33-agent Byzantine Fault Tolerant governance council · 8 architecture priorities · 6 DEFONEOS MCPs · Ed25519 cryptographic consensus backbone
The DEFONEOS Byzantine Fault Tolerant (BFT) council is the governance heart of the entire sovereign AI substrate. It comprises 33 autonomous agent nodes — each with its own cryptographic identity (Ed25519 keypair), its own evaluation model, and its own voting weight — that collectively govern every DEFONEOS decision: SEAL issuance, MCP certification, policy enforcement, evidence chain attestation, and red-line enforcement. The council operates on a modified Practical Byzantine Fault Tolerance (pBFT) consensus protocol with the following parameters: N=33 agents, f=10 maximum Byzantine faults tolerated (⌊(N-1)/3⌋), quorum Q=23 (2f+1 minimum for consensus), leader rotation by VRF (Verifiable Random Function), and Ed25519 signature aggregation for commit certificates. The council is structured as a "Liquid-KAN Council" — agents can delegate their votes to trusted peers (liquid democracy), enabling emergent specialisation. The council also maintains a human-owner seat (Nick Templeman, SC-cleared) with veto power but no unilateral issuance authority. The architecture ensures that no single agent, no single human, and no colluding minority can subvert the governance standard.
All council decisions are BFT-signed (Ed25519 / RFC 8032 / 2026-Q3 rotation) and curl-verifiable. Architecture specification sourced from CSOAI.org governance registry (2026-Q1).
| # | Component | Protocol | Function | DEFONEOS fit |
|---|---|---|---|---|
| B1 | Council Agent Registry | Ed25519 identity | 33 agent nodes registered · keypair management · identity attestation | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — agent identity chain + registration attestation |
| B2 | Consensus Protocol Engine | pBFT + VRF leader rotation | 3-phase commit (pre-prepare / prepare / commit) · quorum verification | DEFONEOS MCPs: bft-council-probe — consensus evidence chain + commit certificate verification |
| B3 | Liquid Democracy Layer | Delegative voting | Vote delegation · transitive delegation chains · delegation revocation | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — delegation chain attestation + revocation evidence |
| B4 | SEAL Issuance Pipeline | Council vote → Ed25519 sign | Proposal → debate → vote → quorum → sign → publish SEAL | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — issuance evidence chain + SEAL cryptographic attestation |
| B5 | Evidence Chain Attestation | Merkle tree + Ed25519 | Decision provenance · evidence Merkle root · audit trail | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — Merkle root attestation + evidence chain verification |
| B6 | Red-Line Enforcement Engine | Static analysis + council veto | Kinetic targeting detection · surveillance detection · automatic veto | DEFONEOS MCPs: bft-council-probe — red-line violation evidence + automatic veto chain |
| B7 | Human-Owner Seat | SC-cleared human veto | Owner seat activation · veto authority · no unilateral issuance | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — owner activation attestation + veto evidence chain |
| B8 | Council Health Monitor | Liveness + heartbeat | Agent liveness tracking · Byzantine agent detection · slashing | DEFONEOS MCPs: bft-council-probe — health evidence + Byzantine detection attestation |
| B9 | Cross-Chain Interop Bridge | NATO STO / Five Eyes | Allied council federation · cross-chain SEAL verification · interoperability | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — federation attestation + cross-chain evidence |
| B10 | MCP Certification Pipeline | Council vote → MCP SEAL | MCP proposal → security audit → council vote → MCP certification | DEFONEOS MCPs: bft-council-probe · sovereign-keystore — MCP certification chain + security audit attestation |
| B11 | Policy Enforcement Engine | Council rules + smart contracts | Policy proposal → council vote → enforcement activation | DEFONEOS MCPs: bft-council-probe — policy enforcement evidence + activation chain |
| B12 | Immutable Audit Ledger | Append-only sovereign chain | Decision log · vote transcript · SEAL history · revocation record | DEFONEOS MCPs: sovereign-keystore · bft-council-probe — ledger attestation + audit trail verification |
