Skip to content

Narrow Dioptron to the web-origin runtime and remove research/intelligence/offensive-ops ownership #55

Description

@forkwright

Finding

Dioptron has a strong enduring authority as the sovereign web-origin runtime: fetch/render/script execution, site/session identity, immutable capture and extraction provenance, browser-native actions, tenant grants, and audit. Its current specification also absorbs research synthesis/intelligence, knowledge-tier judgment, and general offensive/network operations that already have nearer fleet authorities.

Those concerns do not share the web-origin runtime's core invariant. They should consume Dioptron's captured evidence and browser capabilities through typed seams, not become part of Dioptron's public semantic authority.

Evidence

Verified against Dioptron main 28420ad540f6a9666999b4a6a4a32113ed51f6d5 (the only delta from the locally inspected docs commit is release metadata) and Kanon origin/main@bc910dec342e6d3c6cb71cd0fa8146117ef5551b:

  • Kanon projects/dioptron/vision.md:7-25 establishes the coherent center: a tenant-authenticated sovereign web runtime with durable captures, extraction, query, and an agent/operator capability surface.
  • docs/requirements.md:62-68 contains browser/web-adjacent actions that remain coherent with that center.
  • docs/requirements.md:69-80 assigns port scanning, service fingerprinting, MITM, credential testing, exploit execution, and cover traffic to Dioptron.
  • Kanon projects/dioptron/ROADMAP.md:136-152 assigns sentiment and trend extraction to Dioptron's v1 intelligence layer.
  • ROADMAP.md:197-225 later assigns active probing/MITM/exploitation and contradiction detection/knowledge-tier promotion.
  • Kanon projects/zetesis/vision.md:7-21,33-40 already owns provider-normalized, budgeted, cited research orchestration while consumers retain synthesis and persistence policy.
  • Kanon projects/akroasis/ROADMAP.md:70-77 already owns scope-locked penetration testing, vulnerability scanning, and threat-intelligence operations.
  • Open Dioptron Isolate untrusted web content by site/process, not only D11 operation verbs #33 owns origin/process isolation only. Closed [operator-strategic] dioptron v1 scope decision #7 and design-input: D7/D8 ingest taxonomy, classifiers, and evidence patterns #9 explicitly chose the broader intelligence scope; they are decisions to supersede, not live owners of this correction.

Why this matters

A browser/runtime must carry permanent security complexity for hostile origins, rendering/script isolation, identity, grants, durable evidence, and auditable actions. Research judgment and offensive operations add different threat models, review domains, release cadences, and policy owners.

Keeping all three under one authority creates duplicate research and offensive stacks, makes the web runtime responsible for judgments over its own evidence, and expands the most attack-exposed component's privilege surface. The same fleet capability is stronger when Dioptron produces exact, provenance-bound observations and the owning research/security systems consume them.

Desired correction

Record a superseding Dioptron scope decision and update repo-local requirements/decisions plus Kanon vision/STATE/ROADMAP in one coordinated change.

Retain in Dioptron:

  • origin-facing fetch, render, script, storage, extraction, and query mechanisms;
  • site/session/fingerprint identity and privacy controls;
  • immutable capture/provenance and replay;
  • browser-native actions such as forms, feeds, downloads, and account interaction;
  • tenant grants, dry-run, budgets, revocation, audit, and origin/process isolation.

Move or compose:

  • provider routing, deep-research loops, research scheduling, citation synthesis, and briefings through Zetesis;
  • sentiment/trend/contradiction/promotion judgments to consumer-owned intelligence/knowledge pipelines;
  • port scanning, service fingerprinting, MITM, credential testing, exploit execution, and operational cover traffic to Akroasis peira/its scoped offensive authority.

Define typed evidence/action seams between those systems so the capabilities compound without ownership duplication. Explicitly supersede the relevant #7/#9 decisions and add an authority test preventing future phases from reabsorbing research judgment or general network offense merely because the evidence originated on the web.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions