| ORG-AUTH-001 | .github | SPECIFIED | NOT AUDITED | 0/5 (0%)5 openORG-AUTH-R001 SPECIFIED — Duplicate-authority register entry contractORG-AUTH-R002 UNKNOWN — Single authority consolidation per capabilityORG-AUTH-R003 UNKNOWN — Authority register contribution and ownership rulesORG-AUTH-R004 UNKNOWN — Register scope excludes deployment-specific detailORG-AUTH-R005 UNKNOWN — Unresolved-owner decisions stay visible as PROPOSED
| |
| ORG-FRONT-001 | .github | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openORG-FRONT-R001 UNKNOWN — Organization front door describes the five-repository flow (Claimed commit is not on the default branch)
| |
| SDK-CONNECTOR-CONTROL | agent-connector-sdk | UNKNOWN | NOT AUDITED | 0/18 (0%)18 openSDK-CONNECTOR-CONTROL-R001 UNKNOWN — ConnectorPackClient uses a deterministic idempotency keySDK-CONNECTOR-CONTROL-R002 UNKNOWN — Contract pin travels as a claim attribute, not recomputed downstreamSDK-CONNECTOR-CONTROL-R003 UNKNOWN — Canonical output-schema digest on every certified tool pinSDK-CONNECTOR-CONTROL-R004 UNKNOWN — Contract-pin verification owned by the SDK's own test kitSDK-CONNECTOR-CONTROL-R005 BUILDING — Pack publisher and source submission use generated graph-client typesSDK-CONNECTOR-CONTROL-R006 UNKNOWN — Decision-service proposals for tool choice and triage stay observationalSDK-CONNECTOR-CONTROL-R007 SPECIFIED — Fleet-wide re-certification yields nonempty schema fingerprintsSDK-CONNECTOR-CONTROL-R008 UNKNOWN — Closed, canonical pack annotation map across the connector fleetSDK-CONNECTOR-CONTROL-R009 UNKNOWN — Connector batch A-E migrates fully onto the SDK clientSDK-CONNECTOR-CONTROL-R010 UNKNOWN — Connector batch F-J migrates fully onto the SDK clientSDK-CONNECTOR-CONTROL-R011 UNKNOWN — Connector batch K-O migrates fully onto the SDK clientSDK-CONNECTOR-CONTROL-R012 UNKNOWN — Connector batch P-S migrates fully onto the SDK clientSDK-CONNECTOR-CONTROL-R013 UNKNOWN — Connector batch T-Z migrates fully onto the SDK clientSDK-CONNECTOR-CONTROL-R014 SPECIFIED — SDK fully supersedes the duplicated connector toolkitSDK-CONNECTOR-CONTROL-R015 SPECIFIED — SDK is sole owner of connector source lifecycle and certificationSDK-CONNECTOR-CONTROL-R016 BUILDING — Connector base settings live in the SDK's own config moduleSDK-CONNECTOR-CONTROL-R017 UNKNOWN — Every connector uses the shared TLS profile, no bare verify bypassSDK-CONNECTOR-CONTROL-R018 UNKNOWN — SDK source and test suite build cleanly from a fresh checkout
| |
| SDK-FINANCE-SOURCES | agent-connector-sdk | SPECIFIED | NOT AUDITED | 0/5 (0%)5 openSDK-FINANCE-SOURCES-R001 UNKNOWN — Market-data adapters: exchange history fix, CoinMarketCap, FRED/ALFREDSDK-FINANCE-SOURCES-R002 SPECIFIED — Alpaca stocks adapter: history, quotes, fundamentals, calendarsSDK-FINANCE-SOURCES-R003 SPECIFIED — FX, commodities, and real-estate adapters with roll and staleness rulesSDK-FINANCE-SOURCES-R004 SPECIFIED — Alpaca account reads and idempotent CSV activity importSDK-FINANCE-SOURCES-R005 UNKNOWN — Macro and liquidity panels: FRED series, ETF flows, sentiment, on-chain
| |
| SDK-GOVERNED-WRITEBACK | agent-connector-sdk | UNKNOWN | NOT AUDITED | 0/5 (0%)5 openSDK-GOVERNED-WRITEBACK-R001 UNKNOWN — Write-back proposals route through governed authorization, not direct actionSDK-GOVERNED-WRITEBACK-R002 BUILDING — Source-side WriteBackPort composes a durable graph write-back adapterSDK-GOVERNED-WRITEBACK-R003 UNKNOWN — Full write-back requires an authorization resolver and restart recoverySDK-GOVERNED-WRITEBACK-R004 SPECIFIED — Governed write-back: approval, idempotency, and an audit reservationSDK-GOVERNED-WRITEBACK-R005 UNKNOWN — Write-back implementation passes its full durable test suite together
| |
| SDK-OBSERVABILITY-FEEDS | agent-connector-sdk | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openSDK-OBSERVABILITY-FEEDS-R001 UNKNOWN — RUM, security-audit, and CI/CD events join the durable source pipeline
| |
| SDK-QUALITY-RELEASE | agent-connector-sdk | UNKNOWN | NOT AUDITED | 3/5 (60%)2 openSDK-QUALITY-RELEASE-R002 UNKNOWN — Public-documentation scanner catches private addresses and hostsSDK-QUALITY-RELEASE-R004 UNKNOWN — Public documentation follows a task-first README and site structure
| |
| SDK-REPOSITORY-TRANSPORT | agent-connector-sdk | UNKNOWN | NOT AUDITED | 0/5 (0%)5 openSDK-REPOSITORY-TRANSPORT-R001 BUILDING — Repository transport hydrates code and specification sources from GitSDK-REPOSITORY-TRANSPORT-R002 UNKNOWN — SDK is the sole path for repository-native codebase hydrationSDK-REPOSITORY-TRANSPORT-R003 BUILT — Repository ref walk traverses each Git tree once with batched readsSDK-REPOSITORY-TRANSPORT-R004 UNKNOWN — Repository transport submits bounded, outcome-complete index batchesSDK-REPOSITORY-TRANSPORT-R005 UNKNOWN — Branch-aware transport batches indexing into one call per batch
| |
| SDK-SOURCE-INGEST | agent-connector-sdk | UNKNOWN | NOT AUDITED | 1/9 (11%)8 openSDK-SOURCE-INGEST-R002 UNKNOWN — SDK drift classifier quarantines incompatible schema changesSDK-SOURCE-INGEST-R003 UNKNOWN — SDK records and pauses on proposed schema repairsSDK-SOURCE-INGEST-R004 BUILDING — SDK runner performs enterprise source synchronizationSDK-SOURCE-INGEST-R005 SPECIFIED — SDK adapters cover document, conversation, and feed sourcesSDK-SOURCE-INGEST-R006 SPECIFIED — SDK packs own vendor enrichment extraction and write-backSDK-SOURCE-INGEST-R007 UNKNOWN — Drift gate runs inside the SDK connector-sync runnerSDK-SOURCE-INGEST-R008 UNKNOWN — Connectors ingest occurrence and weather observationsSDK-SOURCE-INGEST-R009 UNKNOWN — Taxonomy connector ingests NCBI/GBIF taxa as kg:Taxon
