White paper · 2026

A System Entity Structure Methodology for Verifiable, Embedding-Grounded LLM-Agent Orchestration in DEVS

We present a System Entity Structure methodology for orchestrating large language model agents as a Discrete Event System Specification coupled model, with verification and validation carried out through the DEVS hierarchy of system specifications and its morphisms.

Abstract

We present a System Entity Structure methodology for orchestrating large language model agents as a Discrete Event System Specification coupled model, with verification and validation carried out through the DEVS hierarchy of system specifications and its morphisms. The central claim is that an agent workflow should be specified, pruned, executed, and verified in one system-theoretic chain rather than assembled as an informal action graph. Building on MetaSES, every component is one Agent class specialized by role; coordination is port coupling; and a concrete architecture is obtained by SES pruning followed by a transform to a simulatable DEVS coupled model. We implement the full chain from MetaSES to free digraph to pruning to DEVS, then execute a representative systems-engineering task using LLM-backed atomic DEVS agents grounded by offline sentence embeddings over a technical corpus.

DEVS supplies the verification mechanism. Closure under coupling gives the Network-of-Systems model a behaviorally equivalent atomic realization; the recorded trace is an exact homomorphic image of the coupling structure under an experimental frame; WySE metrics quantify pruning's footprint on a graph-Laplacian diffusion surrogate; and closure licenses compositional verification in place of flattened product-state checking, yielding a computed reduction of more than 350 billion verification operations at 20 leaf agents. A payload-bound proof-carrying workflow further restricts semantic authority: LLMs may generate typed records or candidate certificates, but validators and the proof kernel decide acceptance. The result is verifier-relative for the specified artifact class, not a claim of unrestricted LLM semantic correctness.

Logarithmic plot of modeled verification-operation counts for six Leaf-agent counts with four Branch agents. At 20 Leaves, monolithic verification requires 50,230,616,080,806 modeled operations and compositional verification requires 142.
Figure 1

Verification through composition

Computed verification-operation counts for the role-state model of Theorem 3. At the worked 1 Root, 4 Branch, 20 Leaf construction, monolithic verification requires about 5.0 × 10¹³ operations while closure-licensed compositional verification requires 142.

A candidate certificate passes digest, message-binding and rule-graph checks. Accepted evidence supports a conditional workflow theorem; spliced or tampered evidence is rejected.
Figure 2

Payload-binding anti-splicing invariant

A certificate names exact DEVS messages rather than citing a trace in bulk; the verifier recomputes message identifier, route, parent, and payload-digest equality before proof-kernel rule applications may derive the workflow theorem.

Explore PALLC

PALLC demonstration