PALO: evidence and maturity at 17 September 2026#
PALO connects organizational accountability to agent authority, data fitness and observable outcomes. This dated assessment separates the published baseline, the experimental ANS bridge and a separately evaluated swarm implementation. Publishing their documentation does not qualify a production service.
Read the version and evidence together#
| Surface | Available evidence | Boundary |
|---|---|---|
| PALO Web 3.1 and PALO-AM 2.0 | Governance control packs, six-phase lifecycle, assessment tools and delegated-action methodology | Methodology and local assessment artifacts do not establish operating effectiveness |
| Published PALO-AI 2.7 reference runtime | 21 agentic contracts and 45 MCP reference tools | Developer Preview; the bundled runtime is denied production admission |
| ANS SDK bridge, assessed 16 September | 21 ANS tests within 118 JavaScript tests; eight synthetic offline scenarios | Experimental SDK interoperability; hosted GoDaddy acceptance, authenticated log-checkpoint verification and production qualification remain open |
| Swarm snapshot, assessed 17 September | 23 agentic contracts, 50 MCP tools and 102 JavaScript tests, including 35 swarm tests; four multi-process demo scenarios | Separate unreleased source snapshot, with one central SQLite authority and synthetic external effects |
| Knowledge Reader | Dedicated six-tool, canonical-only read surface with its own release and acceptance gates | Its production-candidate status does not extend to the Curator, Hub or execution runtime |
| Governance Hub | Role-based interface, local demonstrations and optional operator-configured connections | Visible mock records and local checks are not live runtime evidence or host acceptance |
The ANS and swarm totals describe different source snapshots. Do not add them, treat them as one combined test run, or infer that the published 45-tool server already exposes the five swarm tools. The August release verification record remains a historical observation, including its original counts and dependency checks.
What the swarm work establishes#
The swarm implementation binds an accountable owner, objective, registered identities and delegation ancestry to an immutable mandate. It reserves shared exposure in the same central transaction as execution intent, so workers cannot each spend the full aggregate allowance. Admitting or removing a member does not reset the budget.
Remote workers use authenticated leases and single-use start permissions. Membership changes use versioned, auditable revisions. Revoking a subtree prevents new starts and requests cancellation of affected work.
Cancellation is an evidence question. A request or worker acknowledgement is insufficient: confirmation requires a supporting connector and an authoritative observation that the operation stopped without effects. Partitions remain unknown until reconciled. An effect that has already occurred is too late to stop; remediation requires a separate authorized action.
The machine-readable verification record binds the recorded results to source digests. Tests use child processes, loopback transport and a synthetic effects database. They establish the checked reference behavior, without demonstrating controller failover, multi-primary consensus, geographically distributed resilience, external credential isolation or independent security assurance.
Identity, permission and outcome#
The ANS guide describes the experimental identity bridge. ANS identity verification and OAuth authorization complement PALO's organization-specific delegation and outcome controls. Combining the ANS bridge with the swarm dispatcher is a proposed integration, not a completed end-to-end qualification.
A useful evaluation would bind an externally verified agent to a tenant and scoped mandate, admit a second worker, enforce a shared limit, revoke authority during execution and reconcile the observed effects. GoDaddy service acceptance and connector-specific cancellation semantics must be demonstrated separately.
Current priorities#
The capability matrix distinguishes baseline controls from the unreleased swarm snapshot. The production readiness page retains the requirements for workload identity, tenant isolation, managed signing keys, unavoidable connector boundaries, resilient storage and independent assessment.
Regulatory dates are maintained in Regulatory Watch, checked against Commission guidance and the consolidated AI Act on 17 September 2026. Regulatory applicability and technical qualification remain separate decisions.
PALO FRAMEWORK