A map of the five projects
Five repositories, five engineering questions. Each is a working system with its own learning path, grounded in its code, and explicit about what it implements.
| Project | Question | Stack | In this book | |
|---|---|---|---|---|
| I | simple-agent-template | How is a production agent engineered around an untrusted probabilistic component? | Python (NeMo Agent Toolkit), Rust (gateway, MCP), Keycloak, PostgreSQL, OpenTelemetry, MLflow | Part I |
| II | sophos-agent (Σοφός) | How does an agent become durable software that survives crashes and restarts? | TypeScript, SvelteKit, LangGraph.js, SQLite, MCP, Ollama | Part II |
| III | etf-research-agent | How are deterministic policy, evidence and human authority put around probabilistic reasoning? | Rust (rules engine, MCP), Python (NAT), PostgreSQL | Part III |
| IV | arktos-wallet (Άρκτος) | How can software request cryptographic capabilities without holding cryptographic authority? | Rust, Axum, SQLCipher, MCP | Part IV |
| V | tauros-revenue (Ταύρος) | How can agents do operational financial work while humans keep the authority? | Elixir, Phoenix, Ash, AshAI, PostgreSQL | Part V |
How the questions build on each other
flowchart TB
SAT["Part I · simple-agent-template<br/>how a production agent is built and bounded"]
SOP["Part II · sophos-agent<br/>how the agent survives time"]
ETF["Part III · etf-research-agent<br/>how its decisions are governed"]
ARK["Part IV · arktos-wallet<br/>who may exercise a key, and how"]
TAU["Part V · tauros-revenue<br/>who may intend a payment, and why"]
SAT --> SOP
SAT --> ETF
SAT -. "MCP, trust boundaries" .-> ARK
SAT -. "capability vs authority" .-> TAU
TAU -. "planned adapter (not implemented)" .-> ARK
Solid arrows are explicit prerequisites: Sophos and ETF Research link back
into the template's lessons instead of re-teaching them. ETF Research is also
built from the template's code; its UPSTREAM.md records the lineage. The
dotted arrows are conceptual. Arktos and Tauros each draw on ideas from Part I,
but they share no code with it. The arrow from Tauros to Arktos is a roadmap
item in Tauros (Epic 9). No integration code exists in either repository at
the pinned revisions.
From model reasoning to financial authority
The CognoKratos organisation profile describes the portfolio as a ladder. Each rung is held by the component that can be trusted with it:
| Layer | What it holds | Where it is studied | Status at the pinned revisions |
|---|---|---|---|
| Model reasoning | interprets, explains, proposes | every part | implemented everywhere; always advisory |
| Agent capability | bounded tools; no credentials in the model's context | Parts I, IV, V | implemented (MCP tool lists, four wallet tools, eight reviewed Ash actions) |
| Governed intent | deterministic policy and domain rules | Parts III, V | implemented (versioned rules engine; Ash policies and state machine) |
| Human authority | signed or exact approval, verified at mutation | Parts I, III, V | implemented (Part I opt-in; Part III mandatory; Part V exact-payload approval) |
| Cryptographic authority | keys held outside the model | Part IV | key custody and address derivation implemented; no signing |
| Settlement | value moves and is reconciled | none | research direction; not implemented anywhere |
Tauros knows financial intent. Arktos knows cryptographic authority. Today they are deliberately separate. Tauros stores public receiving addresses and never holds a key. Arktos derives addresses but does not sign or broadcast.
The profile and the code
The organisation profile is a summary. The book follows the code at the pinned
revisions. The profile revision used for this edition (cognokratos/.github
2d749e1) agrees with the code on the points earlier revisions had wrong:
- Tauros's invoice lifecycle, exact-payload approval, application-level audit
record and eight reviewed MCP tools are implemented on
main. Payments and reconciliation remain roadmap items. - Original code and documentation in every project are MIT licensed. Third-party material and brand images keep their own terms. See Attribution and licensing.
- The template's example is read-only by default: a human-approved, state-changing action can be enabled.
Research directions
The profile also lists ideas beyond these five projects (analytics, smart-contract vaults, node infrastructure, a platform bringing agents and on-chain workflows together). It states that none has been started. They are not part of this book.