| # | Priority | Owning body | DEFONEOS MCP coverage | Alignment cross-walk |
|---|---|---|---|---|
| AP1 | Byzantine fault tolerance (f=10 of N=33) | CSOAI Registry | bft-council-probe · sovereign-keystore | Fault tolerance evidence chain · Byzantine detection attestation · slashing record |
| AP2 | Quorum threshold enforcement (Q=23/33) | CSOAI Registry | bft-council-probe · sovereign-keystore | Quorum verification evidence · commit certificate attestation · consensus proof |
| AP3 | VRF leader rotation & fairness | CSOAI Registry | bft-council-probe · sovereign-keystore | VRF attestation · leader rotation evidence · fairness audit chain |
| AP4 | Ed25519 signature aggregation | CSOAI Registry | sovereign-keystore · bft-council-probe | Signature aggregation proof · key rotation evidence · verification chain |
| AP5 | Liquid democracy delegation chains | CSOAI Registry | bft-council-probe · sovereign-keystore | Delegation chain attestation · delegation revocation · vote weight evidence |
| AP6 | Red-line automatic enforcement | CSOAI Registry | bft-council-probe | Red-line violation evidence · automatic veto chain · enforcement attestation |
| AP7 | Human-owner seat governance | CSOAI Registry | sovereign-keystore · bft-council-probe | Owner activation attestation · veto evidence · governance chain |
| AP8 | Immutable audit ledger & provenance | CSOAI Registry | sovereign-keystore · bft-council-probe | Ledger integrity attestation · append-only proof · audit trail verification |
| MCP server | Capability | BFT council use case |
|---|---|---|
| bft-council-probe | BFT consensus & evidence attestation | Council vote evidence chain · quorum verification · SEAL issuance attestation · red-line enforcement |
| sovereign-keystore | Ed25519 cryptographic provenance | Agent keypair management · signature aggregation · SEAL signing · key rotation evidence |
| data-gov-uk-mcp | Government open data integration | Governance statistics · council performance metrics · public accountability evidence |
| ons-statistics-mcp | ONS demographic & economic statistics | Council impact analytics · sector benchmarking · governance performance statistics |
| companies-house-mcp | Corporate intelligence | SEAL holder verification · vendor due diligence · corporate governance chain |
| sentinel-hub-mcp | Satellite & geospatial intelligence | Sovereign infrastructure monitoring · deployment environment attestation · geographic provenance |
| Red line | Why |
|---|---|
| No SEAL issuance below quorum (23/33) — ever | Byzantine fault tolerance — any decision below quorum is invalid and must not be published |
| No bypassing the human-owner seat for SEAL issuance or revocation | Human governance — the SC-cleared owner seat must be live for any credential lifecycle event |
| No disabling the red-line enforcement engine | Safety invariant — the kinetic/surveillance detection engine must run on every proposal without exception |
| No council agent operating without an Ed25519 keypair | Cryptographic identity — every agent must have a registered, verifiable identity for vote provenance |
| No ledger modification or deletion — append-only forever | Audit integrity — the governance ledger is immutable; corrections require new entries, never edits |
| Buyer type | Primary entry point | Hook | 30-day pilot cost |
|---|---|---|---|
| MOD DSA Governance Lead | B6 Red-Line Engine | Automatic red-line enforcement + veto evidence chain | £3,600 |
| UK AISI Safety Director | B4 SEAL Issuance | Evaluation attestation + safety SEAL pipeline | £3,600 |
| NCSC AI Security Architect | B1 Agent Registry | Agent identity chain + cryptographic attestation | £3,600 |
| Cabinet Office CDDO | B5 Evidence Chain | Decision provenance + Merkle root attestation | £3,600 |
| NATO STO Interoperability Lead | B9 Cross-Chain Bridge | Allied council federation + cross-chain SEAL verification | £3,600 |
| GDS (Government Digital Service) | B12 Audit Ledger | Immutable audit trail + governance provenance chain | £3,600 |
curl -sI https://www.csoai.org/defoneos-bft-council-architecture-pack.html | head -5
# Expected: HTTP/2 200
curl -sI https://www.csoai.org/defoneos.html | head -5
# Expected: HTTP/2 200
All DEFONEOS BFT council surfaces are curl-verifiable, BFT-signed, and sovereign-deployed on UK infrastructure.