The article describes a Level‑4 safety and governance architecture for LLM systems built from four interlocking contracts. Guardrails are implemented as six independent layers — input, grounding, output scrub, verification, judge, and confidence/routing — each returning a GuardrailResult with action {ok,block,redact,flag} and a layer label; a run_guardrails helper processes layers in order, treats any exception as a block (fail‑closed), and increments a guardrail_blocks_total metric per layer and rule. PII is handled at every boundary using a Sensitivity enum (PUBLIC, INTERNAL, PII, SECRET) and a FIELD_POLICY map; redact() masks fields whose sensitivity ≥ PII, drop_secrets() removes SECRET fields before hashing, and ledger_view() stores a keyed HMAC‑SHA256 of a canonical‑JSON redacted summary plus the summary itself, preventing reversible low‑entropy hashes. An append‑only audit ledger is defined by a decision_ledger table with columns decision_id, ts, tenant_id, identity, capability, inputs_hash, inputs_summary, model_version, prompt_version, decision, confidence, routing, outcome (mutable), supersedes, seq, prev_hash, entry_hash; triggers enforce immutability, and a hash chain over immutable fields provides tamper evidence, verified by verify_chain(). Memory is typed via MemoryCategory (TENANT_SHARED, AGENT_NAMESPACE, WORKFLOW_CONTEXT, AUDIT, SEMANTIC_KNOWLEDGE, CONVERSATION); partition_key() builds scoped keys, enforce_access() blocks cross‑tenant and unauthorized reads/writes, and write() rejects PII in shared namespaces. Finally, a seed/runtime split isolates version‑controlled prompts/policies (seed) from mutable ledger, learned memory, drift, and session state; clear_state() raises ValueError for non‑runtime scopes, preventing accidental seed wipes. Together these contracts provide defense‑in‑depth, verifiable decisions, and leak‑free multi‑tenant operation.

Read original