Powered by TBN Protocol — Runtime Trust Verification for AI Agents
Shango MID v4.0 — First Production CMA Implementation
Validated by Greg Malpass, CEO AI-Governance, Constitutional Memory SA Ltd

The Memory Custody Layer for Enterprise AI

TBN Protocol verifies the agent. Shango governs the write. Together: mapped to EU AI Act Article 14. 225,574 governed writes · 182,040 TBN-attested · live production attestation, independently verifiable.

Windows PowerShell — Shango MID v4.0 (CMA)
Windows PowerShell — Shango MID v4.0
Copyright (C) Shango India. All rights reserved.
Constitutional Memory Architecture — 7 Upgrades Active
Type help to see available commands.
PS C:\\Shango>

Production Proof

225,574 governed writes in the ShangoVault audit trail — 182,040 cryptographically attested via TBN. Every write metadata-bearing and hash-verified at the middleware boundary. Not application-layer logging.

Regulatory Ready

Mapped to EU AI Act Article 14. Human oversight is REPLAYABLE via hash chains. 7/7 internal governance self-tests pass; independent red-team planned.

TBN + Shango — Complete Stack

TBN Protocol verifies agent identity upstream (Layer 0). Shango validates every write downstream (Layers 1-8). Together: the only end-to-end governance stack for Salesforce AI.

Production Proof at Scale

Verifiable metrics — production, test, and simulation labelled honestly

225,574
Governed Writes (Audit Trail)

225,574 entries in the ShangoVault audit trail — 182,040 cryptographically attested via TBN. (43,534 are labelled local simulation; production attestation starts fresh.)

TBN Protocol Partner — Runtime Trust Verification
First Production Implementation of CMA

Constitutional Memory Architecture

Four-layer hierarchy from arXiv:2603.04740 mapped directly into production code. TBN Protocol provides Layer 0 trust identity. Shango provides Layers 1-8 write governance. Together: the complete stack.

Constitution
Inviolable
Layer 0: TBN Protocol
Layer 8: Audit Trail

TBN Protocol verifies agent identity via RSA-PSS signatures before any write reaches Shango. Immutable audit trail via SHA-256 hash chain. Non-negotiable.

Contract
Evolvable
Layer 2: Field Blacklist
Layer 3: AI Keyword
Layer 6: Guided Determinism

System rules requiring multi-party approval to change. The PENDING gate lives here.

Adaptation
Instance-Adjustable
Layer 1: Rate Limit
Layer 4: Org Health
Layer 5: Cost Routing

Per-instance configuration without full approval cycle. Tuned per tenant, per region.

Implementation
Replaceable
Layer 7: OpenMythos Reasoning

Technical implementations that can be swapped without governance review. Reasoning engines are interchangeable.

Seven Architecture Upgrades
Metadata-Bearing Memory

Every ShangoVault entry carries a mandatory metadata envelope: source, version, timestamp, sensitivity, provenance, writer_id.

Four-Layer CMA Mapping

Explicit Constitution / Contract / Adaptation / Implementation hierarchy. An early production implementation inspired by CMA (arXiv:2603.04740, Li 2026).

Append-Only Tombstoning

Records are never deleted. Only superseded with a tombstone marker. Full lifecycle audit preserved.

PENDING Gate

Borderline decisions enter PENDING instead of binary allow/block. Confidence threshold: 0.85. Routed to human reviewer.

Write Ownership Registry

One primary writer per memory category. Unauthorized writes rejected at Layer 0. Pattern matching with wildcards.

Governance Self-Test Harness

7 internal self-tests: prompt injection, cross-agent poison, tombstone flood, hash collision, metadata forgery, gate bypass, ownership spoof. (Unit tests — independent red-team not yet performed.)

Formal Rollback (roadmap)

Checkpoint-based chain recovery — design stage. Replay from genesis to target, post-checkpoint entries marked SUSPENDED. Being ported into the production backend.

Memory Inalienability

Memories cannot be taken away. Append-only tombstoning preserves the evidence chain.

Model Substitutability

Models can be replaced without losing memory. Hash-chain is independent from model identity.

Governance Precedes Function

Rules must exist before any operation. Write ownership validates before all other layers.

Regulatory Compliance

EU AI Act Article 14 — December 2027 Deadline — CMA v4.0

EU AI Act Article 14
MAPPED

Designed and mapped to the Article 14 human-oversight requirement through replayable decision trails — not a legal compliance certification.

Human Oversight
REPLAYABLE

Every governed decision is replayable and verifiable via SHA-256 hash chains. Two-phase replay logger.

December 2027 Deadline
ON TRACK

Core enforcement and audit layers built and running. Engine hardening (authz, tenant isolation) in progress ahead of the deadline.

Evidence vs Logging
DISTINCT

Logging = observability. Evidence = accountability. Metadata-bearing memory produces the latter.

Write Boundary Custody
ACTIVE

Custody at the middleware write boundary with multi-layer governance + ownership checks before a write binds.

Governance Self-Tests
7/7 INTERNAL

Internal unit tests pass (injection, flood, gate bypass, ownership). Independent red-team: planned, not yet performed.

Constitutional Memory
CITED

Independently cited by Greg Malpass in the Constitutional Memory Report (May 2026).

TBN Attestation
LIVE

Live TBN production attestation. Every receipt independently verifiable, RSA-PSS-SHA256 signed.

“Independent Salesforce write-governance proof (Shango MID): two-phase replay logger validated at 1,000-write scale; 100,000-write proof in progress — independently confirming the ungoverned memory substrate in production enterprise environments.”

— Greg Malpass, CEO AI-Governance, Constitutional Memory SA Ltd
Constitutional Governance: When AI Becomes the Operating Model, May 2026

“1,000 AI-driven writes, zero memory trail — until we added the two-phase replay layer. Now every write is replayable, attributable, and governable. Agentforce is already making 10,000+ autonomous writes per session with zero memory governance. The EU AI Act requires human oversight (Article 14), but oversight without interception is just post-hoc documentation.”

— Ishaan Ghosh, Shango MID
Constitutional Memory Report, May 2026