PALO-AI | v2.7 | Data-assurance developer preview
Agentic capability matrix
One evidence-based view of what is specified, prototyped and implemented - and what still blocks production use. No PALO-AI runtime capability is represented as production-ready.
Safety boundary: this preview is not a production authorization service, security certification or substitute for organization-owned identity, access control, key management, monitoring, backup, retention and independent assurance.
Scope: this matrix measures the operational PALO-AI authorization and execution runtime. The separate stateless Knowledge Reader has its own production-candidate profile and live qualification gates; its status does not increase the PALO-AI production-ready count.
| Capability | Status | Available evidence | Remaining production gate |
|---|---|---|---|
| Official MCP SDK 2.0 | dual era | Implemented | 45-tool pinned-2026 and legacy stdio/HTTP protocol tests, including exact Reader and Curator profiles. | Standard MCP Tasks/MRTR adoption, process isolation and deployment assurance. |
| Operational OIDC Streamable HTTP MCP | Prototype | JWKS signature, issuer/audience, scope/role, RFC 9728 and anonymous-denial tests. | Authorization server, EMA ID-JAG, PoP, workload attestation, tenant isolation and operational-runtime rate limiting. |
| OIDC principal and reviewer binding | Prototype | Protected MCP requests bind verified subjects, clients and scopes to tool access and reviewer attribution. | Organization-owned token issuance, workload attestation, proof-of-possession and device or session assurance. |
| OIDC tenant-to-claim binding | Prototype | Token tenant must match Action Claim 1.3/1.4 and data-assurance tenant inputs before protected MCP processing. | Database-level tenant isolation, per-tenant encryption, negative isolation assurance and tenant-scoped recovery. |
| Fail-closed production admission | Implemented | Strict production profile, expiry and evidence checks, startup enforcement and runtime-compatibility denial tests. | The reference runtime is denied; production persistence, keys, connector isolation and independent deployment assurance require another implementation. |
| Versioned trusted registry | Prototype | SQLite records and semantic-version checks. | Administrative authorization, publisher signatures, backup and recovery. |
| Canonical Action Claims | Implemented | Action Claim 1.1/1.2/1.3 compatibility and data-governed 1.4 authority, fitness and disclosure binding. | Host credential verification, connector-specific schemas and interoperability validation. |
| Effect Contract predicate DSL | Implemented | Effect Contract 1.1 closed predicates, delayed verification, retries and compensation proposal. | Temporal/cross-resource domain packs and formal verification. |
| Context Bridge evidence references | Prototype | Immutable payload-minimized context evidence plus tested Actian normalization profile. | Authenticated source clients, remote connector attestation, pagination and reconciliation. |
| Data Fitness Gate | Prototype | Purpose-bound quality, freshness, authority, owner, lineage, access, incident and classification decisions. | Enterprise source-of-record workflow, distributed invalidation and independent policy validation. |
| Data Disclosure Contract | Prototype | Signed row/field/provider/model/region/trace/export contract and receipt with mismatch incident tests. | Non-bypass connector boundary, managed signing keys and external DLP verification. |
| AI System & Agent Registry | Prototype | Versioned system-model-agent-tool-data-provider-owner-policy relationship records. | Administrative authorization, portfolio workflow, graph query and enterprise synchronization. |
| Continuous data assurance | Prototype | Change signals invalidate fitness and revoke matching unconsumed capabilities. | Guaranteed event delivery, enterprise gate reopening, ITSM routing and reconciliation. |
| Disclosure result minimization | Prototype | Action Claim 1.4 stores result digest and disclosure metadata, not executor row payloads. | Process-memory controls, external-log assurance and connector non-bypassability. |
| One-time execution capability | Prototype | Claim, tenant, resource, executor and verifier binding with replay tests. | Distributed capability service and workload identity. |
| Trusted Execution Receipt | Prototype | Runtime-generated signed receipt and idempotent retry tests. | Connector workload attestation and distributed recovery. |