| |
| TUI-RUNTIME-001 | agent-terminal-ui | SPECIFIED | NOT AUDITED | 0/2 (0%)2 openTUI-RUNTIME-R001 BUILDING — Terminal operation client issues typed commands with pending approvalsTUI-RUNTIME-R002 BUILT — Terminal chat transport is reconciled with the current Graph OS boundary
| |
| AU-BOUNDARY-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/48 (0%)48 openAU-BOUNDARY-R001 BUILDING — Retire AU's duplicated gateway moduleAU-BOUNDARY-R002 SPECIFIED — Retire AU's deployment and skill-certification toolingAU-BOUNDARY-R003 BUILDING — Retire AU's legacy MCP host and action manifestAU-BOUNDARY-R004 SPECIFIED — Retire AU's multiplexer family duplicated in graph-osAU-BOUNDARY-R005 UNKNOWN — Migrate connector packages A-E onto the SDKAU-BOUNDARY-R006 UNKNOWN — Migrate connector packages F-J onto the SDKAU-BOUNDARY-R007 UNKNOWN — Migrate connector packages K-O onto the SDKAU-BOUNDARY-R008 UNKNOWN — Migrate connector packages P-S onto the SDKAU-BOUNDARY-R009 UNKNOWN — Migrate connector packages T-Z onto the SDKAU-BOUNDARY-R010 SPECIFIED — Delete AU's SDK-duplicated connector toolkitAU-BOUNDARY-R011 SPECIFIED — Delete AU's source lifecycle and certification codeAU-BOUNDARY-R012 BUILT — Delete the second EG projection and leftover shimsAU-BOUNDARY-R013 SPECIFIED — Restrict graph-os to AU's public API onlyAU-BOUNDARY-R014 SPECIFIED — Move graph-os boundary modules out of AUAU-BOUNDARY-R015 SPECIFIED — Move the agent HTTP and A2A/ACP host out of AUAU-BOUNDARY-R016 SPECIFIED — Split AU's monolithic configuration moduleAU-BOUNDARY-R017 BUILDING — Split messaging behavior and authority across AU, graph-os, and EGAU-BOUNDARY-R018 BUILDING — Replace the AU graph engine facade with the EG clientAU-BOUNDARY-R019 SPECIFIED — Replace AU's graph-compute and state facades with the EG clientAU-BOUNDARY-R020 BUILDING — Move durable work, queues, and state to EGAU-BOUNDARY-R021 BUILDING — Move graph tenancy, topology, and admission to EGAU-BOUNDARY-R022 BUILDING — Retire AU's reasoning and graph-analytics duplicatesAU-BOUNDARY-R023 BUILDING — Split ingestion commit and derivation into EGAU-BOUNDARY-R024 BUILDING — Move enterprise source synchronization to the SDKAU-BOUNDARY-R025 SPECIFIED — Move document, conversation, and feed sources to the SDKAU-BOUNDARY-R026 SPECIFIED — Move vendor enrichment extractors and write-back to the SDKAU-BOUNDARY-R027 BUILT — Move deterministic enrichment and derivation to EGAU-BOUNDARY-R028 SPECIFIED — Move remaining graph standardization and security modules to EGAU-BOUNDARY-R029 BUILDING — Move the ontology object model to EGAU-BOUNDARY-R030 BUILDING — Move hand-written ontology emitters behind EG pack compilationAU-BOUNDARY-R031 SPECIFIED — Replace AU's graph-schema DTOs with EG-generated typesAU-BOUNDARY-R032 BUILDING — Delete AU's legacy SPARQL backend and setup pathAU-BOUNDARY-R033 SPECIFIED — Move external graph and database federation to EGAU-BOUNDARY-R034 SPECIFIED — Move retrieval engines to EGAU-BOUNDARY-R035 UNKNOWN — Re-home the schema-drift package before it landsAU-BOUNDARY-R036 SPECIFIED — Move the usage fact store to EGAU-BOUNDARY-R037 BUILT — Move development-governance tooling to repository-managerAU-BOUNDARY-R038 SPECIFIED — Add a cross-owner component registry and path guardAU-BOUNDARY-R039 SPECIFIED — Move front ends off AU internalsAU-BOUNDARY-R040 SPECIFIED — Move agent memory and the learning engine to EGAU-BOUNDARY-R041 UNKNOWN — Finance modules that produced fabricated data are removedAU-BOUNDARY-R042 SPECIFIED — Every package directory has one recorded dispositionAU-BOUNDARY-R043 SPECIFIED — Retained agent surface is declared and import-boundedAU-BOUNDARY-R044 SPECIFIED — Fleet, scaling and deployment modules leave orchestrationAU-BOUNDARY-R045 SPECIFIED — Unplaced knowledge-graph packages receive file-level ownersAU-BOUNDARY-R046 SPECIFIED — Partly covered packages list every file with its ownerAU-BOUNDARY-R047 SPECIFIED — Engine-facing adapters and caches are thin clients or removedAU-BOUNDARY-R048 SPECIFIED — Domain models, shapes, assets and skill content are placed
| |
| AU-CONTEXT-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/8 (0%)8 openAU-CONTEXT-R001 UNKNOWN — RetrievalPath templates feed EG-DECISION-ENGINE-R029 as candidatesAU-CONTEXT-R002 UNKNOWN — Corpus re-embedding uses a governed shadow ANN swapAU-CONTEXT-R003 UNKNOWN — Embedding admission changes come from reviewed proposals onlyAU-CONTEXT-R004 UNKNOWN — Context sizing solves a certified multi-resolution knapsackAU-CONTEXT-R005 BUILT — Finance scheduling and a sourced flip-explainer agentAU-CONTEXT-R006 BUILT — Paper trading is isolated; live orders need governed approvalAU-CONTEXT-R007 BUILT — Finance math and feeds move out of agent-utilitiesAU-CONTEXT-R008 SPECIFIED — Finance recommendations are calibrated, cited, and informational
| |
