ALPHA ARCHITECTURE
Artifact MCP and Live MCP
Artifact interprets a session that has already ended. Live exercises authority over a run. Keeping them separate keeps shared evidence away from control of a Mac.
In preparation
This architecture is approved, but Artifact MCP is not yet available to connect. Today, the published remote connector remains the Live door, and the MCPB extension remains the local door.
Two authorities, three paths
Sharing a project is not sharing a credential
The creator grants access to a named Kelvin person or organization. The HTML and identifiers only locate the project; every read uses the viewer's own account and rechecks the share.
Access may have no end date, but it remains revocable. When the creator revokes it, the next read fails, even if a read had been authorized moments earlier.
The original remains the original
Observed reuses screens and transitions present in the sealed evidence. Pixels come from the original capture and the derivative points to the source hash.
Modelled is a separate, visibly marked hypothesis. It never enters the seal or appears as a screen the session proved.
When the requested screen was not observed
- Artifact stops at not observed and offers to prepare a new capture.
- A separate dashboard page requires a recent login and shows exactly what will run.
- Kelvin.app shows the same request on the selected Mac and requires local approval.
- Only after both approvals does Live create a new run. The previous seal is never changed.
The boundary that matters
A token, catalog, or permission from one surface is invalid on the other. Artifact never calls local MCP, and knowing an ID or sharing the HTML never grants authority.