FloCORE

Fleet & governance

Trust, built in, not bolted on.

A named fleet of oracles and sentinels watches the platform continuously and fuses one Operational Trust Score. AI can move fast, because it can never move unwatched, or unapproved.

The oracles

Four guardians over the fleet.

AO

The conductor. Runs one pass over the whole sentinel fleet, folds in every signal, and fuses the single Operational Trust Score. Nothing goes unwatched.

BO

The AI guardian. Screens every inbound prompt for injection, jailbreak and exfiltration. Defensive-only, human-gated, it watches the AI so the AI stays honest.

CO

The distillation oracle. Turns observations into learned, gated micro-model policy, the keymaker over the AI engines. Effectiveness is the gate; no data, no distillation.

JO

The compliance oracle. Grounds regulation and SOPs into citable policy, and gates the learning loop, not just serving. A model can never promote a non-compliant action just because it worked.

The sentinels

Eleven guardians, one honest score.

Below the four oracles, a fleet of sentinels each watches one dimension of the platform, and folds into a single Operational Trust Score that is measured, never assumed.

Drift

Reconciles each tenant's records vs the rollup, no silent drop, no double-count.

Freshness

Tracks the age of every surface and catches any that has gone silent.

Fraud

Ghost sales, amount outliers, refund and void spikes.

Behaviour

Override and bypass anomalies in the role-decision stream.

Availability

Dependencies, disk, event throughput, and the host watchdog.

Exposure

Weak secrets, enforcement-off, config drift, the platform's own attack surface.

Refactor

Watches FLOCORE's own code-health debt and holds the line in CI.

Smart-Switch

Routes every AI job to the fastest free engine with headroom, on-box for regulated data.

Training

Grounded vs placeholder learning; every module human- and compliance-gated before it publishes.

Booking

No resource double-booked; every money-moving step needs a real human approver.

Visibility

Answer-engine and structured-data readiness for every tenant surface.

Honest by construction

It grades itself, and won't fake green.

When the platform can't prove a dimension is healthy, it says so, and its own score drops. It would rather show a true 76 than a comfortable 100. No dimension defaults to green; every one is earned.

The rules

Guardrails that don't depend on willpower.

A human approves every write

No autonomous world-affecting action. The approver is a real, server-bound identity, distinct from the agent, enforced in code, not policy.

Compliance in every loop

JO sits on the learning loop and the serving loop. A regulated learned action is held for review and never auto-promoted. "It worked in the data" never overrides "it's compliant."

Prod read-only by default

Writes to production need explicit confirmation and provenance. Tests never touch prod. A definition-of-done gate stands before anything is called "done."

The platform watches itself

An interior sentinel wing checks its own durability, invariants and recoverability, feeding the trust score. The fleet reviews everyone; structure reviews the fleet.