One node, from the inside
CHAPTER THREE · THE MACHINERY
Getting into the details
How the technology works, and why it’s different — the machinery under everything you have just seen.
01
The layer
Actors, skills, and how work gets matched
02
Compiled AI
Deterministic by construction — not another chatbot
03
The network
Nodes, federation, and negative-trust security
Otonoma Confidential
Anatomy of an intelligent network
Every system, machine and person becomes an actor. Actors form nodes, nodes form a network, networks federate.
Otonoma Confidential
A new layer, not another app
A new eighth layer above the Open Systems Interconnection (OSI) stack — nothing below it is replaced
Layer 8 · the Paranet
Actors · skills · conversations
Persistent, secure, semantic — where work moves
Layers 1–7 · the internet you have
Addresses · packets · transport
Where HTTP, application programming interfaces (APIs), and apps live — untouched
The internet moves packets. It does not move work. The Paranet overlays what you already run — and moves the work.
Apps
→
Actors
Participants with goals and memory — not installed endpoints
APIs
→
Skills
Declared capabilities — not hand-wired connections
HTTP
→
PnCP
The PnCP (Paranet Collaboration Protocol) — persistent conversations, not one-shot requests
Stateless
→
Persistent
State survives restarts — work resumes exactly where it left off
Bolt-on security
→
Verified
Every actor carries a certificate; every PnCP call is verified and written to the ledger — identity and audit are the protocol, not a layer on top of it
Otonoma Confidential
Everything becomes an actor
Software, hardware, AI models, and people — participants, not endpoints
The actor wrapper
Goals
Plans
Tasks
Decisions
Events
Memory
An actor knows what it is trying to do, remembers what has happened, and reasons about what to do next. The wrapper registers what the system can do — its internals, and its intellectual property (IP), stay its own.
Anything can be actorized
Legacy software AI agents Robots & drones Databases Sensors & Internet of Things (IoT) devices People
Adding an actor is modular, with zero disruption — the network gets smarter, nothing gets rebuilt.
Protected · US 12,578,995 · US 12,670,018
Otonoma Confidential
Skills: capabilities, not connections
Actors declare what they can do — not where they live
A declared skill
airport / book_slot_for_window
flight  ·  identifier
start_time  ·  date & time
A subject / action pair with a typed contract
Declared, not documented
A skill says what is done, never how — the network knows every capability on it, with nothing to read up on.
Typed contracts
Requests are validated against the skill’s schema before they run.
Many providers, one skill
Any qualified actor can fulfill it — the seed of resilience and choice.
Late-bound at runtime
Nothing names a provider in advance. The network discovers every actor declaring the skill and picks one by rule — the defaults, or your own.
Protected · US 12,578,995Pending · addressable skill marketplace
Otonoma Confidential
Work is matched, not wired
Skill requests are late-bound through the broker — matched to a qualified, live provider at request time
Requester
“I need airport / book_slot_for_window” in the New York area — no address, no endpoint
→
Broker
Matches the request to a provider — at that moment
→
Airport actor · JFKMATCHED
Qualified · live · best quality-of-service (QoS) history and headroom
Airport actor · LGA
Qualified · live — ready if JFK can’t take it
Airport actor · EWR
Offline — simply never matches. Liveness comes free.
Late binding — providers join, leave, upgrade, or fail; nothing is rewired.
Liveness for free — an offline actor never matches; no separate health checks.
Smart selection — qualification, QoS history, and load decide who gets the work; software first, people as the backstop.
Protected · US 12,670,018Pending · network-group routing · QoS selection · load balancing
Otonoma Confidential
Conversations, not calls
Requests, responses, status, and questions — grouped into conversations that persist
Request
“Book the slot”
→
Status
“Working — 40%”
→
Question
“Two windows free — which?”
→
Answer
“The earlier one”
→
Response
“Booked · 06:40”
The ledger
Every message in every conversation, durably recorded — who asked, who answered, what happened. Auditable by construction, in real time and after the fact.
The protocol is plumbing — the conversation record is the point.
Otonoma Confidential
Compiled AI: deterministic by construction
Generative AI builds the workflow — the network runs it as compiled goal trees
1
Build
Generative AI drafts the workflow up front — with review-and-validate gates, not vibe coding.
2
Compile
The workflow becomes a goal tree — machine-executable, statically checked.
3
Run — in two phases
The plan is generated before execution and can be reviewed in full. You know what will happen before it happens.
4
Recover
A failed step re-plans with a substitute task; judgment escalates to a human. The brain and the rulebook, bound together.
100x faster
Milliseconds — no large-language-model (LLM) round-trip per decision
98% cheaper
Near-zero tokens at runtime
100% reliable
Outcomes executed, not hallucinated
The plan re-plans itself
Step fails
Goal not achieved — detected immediately
Substitute task
Same goal, new plan — generated automatically
Human judgment
Escalation is a step, not an exception
Goal achieved
Guaranteed outcome, recorded in the ledger
Protected · US 11,580,190 · US 12,326,913 · US 12,670,018
Otonoma Confidential
Programming the Paranet
Paraflow: a small language with four ideas — goals, rules, tasks, and events
Goal !TransferBlock($cid)
A desired outcome, with state — active, failed, or complete.
Rule
Breaks a goal into sub-goals. A rule’s output is a plan, not execution — rules have no side effects, so the full plan exists before anything runs.
Task
The leaf that does the work — often by delegating to another actor via a skill request.
Event
How the world starts new goals — an incoming skill request arrives as an event.
Dynamic, still deterministic — a forall over live data expands into parallel sub-goals before execution. This is where two-phase determinism comes from — a property of the language, not a policy.
