PALO-AI · v2.5 · Full-cycle developer preview
Agentic capability matrix
One evidence-based view of what is specified, prototyped and implemented—and what still blocks production use. No PALO-AI runtime capability is represented as production-ready.
Safety boundary: this preview is not a production authorization service, security certification or substitute for organization-owned identity, access control, key management, monitoring, backup, retention and independent assurance.
| Capability | Status | Available evidence | Remaining production gate |
|---|---|---|---|
| Official MCP SDK · stdio | Implemented | 19-tool protocol test. | Production process isolation and deployment assurance. |
| Authenticated Streamable HTTP MCP | Prototype | Anonymous denial and authenticated protocol tests. | Workload identity, principal RBAC, rotation and rate limiting. |
| Versioned trusted registry | Prototype | SQLite records and semantic-version checks. | Administrative authorization, publisher signatures, backup and recovery. |
| Canonical Action Claims | Implemented | Action Claim 1.1 compatibility and 1.2 Effect Contract binding. | Connector-specific production schemas and interoperability validation. |
| Effect Contract predicate DSL | Implemented | Closed JSON-Pointer predicates and schema validation. | Domain predicate packs and formal verification. |
| One-time execution capability | Prototype | Claim, tenant, resource, executor and verifier binding with replay tests. | Distributed capability service and workload identity. |
| Trusted Execution Receipt | Prototype | Runtime-generated signed receipt and idempotent retry tests. | Connector workload attestation and distributed recovery. |
| Authoritative outcome verification | Prototype | Verified, mismatch and inconclusive scenarios. | Production connector validation, HA and recovery. |
| Assurance Incident lifecycle | Prototype | Resource hold, human resolution and ledger evidence. | Enterprise incident integration and production approval identity. |
| OPA Rego v1 default deny | Implemented | Positive and negative reference-policy tests. | Authenticated policy distribution and bundle attestation. |
| HMAC evidence signatures | Prototype | Canonicalization and signature verification tests. | KMS/HSM custody, rotation and external anchoring. |
| Replay protection | Prototype | Nonce, idempotency-key and sequence tests. | Distributed coordination; no universal exactly-once claim. |
| Append-only SQLite ledger | Prototype | WAL/FULL mode, immutable triggers and chain verification. | PostgreSQL, durable outbox, retention, backup and tested restore. |
| Single-instance recovery | Prototype | Stale pending entries become signed unknown receipts and incidents. | Distributed leasing, reconciliation and multi-replica recovery. |
| Human approval · Web and Android | Prototype | Digest-bound state transition and demonstration clients. | Authenticated reviewer identity, delivery and production workflow assurance. |
| PALO-AM profile exchange | Prototype | Local profile and decision import/export. | Owner validation and enterprise synchronization. |
| Vibe Coding pre-tool gate | Prototype | Claim metadata and reference Rego rule. | Trusted attestation and unavoidable execution proxy. |
| Hierarchical subagents | Prototype | Profiles, delegation limits and parent metadata. | Trusted spawning, lineage verification and evidence handback. |
| Collaborative agent teams | Specified | Architecture and governance model. | Team registry, leases, conflict handling and team evidence. |
| Dify connector | Prototype | Authenticated claim-submission example. | Production credentials, packaging and connector validation. |
| n8n visual decision gate | Prototype | Package 0.2 decision node and fail-closed gateway path. | Fresh canvas validation, publication and unavoidable execution boundary. |
| n8n governed executor | Prototype | Full-cycle node with four explicit result routes. | Real reversible connectors, npm publication and n8n review. |
| n8n secure approval resume | Specified | Exact-claim approval contract. | Authenticated delivery and one-time backend-controlled resume. |
| n8n workflow admission | Specified | Architecture and digest registration design. | Activation and pre-execution enforcement hooks. |
| Governance Hub GUI | Prototype | Executive and technical mock-data interface. | Same-origin BFF, authenticated sessions and tenant authorization. |
| Governance E2E | Prototype | Authorize, approve, execute, receipt, verify, incident and ledger tests. | Distributed staging with production identity, observability and recovery. |
No capabilities match these filters.
PALO FRAMEWORK