| AU-CONTROL-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/23 (0%)23 openAU-CONTROL-R001 BUILDING — Layered agent execution stack from task mapping to harness runAU-CONTROL-R002 UNKNOWN — Component routing through one committed graph-engine decisionAU-CONTROL-R003 UNKNOWN — Agent graph composition via epistemic-graph assembly, not an LLMAU-CONTROL-R004 UNKNOWN — Abstention escalations re-enter as labelled claims, not proofsAU-CONTROL-R005 UNKNOWN — Advisory pre-tool risk scoringAU-CONTROL-R006 UNKNOWN — Cost-aware routing informed by usage accountingAU-CONTROL-R007 BUILT — Swarm topology selection routed through DecideAU-CONTROL-R008 UNKNOWN — Free-text task mapping accepted only as a labelled claimAU-CONTROL-R009 UNKNOWN — Swarm topology ontology and schema publicationAU-CONTROL-R010 UNKNOWN — Reference swarm topology templatesAU-CONTROL-R011 UNKNOWN — Consume the generated topology contract via a pinned dependencyAU-CONTROL-R012 UNKNOWN — Agent-graph templates validated against topology shape at publishAU-CONTROL-R013 UNKNOWN — Topology options filtered by admissibility derivationAU-CONTROL-R014 UNKNOWN — No local topology solver, defer to the validated graph-engine modelAU-CONTROL-R015 UNKNOWN — Topology consumer asks the graph engine, not a local success storeAU-CONTROL-R016 UNKNOWN — Topology decisions respect capacity headroom at request priorityAU-CONTROL-R017 UNKNOWN — Single re-decision on capacity denial for topology admissionAU-CONTROL-R018 UNKNOWN — Subagent allowance negotiated into the run specificationAU-CONTROL-R019 UNKNOWN — Swarm continuation restricted to narrow-only decisionsAU-CONTROL-R020 UNKNOWN — Learned topology routing term with a benchmark gold setAU-CONTROL-R021 UNKNOWN — Harness and sandbox access via direct typed ports, not a registrarAU-CONTROL-R022 UNKNOWN — Model selection routed through the committed decision, not ad hocAU-CONTROL-R023 UNKNOWN — Catalog entries attributed to their originating server
| |
| AU-DEV-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/3 (0%)3 openAU-DEV-R001 UNKNOWN — A development skill documents AU's contribution workflowAU-DEV-R002 UNKNOWN — Deployment and genesis tooling move to graph-osAU-DEV-R003 UNKNOWN — Skill inventory refresh stays deterministic after moves
| |
| AU-FREEZE-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/2 (0%)2 openAU-FREEZE-R001 SPECIFIED — Canonical AU release-evidence freeze manifestAU-FREEZE-R002 UNKNOWN — Quarantine unresolved scanner findings from the freeze
| |
| AU-HARNESS-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/6 (0%)6 openAU-HARNESS-R001 UNKNOWN — Capability-gated capture of policy trajectoriesAU-HARNESS-R002 UNKNOWN — External training path supports an optional KLPO methodAU-HARNESS-R003 UNKNOWN — Graph-driven work market on Gap and WorkItem contractsAU-HARNESS-R004 UNKNOWN — AU proposes corrections through the graph, never writes Git directlyAU-HARNESS-R005 SPECIFIED — Defer generative model work pending evidence-backed needAU-HARNESS-R006 UNKNOWN — Statistical scoring head ranks work-market offers
| |
| AU-INTEGRATION-001 | agent-utilities | SPECIFIED | NOT AUDITED | 7/18 (38%)11 openAU-INTEGRATION-R001 UNKNOWN — Clustered mode deliberately refuses local-only agent writesAU-INTEGRATION-R002 UNKNOWN — Control graph auto-creation and messaging intake propagationAU-INTEGRATION-R003 UNKNOWN — Reconcile previously tracked fixes against current mainAU-INTEGRATION-R007 UNKNOWN — Gold-set generation is synthetic, not manually labelledAU-INTEGRATION-R010 UNKNOWN — Kafka enqueue-only-proof contract runs and passes honestlyAU-INTEGRATION-R011 SPECIFIED — Prove disposability before pruning a branch checkoutAU-INTEGRATION-R012 UNKNOWN — External-graph contract check follows relocated docsAU-INTEGRATION-R013 UNKNOWN — Privacy gate accepts canonical automation author identitiesAU-INTEGRATION-R014 SPECIFIED — Benchmark query-serving improvements against the existing pathAU-INTEGRATION-R015 BUILT — Remove the unused legacy ontology publisher surfaceAU-INTEGRATION-R018 UNKNOWN — Public docs site passes the full documentation gate suite
| |
| AU-QUAL-01 | agent-utilities | SPECIFIED | NOT AUDITED | 0/7 (0%)7 openAU-QUAL-R001 UNKNOWN — Liveness deferrals fail visibly when they expireAU-QUAL-R002 BUILT — Tiny-profile RBAC and bootstrap-isolation tests cover real codeAU-QUAL-R003 UNKNOWN — Connector validation uses EG's composed GraphSchemaAU-QUAL-R004 UNKNOWN — Named AU test failures are fixed, not skippedAU-QUAL-R005 SPECIFIED — Test files are included in mypy with real fixesAU-QUAL-R006 SPECIFIED — A privacy check covers the final tree and commit historyAU-QUAL-R007 UNKNOWN — Liveness placeholder detector ignores documentation prose
| |
| AU-RETIRE-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/8 (0%)8 openAU-RETIRE-R001 SPECIFIED — Complete inventory and retirement of duplicate graph engine codeAU-RETIRE-R002 UNKNOWN — Enrichment edges carry a provenance rung and confidenceAU-RETIRE-R003 UNKNOWN — OBO ontology terms ingest as typed ReferenceTerm individualsAU-RETIRE-R004 UNKNOWN — Fix doubled node_type text in embedding compositionAU-RETIRE-R005 UNKNOWN — Per-stage timing instrumentation across the full ingest pathAU-RETIRE-R006 UNKNOWN — Delta ingest reaps nodes for deleted filesAU-RETIRE-R007 BUILT — Deterministic embedding admission classifier at the ingest chokepointAU-RETIRE-R008 UNKNOWN — Sequence ingestion-economics work ahead of file relocation
| |
| AU-RETRIEVAL-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openAU-RETRIEVAL-R001 BUILDING — Benchmark structure-aware retrieval against served hybrid search
| |
