{
  "format": "palo-agentic-capability-matrix",
  "schemaVersion": "1.3.0",
  "release": "2.7.0",
  "releaseStatus": "developer-preview",
  "updatedAt": "2026-08-25",
  "statusVocabulary": [
    "specified",
    "prototype",
    "implemented",
    "production-ready"
  ],
  "disclaimer": "PALO-AI v2.7.0 is a developer preview and reference implementation. Its production profile and fail-closed admission check specify controls that the bundled SQLite and in-process runtime does not satisfy. Context evidence, fitness decisions and disclosure receipts remain assertions inside a non-attested reference boundary. It is not a production authorization service, security boundary, compliance certification, or substitute for organization-owned identity, tenant isolation, managed key custody, monitoring, backup, retention, legal review, independent assurance and security testing.",
  "capabilities": [
    { "id": "mcp-stdio", "status": "implemented", "note": "Official SDK reference transport covered by protocol tests; deployment hardening remains the adopter's responsibility." },
    { "id": "mcp-streamable-http-auth", "status": "prototype", "note": "The resource-server path validates OIDC/JWKS issuer, audience, expiry, algorithms and least-privilege scopes. It does not issue or rotate tokens, terminate TLS, attest workloads or provide rate limiting; shared-token mode remains development-only." },
    { "id": "trusted-registry", "status": "prototype", "note": "Versioned SQLite records exist, but administrative authorization, publisher signatures, backup, and recovery are not implemented." },
    { "id": "canonical-action-claim", "status": "implemented", "note": "Action Claim 1.4 binds human/workload/agent authority, tenant and Effect Contract to exact Data Fitness Decision and signed Disclosure Contract digests. Action Claim 1.1, 1.2 and 1.3 remain compatibility contracts." },
    { "id": "effect-contract", "status": "implemented", "note": "A closed JSON-Pointer predicate DSL represents preconditions, expected effects, forbidden effects and inconclusive handling without arbitrary executable expressions." },
    { "id": "context-bridge-evidence-reference", "status": "prototype", "note": "Immutable external evidence references retain source/version/URI, normalized context, authority, connector provenance, freshness and payload digest without retaining the source payload. The Actian mapper is a tested normalization profile, not an authenticated or remotely attested SaaS connector." },
    { "id": "data-fitness-gate", "status": "prototype", "note": "Purpose-bound deterministic evaluation covers evidence types, quality, age, verified authority, ownership, approval, lineage, access, incident, classification and source-permitted purpose. Decisions are immutable and expire, but the SQLite store is not an enterprise source of record." },
    { "id": "data-disclosure-contract", "status": "prototype", "note": "Signed contracts and receipts bind read fields/rows, egress mode, sensitive categories, redaction, recipient, provider, model, region, endpoint, trace retention and export to an allowed fitness decision. Connector observations are not independently attested." },
    { "id": "ai-system-agent-registry", "status": "prototype", "note": "Versioned records link AI systems to models, agents, tools, data subjects, providers, owners, jurisdictions, risk class, policy digest and evidence. Administrative authorization, graph query, enterprise synchronization and portfolio workflow remain incomplete." },
    { "id": "continuous-data-assurance", "status": "prototype", "note": "Catalog/observability/source signals invalidate allowed fitness decisions and revoke matching unconsumed capabilities. Distributed event delivery, enterprise gate reopening, ITSM routing and reconciliation are not implemented." },
    { "id": "disclosure-result-minimization", "status": "prototype", "note": "Action Claim 1.4 execution stores a result digest and signed disclosure metadata rather than executor row payloads. Process memory, connector egress, logs outside PALO and non-bypassability still require production controls." },
    { "id": "rego-default-deny", "status": "implemented", "note": "Rego v1 reference policy and tests are included; production policy distribution and bundle attestation are not provided." },
    { "id": "evidence-signatures", "status": "prototype", "note": "Evidence Envelope 2.0 supports RFC 8785 canonicalization and Ed25519, while internal runtime records retain HMAC compatibility. Keys still enter the application process; KMS/HSM custody, automated rotation, revocation and external anchoring are not implemented." },
    { "id": "oidc-identity-binding", "status": "prototype", "note": "OIDC subjects, clients and scopes are bound to protected MCP requests and reviewer attribution. Identity issuance, workload attestation, proof-of-possession and an organization-owned authorization service remain external dependencies." },
    { "id": "oidc-tenant-claim-binding", "status": "prototype", "note": "The request path requires the configured OIDC tenant claim to match Action Claim 1.3/1.4 and data-assurance tenant inputs before protected processing. This does not provide tenant-isolated storage, per-tenant encryption, tenant-scoped backup or negative-isolation assurance." },
    { "id": "replay-protection", "status": "prototype", "note": "Nonce, idempotency-key, and sequence checks exist, but the reference executor does not provide production-grade exactly-once execution." },
    { "id": "transactional-ledger", "status": "prototype", "note": "SQLite WAL, append-only triggers, capability consumption, execution intent and hash-chain verification are implemented; external tools cannot participate in the local transaction and production durability remains incomplete." },
    { "id": "single-instance-execution-recovery", "status": "prototype", "note": "Startup recovery converts stale pending outbox entries into signed unknown receipts, inconclusive attestations, incidents and resource holds; distributed leasing and exactly-once execution are not provided." },
