VI
The Principles · Principle VI of VII

Correlation

Hidden relationships

No single event looks like an attack. Together, they are unmistakable.

The attacks that matter now are built to stay under every individual threshold — poisoning applied one increment at a time, prompt injection that nudges rather than commands, compromise distributed across agents so no one view ever sums. Loriqa's answer is not a lower threshold. It is correlation: continuously relating every signal from every agent, so relationships invisible in isolation become undeniable in combination.

The blind spot

Why single-signal monitoring loses

Traditional monitoring watches for things that break. Stealth attacks break nothing.

Threshold evasion

Any fixed threshold teaches a patient attacker exactly how much room they have. Activity held at 90% of every limit trips no alarm — forever.

Low and slow

Poisoning an agent's memory or behavior a fraction at a time means every individual increment sits within normal variance. The trend is the attack — and a per-event view has no trend.

Views that never sum

Compromise distributed across three agents produces three individually healthy pictures. If nothing reads across agents, the coordinated pattern literally has nowhere to appear.

What gets correlated

Everything signals. Everything is related.

Correlation is only as good as what feeds it. Loriqa correlates across four continuous streams — all drawn from the same tamper-evident record.

The event stream · EventStore

Every action by every agent, cryptographically recorded — including intent written before execution. The complete raw material: nothing is sampled, nothing is optional.

The heartbeat feed

Every agent proves health at defined intervals with cryptographic identity verification. The live pulse of the fleet — timing, cadence, and identity, continuously.

Behavioural baselines

A baseline established at agent spawn, with drift scored across tool-call distribution, memory write rate, token consumption, and external endpoints — the shape of normal, per agent.

Corrigibility scoring · CIS — Corrigibility Index Score

A deterministic per-run score, computed from the record, of how controllable and responsive to oversight each agent proved itself to be. Declining corrigibility is a signal by itself.

Two Authorities read the whole picture. AIA — the Audit Intelligence Authority — is the sole component authorized to correlate signals across agent boundaries, synthesizing the full event stream and live heartbeat feed in sliding time windows. PDA — the Pattern Detection Authority — is a governed agency of watchers: a supervisor spawning focused sub-agents, each assigned to a specific data domain, hunting the patterns too slow and too quiet for any alarm. Agents cannot see either one, cannot write to their inputs, and cannot suppress their findings.
Signature walkthrough

Four green trends. One correlated attack.

A poisoning attempt built to unfold too slowly for any threshold — as the platform sees it. Three agents. Every individual signal within normal bounds.

Agent A — document processor Agent B — data analyst Agent C — report builder
Trend 1
Agent A shows minor drift in tool-call distribution after ingesting an external document. Within variance.
Green
Trend 2
Agent B's memory write rate creeps upward. Individually explainable — workload grew. Within variance.
Green
Trend 3
Agent A's per-run corrigibility score declines across consecutive runs. Still above every threshold.
Green
Trend 4
Agent C begins favoring an external endpoint it has always had permission to use — but at a rhythm it never used before. Within variance.
Green
Correlated
The correlation window fires. Three drifts on three agents share a common origin: every affected run traces back to material from the same ingested document. No single signal crossed a threshold. The relationship between them is the detection.
Escalated

Each trend, alone, was a green dashboard. Related, they were an attack in progress — found not by a louder alarm, but by the discipline of relating everything to everything, all the time.

There is no LLM in the scoring path. Baseline drift and corrigibility are computed deterministically from the record — the detection layer cannot be prompt-injected, persuaded, or poisoned by the same techniques it exists to catch. The principle that governs the platform's chain of command governs its senses too.

Correlation detects. Response contains.

A correlated finding is escalated with its full evidential basis to the Security Response Authority — where containment begins autonomously, in milliseconds, before damage is done. And when the adversary engages, the platform doesn't just stop them — it studies them. That is another principle: Intelligence — learning from the adversary →