| Authoritative outcome verification | Prototype | Verified, mismatch and inconclusive scenarios. | Production connector validation, HA and recovery. |
| Assurance Incident lifecycle | Prototype | Resource hold, human resolution and ledger evidence. | Enterprise incident integration and production approval identity. |
| OPA Rego v1 default deny | Implemented | Positive and negative reference-policy tests. | Authenticated policy distribution and bundle attestation. |
| Portable evidence signatures | Prototype | HMAC compatibility plus RFC 8785/Ed25519 envelope and offline verifier tests. | KMS/HSM custody, revocation and external anchoring. |
| Replay protection | Prototype | Nonce, idempotency-key and sequence tests. | Distributed coordination; no universal exactly-once claim. |
| Append-only SQLite ledger | Prototype | WAL/FULL mode, immutable triggers and chain verification. | PostgreSQL, durable outbox, retention, backup and tested restore. |
| Single-instance recovery | Prototype | Stale pending entries become signed unknown receipts and incidents. | Distributed leasing, reconciliation and multi-replica recovery. |
| Human approval | Web and Android | Prototype | Digest-bound state transition; OIDC MCP resolutions use the verified reviewer subject. | OIDC-enabled BFF/mobile delivery, roster, device assurance and production workflow validation. |
| PALO-AM profile exchange | Prototype | Local profile and decision import/export. | Owner validation and enterprise synchronization. |
| Vibe Coding pre-tool gate | Prototype | Claim metadata and reference Rego rule. | Trusted attestation and unavoidable execution proxy. |
| Hierarchical subagents | Prototype | Profiles, delegation limits and parent metadata. | Trusted spawning, lineage verification and evidence handback. |
| Collaborative agent teams | Specified | Architecture and governance model. | Team registry, leases, conflict handling and team evidence. |
| Dify connector | Prototype | Authenticated claim-submission example. | Production credentials, packaging and connector validation. |
| n8n visual decision gate | Prototype | Package 0.2 decision node and fail-closed gateway path. | Fresh canvas validation, publication and unavoidable execution boundary. |
| n8n governed executor | Prototype | Full-cycle node with four explicit result routes. | Real reversible connectors, npm publication and n8n review. |
| n8n secure approval resume | Specified | Exact-claim approval contract. | Authenticated delivery and one-time backend-controlled resume. |
| n8n workflow admission | Specified | Architecture and digest registration design. | Activation and pre-execution enforcement hooks. |
| Governance Hub GUI | Prototype | Executive and technical mock-data interface. | Same-origin BFF, authenticated sessions and tenant authorization. |
| OpenTelemetry assurance bridge | Prototype | Trace-correlated allowlisted spans that exclude token and arbitrary payload fields. | Host SDK/exporter, metrics, downstream propagation, dashboard and SIEM integration. |
| Governance E2E | Prototype | Authorize, fitness, disclosure, approve, execute, receipt, verify, invalidate, incident, task and ledger tests. | Distributed staging with production identity, observability and recovery. |
| Production persistence and durable work | Specified | Production profile requires HA database, durable queue, backup-recovery evidence and controlled migrations. | No PostgreSQL adapter, multi-replica lease or production recovery implementation is bundled. |
| Managed key custody | Specified | Production profile requires KMS/HSM or managed signing, no private process key, rotation, revocation and custody attestation. | No managed key provider or independent custody attestation implementation is bundled. |
| Non-bypassable remote connectors | Specified | Production profile requires allowlisted or remotely attested connectors, disabled in-process bypass and bypass-resistance tests. | No external connector isolation or unavoidable enforcement implementation is bundled. |
| Independent production assurance | Specified | Production profile requires a current independent report, zero open critical findings and an accountable admission decision. | The repository supplies the contract and denial path, not an external assessment or deployment attestation. |
No capabilities match these filters.
PALO FRAMEWORK