Overview — Purpose and scope
Mars® Spec › Overview › Purpose and scope
Section index · How to read this specification →
Mars® Protocol — Overview
Version 1.0-draft
PROPRIETARY — LICENSED SPECIFICATION. The Mars® Protocol is a proprietary technical specification owned by Causum. It is not an open standard, an open-source specification, or a public-domain work. Publication of this specification is for evaluation and teaching purposes only and grants no license. Implementing any mechanism described herein requires a valid, executed license agreement with Causum. Patent pending — all patent rights are expressly reserved.
© 2026 Causum. All rights reserved. Mars® is a registered trademark of Causum; the mark is not licensed with this specification.
Licensing: License and IP notice · Patent notice · licensing@causum.com
1. Purpose and scope
Mars® is a formal governance architecture for AI invocations. It is a licensable technical specification. Its subject is the act of governing a single AI invocation: establishing who may direct it, under what authority, within what specification-declared bounds, and with what formal evidence that those bounds were met.
The Capitoline Triad. The architecture is organized under three co-named layers corresponding to the Capitoline Triad — Juno, Jupiter, and Minerva — in that operational sequence.
- Juno (§01) — Modeling. Juno governs form, identity, and the organized expression of living structure. The modeling layer gives form to a domain: it produces the multi-order, multi-perspective, multi-variant formal domain model that every downstream operation takes as its governing reference. Without form, there is nothing for judgment to act on.
- Jupiter (§02) — Analysis. Jupiter governs sovereignty, law, and judgment — the determination of what is true and lawful. The analysis layer applies judgment to the model: it runs the governed battery, lifts artifacts to order-typed form, derives verdicts, and issues certificates. Judgment presupposes form; it cannot operate without it.
- Minerva (§03) — Utilities, APIs, and Applications. Minerva governs skilled craft, strategic intelligence, and the application of knowledge in the world. The Minerva layer provides the knowledge bases, semantic bindings, evidence-gathering mechanisms, governed production pipelines, and service APIs through which judgment is made effective. Craft without form and judgment is unmoored; form and judgment without craft remain inert.
The sequence is a logical necessity: form must precede judgment, and judgment must precede its effective application.
The defining commitment: independent-inspector evaluability. A governed invocation is one for which an independent qualified third party — with no access to internal system state, no trust in the licensee, and no knowledge of the system’s implementation — can re-derive every verdict from retained evidence alone. This property is not a quality claim. It is a structural requirement that every mechanism in this specification is designed to satisfy. Policy documents, audit logs, and content moderation classifiers do not satisfy it: they record, detect, or assert, but they do not produce independently re-derivable verdicts.
The model is opaque. This specification does not govern model internals, training procedures, weights, or gradients. An input enters; an output exits. All governance acts occur at those two boundaries — before the input enters (pre-invocation admissibility) and after the output exits (post-invocation conformance assessment). A model may be substituted, retrained, or replaced entirely; the governance architecture persists.
The invocation is the unit of governance. A single prompt-in / output-out act is the governed unit. Multi-turn sessions are governed by accumulated per-invocation records. The governed artifact is not the model and not the data; it is the invocation and its output, bound together by a recomputation witness and, at the end of the chain, by a conformance certificate.