Skip to content

§02e Jupiter — AIGP & Pre-Invocation — AIGP: Causum's pre-invocation governance specification

Mars® Spec§02e Jupiter — AIGP & Pre-Invocation › AIGP: Causum’s pre-invocation governance specification

← Non-AIGP sources — minimum conformance requirements · Section index · What Mars® receives from AIGP at the boundary →

9. AIGP: Causum’s pre-invocation governance specification

AIGP is a specification owned by Kanjani AI Research and commercially licensed exclusively through Causum. Its principal role in the governed round-trip is the pre-invocation phase: from the moment a prompt arrives at the governed system through the moment the model produces its output — the phase in which AIGP is the fail gate. AIGP also governs its own post-invocation stages over the completed invocation (persistence and memory, observation and audit, reflection and optimization), which receive the bundled result and may feed post-hoc processes. This section specifies the pre-invocation phase, which is the phase Mars® takes as a boundary input; AIGP’s post-invocation stages are governed by AIGP and are not part of the Mars® boundary contract (§02e appendix §2). AIGP is the preferred pre-invocation companion for Mars®.

At the category level, AIGP covers:

  • Pre-execution admissibility verdict. Before the model runs, AIGP evaluates the inbound prompt against a governing specification and produces a mechanical, recomputable tri-state verdict — ADMIT, REFUSE, or REFER. The verdict is spec-relative (it changes when the governing specification changes) and is accompanied by a recomputation witness from which an independent inspector can re-derive the ADMIT/REFUSE/REFER result from the order-typed prompt and the governing specification, without executing the original deployment.

  • Context enrichment. For context-starved prompts — particularly those emitted by agents, orchestrators, or automated systems — AIGP traverses knowledge bases and data sources to acquire the context the prompt presupposes but does not carry. The result is an order-typed enriched prompt: the original prompt together with traversed context and a typed gap record, bound to source by a recomputation witness.

  • Model moderation. AIGP governs the model itself across the full model lifecycle: dataset and model generation relative to governing assets, iterative development with recomputable convergence, characterization across multiple governance dimensions, and runtime governance during deployment.

  • Sycophancy gating. At the output locus, before the output is handed to Mars®, AIGP evaluates it against an order-typed, domain-bracketed discrete sycophancy representation. The disposition — admit, refuse, or revise — is mechanical and recomputable.

  • Witness retention. For each admission decision, AIGP retains a recomputation witness: not a record of the decision, but a structured derivation trace from which the decision can be re-derived by any inspector holding the governing specification version. These retained witnesses are the soundness anchors that Mars®-issued conformance certificates inherit.

  • Governance reinforcement loop. AIGP closes a governance loop across the full governed deployment: forensic findings about model behavior route to typed reinforcement actions (update the knowledge base, revise the prompt, swap the model), which change the pre-invocation controls, which produce new evidence, which seed the next forensic cycle. Every arc of this loop is order-typed and recomputable end-to-end across iterations.

AIGP is the preferred pre-invocation companion for Mars® because the two specifications share the same governing infrastructure. Both are built on the same order-decomposition, the same recomputation witness discipline, and the same delta-attestation lifecycle for governing specification amendments. This shared infrastructure is what makes the full governed round-trip coherent end-to-end: an independent inspector can re-derive every verdict in the chain — from the pre-invocation admission decision through the Mars® conformance certificate — from retained witnesses alone, following a single continuous derivation chain across both specifications.

Pre-invocation governance built on different foundations does not provide this continuity. A learned moderation classifier, a policy-file check, or a rules-engine filter can provide admission signals, but they cannot provide recomputation witnesses compatible with Mars®’s soundness-anchor structure, and they cannot participate in the same delta-attestation lifecycle. Mars® can still consume their outputs (§8 covers this), but the resulting round-trip is not end-to-end recomputable in the AIGP sense.

AIGP is a separate specification available from Causum. This document does not substitute for it.



← Non-AIGP sources — minimum conformance requirements · Section index · What Mars® receives from AIGP at the boundary →