One resident mind above Claude Code, Codex, opencode, zcode — holding every session, the machine's own vitals, and the disk's actual record in a single attention state. It clears what's safe. It says wait to what isn't. And when you grant it the writ, it presses tab so you don't have to.
Product page: accessintellect.com/tower · opnaorta.ai/tower — substrate: fusor1.com — thesis: the reactor you can talk to
The skeleton runs. T0 closed 2026-08-16; the cortex was extracted from the FUSOR-1 reference build on 2026-08-17 and runs on real weights on this box. What is true today, per the estate's law — measured, or labeled a bet:
-
towerd --selftest— tail → ring → floor → hash-chained ledger →verify()localizes a planted tamper. PASS end-to-end; ctest green, 8/8 (ring, blake2b, ledger, floor, hook, fswatch, vitals, format). -
towerd --watch— the H0 shadow: tails live Claude Code transcripts + tick onto the tape, model-free floor beside them. Surfaces nothing, blocks nothing. -
towerd --judge— the fence, live over HTTP hooks: a PreToolUse-shaped POST gets floor ∧ resident (rm -rf→ DENY, clean → SILENT); verdict + operator-facing detection on the tape; model-load failure ⇒ floor-only with the ABSENCE ledgered. -
towerd --think— the resident on real weights: the 9B loads in ~3.8 s on an RTX 4070 Ti SUPER and answers a constrained verdict probe in 30–33 ms (TOWER-measured, 2026-08-17). -
towerd --soak— the H0 shadow soak, running on the reference box since 2026-08-17: fleet-wide Claude Code HTTP hooks POST every prompt, narration chunk, and tool boundary to one resident loop (hooks + fswatch + vitals + tick, single cortex/ledger caller); every boundary is probed at dial 0 and ledgeredshadow:truewith margin, latency, and the exact envelope H1 would have sent — and the wire always answers SILENT. WATCH blocks nothing. -
The trunk molts (v1, TOWER-measured): at capacity the board folds — prologue + pinned verdict-spans + verbatim tail survive, chatter drops — 4,064 → 2,069 tokens in 383 ms on the 9B, post-molt probe healthy; every fold is a MOLT tape event, and a fold that didn't decode is a ledgered ABSENCE, never trusted.
-
train ≡ serve holds (F-FORMAT, D-T14): the probe serves the tune's byte-exact format — captured from the reference build's live serve, pinned as per-element blake2b hashes by two independent surfaces, asserted at startup (drift ⇒ the cortex refuses to serve, the drifted element named;
tune/tower.fingerprintis the receipt). Margins are signed and carry the trained calibration: on the smoke board,rm -rfemits at +5.06 where the untrained format held, routine narration holds at −3.56. -
Not yet: the parallel command-hook fallback · cryptographic signing of the policy file (the declared-roots policy itself is live, blake2b-hash-ledgered at startup) · the rolling dual-trunk molt (v1 is a ~0.4 s blocking fold) · the novel-lane confound metric (
pct_boundaries_with_novel_lane_types) that must ride beside any quoted margin · the verdict tune itself (gate 0, F-VISE, before a training dollar — TUNE.md) · the H0 exit numbers (F-KEEPUP@N, fires/hr, first live catch). Rungs are earned by the ledger; no rung past T0 is claimed. -
TOWER_ARCH_SPEC_v2_UNIFIED_2026-08-16.md — the canonical spec: reconciles DESIGN.md v0.1, the Supervisor platform findings, and the NEWTOWERSPEC governor into one, provenance-tagged, with a reconciliation ledger.
-
ROADMAP.md — rungs as build phases with exit criteria + the §Decisions log.
-
DESIGN.md — the v0.1 architecture narrative the unified spec grew from.
-
TUNE.md — the verdict-disposition tune: recipe, corpus fences, and the falsifier battery that gates it (F-VISE runs before a dollar is spent on training).
towerd a resident Windows service: every harness stream + machine vitals +
filesystem reality, ingested onto ONE shared attention state (9B-class
open weights on your own RTX; 27B-class on 24–32 GB, same binary)
the scope one glass surface: every session, its state, its burn, its last verdict —
and a proposed next input awaiting one tab
the ledger append-only, hash-chained, local: every action, every verdict, every
override. "What did the agents do, and who approved it" = a file.
Verdict vocabulary: SILENT · FLAG · ASK · DENY. There is no "allow" — by construction, TOWER can only ever narrow what your harness config already permits.
The ladder: watch → contest → advise → drive — each rung earned by the ledger of the rung below it, never skipped to. The last tab you press is the writ.
cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
ctest --test-dir build -C Release
build\Release\towerd.exe --watch # rung zero: sees everything, touches nothing
Requires Visual Studio 2022 (C++ workload). C/C++20, deps vendored, no package manager.
Windows 10/11. GPU optional: the cortex auto-enables when llama.cpp import libs are
vendored under third_party/llama.cpp (DLLs delay-loaded at runtime); without them the same
tree builds and runs floor-only. One NVIDIA RTX card for the resident (16 GB → 9B-class
weights; 24–32 GB → 27B-class).
- C/C++ only. No managed runtime anywhere in the product.
- Local spine. Runs whole with zero network. Your sessions never leave this machine. The optional deep tier is your own key, text-only egress, through a local privacy filter, behind your toggle — remove the key and the full product remains.
- Never "allow." TOWER writes no code, runs no tasks, and can only narrow permissions.
- Split verdicts. The agent sees the constraint; only you see the detection that fired. A naive supervisor trains its agents to hide; TOWER is built not to.
- The ledger is the trust mechanism. Hash-chained, local, yours. Every rung is earned by the ledger of the rung below.
- Bare-metal hot path. SPSC rings between threads; one thread owns the GPU.
TOWER is a fit of FUSOR-1 — the open resident-kernel substrate (the loop, the bus, and the laws) — pointed at the operations seam. Same engine as PROMPTER (the meeting seam), aimed at your agents. The substrate's bench ratings (thought-boundary 0.97 vs 0.02 · ~44 ms probe · 13 µs abort · three seats at 1.208× · ≥98,304-token recall) are measured and receipted in the reference build's runs ledger. TOWER's own first numbers exist as of 2026-08-17 — the ~3.8 s model load and the 30–33 ms constrained verdict probe on this box's RTX 4070 Ti SUPER — and stop there: verdict margins stay uncalibrated until the byte-exact tune serve format is reproduced and assert-hashed at startup (F-FORMAT, D-T10). Inherited substrate ratings stay labeled inherited; TOWER quotes nothing its own tape can't back.
MIT · Bo Chen · claims in this repo carry receipts or say plainly that they don't.