authorized typed input.

Works withUses the Emerald capsule, Sapphire route limits, Silicon endpoint health and Alloy channel identity. Proposals return to Sapphire; route evidence goes to Amber.

Titanium

Controlled execution

Turns an authorized request or proposal into one typed, target-bound and time-limited operation. It binds the action to current state, approval, parameter limits and a result contract before release.

Revalidate authority and state

Confirms requester, target, purpose, action, approval, expiry and prerequisites still match the current request and destination state.

Build the operation envelope

Binds typed parameters and bounds to the connector contract’s side-effect, timeout, idempotency, rate, retry and compensation rules.

Release through a connector

Provides one constrained operation to the selected connector. The operation carries scoped authority while downstream credentials remain inside the connector boundary.

Reconcile the outcome

Separates delivery, native acknowledgement and observed state, and preserves an indeterminate result when completion cannot be proven.

Bounded operation
Target
drone-17
Action
survey
Bounds
geofence + 90 m
Valid
14:00–14:20
Approval
ops-approval-42
Replay
single use
issueddeliveredacknowledgedobserved
Authorization, delivery, acknowledgement and verified outcome remain separate facts throughout execution.

Works withUses Sapphire authority, an optional Opal proposal, and Copper target state and action contracts. Copper translates the operation, Alloy protects it, and Amber records its lifecycle.

Amber

Evidence and provenance

Creates a linked history of each governed request from identity and disclosed context through route selection, approval, attempted execution, native acknowledgement and observed result.

Capture typed events

Receives distinct decision, disclosure, approval, grant, delivery, acknowledgement, outcome and indeterminate event variants.

Link versions and provenance

Correlates requester, policy, context digest, model release, capability, command, connector and native target state.

Minimize and protect

Applies privacy, retention, isolation, integrity links and checkpoints. Evidence records favor references, digests and source attribution over broad raw-content capture.

Verify and export

Produces reconstructable histories, verification status, checkpoints and governed exports for investigation and assurance.

  1. Requestidentity + purpose
  2. Decisionpolicy + obligations
  3. Disclosurecapsule digest
  4. Approvalactor + scope
  5. Issuedoperation digest
  6. Native ackcontroller source
  7. Outcomeobserved or indeterminate
The evidence timeline records denials, failures and unknown outcomes as first-class results as well as successful operations.

Works withEvery layer emits correlated events. Alloy protects their integrity, Silicon supplies runtime posture, and evidence freshness can inform later Sapphire decisions.

Alloy

Cryptographic protection

Protects identities, channels, commands, software artifacts, policy bundles and evidence across every other layer. Versioned profiles support key rotation and staged migration to new algorithms, including post-quantum profiles where required.

Inventory every boundary

Tracks algorithms, keys, certificates, providers, libraries, hardware limits, owners and the objects or channels they protect.

Select a protection profile

Applies tenant, environment and purpose-specific requirements to identity, channel, command, artifact and evidence protection.

Operate the key lifecycle

Handles issuance, custody, signing, verification, rotation, revocation, recovery and retirement with separated responsibilities.

Migrate in stages

Moves selected links through conventional, hybrid and post-quantum profiles while preserving version evidence and downgrade detection.

Protection profile v4Identity · channel · command · evidence
Requester identityContext capsuleCapabilityOperationConnector sessionEvidence event
ConventionalHybridPost-quantum
Each protected object records the profile and version used so migration can proceed by boundary and customer environment.

Works withEvery layer requests protection for its identities, channels or artifacts. Sapphire evaluates the authority behind verified identities, Silicon runs protected workloads, and Amber records validation and migration events.

Copper

Integration fabric

Connects applications, data platforms, infrastructure managers, industrial systems, gateways and machines through consistent typed capabilities and results. It translates both incoming state and authorized outgoing operations.

Discover the estate

Discovers and reports asset and controller identity, protocol and firmware versions, posture, health and the typed capabilities each target supports.

Normalize state

Publishes telemetry and source references with units, timestamps, quality and freshness so policy can reason over comparable facts.

Translate bounded operations

Checks target, expiry, sequence, replay state, limits, prerequisites and local readiness before mapping an operation to a native API or protocol.

Return native evidence

Reports delivery, controller acknowledgement, before-and-after state, errors and a completed, failed or indeterminate outcome.

FortEmerald contracttyped capability + bounded operation
Connector nodeidentity · validation · translation
REST / gRPCOPC UAMQTTMAVLinkROS 2vendor API
Return pathacknowledgement · state · result · error
The highest stable destination interface receives the validated bounded operation as the source for native translation.

Works withSupplies target state to Sapphire, Emerald and Titanium. Titanium provides authorized operations; Alloy protects the connection, Silicon monitors runtime health, and Amber receives the returned evidence.

How the layers work together.

Each request uses the layers it needs. Permission to disclose information and permission to act are separate decisions, so the authority layer is consulted at both points.

  1. CopperIngressPublishes normalized target identity, capabilities, posture and current external state.
  2. SapphireDisclosure decisionEvaluates identity, purpose and permission to access context.
  3. EmeraldContext capsuleBuilds the minimum temporary information package.
  4. OpalOptional intelligenceSelects an approved model, agent or deterministic service.
  5. SapphireAction decisionEvaluates the exact proposal and any required approval.
  6. TitaniumBounded operationCreates one typed, target-bound and time-limited action.
  7. CopperDestination and returnTranslates the bounded operation and returns native acknowledgement, observed state and result.
Silicon

Runs and monitors the runtime services, queues, storage, model endpoints and edge runtimes used by the request.

Alloy

Protects identities, channels, commands, artifacts and evidence with the selected cryptographic profile.

Amber

Receives a correlated evidence event at each material decision, disclosure, delivery and outcome.

Platform evaluation for one governed operation.

Request a platform session