    { "id": "one-time-execution-capability", "status": "prototype", "note": "Signed, short-lived capabilities bind claim, decision, tenant, resource, executor and verifier and are consumed once inside the reference runtime." },
    { "id": "trusted-execution-receipt", "status": "prototype", "note": "Operator-provisioned in-process executors generate signed receipts inside the runtime; workload attestation, connector isolation and distributed recovery remain under development." },
    { "id": "authoritative-outcome-verification", "status": "prototype", "note": "Separately registered verifiers compare authoritative pre/post state with the Effect Contract and emit verified, mismatch or inconclusive attestations." },
    { "id": "assurance-incident-lifecycle", "status": "prototype", "note": "Mismatch and inconclusive outcomes open a resource hold and incident that can be acknowledged or resolved; automatic rollback is intentionally excluded." },
    { "id": "web-mobile-approval", "status": "prototype", "note": "The Web client demonstrates the approval contract. Android integration is referenced by release artifacts outside this repository's tested source tree; authenticated reviewer identity, meaningful action presentation, notification delivery, traceable mobile build evidence, and production workflow assurance remain under development." },
    { "id": "palo-am-exchange", "status": "prototype", "note": "Local profile and decision import/export is available for evaluation; owner validation and enterprise synchronization are not provided." },
    { "id": "vibe-pre-tool-gate", "status": "prototype", "note": "The current gate demonstrates claim metadata and policy checks; it is not a trusted attestation or an unavoidable tool-execution proxy." },
    { "id": "hierarchical-subagents", "status": "prototype", "note": "Individual profiles, delegation limits, and parent metadata exist; trusted spawning, lineage verification, and evidence handback are incomplete." },
    { "id": "collaborative-agent-teams", "status": "specified", "note": "Team registry, shared task claims, peer assignment, leases, conflict handling, and team-level evidence are not implemented." },
    { "id": "dify-connector", "status": "prototype", "note": "A non-production example demonstrates authenticated claim submission; production credentials, distributed retry semantics, packaging and connector certification are not included." },
    { "id": "n8n-visual-decision-gate", "status": "prototype", "note": "The compatibility decision node remains available in the installable 0.2.0 package and routes a live fail-closed gateway decision. It remains optional, unpublished, unverified and not an unavoidable execution boundary." },
    { "id": "n8n-governed-executor", "status": "prototype", "note": "Package 0.2 adds a PALO Governed Action node with Verified, Review Required, Denied and Execution Failed outputs backed by the current PALO-AI v2.7 reference gateway/runtime; it is unpublished and not n8n-verified." },
    { "id": "n8n-secure-approval-resume", "status": "specified", "note": "The exact-claim approval contract is prototyped; authenticated reviewer delivery and one-time backend-controlled n8n resume are not implemented." },
    { "id": "n8n-workflow-admission", "status": "specified", "note": "Workflow assessment, digest registration and activation/pre-execution enforcement hooks are architected but not implemented." },
    { "id": "governance-e2e", "status": "prototype", "note": "Automated tests cover authorize, approval, one-time execution, signed receipt, verified effect, stale-state prevention, mismatch incident, inconclusive verification and ledger integrity; distributed production staging remains incomplete." },
    { "id": "opentelemetry-assurance-bridge", "status": "prototype", "note": "An allowlisted lifecycle-event bridge can create trace-correlated OpenTelemetry spans without arbitrary payload or token fields. The host must supply the SDK, exporter, sampling, metrics, dashboards and SIEM controls." },
    { "id": "governance-hub-gui", "status": "prototype", "note": "A white role-adaptive Executive and Technical interface demonstrates guided authority setup, portfolio signals, decision queues, execution traces, approvals and incidents with realistic evaluation data. It is not yet connected to production identity, tenant authorization, managed keys or an independently assessed runtime boundary." },
    { "id": "production-admission-contract", "status": "implemented", "note": "A schema-validated production profile and startup admission check fail closed on identity, tenant isolation, persistence, durable work, key custody, connector boundary, observability and independent-assurance requirements. The reference runtime is intentionally denied because it cannot truthfully attest these capabilities." },
    { "id": "production-persistence", "status": "specified", "note": "The production profile requires an organization-operated production database, high availability, a durable queue, backup-recovery evidence and controlled migrations. The bundled runtime remains SQLite and single-instance." },
    { "id": "managed-key-custody", "status": "specified", "note": "The production profile requires KMS, HSM or managed signing with no private signing key in the application process plus rotation, revocation and attestation evidence. The reference runtime does not implement this boundary." },
    { "id": "non-bypassable-remote-connectors", "status": "specified", "note": "The production profile requires allowlisted or remote governed connectors, disabled in-process bypass, one-time capabilities, verified receipts and authoritative outcomes. The reference in-process connector path is not an unavoidable execution boundary." },
    { "id": "independent-production-assurance", "status": "specified", "note": "Production admission requires a current independent assurance report and an accountable approval decision. The repository supplies the contract and testable denial, not the external assessment or deployment evidence." }
  ]
}