| AU-SEC-01 | agent-utilities | SPECIFIED | NOT AUDITED | 0/9 (0%)9 openAU-SEC-R001 UNKNOWN — Tiny profile grants scoped authority, not blanket adminAU-SEC-R002 BUILT — Control view failure never falls back to the content graphAU-SEC-R003 UNKNOWN — Caches subscribe to invalidation with volatility-bounded TTLAU-SEC-R004 UNKNOWN — AU treats schema drift as a fail-closed typed resultAU-SEC-R005 UNKNOWN — AU proposes schema-repair mappings; EG alone activates themAU-SEC-R006 BUILT — Elevation can be requested, approved, and revokedAU-SEC-R007 BUILT — Guardrail tightening is automatic; loosening needs approvalAU-SEC-R008 UNKNOWN — AU allowlist is generated from the canonical scope registryAU-SEC-R009 UNKNOWN — Learned scores never grant security authority
| |
| AU-SEMANTIC-001 | agent-utilities | SPECIFIED | NOT AUDITED | 0/28 (0%)28 openAU-SEMANTIC-R001 UNKNOWN — OntologyLifecycle.set_active() fails closed, not a silent local fallbackAU-SEMANTIC-R002 UNKNOWN — AU verifies domain-pack class names against EG's schema-class listAU-SEMANTIC-R003 UNKNOWN — AU's knowledge_graph shape files are published to the EG pack or removedAU-SEMANTIC-R004 UNKNOWN — AU's remaining SHACL shape files move into EG-owned schema packsAU-SEMANTIC-R005 BUILT — Ontology lifecycle, integrity and schema parsing become EG client callsAU-SEMANTIC-R006 UNKNOWN — AU removes rdflib and submits typed payloads to EG insteadAU-SEMANTIC-R007 UNKNOWN — AU tests drop pyshacl and assert through EG shape validationAU-SEMANTIC-R008 BUILT — Reasoning-topology selection uses a served policy, not a local outcome storeAU-SEMANTIC-R009 BUILDING — The local engine facade is deleted in favor of the generated EG clientAU-SEMANTIC-R010 SPECIFIED — Graph-compute and session facades route through the generated EG clientAU-SEMANTIC-R011 BUILDING — Durable jobs, queues and state move to EGAU-SEMANTIC-R012 BUILDING — Tenancy, topology and admission authority move to EGAU-SEMANTIC-R013 BUILDING — Reasoning and analytics duplicates are deleted only with proven EG parityAU-SEMANTIC-R014 BUILDING — Ingestion commit and derivation logic moves to EG's SourceIngestAU-SEMANTIC-R015 BUILDING — Enterprise source sync becomes an SDK runner over EG SourceIngestAU-SEMANTIC-R016 SPECIFIED — Document, session and feed source ingestion moves to the SDKAU-SEMANTIC-R017 SPECIFIED — Vendor enrichment extraction and writeback move to the SDK and EGAU-SEMANTIC-R018 BUILT — Deterministic derivation modules move to EGAU-SEMANTIC-R019 SPECIFIED — Remaining EG-bound standardization, infra and governance modules move outAU-SEMANTIC-R020 BUILDING — The ontology object model moves to EGAU-SEMANTIC-R021 BUILDING — AU's hand-written RDF/OWL/SHACL emitters move behind EG pack compilationAU-SEMANTIC-R022 SPECIFIED — Graph-schema DTOs become EG-generated typesAU-SEMANTIC-R023 BUILDING — Legacy SPARQL backend and setup modules are deletedAU-SEMANTIC-R024 SPECIFIED — External graph and database backends move into EG as federation sourcesAU-SEMANTIC-R025 SPECIFIED — Retrieval and neural-search engines move to EGAU-SEMANTIC-R026 UNKNOWN — The schema-drift package is re-homed before it landsAU-SEMANTIC-R027 UNKNOWN — Capability-gap checks must search the target system's own vocabularyAU-SEMANTIC-R028 UNKNOWN — Configured embedding dimension must match the deployed model's output size
| |
| FIN-UI-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/16 (0%)16 openFIN-UI-R001 SPECIFIED — Mobile-first Markets app with five-destination navigationFIN-UI-R002 SPECIFIED — Shared ChartRenderer for line, candle, and overlay dataFUI-01 SPECIFIED — Responsive five-destination navigationFUI-02 SPECIFIED — Instrument groups with distinct data statesFUI-03 SPECIFIED — Search resolves by stable identity, not ticker textFUI-04 SPECIFIED — Instrument rows show price, provenance, after-hours valueFUI-05 SPECIFIED — Detail tabs and range controls expose only supported dataFUI-06 SPECIFIED — Shared ChartRenderer preserves gaps and revisionsFUI-07 SPECIFIED — Chart overlays show strategy version and simulation stateFUI-08 SPECIFIED — Performance cards render owner-calculated values verbatimFUI-09 SPECIFIED — Strategy views cite evidence and never submit ordersFUI-10 SPECIFIED — DCA and alert views distinguish delivery statesFUI-11 SPECIFIED — CSV import preview with idempotent receiptFUI-12 SPECIFIED — Offline PWA shell marks cached data staleFUI-13 SPECIFIED — Charts and controls meet accessibility requirementsFIN-UI-R003 UNKNOWN — GraphOS Markets app with scanner, search, and layered chart
| |
| WEBUI-API-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/9 (0%)9 openWEBUI-API-R001 BUILDING — Generated GraphOS API client with typed decisions and confirmation flowsWEBUI-API-R002 BUILDING — Typed ontology, graph, Atlas and object-set operations replace host routesWEBUI-API-R003 BUILDING — Remaining domain routes migrate to generated operations with a route censusAPIUI-01 SPECIFIED — Generated TypeScript client from a pinned Graph OS schemaAPIUI-02 SPECIFIED — Typed operations preserve preview-confirm-step-up for effectsAPIUI-03 SPECIFIED — Ontology, graph, Atlas and object-set operations preserve tenant semanticsAPIUI-04 SPECIFIED — Prompts, SDD, knowledge base, sessions and goals migrate to typed callsAPIUI-05 SPECIFIED — Host drops direct internal imports once replacement operations are provenAPIUI-06 SPECIFIED — Shared auth and streaming are preserved without exposing a service bearer
| |
