Skip to content

Core Boundary

All business rules live in src/argus/core. CLI + Skill and MCP are the primary AI-agent adapters; REST is the HTTPS and batch adapter. All call the same core service and serialize the same result contract.

Tenant, permission, license, schema, provenance, and audit checks execute in one shared governance sequence

Shared Core Responsibilities

  • Machine authentication context consumption.
  • Permission and tool whitelist decisions.
  • Data license decisions.
  • Schema, evidence, provenance, and output-origin validation.
  • Write-ahead audit records.
  • Source evidence and data quality validation.
  • Point-in-time filtering.

Access adapters must not duplicate these rules. If a behavior differs between CLI, REST, and MCP, the fix belongs in core, not in one adapter.

Current Shared Boundary

CoreServiceBoundary is the central execution wrapper. It receives a CoreRequestContext, writes audit state, evaluates tenant and permission checks, invokes the operation, enforces data licenses and schema/provenance rules, records observability metrics, and returns a structured result. It does not reject a fact request because the client intends to perform investment analysis, and it does not constrain the client AI agent's independent reasoning or final output.

The adapter files are:

  • src/argus/cli/app.py
  • src/argus/api/routes/tools.py
  • src/argus/mcp/server.py

Each adapter must preserve the same facts, source evidence, license status, quality result, output restrictions, and audit id for equivalent requests.