Molt AI · Deterministic Graph Compilation
Your agents write code in minutes. Shipping it still takes a department.
AI broke the human rate limit on writing software. It did not touch the rate limit on trusting it — secrets, infrastructure, permissions, review, compliance, evidence. Code generation accelerated. Everything after code did not.
Act I · The Scissors
The bottleneck didn't disappear. It moved.
Every software organization still does enormous manual work after the code exists — and none of it got faster when the code got fast:
- secrets
- infrastructure
- IAM & permissions
- deployment
- approvals
- compliance
- audit evidence
- runtime identity
Ten times the code now waits on the same review meetings, the same ticket queues, the same hand-built environments. The scissors open wider every quarter — and hiring more reviewers is buying rate limit with headcount.
Act II · The Thesis
Assurance should be a property of the artifact — not a department.
Not documented. Not reviewed. Compiled.
Trust that is reconstructed after the fact — by reviewers, auditors and change boards — cannot keep pace with machine-speed production. Trust that is compiled into the artifact arrives at the same speed as the artifact. That is the only assurance model that survives agentic development.
Act III · The Compiler
DGC is the first implementation of compiled assurance.
One specification goes in. One admitted graph comes out — and every operational artifact is derived from it, automatically, with a receipt.
The compiler does more than produce binaries. It decides how the work divides: each missing implementation is emitted as a complete, self-contained specification — so N missing pieces means N agents working in parallel with nothing to coordinate. The compiler partitions the labor, proves the structure, builds the machine, and derives the deployment.
Act IV · The Proof — the page you are reading
This page is served by a machine that compiled itself.
dgc is a DGC application: 25 contracts of specification, partitioned into independent nodes, realized as signed closures, composed into one root, and attested onto one cell. Everything in this section is read from that machine's receipts, on the machine, as you load the page.
- partitioned—independent nodes derived from one specification — one agent each, nothing to coordinate, no conflicts to resolve.
- named—cryptographically named builds: every node by its H_nix, plus the composed service that is answering this request.
- bound—typed state slots resolved from the vault at gate 06. No adapter holds an authored string — a string is a program nobody declared.
- attested—gates walked to admit this root, ending in a delegation chain minted for it and an instantiation attestation naming the cell it runs on.
machine identity · b2dfe89867f70236c05fe4a0cd969ca7577f375d85f7b7334b563fc7e5df6957
For the CISO
Security is attestation, not policy.
Agents can be talked out of a policy. They cannot be talked out of cryptography.
Every binary in a DGC machine is named by what it is — its type, its implementation and its build environment hashed together. Only attested binaries run; only attested machines receive traffic; every deployment carries a delegation chain rooted in a human-held passkey.
Agents operate with read-only reach. Production writes happen exactly one way: a human passkey ceremony authorizes the promotion and the compiler performs the write. There is no credential an agent can leak that grants what the ceremony grants — the write path does not exist outside it.
And when the auditor asks how you know what is running: every stage of every deployment emitted a verifiable receipt. Evidence is not assembled for the audit. It is the exhaust of the compiler.
Where this goes
The operating system for the agentic SDLC.
Today: one compiler, one live machine, receipts end to end — and the compiler is now compiled by itself. Next: every application in the portfolio compiled, attested and promoted through the same ceremony, with agents doing all of the work and humans holding all of the authority.