| WEBUI-APPS-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/10 (0%)10 openAPP-01 SPECIFIED — Browser identity consistently reads GraphOS across titles and assetsAPP-02 SPECIFIED — Package, import and environment naming use the new public identityAPP-03 SPECIFIED — AppSurface contract declares each app's route, capability and clientAPP-04 SPECIFIED — Contributed app descriptors cannot escalate privilege beyond the contractAPP-05 SPECIFIED — Markets consumes the AppSurface contract without shell-side duplicationAPP-06 SPECIFIED — Legacy browser state migrates safely with renewed consentAPP-07 SPECIFIED — App navigation supports accessibility and layout states across devicesWEBUI-APPS-R001 UNKNOWN — Apps information-architecture section and AppSurface contractWEBUI-APPS-R002 BUILT — GraphOS brand layer covers titles, assets, theme and documentationWEBUI-APPS-R003 BUILT — Repository, package and runtime identifiers rename to graph-os-webui
| |
| WEBUI-DECIDE-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/8 (0%)8 openWEBUI-DECIDE-R001 BUILDING — Evaluation dashboard shows calibration and coverageDEC-01 SPECIFIED — Decision explorer cites premises, derivations and certificateDEC-02 SPECIFIED — Why-not explanations run on demand within a bounded budgetDEC-03 SPECIFIED — Dashboard labels each evaluation field independentlyDEC-04 SPECIFIED — No coverage claim shown for inadequate evaluation dataDEC-05 SPECIFIED — Tenant or purpose change invalidates cached decision queriesDEC-06 SPECIFIED — Explanation views work without color, hover or pointerWEBUI-DECIDE-R002 BUILT — Decision explorer surfaces premises, derivations and violations
| |
| WEBUI-DESIGN-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/7 (0%)7 openWEBUI-DESIGN-R001 BUILDING — Design guidance distilled into component system and skillsDS-01 SPECIFIED — Design tokens documented with contrast targetsDS-02 SPECIFIED — Controls have accessible names and visible focusDS-03 SPECIFIED — Responsive layout covers 320px mobile through desktopDS-04 SPECIFIED — Gesture actions have alternatives and respect reduced motionDS-05 SPECIFIED — Status states are distinguishable by text, not only colorDS-06 SPECIFIED — No duplicate primitives or unsolicited telemetry introduced
| |
| WEBUI-IDENTITY-001 | agent-webui | SPECIFIED | NOT AUDITED | 0/9 (0%)9 openIDUI-01 SPECIFIED — Identity mode wizard shows the active auth mode with no hidden bypassIDUI-02 SPECIFIED — Local account flows use server sessions with no stored credentialsIDUI-03 SPECIFIED — MFA enrollment and recovery cover TOTP and WebAuthnIDUI-04 SPECIFIED — Identity admin tabs cover users, roles, groups and mapping dry runIDUI-05 SPECIFIED — Elevation requests display scope, expiry and a bound receiptIDUI-06 SPECIFIED — Identity or tenant change invalidates cached protected dataIDUI-07 SPECIFIED — Identity forms and confirmations are accessible on desktop and mobileWEBUI-IDENTITY-R001 UNKNOWN — Release-qualification identity test client supports a live sign-in probeWEBUI-IDENTITY-R002 BUILT — Admin UI surfaces identity operations for users, roles and navigation
| |
| EMERALD-GUIDE-001 | emerald-exchange | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openEMERALD-GUIDE-R001 SPECIFIED — Leveraged trading guide across docs, skill, and explainer
| |
| EMERALD-MEDIA-001 | emerald-exchange | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openEMERALD-MEDIA-R001 SPECIFIED — Finance media intake into reviewable Emerald skills
| |
| EG-CONTRACT-001 | epistemic-graph | SPECIFIED | NOT AUDITED | 19/46 (41%)27 openEG-CONTRACT-R002 UNKNOWN — Served Agent Library test coverage for pack import and DecideEG-CONTRACT-R003 UNKNOWN — Privacy scan covers the relocated graph-backends documentationEG-CONTRACT-R005 UNKNOWN — One generated model per wire shape, with typed SPARQL decodeEG-CONTRACT-R006 UNKNOWN — Deterministic, size-budgeted WASM codec artifactEG-CONTRACT-R007 UNKNOWN — Dispatch decomposition test is current and runs in CIEG-CONTRACT-R008 UNKNOWN — Repo-parity check validates the resolved checkoutEG-CONTRACT-R009 UNKNOWN — Release workflow runs the full root Python test suiteEG-CONTRACT-R010 BUILT — Complexity gate scores exhaustive matches by arm body, not countEG-CONTRACT-R011 UNKNOWN — Parallel fan-out for the land gate across build hostsEG-CONTRACT-R012 UNKNOWN — Complexity scanner resolves modules declared in inline mod blocksEG-CONTRACT-R013 UNKNOWN — KISS config keys migrated to avoid a silently dropped sectionEG-CONTRACT-R014 SPECIFIED — Generated error catalog with stable auth-mismatch codesEG-CONTRACT-R015 BUILDING — Wheel ships the method, error and scope contract with callability flagsEG-CONTRACT-R016 UNKNOWN — Consumer-profile allowlist covers all generated PolicyEvolution sendersEG-CONTRACT-R017 BUILT — Dispatch census pins cover the current compiler-declared modulesEG-CONTRACT-R018 UNKNOWN — Release feature matrix includes the motif Cargo featureEG-CONTRACT-R019 BUILT — Dispatch reachability gate follows the current FOREIGN pathsEG-CONTRACT-R020 UNKNOWN — Topology test names avoid version-number suffixesEG-CONTRACT-R021 BUILT — Failed-connect test checks its own teardown, not process countsEG-CONTRACT-R022 SPECIFIED — Zero new duplicate-code pairs across the combined source treeEG-CONTRACT-R023 SPECIFIED — Pre-commit hooks pass clean without bypass flagsEG-CONTRACT-R024 UNKNOWN — Pre-commit and codespell configuration finalized and lockedEG-CONTRACT-R028 SPECIFIED — SQLite-format and speech-recognition differential tests run in CIEG-CONTRACT-R034 UNKNOWN — Complexity test derives its residual from the dispatch arm countEG-CONTRACT-R035 SPECIFIED — Release workflow executes end to end with all declared targetsEG-CONTRACT-R037 SPECIFIED — Clippy is warning-free across every release profileEG-CONTRACT-R043 UNKNOWN — Test fixtures carry no credential-shaped literals
