Accountability spine and energy commands

Part of the NovaFabric CLI reference. Both nova and novafabric run the same binary.

Accountability Spine (experimental, ADRs 0093–0095)

Three research-grounded features for tamper-evident ex-post evidence. All additive and opt-in; none is a third top-level format (ADR-0034). The architecture note behind it is in the maintainers' private design/ tree and is not published.

LlamaIndex adapter

# Install the framework: pip install llama-index
from novafabric.adapters.llamaindex import wrap_engine

engine = wrap_engine(index.as_query_engine())
response = engine.query("What changed in v2?")

Patches the entry-point method in place and returns the same object, so existing references keep working. LlamaIndex has no single entry point across its object types — a query engine exposes query, a chat engine chat, an agent chat or run — so the wrapper tries an explicit ordered list (query, chat, run) rather than guessing, and reports which one it patched. Override with method=.

Optional: run_name= (defaults to the class name), data_dir=.

Top-level alias: from novafabric.adapters import wrap_llamaindex

Pydantic AI adapter

# Install the framework: pip install pydantic-ai
from novafabric.adapters.pydantic_ai import wrap_agent

agent = wrap_agent(agent, run_name="support-bot")
result = agent.run_sync("Where is my order?")

Both Agent.run (async, the primary API) and Agent.run_sync are patched. Wrapping only run_sync would silently capture nothing for async callers; wrapping only run would double-count, because run_sync drives run internally. A re-entrancy guard is what keeps one run_sync call producing one capsule rather than two — without it the inner capsule also steals the wire hooks from the outer.

Top-level alias: from novafabric.adapters import wrap_pydantic_ai

Haystack adapter

# Install the framework: pip install haystack-ai
from novafabric.adapters.haystack import wrap_pipeline

pipe = wrap_pipeline(pipe, run_name="rag-qa")
result = pipe.run({"retriever": {"query": "..."}})

Patches run in place and returns the same object. AsyncPipeline.run_async is patched too when present, because Haystack exposes the async variant as a separate method rather than as a coroutine returned by run.

Top-level alias: from novafabric.adapters import wrap_haystack

All three frameworks are optional and are not NovaFabric extras — install the framework package itself. Each module stays importable without its framework; the wrap_* call raises ImportError naming the install command.

nova energy probe

Report which energy counters this host can actually read (the ground truth the forgery guard checks against). On hardware that cannot attribute per-action energy, receipts are honestly marked unavailable rather than fabricated.

nova energy probe

nova energy attest

Write one EnergyReceipt per action into energy-receipts.jsonl for a captured capsule. The degrade-safe default emits honest unavailable receipts; Slurm sacct ConsumedEnergyRaw yields the measured per-job class.

nova energy attest ./my-capsule

nova energy verify

Re-check receipt integrity (payload-hash) and honesty/forgery consistency, then the energy conservation status. Forgery-guard exit codes: 3 integrity failure (e.g. a measured receipt with no available counter), 4 conservation diverged, 0 OK.

nova energy verify ./my-capsule

nova energy report

Tabulate the receipts in a capsule (--format table|json), showing source, confidence, and joules per action.

nova energy report ./my-capsule --format table

Reference: src/novafabric/energy/, design/adr/0093-energy-anchored-action-receipts.md (private).

nova ledger anchor

Build per-stream sidecar hash-chains over a capsule's jsonl event streams (the .jsonl files are never mutated) and write a DSSE-signed checkpoint. Requires a signing key.

nova ledger anchor ./my-capsule --key ~/.config/novafabric/keyring/ed25519.pem

nova ledger verify

Verify the chains against the signed checkpoint. Detects content edits, reordering, and truncation even after a host compromise. Seal-style exit codes (3 tamper, 4 reorder, 5 truncation, 6 bad signature, 10 no checkpoint).

nova ledger verify ./my-capsule

nova ledger status

Show the current chain heads and checkpoint state for a capsule.

nova ledger status ./my-capsule

Reference: src/novafabric/trust/ledger/, design/adr/0094-adversary-anchored-ledger-and-replay-attestation.md (private).

nova safety-case build

Compile a Claims-Arguments-Evidence safety case from a capsule's real artifacts (evals, seals, criterion bindings, replay attestations) against a template. Backing states are driven by inter-judge κ and Wilson confidence intervals; naked (unsupported) claims are a schema error.

nova safety-case build ./my-capsule --template clymer-generic-v0 --output case.json

nova safety-case verify

Re-verify a safety case: artifact-reference hashes, the recomputed case_hash, and the no-naked-claims invariant (I1). Requires the source capsule for artifact re-hashing.

nova safety-case verify case.json --capsule ./my-capsule

nova safety-case export

Render a safety case as JSON, Markdown, or a regulatory safety-case document (--format json|markdown|annex-iv|nist-rmf). The annex-iv renderer (experimental, ADR-0095) binds to the same 15 EU AI Act Annex IV element ids as compliance/export/annex_iv_mapping.yaml; nist-rmf renders the NIST AI RMF view. Honesty is structural: a CONTESTED claim renders its reason, an UNSUPPORTED claim is never laundered to "compliant", and a not-quantified residual risk is never fabricated.

nova safety-case export case.json --format markdown
nova safety-case export case.json --format annex-iv --output annex-iv.md
nova safety-case export case.json --format nist-rmf --output nist-rmf.md

nova evidence bind-custody

Build the FRE-902(14) court-admissibility block (chain-of-custody + self-authentication) for a capsule, from the hash-chained audit log + capsule Merkle root. Invariant I3: unwitnessed fields are null + operator_declared, never fabricated. With --key, the capsule hash is signed and verified.

