Federation
One Vant install is sovereign: its state, its gates, its books. A mesh is several sovereign installs meeting over a signed wire - each keeps its own brain, its own org model, and its own money, while decisions, work, and announcements cross org boundaries safely.
On this page
The layering
org (one install: brain, crews, org model, gates)
-> crew (agents inside one install)
-> mesh (sovereign installs over the signed wire)
-> group (a mesh with a dedicated steward install)
A crew lives inside one install. A mesh is what you get when two or more installs register each other and start exchanging signed envelopes. A group adds a steward: a small, dedicated install that hosts the shared org model and the group’s agora topics, running no production work (see the Steward Runbook).
Every mesh node has four things, all local by construction:
| Always local | Why |
|---|---|
| State (ledgers, claims, brains) | The sovereignty line: books never move |
| Gates (scope, sandbox, registry) | A vote is decided where the trust anchors live |
| Org model (teams, assignments) | Each org describes itself; a group model is a separate replica |
| Budgets | Money debits where the budget lives |
The six moving parts
| Part | What it does | Interface |
|---|---|---|
| Genesis and the ring rite | Two nodes form a pair; the ring admits members without re-keying | vant genesis, CLI |
| agora-sync | Remote votes and ledger sync over the signed bus | Agora: agora_vote, agora_pull |
| org-sync | The steward’s org model, replicated as a resolution cache | Automatic on push; read locally |
| Settlement | Cross-node payment: buyer debits its own escrow, the other side records a claim | Settlement |
| Notices | The board: plain announcements with durable catch-up | Notices |
| Mesh status | What is everyone working on, one command, federated view | vant mesh status --peers |
The authority rules
Four rules make the mesh safe to reason about, and each one is pinned by tests:
- Scope resolves where the model lives. A scoped topic is decided on the node whose org model the scope points into. Members vote remotely; the owner’s gates run unchanged.
- The wire never declares truth. Synced ledgers merge adopt-only; status is re-derived locally. A peer cannot declare a topic passed.
- Membership facts travel, scope content does not. Scoped decisions stay in the agora; the board carries only plain outcome notices. The bridge refuses scoped topics by design.
- Money is recorded, not held. A cross-node payment debits the buyer’s escrow locally; the other side records a claim. No shared bank.
Where to go next
- Join a running mesh: Join a Mesh playbook
- Run the group pattern as an operator: Steward Runbook
- CLI surface: CLI Reference, section “Federation”
- Crew coordination inside one install: Coordination