%skill(subject=factory, action=transfer_block)
event newTransferBlock($conversation) {
  !TransferBlock(cid -> $conversation);
}
rule !TransferBlock($cid) {
  !PushBlock($cid);
  !PlaceBlock($cid);
  !Complete($cid);
}
task !PushBlock($cid) is
  pncp jetbot_phy/push_block(block -> "A");
!PushBlock → !PlaceBlock → !Complete
The resulting plan — built, inspected, then executed
Otonoma Confidential
Start with the code you have
Decorate, don’t rewrite — existing software joins the network as-is
A decorator turns a function into a skill
Existing Python or TypeScript code declares what it can do — its internals don’t change.
Keep your toolchain
The package managers, repositories, and libraries your team already uses.
Orchestrate above, not inside
The workflow lives in Paraflow; the wrapped code below it stays untouched.
Same code, sim and real
One actor runs against the simulation and the live system — demonstrated driving NVIDIA Isaac Sim from a live Atlassian Jira board.
Python jira_actor.py
@actor.actor
class Jira(BaseActor):
  @actor.skill(subject='jira',
              response=TaskStatus)
  def create_ticket(self, cell, conv):
    …  # the code you already had
Static software becomes a live network participant — in days, not months.
Otonoma Confidential
Anatomy of a node
Self-contained: everything a node needs, wherever it runs
One Paranet node
Broker
Routes every skill request; observes the node’s actors
Skill matcher
Finds the qualified, live provider for each request
Paraflow interpreter
Runs the compiled goal trees; persists their state
Certificate manager
Identity for every actor on the node
Ledger
The durable record of every conversation on the node
ActorActorActor… its own actors, its own state
No center to fail
No central workflow server, no shared database — each node is complete on its own.
Runs where the work is
Cloud, on-premise, or at the edge — the same node, the same behavior.
Restart and resume
State is local and persistent — a node that restarts picks up exactly where it left off.
Otonoma Confidential
A network of networks
Organizations federate deliberately — and directionally
Carrier
Its own paranet · its own data
Airport
Its own paranet · its own data
Public and private paranets coexist
A federation of networks — each org runs its own nodes and federates only what it chooses.
Network groups
Skills are segmented by group — a request only routes to actors the requester is entitled to use.
Exactly the skills you choose
Nothing else is exposed. No central brain, no shared database, no disintermediation.
Pending · network-group skill routing · hierarchical actor delegation
Otonoma Confidential
Negative trust security
Zero-trust verifies at the door — negative trust keeps watching inside
Every actor carries a certificate
Identity by asymmetric key pairs — issued, managed, and revocable per node.
Registered skills only
If a capability isn’t declared to the network, it cannot be requested or performed.
Skill-level access control
Allow or deny per subject, action, and actor — on the request and on the fulfillment.
Observers & security actors
Invisible watchers monitor behavior continuously — and can flag, pause, or remove a misbehaving actor.
Watching what, not just who
Perimeter security asks who are you? once. Negative trust assumes bad actors will get inside — so the network itself watches behavior, continuously, everywhere.
Taint tracking is built into the workflow language — untrusted data is marked at the boundary and contained wherever it flows.
Building on Microsoft’s information-flow control research (FIDES): arxiv.org/abs/2505.23643 · github.com/microsoft/fides
Protected · US 12,474,957Pending · private network access control
Otonoma Confidential
Humans are actors too
Escalation is a first-class workflow step — not an exception path
Step one
Actor working
An automated actor is mid-workflow — booking, filing, verifying.
→
Step two
Judgment needed
A step needs a person — an approval, an exception, a hard decision.
→
Step three
Replicate the slice
Only the necessary part of the session is shared — code-level, permissioned, inputs constrained.
→
Step four
Decide & resume
The person decides; the actor continues. The workflow never left the rails.
Routed like any other actor
Skills — a person declares what they can approve, sign, or resolve, exactly as software does
Work schedules — shift, on-call rota and time zone decide who is actually available to be matched
The same broker — qualification, load and quality-of-service history pick the person, not a hard-coded name
Every decision lands in the ledger
A durable record of who decided what, and when — auditable by construction
Business Intelligence (BI) tools connect straight to it — the record is queryable, never locked in
Machine learning over that history finds the roadblocks — the steps that keep needing a person, so they can be corrected
Protected · US 12,474,957 — code-driven session replication · AATP (Actor-Actor Telemission Protocol)
Otonoma Confidential
Protected: the patent portfolio
Seventeen patent assets — nine issued, eight pending
Issued · the distributed actor network
US 12,578,995 · ParaNet multi-agent coordination
The actor network itself — declared skills, skill-matched assignment, persistent shared context
US 12,670,018 · Generative-AI skill execution
AI actors whose matched skills run as compiled, machine-executable scripts
US 12,474,957 · Session replication & AATP
Permissioned, code-level human-in-the-loop collaboration
Issued · the automation pipeline
US 11,416,575 · core task-decomposition architecture
US 11,568,019 · site & interface modeling
US 11,580,190 · self-healing orchestration (substitute tasks)
US 11,640,440 · visual model builder
US 12,259,940 · machine-learning model generation
US 12,326,913 · end-to-end automation
Pending applications include
Network-group skill routing Hierarchical actor delegation Private network access control Skill-gap detection Quality-of-service selection Utilization-based load balancing Addressable skill marketplace
Assigned to Grokit Data, Inc. — now Otonoma. Source: Holland & Knight LLP portfolio summary, August 2026.
Otonoma Confidential