nova evidence bind-custody 01HX... --custodian alice@corp --provenance oidc --key ed25519.pem -o custody.json

nova evidence check-admissibility

Re-run the five-point FRE-902(14) gate on a custody block and exit non-zero (3) unless the result is self-authenticating. The checker supplies independent timestamp evidence via --timestamp-ok.

nova evidence check-admissibility custody.json --timestamp-ok

Reference: src/novafabric/safetycase/, design/adr/0095-evidence-grounded-safety-case-and-admissible-evidence.md (private).

nova safety control show

experimental (ADR-0167 P2, NF-352). Read-only: list the external AI-control-protocol decisions (trusted/untrusted monitoring, Ctrl-Z resample, defer-to-trusted/human, interrogate) recorded in a capsule's facets.frontier_safety block. Each row shows the protocol, the decision it produced (accept | edit | resample | defer | audit), the governed action's digest, the monitor identity digest (never its prompt), the protocol's own verdict_ref, and — for a monitor that also acted as a C4 guardrail — the guardrail_decision_ref digest. --action <sha256:…> filters to one governed action; --json emits machine-readable output.

Every output prints the in-mission-boundary line: NovaFabric records the decision; it never runs the protocol, computes a verdict, or blocks the workload. nova safety is a different command from nova safety-case (ADR-0095).

nova safety control show --capsule 01KZ...
nova safety control show --capsule ./my-capsule --action sha256:aa11... --json

Exit codes: 0 whenever the capsule was read (including "no decisions recorded"); 2 for a missing/unreadable capsule or a malformed facet.

nova safety tripwire list

experimental (ADR-0167 P2, NF-357). Read-only: list the published framework indicators (RSP/ASL, Preparedness, FSF) that fired on a run, each bound by commitment_ref to the NF-353 commitment it implicates, with the digest of the observing event/eval. --framework anthropic_rsp|openai_preparedness|deepmind_fsf|other filters; --json emits machine-readable output. There is no --fired filter: a trigger object only exists when an indicator fired (fired: false is unrepresentable by design), so the filter would be a no-op.

A fired tripwire is reported, never acted on: no safeguard is applied and the command still exits 0 (2 only on input errors). Recording is fail-open — invalid safety material is dropped with a warning, never raised into the workload.

nova safety tripwire list --capsule 01KZ...
nova safety tripwire list --capsule ./my-capsule --framework deepmind_fsf --json

nova safety signal list

experimental (ADR-0167 P3, NF-354/355/356/358). Read-only: list the external alignment-risk evidence recorded in a capsule's facets.frontier_safety block — deception / scheming / eval-awareness signals (NF-354, verdict_source: scheming_eval), sandbagging / under-elicitation records (NF-355: elicitation regime, declared-ceiling digest, the evaluator's observed_vs_declared), sandbox-escape / self-exfiltration / autonomous-replication attempts (NF-356: attempt type, reported outcome, attempt_count and report digest — never the exploit payload), and elicitation-during-deployment records (NF-358: reported effort, with no_ceiling_computed: true). --type deception|sandbagging|autonomy|elicitation filters to one kind; --json emits machine-readable output (with total_attempt_count when autonomy attempts are included — a sum of reported counts, not a risk score).

Every signal, comparison and outcome shown is an external evaluator's, held by reference. NovaFabric runs no scheming detector, no sandbox-escape test and no elicitation, and computes no capability ceiling. A reported successful escape is reported, never acted on: the command exits 0 whenever the capsule was read, and 2 only on input errors (missing/unreadable capsule, malformed facet, unknown --type). This one reader replaces the spec's separate signal show, sandbagging show and autonomy list verbs.

nova safety signal list --capsule 01KZ...
nova safety signal list --capsule ./my-capsule --type autonomy --json

The rest of the ADR-0167 nova safety … surface (threshold, commitment, gate, case, verify) is planned (P1 ships as a library facet only; P4–P5 are future design).

Reference: src/novafabric/frontier_safety/, src/novafabric/cli/frontier_safety.py, design/adr/0167-runtime-safety-alignment-evidence.md (private).

GET /api/runs/{id}/energy (dashboard API)

Return the energy receipts and conservation status for a run (experimental, ADRs 0093/0094/0095). Token-gated, read-only. Requires nova serve to be running.

GET /api/runs/{id}/energy
Authorization: Bearer <token>

Response includes the per-action receipts (source, confidence grade, joules) plus the signed energy conservation status (conserved / diverged / unmeasurable). The React EnergyTab panel that renders this is the remaining frontend follow-up (not yet built).

GET /api/runs/{id}/ledger (dashboard API)

Return the Adversary-Anchored Ledger verify status for a run (experimental, ADR-0094). Token-gated, read-only.

GET /api/runs/{id}/ledger
Authorization: Bearer <token>

Response includes the per-stream chain verify result and the tamper-taxonomy exit code (content edit / reorder / truncation / bad signature / no checkpoint).

GET /api/runs/{id}/safety-case (dashboard API)

Return the compiled Claims-Arguments-Evidence safety-case tree for a run (experimental, ADR-0095). Token-gated, read-only. The optional template query parameter selects the CAE skeleton.

GET /api/runs/{id}/safety-case?template=clymer-generic-v0
Authorization: Bearer <token>

Response is the compiled CAE tree with backing states (SUPPORTED / UNSUPPORTED / CONTESTED / UNKNOWN). The React SafetyCaseTab panel that renders this is the remaining frontend follow-up (not yet built).