The live navigator loop as the default path: LLM
runs under identical receipts, benchmarked against the deterministic
baseline; Rust parity for the full loop (search and plan are shared
today; the LLM binding is Python-first).
The remaining /v1 surface: lineage
event queries, audit verification listings, access explanation
(why was this denied?) — all behind envelope auth.
Adopting Torcello: TypeSec’s interop plane,
mcp-gate in front of QueryGraph’s own MCP servers, signed
decision receipts unified with QueryGraph’s access receipts, and the
enforcement proxy as the governed inference layer. The dependency bump
is done; the integration is the work.
The wider arc (from the workspace review, FABLE-REVIEW-1 in the
meta-repo):
Catalog ecosystem: Apache Polaris
SemanticModel entities and a /navigator-bundle
projection endpoint — LakeCat-first, then the upstream conversation; ODS
packaging under /.well-known/.
Standards round-trips: OSIMetricFacet
upstreaming to OpenLineage; Marquez in CI; mlcroissant
validation; importers from dbt MetricFlow and Cube into OSI; a Hugging
Face Croissant importer.
Distribution: crates.io publication once the
path-dependency knot is cut; an ADBC/Flight SQL path so notebooks can
query Sail without the PySpark stack; a docker compose up
demo of the whole evidence chain.
Scale and research: Merkle-batched attestations per
tenant and time window; OWL/SKOS ontology import into the Grust graph;
cross-node federation with inbound signed bundles; and the benchmark
that motivates the whole stack — how much does a governed semantic
layer improve agent accuracy over the same lakehouse? — measured on
text-to-SQL tasks with and without OSI/Croissant context.