| merged_head |
| EG-DECISION-ENGINE | epistemic-graph | SPECIFIED | NOT AUDITED | 51/125 (40%)74 openEG-DECISION-ENGINE-R001 UNKNOWN — Typed decision ladder with explicit resolution kindsEG-DECISION-ENGINE-R009 UNKNOWN — Learned ranking stays monotone with respect to safetyEG-DECISION-ENGINE-R010 UNKNOWN — Typed abstention reason for unmet capabilityEG-DECISION-ENGINE-R015 UNKNOWN — No generative model weights inside the decision engineEG-DECISION-ENGINE-R017 UNKNOWN — Single write authority per durable decision state kindEG-DECISION-ENGINE-R018 UNKNOWN — Unknown facts never default to zero in the solverEG-DECISION-ENGINE-R019 UNKNOWN — Decision commit re-derives and verifies before writingEG-DECISION-ENGINE-R029 UNKNOWN — Decision-based retrieval-plan selectionEG-DECISION-ENGINE-R030 UNKNOWN — Decision-based ingestion path routingEG-DECISION-ENGINE-R031 UNKNOWN — Expected-value scheduling for enrichment workEG-DECISION-ENGINE-R034 UNKNOWN — Proposal-only contradiction-handling suggestionsEG-DECISION-ENGINE-R035 UNKNOWN — Decision-based routing for execution configurationEG-DECISION-ENGINE-R036 UNKNOWN — graph.assemble() as the authority for agent compositionEG-DECISION-ENGINE-R037 UNKNOWN — Escalated abstentions re-enter as claimsEG-DECISION-ENGINE-R038 UNKNOWN — Advisory pre-tool risk scoringEG-DECISION-ENGINE-R039 UNKNOWN — Cost-aware routing using accounting dataEG-DECISION-ENGINE-R041 UNKNOWN — Connector event triage through DecideEG-DECISION-ENGINE-R042 UNKNOWN — Connector tool-choice advisory via DecideEG-DECISION-ENGINE-R043 UNKNOWN — Write-back proposals routed through DecideEG-DECISION-ENGINE-R044 UNKNOWN — A2A task routing through the decision ladderEG-DECISION-ENGINE-R045 UNKNOWN — Smallest covering tool subset within a context budgetEG-DECISION-ENGINE-R046 UNKNOWN — Swarm topology decisions via the decision ladderEG-DECISION-ENGINE-R047 UNKNOWN — DecisionRecord v1 contract: types and methodsEG-DECISION-ENGINE-R049 UNKNOWN — Exact 0-1 solver with certificate and verifierEG-DECISION-ENGINE-R056 UNKNOWN — Statistical-path release of the exact solverEG-DECISION-ENGINE-R058 UNKNOWN — Graph-sourced decision records with RLS-routed readsEG-DECISION-ENGINE-R059 UNKNOWN — Outcome aggregate with independent-evaluation joinEG-DECISION-ENGINE-R061 UNKNOWN — Assembly facts extended for the statistical pathEG-DECISION-ENGINE-R062 UNKNOWN — NlTemplate selection without a language modelEG-DECISION-ENGINE-R064 UNKNOWN — Optional read views of decision recordsEG-DECISION-ENGINE-R074 UNKNOWN — Agent-slot component-kind closure rule kept currentEG-DECISION-ENGINE-R075 UNKNOWN — Component-id uniqueness and forbidden decision kindsEG-DECISION-ENGINE-R076 UNKNOWN — Opt-in nested models for decision result markersEG-DECISION-ENGINE-R078 UNKNOWN — Contract freeze reissued with the decide featureEG-DECISION-ENGINE-R079 UNKNOWN — Per-unit embedding admission classifier for ingestionEG-DECISION-ENGINE-R080 UNKNOWN — Ingestion cost ladder with provenance rungsEG-DECISION-ENGINE-R081 UNKNOWN — Confidence-weighted community detection excluding similarity edgesEG-DECISION-ENGINE-R082 UNKNOWN — Single-pass option-marker scoring head for DecideEG-DECISION-ENGINE-R083 UNKNOWN — Options encode structured facts, not option-label textEG-DECISION-ENGINE-R084 UNKNOWN — Conformal calibration as primary rung over temperature scalingEG-DECISION-ENGINE-R085 UNKNOWN — Legal option sets are derived from the ontology, never received as-isEG-DECISION-ENGINE-R086 UNKNOWN — DecisionFit promotion protocol reports nine metricsEG-DECISION-ENGINE-R087 UNKNOWN — Scorer always receives a bounded shortlist, never a full catalogEG-DECISION-ENGINE-R088 UNKNOWN — Belief-as-of-t exposed as a Decide primitive over prefixesEG-DECISION-ENGINE-R089 UNKNOWN — Learned ranking never replaces the constraint-first decision ladderEG-DECISION-ENGINE-R090 UNKNOWN — Resident native decision-scorer head in eg-decisionEG-DECISION-ENGINE-R091 UNKNOWN — Resident scorer is bit-reproducible via fixed-point arithmeticEG-DECISION-ENGINE-R092 UNKNOWN — Scorer selection and structured encoding apply ladder-wideEG-DECISION-ENGINE-R093 UNKNOWN — Resident scorer is trained from the served synthetic-episode generatorEG-DECISION-ENGINE-R094 UNKNOWN — Decision scoring requires no GPU or model-server dependencyEG-DECISION-ENGINE-R098 SPECIFIED — Decide ladder excludes generative free-text models by designEG-DECISION-ENGINE-R100 UNKNOWN — Retrieval decisions join cited evidence with independent outcomesEG-DECISION-ENGINE-R101 UNKNOWN — Query-side embedding adapter head promoted via DecisionEvalEG-DECISION-ENGINE-R102 UNKNOWN — Schema repair proposals pass a decided mapping and shadow-branch checkEG-DECISION-ENGINE-R103 UNKNOWN — Calibrated per-horizon flip confidence with conformal abstentionEG-DECISION-ENGINE-R104 UNKNOWN — DecideText shares the UQL lexer and grammar familyEG-DECISION-ENGINE-R105 UNKNOWN — GraphSchema.attach publishes the swarm-topology ontologyEG-DECISION-ENGINE-R106 UNKNOWN — AgentGraph templates carry topology facts for standard shapesEG-DECISION-ENGINE-R107 UNKNOWN — Typed topology contract in eg-types with versioned goldensEG-DECISION-ENGINE-R108 UNKNOWN — Publish-time topology-shape validation fails closedEG-DECISION-ENGINE-R109 UNKNOWN — OWL entailment derives topology admissibility before assemblyEG-DECISION-ENGINE-R110 UNKNOWN — Topology optimization model rows with a brute-force oracleEG-DECISION-ENGINE-R111 UNKNOWN — Decide exposes the topology decision as a single typed questionEG-DECISION-ENGINE-R112 UNKNOWN — Capacity premise derives headroom observations by priorityEG-DECISION-ENGINE-R113 UNKNOWN — EG commits capacity acquisition atomically with synthesis evidenceEG-DECISION-ENGINE-R114 UNKNOWN — Subagent allowance negotiation reads EG's topology factsEG-DECISION-ENGINE-R115 UNKNOWN — Continuation decisions are evaluate-only and narrow-onlyEG-DECISION-ENGINE-R116 BUILDING — Consumers reach EG only through the versioned client contractEG-DECISION-ENGINE-R117 BUILDING — DERIVE series functions share one incremental kernelEG-DECISION-ENGINE-R118 BUILDING — Reputation view backs source reliability across all readersEG-DECISION-ENGINE-R119 SPECIFIED — Walk-forward replay seals deflated Sharpe and PBO evidenceEG-DECISION-ENGINE-R120 BUILT — Admission anchors are limited to persisted write pathsEG-DECISION-ENGINE-R122 UNKNOWN — Synthetic decision data stays separate from calibrationEG-DECISION-ENGINE-R125 UNKNOWN — Telemetry binds to ontology entities as BehaviourObservation
| |
| EG-DURABLE-KERNEL | epistemic-graph | SPECIFIED | NOT AUDITED | 29/69 (42%)40 openEG-DURABLE-KERNEL-R005 UNKNOWN — Outbox delivery state remains local to the owning nodeEG-DURABLE-KERNEL-R006 UNKNOWN — Engine startup does not block on one store's lazy openEG-DURABLE-KERNEL-R007 UNKNOWN — Host binary exposes a storage inspect and upgrade commandEG-DURABLE-KERNEL-R011 SPECIFIED — Clippy and targeted tests cover the full and all-features buildsEG-DURABLE-KERNEL-R014 UNKNOWN — Raft cluster tests pass reliably under loadEG-DURABLE-KERNEL-R015 UNKNOWN — Raft heartbeat flush and batch dispatch avoid head-of-line blockingEG-DURABLE-KERNEL-R017 UNKNOWN — Correctness-gated benchmark compares EG against HelixDBEG-DURABLE-KERNEL-R020 BUILT — Bounded background scrub detects node corruption between restartsEG-DURABLE-KERNEL-R021 BUILT — Store-authority binding validates once per write transactionEG-DURABLE-KERNEL-R022 UNKNOWN — Just-in-time RBAC elevation requires two-person approvalEG-DURABLE-KERNEL-R023 UNKNOWN — UQL enforces a read-only guarantee at compile time and by testEG-DURABLE-KERNEL-R024 BUILDING — External graph and database backends become EG federation sourcesEG-DURABLE-KERNEL-R025 UNKNOWN — Raft admin follows the current leader and traces are leader-agnosticEG-DURABLE-KERNEL-R026 SPECIFIED — Auth modes share one principal and RBAC evaluation pathEG-DURABLE-KERNEL-R027 UNKNOWN — Schema repair uses a reserved two-person approval leaseEG-DURABLE-KERNEL-R028 BUILT — WorkItem lifecycle test uses a consistent verified tenantEG-DURABLE-KERNEL-R029 BUILT — Universal read-RLS gate checks the current TsScan dispatch pathEG-DURABLE-KERNEL-R030 BUILT — Reserved RBAC elevation lease kind cannot be issued genericallyEG-DURABLE-KERNEL-R031 BUILDING — Audit append supports tenant-scoped idempotent reservationEG-DURABLE-KERNEL-R032 SPECIFIED — Native primary-key fast path bypasses the SQL plannerEG-DURABLE-KERNEL-R033 SPECIFIED — Hot-store engine choice is evaluated against captured workloadsEG-DURABLE-KERNEL-R034 SPECIFIED — Cross-store atomicity is proven and scoped to mixed transactionsEG-DURABLE-KERNEL-R035 SPECIFIED — PostgreSQL wire protocol reaches operational and dump/restore parityEG-DURABLE-KERNEL-R036 SPECIFIED — Mirror sinks reach fan-out parity and include Postgres table mirroringEG-DURABLE-KERNEL-R037 SPECIFIED — Workload classifier routes point operations around the SQL plannerEG-DURABLE-KERNEL-R038 SPECIFIED — KV namespaces declare an explicit, enforced durability classEG-DURABLE-KERNEL-R039 SPECIFIED — In-memory data structures rebuild from the redb durability logEG-DURABLE-KERNEL-R040 SPECIFIED — Pipelined requests commit as a single batchEG-DURABLE-KERNEL-R041 SPECIFIED — SQL plan cache keyed by statement digest and schema versionEG-DURABLE-KERNEL-R042 SPECIFIED — Benchmark gate defines and proves performance superiority claimsEG-DURABLE-KERNEL-R045 UNKNOWN — A single owner-manifest lineage check governs format upgradesEG-DURABLE-KERNEL-R052 UNKNOWN — Outbox delivery is organized by semantic class topicsEG-DURABLE-KERNEL-R057 UNKNOWN — Sealed record classes are protected by a create-only write guardEG-DURABLE-KERNEL-R058 UNKNOWN — Source-batch publication waiter cancellation is deterministicEG-DURABLE-KERNEL-R060 UNKNOWN — Unsupported legacy graph-data layouts are not silently migratedEG-DURABLE-KERNEL-R061 UNKNOWN — Test threading avoids unbounded channels and dead-time joinsEG-DURABLE-KERNEL-R063 UNKNOWN — Version-2 control-state rows are lifted losslessly on readEG-DURABLE-KERNEL-R064 UNKNOWN — Compiled shape memoization is benchmarked against parsing per writeEG-DURABLE-KERNEL-R068 UNKNOWN — Channel-group leave returns its own result, not a replayed join resultEG-DURABLE-KERNEL-R069 UNKNOWN — Scrub cursor fixture reliably tests the no-key encryption state
| |
