The hardest problem in deploying autonomous AI systems is not capability, it is constraint. How do you build a system that can operate at high speed and scale, make consequential decisions autonomously, and yet remain reliably within safe boundaries, even under adversarial inputs, novel situations, or system failures?
DetraCore's answer is seven sequential safety layers that every action must pass through, in order, regardless of its source. A Tier 1 reflex decision, a Tier 2 reasoning decision, a replayed audit decision, an admin override, all go through all seven layers. There are no bypasses.
Layer 1: Input Normalisation and Schema Validation
The first layer verifies JWT identity and validates input against the vertical's schema before any processing begins. Malformed, unauthorised, or out-of-schema inputs are rejected at the perimeter with a structured error response. Feature uncertainty is explicitly computed per input, it is never assumed to be zero.
Budget: ≤5ms. This is a hard rejection gate. Nothing passes this layer without a valid identity and a schema-compliant input.
Layer 2: Confidence-Gated Routing
The Deterministic Router only sends a request to the Tier 1 fast-path if intent confidence ≥ 0.85 (configurable per vertical). Below threshold, the request escalates to Tier 2 reasoning. The system never guesses. A low-confidence input is not processed at speed, it waits for more careful reasoning.
Layer 3: Capability Gap Detection
The Meta-Learning Engine measures the distance between the input and the system's Knowledge Space. If this distance exceeds 0.7, the input is flagged as too novel for safe autonomous processing. The system routes to human review and explains why, rather than attempting to reason beyond its competence.
The safest thing an AI system can do with something it does not understand is say so. DetraCore is designed to fail loudly, not confidently incorrectly.
Layers 4 and 5: Causal Consistency and Guardrail Engine
Layer 4 runs a do-calculus query against the Causal World Model to verify that the proposed plan will achieve the goal and will not violate any registered safety variable. If either check fails, the planner replans with the violated constraint. Maximum two replans, then human review.
Layer 5 is the three-stage Guardrail Engine: policy validation (regulatory rules, PII restrictions), risk scoring (ONNX risk model vs per-vertical threshold), and sequence validation (state machine check for valid action transitions). All three must pass. A failure at any stage halts execution.
Layer 6: Autonomy Level Gate
Even after passing all five previous layers, autonomous execution depends on the configured autonomy level. L0 and L1 always queue for human approval, regardless of confidence or guardrail results. L2 auto-executes only when all layers pass and confidence meets the L2 threshold. The default for novel Tier 2 decisions is L1.
Layer 7: Circuit Breakers and Rollback
Every adapter has a registered circuit breaker configuration and a rollback procedure ID. Sync adapters have a hard timeout, failure returns a safe response, never a partial execution. Async adapters retry with exponential backoff. Every action is reversible by design.
Safety in DetraCore is a structural property of the architecture. It cannot be disabled by a configuration flag, a prompt instruction, or a runtime override. All seven layers execute on every action.
Why All Seven, Every Time
Each layer defends against a different failure mode. Removing any one layer creates a gap that the others cannot compensate for. Schema validation cannot catch a semantically valid but causally dangerous input. The guardrail engine cannot catch a novel input the system should not be processing at all. The circuit breaker cannot prevent a decision that should have been escalated to a human in the first place.
The seven-layer requirement is not conservatism for its own sake. It is the minimum necessary architecture for a system that operates autonomously at enterprise scale in regulated industries.