The gap this names
An audit, an authorization, a provenance claim: each is only as trustworthy as the data underneath it.
When a model provider loosens its guardrails for a benchmark or a release, the model's own refusals turn out to be the wrong layer to have depended on. The durable control is authorization bound below the model, at the data and action boundary, where it does not move when a vendor tunes a setting.
That is the layer a governance framework sits on. Operationalize forty-two steps of control on top of data that cannot say what it means, and you have built assurance on an assumption. Bind the meaning, the constraints and the provenance to the data first, and the framework finally has something real to govern.
Three layers, composing rather than competing
Symphony of Defense does not replace the substrate, and the substrate does not replace Symphony. One governs the data; the other governs the action it enables.
Layer 1 · Meaning — domain experts define it
Controlled vocabularies and ontologies, authored by the people who own the domain. What a value actually means, before any system touches it.
Layer 2 · Data substrate — Semantic Data Charter
Meaning, constraints and provenance bound to the data at the source, with a deterministic PERMIT, DENY or INDETERMINATE decision and a tamper-evident receipt. Sovereign and air-gapped capable.
Layer 3 · Execution — Symphony of Defense™
The execution and assurance framework: the audit chain, the approval gates, the controls that govern what an agent is allowed to do. It deploys on the substrate rather than being rebuilt per engagement.
Why this matters commercially
Bind the constructs, the bill of materials, the audit chain and the approval gates to a shared substrate once, instead of rebuilding them for every client. Governance becomes infrastructure rather than a bespoke rebuild.
What the Semantic Data Charter is
- Open, ratified standards. Built on RDF, SHACL, W3C PROV, OASIS XACML and W3C XSD 1.1. There is no private format.
- Apache-2.0 engines. The reference model and core engines are open source.
- Meaning bound to the data. A value carries its own definition, constraints and provenance wherever it lands.
- Deterministic governance. The same input yields the same verdict, every time, with a tamper-evident receipt.
- Sovereign and air-gapped capable. Identity is minted offline, and no external service is required to interpret a value.
- Reproducible. Everything can be reconstructed and checked, rather than asserted.
Symphony of Defense™
Symphony of Defense™ is the agentic-security governance framework created by Timothy Lee. It is his framework, and it stays his. Axius SDC supports it as the trusted data substrate beneath its provenance, supply-chain and open-standards work, not as a competitor to it.
Where Symphony governs the action, the Semantic Data Charter governs the data that action is taken on. A shared substrate turns the framework from a per-client rebuild into a deployable layer.
Two paths from here
Wherever you sit, there is a next step.
You govern, audit or secure AI
For regulated and sovereign environments, SDCStudio Sovereign runs air-gapped, with meaning and provenance bound to the data and deterministic decisions you can audit. This is where a governance program becomes verifiable rather than asserted. SDCStudio Sovereign →
You build or consult on data and AI
The specification, the Apache-2.0 engines and the learning materials are open. Build on them and become an SDC practitioner. The graph and governance consultants deploying this are the practitioners of what comes next. Practitioner path →