Skip to main content
PALOPALO FRAMEWORK

PALO-AI | v2.7 | Data-assurance developer preview

Agentic capability matrix

One evidence-based view of what is specified, prototyped and implemented - and what still blocks production use. No PALO-AI runtime capability is represented as production-ready.

Safety boundary: this preview is not a production authorization service, security certification or substitute for organization-owned identity, access control, key management, monitoring, backup, retention and independent assurance.
0Implemented
0Prototype
0Specified
0Production-ready
Filter by status

Scope: this matrix measures the operational PALO-AI authorization and execution runtime. The separate stateless Knowledge Reader has its own production-candidate profile and live qualification gates; its status does not increase the PALO-AI production-ready count.

CapabilityStatusAvailable evidenceRemaining production gate
Official MCP SDK 2.0 | dual eraImplemented45-tool pinned-2026 and legacy stdio/HTTP protocol tests, including exact Reader and Curator profiles.Standard MCP Tasks/MRTR adoption, process isolation and deployment assurance.
Operational OIDC Streamable HTTP MCPPrototypeJWKS signature, issuer/audience, scope/role, RFC 9728 and anonymous-denial tests.Authorization server, EMA ID-JAG, PoP, workload attestation, tenant isolation and operational-runtime rate limiting.
OIDC principal and reviewer bindingPrototypeProtected MCP requests bind verified subjects, clients and scopes to tool access and reviewer attribution.Organization-owned token issuance, workload attestation, proof-of-possession and device or session assurance.
OIDC tenant-to-claim bindingPrototypeToken tenant must match Action Claim 1.3/1.4 and data-assurance tenant inputs before protected MCP processing.Database-level tenant isolation, per-tenant encryption, negative isolation assurance and tenant-scoped recovery.
Fail-closed production admissionImplementedStrict production profile, expiry and evidence checks, startup enforcement and runtime-compatibility denial tests.The reference runtime is denied; production persistence, keys, connector isolation and independent deployment assurance require another implementation.
Versioned trusted registryPrototypeSQLite records and semantic-version checks.Administrative authorization, publisher signatures, backup and recovery.
Canonical Action ClaimsImplementedAction Claim 1.1/1.2/1.3 compatibility and data-governed 1.4 authority, fitness and disclosure binding.Host credential verification, connector-specific schemas and interoperability validation.
Effect Contract predicate DSLImplementedEffect Contract 1.1 closed predicates, delayed verification, retries and compensation proposal.Temporal/cross-resource domain packs and formal verification.
Context Bridge evidence referencesPrototypeImmutable payload-minimized context evidence plus tested Actian normalization profile.Authenticated source clients, remote connector attestation, pagination and reconciliation.
Data Fitness GatePrototypePurpose-bound quality, freshness, authority, owner, lineage, access, incident and classification decisions.Enterprise source-of-record workflow, distributed invalidation and independent policy validation.
Data Disclosure ContractPrototypeSigned row/field/provider/model/region/trace/export contract and receipt with mismatch incident tests.Non-bypass connector boundary, managed signing keys and external DLP verification.
AI System & Agent RegistryPrototypeVersioned system-model-agent-tool-data-provider-owner-policy relationship records.Administrative authorization, portfolio workflow, graph query and enterprise synchronization.
Continuous data assurancePrototypeChange signals invalidate fitness and revoke matching unconsumed capabilities.Guaranteed event delivery, enterprise gate reopening, ITSM routing and reconciliation.
Disclosure result minimizationPrototypeAction Claim 1.4 stores result digest and disclosure metadata, not executor row payloads.Process-memory controls, external-log assurance and connector non-bypassability.
One-time execution capabilityPrototypeClaim, tenant, resource, executor and verifier binding with replay tests.Distributed capability service and workload identity.
Trusted Execution ReceiptPrototypeRuntime-generated signed receipt and idempotent retry tests.Connector workload attestation and distributed recovery.
Authoritative outcome verificationPrototypeVerified, mismatch and inconclusive scenarios.Production connector validation, HA and recovery.
Assurance Incident lifecyclePrototypeResource hold, human resolution and ledger evidence.Enterprise incident integration and production approval identity.
OPA Rego v1 default denyImplementedPositive and negative reference-policy tests.Authenticated policy distribution and bundle attestation.
Portable evidence signaturesPrototypeHMAC compatibility plus RFC 8785/Ed25519 envelope and offline verifier tests.KMS/HSM custody, revocation and external anchoring.
Replay protectionPrototypeNonce, idempotency-key and sequence tests.Distributed coordination; no universal exactly-once claim.
Append-only SQLite ledgerPrototypeWAL/FULL mode, immutable triggers and chain verification.PostgreSQL, durable outbox, retention, backup and tested restore.
Single-instance recoveryPrototypeStale pending entries become signed unknown receipts and incidents.Distributed leasing, reconciliation and multi-replica recovery.
Human approval | Web and AndroidPrototypeDigest-bound state transition; OIDC MCP resolutions use the verified reviewer subject.OIDC-enabled BFF/mobile delivery, roster, device assurance and production workflow validation.
PALO-AM profile exchangePrototypeLocal profile and decision import/export.Owner validation and enterprise synchronization.
Vibe Coding pre-tool gatePrototypeClaim metadata and reference Rego rule.Trusted attestation and unavoidable execution proxy.
Hierarchical subagentsPrototypeProfiles, delegation limits and parent metadata.Trusted spawning, lineage verification and evidence handback.
Collaborative agent teamsSpecifiedArchitecture and governance model.Team registry, leases, conflict handling and team evidence.
Dify connectorPrototypeAuthenticated claim-submission example.Production credentials, packaging and connector validation.
n8n visual decision gatePrototypePackage 0.2 decision node and fail-closed gateway path.Fresh canvas validation, publication and unavoidable execution boundary.
n8n governed executorPrototypeFull-cycle node with four explicit result routes.Real reversible connectors, npm publication and n8n review.
n8n secure approval resumeSpecifiedExact-claim approval contract.Authenticated delivery and one-time backend-controlled resume.
n8n workflow admissionSpecifiedArchitecture and digest registration design.Activation and pre-execution enforcement hooks.
Governance Hub GUIPrototypeExecutive and technical mock-data interface.Same-origin BFF, authenticated sessions and tenant authorization.
OpenTelemetry assurance bridgePrototypeTrace-correlated allowlisted spans that exclude token and arbitrary payload fields.Host SDK/exporter, metrics, downstream propagation, dashboard and SIEM integration.
Governance E2EPrototypeAuthorize, fitness, disclosure, approve, execute, receipt, verify, invalidate, incident, task and ledger tests.Distributed staging with production identity, observability and recovery.
Production persistence and durable workSpecifiedProduction profile requires HA database, durable queue, backup-recovery evidence and controlled migrations.No PostgreSQL adapter, multi-replica lease or production recovery implementation is bundled.
Managed key custodySpecifiedProduction profile requires KMS/HSM or managed signing, no private process key, rotation, revocation and custody attestation.No managed key provider or independent custody attestation implementation is bundled.
Non-bypassable remote connectorsSpecifiedProduction profile requires allowlisted or remotely attested connectors, disabled in-process bypass and bypass-resistance tests.No external connector isolation or unavoidable enforcement implementation is bundled.
Independent production assuranceSpecifiedProduction profile requires a current independent report, zero open critical findings and an accountable admission decision.The repository supplies the contract and denial path, not an external assessment or deployment attestation.

No capabilities match these filters.