Horos Engineering

Horos ODC — observation, decision and control architecture

A horos is a boundary: the line where a thing's competence ends. The architecture is named for what every unit in it enforces — it reads another system's state from the signals that system already produces, decides what may be acted on and what may be kept, and refuses rather than guesses past the line.

Engineering practice treats the error of a sensing-and-control system as a quantity that can, in principle, be driven to zero. That is the premise this work is built against — because a system built as though it can fails silently: it has no channel in which to say it is acting past what it measured.

No finite observer can be exact, universal and self-certifying at once. So the limits are built as parts rather than assumed as good behaviour — seven units. What observes without writing back. What detects, to a declared error budget with an explicit boundary of competence. What admits, abstains or refuses. What holds state coherent across sessions. What remembers with provenance. What watches the loop for the failures a fluent loop cannot see in itself. What keeps the account. Every unit is advisory — the operator keeps the plant at every depth.

What is above is the architecture as specified — what the records call specified geometry: coherent, and derivable from the limits it is built inside. Whether a given unit has run, on a given rail, is a separate question with a separate answer. The three sections below state both — what is built and running, and what is gated and on what.

Three instantiations — and each one is three published records, set out from the premise they answer:

The inference layer #

inference · finite cognition

Inference practice treats a fluent answer and a grounded one as the same output. Nothing in the channel says which one was just produced. No finite observer is at once exact, universal and self-certifying. Under a declared criterion of bounded-error correctness, those limits force a declared error budget, an explicit boundary of competence, and abstention outside it. This is the rail the other two inherit from.

Built and running

  • The stream — arriving claims and proposed acts, generated by the work itself
  • The act governor — reads the perturbation, advises, never certifies
  • The consideration — a paired residual under a declared perturbation
  • The outbound gate — allow, abstain, refuse; fired by reflex, not recall
  • The memory governor — four fail-closed gates on everything durable
  • The observer — watches coupling integrity; detects silent divergence
  • The supervisor — boot, recovery, and the verdict ladder at a wall
  • The account — append-only, each entry chained to the previous tail

Held, not automated

  • The orchestrator — a person occupies this station. It sequences the work and reads what a kernel would read: the work done and the state banked.

In daily use

  • Every declared unit runs here, every day, on already-trained inference engines. This rail governed the campaign that produced and published the other two rails' records.
limit
The Physical Limits of Finite Observation: Seven Bounds on Sensing, Inference, and Control
10.5281/zenodo.21994190
instrument
Deviation as Located Missingness: Turning the Finite-Observation Bound into a Diagnostic Instrument
10.5281/zenodo.21994447
architecture
The Isolation Requirement: Contradictory Demands, Favoured Partition, and Guarded Finalisation in Finite Systems
10.5281/zenodo.21994574
Try to get something past the governorthe fail-closed ladder, and 81 hash declarations checked in your browser

This rail has no plant and no telemetry reader. What runs is governance. The records make no empirical claim — the bounds are established results from information theory, statistical estimation, thermodynamics, computability and learning theory; the contribution is their assembly and the discipline it forces. The isolation result is a scoped design argument, not a theorem about which dynamics make a shared plane infeasible, and its interference threshold is declared rather than derived.

Next rung: the kernel that reads what the architect currently reads, and an orchestration element sealed inside the machine — at which point the person leaves the loop.

Quantum control #

micro · QCA

Quantum control practice runs on characterisations — coherence times, gate errors, frequencies, crosstalk — taken at calibration and consumed by every layer of the stack until the next one replaces them. A device characterisation is an estimate with an expiry, not a standing fact. A control stack that consumes one without an expiry is acting on an unexamined exactness claim.

Built and running

  • The stream — a real device's published calibration history
  • The act governor — QCK; thresholds frozen before the batch
  • The consideration — declared error budget with an explicit competence boundary
  • The outbound gate — three-way inside the detector; the standing unit is specified
  • The observer — the calibration read is itself zero-write; the standing unit is specified
  • The account — hashed manifest; the append-only chain is specified

Gated, and on what

  • The memory governor — opens on a live plant and an operator whose decision the verdict enters
  • The supervisor — opens on a continuously running advisory loop to watch
  • The orchestrator — opens on something downstream that acts on the verdict
limit
The Finite-Calibration Limit: What a Device Characterisation Can Claim Between Calibrations
10.5281/zenodo.21994692
instrument
Detecting Systematic Bias Drift Before Saturation: A Fail-Closed Precursor Estimator for Cryogenic Quantum Control
10.5281/zenodo.21994845
architecture
The Quantum Control Architecture: From a Fail-Closed Estimator to a Governed Measurement-and-Control Layer for Cryogenic Quantum Systems
10.5281/zenodo.21994890
Run the detectora 156-qubit IBM Heron's own calibration history, in your browser

Not exercised on a partner's live telemetry, and not on hardware. Advisory-only under the programme's interface contract: it emits verdicts and writes nothing to the plant. The flagged hardware event is one of four recurring excursions on the same qubit, and the detector's cost on the other three is stated in the record. The schedulability result that would make the partitioned construction the only admissible one does not exist — the construction stands as favoured, not forced.

Next rung: the same kernel on a device's live calibration stream — then that run conducted with the device's operator.

Structural monitoring #

macro · SCA

Structural monitoring rests on a silent premise: that the telemetry a structure produces determines, well enough, the structural state it is in. Telemetry does not determine structural state — not in an un-sensed region, and not below the instrument's resolution within any positive noise floor. Two constructive theorems for a declared observation class. Everything above is built inside that.

Built and running

  • The stream — two public run-to-failure benchmarks
  • The act governor — causal precursor detector, constants fixed before the run
  • The consideration — consistent-set semantics; unresolved spoken as a verdict
  • The outbound gate — two governors ran; the standing unit is specified
  • The account — hashed receipt; the append-only chain is specified

Gated, and on what

  • The memory governor — opens on a live plant and an operator whose decision the verdict enters
  • The observer — opens on an instrumented asset carrying component and sensor identity
  • The supervisor — opens on a continuously running advisory loop to watch
  • The orchestrator — opens on something downstream that acts on the verdict
limit
The Non-Identifiability Limit in Structural Monitoring
10.5281/zenodo.21994945
instrument
Precursor Detection for Structural Systems, Two-Sided: Benchmarked Telemetry Governance and a Proposed Material-State Layer
10.5281/zenodo.21994986
architecture
The Structural Control Architecture: Three Channels and a Governed Seam
10.5281/zenodo.21995057
Run the precursor detectorNASA C-MAPSS turbofans and FEMTO bearings, in your browser

Not exercised inside an operating asset. Both substrates are public archives of units run to failure in a rig. The material-state layer is proposed, not accomplished — design targets with an oracle-free simulation, priced separately from the telemetry evidence throughout. The adversarial ladder closes at a named boundary: a statistically faithful forgery evades a telemetry-only observer in the majority of trials. Two channels agreeing is not yet independent evidence — the common-mode study that would license that reading is unbuilt.

Next rung: the same detector, unchanged, on an operating asset's own stream — then that run conducted with the asset's owner.

Contact #

Horos Engineering builds machine architecture — the observation, decision and control layer between a plant and the person answerable for it. What is published is above, in full, with the limits it was built inside. What is next on each rail is named in that rail's own section.

info@horosengineering.com