Capability status

What ships, what does not,
and where the record ends.

Dated, with the basis stated for every line.

Last checked 24 September 2026. Re-checked quarterly, and whenever a capability moves.

[A]  Checked against the codebase, 17 September 2026.

[B]  Confirmed by the engineer who built it, 24 September 2026. Not yet re-checked against the codebase.

What ships

Built, and hard to fake.

  • [A]The map is derived from the platform’s own declarations, and drift fails the build.
  • [A]Rails and conformance suites, enforced in CI.
  • [A]One door for every action.
  • [A]The record written in the same commit as the work, append-only, enforced at the database by role.
  • [A]The same keys on every row.
  • [A]Agents are principals: on behalf of a named requester, with a grant id.
  • [A]The exact rendered prompt on the record.
  • [A]Retrieved context snapshotted at the version the agent saw.
  • [A]Durable approvals that survive restarts, redeploys, years.
  • [A]Denials recorded with the rule that matched. Not a warning comment: no merge, no approval requested, and a row that names the rule.
  • [A]Your identity provider and your authorization configuration plug in from day one.
  • [A]The model port is the contract. Anthropic ships today; other providers and local models drop in behind it. Fine-tuning pipelines are out of scope.
  • [A]Built to run inside your boundary: self-hosted or your private cloud, air-gap on request.
  • [B]Dry run with blast radius before commit: what a change would touch, and how far, previewed before it is allowed to happen.
  • [B]A denial lands in the same population, with the same keys, that a sample draws from. The refusal is a row like any other.
  • [B]A value-band conformance rule keyed to a program and a state filing runs as a check.
  • [B]Retention policies set per client build and per class of information.
  • [B]Protected health information redacted in logs, with a token preserved so an agent can still triage the record.
What is not built

We print this so you can check the rest.

  • Alert badges on a map node.
  • An MCP server. The MCP seam is derived from the same registry; no server ships.
  • Interfaces rendered from the map.
  • Self-healing edges.
  • Evidence-pack generation. A person assembles exhibits from receipts the line already emits; nothing generates a pack.
  • Brownfield ingestion of an existing system into the map. The map is derived from the platform’s own declarations.
  • A hash chain over the record. The record is append-only, enforced at the database by role; the chain that would make the sequence self-checking is not built, and we are not going to call this tamper-evident.
The population

Where the record’s population ends.

What is not in the record: systems that predate the line. Enforcement starts at what you build next, and existing systems enter the record as they move onto it. We would rather you read that here than find it on exam.

The spec

Fields the spec marks proposed.

change  ·  work_order  ·  agent.confidence  ·  agent.alternatives  ·  seal  ·  pack[]

These are part of the v1 shape and are not emitted today. Demo captions say so wherever they appear, and the schema carries x-proposed on each one. The receipt format.

Changelog

24 September 2026.

First published. Relocated from the platform page, unchanged in substance, with the basis added per line.

Read the record before you read the pitch.

Start with the workflow you
already have to build.

Thirty minutes, with the engineers who build the line. You name the workflow and the examiner you answer to; we tell you what a governed build of it looks like, what it costs, and when it can start. Bring your compliance lead.

Inquiries are answered within one business day, by someone who can answer them.