10. Central Service and Secure Execution Architecture
10.1 Overall structure
The Interaction Plane captures intent and approval. The Control Plane manages request state, consent, policy, trust level, and recovery. The Execution Plane runs isolated Task Capsules through approved Nodes. The Settlement Plane may later reconcile verified B2B service outcomes. Personal data remains off-chain; public evidence is minimal.
10.2 Central-service responsibilities
- Request lifecycle and idempotency
- Consent, policy, trust-level, and service-catalog management
- Node discovery, eligibility, health, and routing
- Minimum evidence, dispute, and audit coordination
- Human-help matching and safe handoff
- Reward calculation and budget controls
The central service does not become a permanent warehouse of passwords, OTPs, payment keys, raw health records, or complete household observation.
10.3 Node responsibilities
Nodes attest their operator, device, software image, security state, allowed data class, region, and service capability; accept only matching Task Capsules; perform bounded work; return outcome and deletion receipts; and support incident containment and revocation.
10.4 Request assignment
Routing considers task risk, data class, required institution or region, accessibility capability, available official integration, Node trust, latency, cost, energy, and human-help availability. The cheapest Node is not automatically selected.
10.5 Data classes
| Class | Example | Default handling |
|---|---|---|
| D0 | Public service information | Approved public compute |
| D1 | De-identified preferences or telemetry | Minimum retention and bounded analysis |
| D2 | Booking identity and contact data | Isolated managed execution |
| D3 | Health, disability, or financial context | Contracted or institutional environment |
| D4 | Credential use or consequential approval | Personal approval point only |
10.6 Failure and recovery
Requests use idempotency keys, bounded retry, checkpoints, external outcome reconciliation, cancellation and refund state, and explicit handoff. A Node failure does not silently become a duplicate purchase or submission.