| EG-FEDERATED-QUERY | epistemic-graph | SPECIFIED | NOT AUDITED | 8/71 (11%)63 openEG-FEDERATED-QUERY-R002 UNKNOWN — Rejection reasons stay out of the core kernel row schemaEG-FEDERATED-QUERY-R003 UNKNOWN — Derivation-step budget is enforced once, not duplicated per pathEG-FEDERATED-QUERY-R004 UNKNOWN — Reasoning projection rebuilds after any skipped eventEG-FEDERATED-QUERY-R006 UNKNOWN — Proof-carrying results for SPARQL and rule-derived queriesEG-FEDERATED-QUERY-R008 UNKNOWN — Edge-native text and vector search with stable identityEG-FEDERATED-QUERY-R009 UNKNOWN — Durable user-managed graph-index lifecycleEG-FEDERATED-QUERY-R012 UNKNOWN — Tableau honors AllDisjointClasses and core disjointness factsEG-FEDERATED-QUERY-R013 BUILT — Foreign-source resolution is scoped to the owning principalEG-FEDERATED-QUERY-R016 SPECIFIED — UQL AS OF uses Unix-second timestamps, not ISO datesEG-FEDERATED-QUERY-R017 UNKNOWN — Dependency tracking covers edge-type and embedding generationsEG-FEDERATED-QUERY-R018 UNKNOWN — Class-level volatility drives invalidation and cache freshnessEG-FEDERATED-QUERY-R019 UNKNOWN — Per-bar signal-state advancement with revisable trend recordsEG-FEDERATED-QUERY-R020 UNKNOWN — One query-text method surface, with the legacy method retiredEG-FEDERATED-QUERY-R021 UNKNOWN — Full UQL predicate algebra with SQL-consistent evaluationEG-FEDERATED-QUERY-R022 UNKNOWN — UQL source clauses are first-class, with typed empty-result casesEG-FEDERATED-QUERY-R023 UNKNOWN — Every query modality has a published UQL spellingEG-FEDERATED-QUERY-R024 UNKNOWN — Traversal syntax compiles to one canonical Expand encodingEG-FEDERATED-QUERY-R025 UNKNOWN — Typed parameter binding end-to-end through the Python clientEG-FEDERATED-QUERY-R026 UNKNOWN — UQL documentation is test-verified with an embedded grammarEG-FEDERATED-QUERY-R027 UNKNOWN — EXPLAIN, PROFILE and RETURN support multi-stage UQL programsEG-FEDERATED-QUERY-R028 UNKNOWN — KnowledgeSet is reachable from UQLEG-FEDERATED-QUERY-R029 UNKNOWN — UQL text from graph-exploration clients matches the grammarEG-FEDERATED-QUERY-R030 UNKNOWN — TSSCAN preserves per-series row identity and full precisionEG-FEDERATED-QUERY-R031 UNKNOWN — Contribution attribution kernels exposed through UQL ATTRIBUTEEG-FEDERATED-QUERY-R032 UNKNOWN — Probabilistic impact propagation with cone-scoped recomputationEG-FEDERATED-QUERY-R033 UNKNOWN — Barrier-hit and time-to-exhaustion derivations, one shared CDFEG-FEDERATED-QUERY-R034 UNKNOWN — Motif and discord search over time series, batch and streamingEG-FEDERATED-QUERY-R035 UNKNOWN — Filtered text search evaluates within the filtered candidate setEG-FEDERATED-QUERY-R036 UNKNOWN — Bounded, observable graph reopen after a restartEG-FEDERATED-QUERY-R037 BUILT — Rolling window statistics are both O(1) and numerically exactEG-FEDERATED-QUERY-R038 SPECIFIED — Federation optimizer: cost-aware pushdown, freshness-aware cacheEG-FEDERATED-QUERY-R039 UNKNOWN — Mixed traversal and vector queries return k or a typed shortfallEG-FEDERATED-QUERY-R040 UNKNOWN — Filter-aware index scans for filtered vector and text searchEG-FEDERATED-QUERY-R041 BUILT — Federation optimizer core drives pushdown decisions for every queryEG-FEDERATED-QUERY-R042 BUILT — OBDA pushes per-predicate scans and semi-join reduction to SQL sourcesEG-FEDERATED-QUERY-R043 BUILT — SQL foreign-source connections share the one outbound SSRF guardEG-FEDERATED-QUERY-R044 BUILDING — UQL EXPLAIN and PROFILE surface federation trace and budget hintsEG-FEDERATED-QUERY-R045 BUILDING — Foreign rows carry typed columns for filter and projection pushdownEG-FEDERATED-QUERY-R046 BUILDING — OBDA pushes SPARQL LIMIT, ORDER, aggregates and same-source joinsEG-FEDERATED-QUERY-R047 BUILDING — Federation enforces per-source parallelism caps and rate limitsEG-FEDERATED-QUERY-R048 SPECIFIED — Join ordering across foreign sources uses learned, provenanced statisticsEG-FEDERATED-QUERY-R049 BUILDING — Foreign query fragment cache is freshness-aware and owner-saltedEG-FEDERATED-QUERY-R050 SPECIFIED — SPARQL SERVICE uses bind joins and pushes FILTER/LIMITEG-FEDERATED-QUERY-R051 BUILDING — Iceberg scans prune manifests using the final pushed predicatesEG-FEDERATED-QUERY-R052 BUILDING — RemoteEngine sources receive pushed key filters and bounded LIMITEG-FEDERATED-QUERY-R053 BUILDING — Trino, Cypher and Spark sources are typed ForeignSourceSpec kindsEG-FEDERATED-QUERY-R054 BUILDING — SPARQL SERVICE and peer federation share the one outbound SSRF guardEG-FEDERATED-QUERY-R055 BUILT — SPARQL evaluation binds every value of a multi-valued propertyEG-FEDERATED-QUERY-R056 BUILT — Causal-impact p-values reuse the shared numeric tail functionsEG-FEDERATED-QUERY-R057 BUILDING — SQL provider module stays within the repository's file-size limitEG-FEDERATED-QUERY-R058 UNKNOWN — Natural language produces only a previewed, reviewed UQL candidateEG-FEDERATED-QUERY-R059 BUILDING — Semantic index lifecycle is fenced, durable and restart-safeEG-FEDERATED-QUERY-R061 UNKNOWN — One grammar table drives UQL docs, prompts and error messagesEG-FEDERATED-QUERY-R062 BUILT — Streaming memory test measures only its own allocationsEG-FEDERATED-QUERY-R063 UNKNOWN — Leiden provides stable community naming and a connectivity checkEG-FEDERATED-QUERY-R064 UNKNOWN — UQL lexer supports its full token set and structured diagnosticsEG-FEDERATED-QUERY-R065 UNKNOWN — Named UQL sub-plans compile to an ordered plan DAGEG-FEDERATED-QUERY-R066 BUILT — SPARQL evaluator is split into modules within the file-size limitEG-FEDERATED-QUERY-R067 UNKNOWN — UQL RETURN exposes multiple named score channels per rowEG-FEDERATED-QUERY-R068 UNKNOWN — UQL supports WITH PROOF for proof-carrying resultsEG-FEDERATED-QUERY-R069 BUILT — SQL pushdown batches key lookups and shares rendering with OBDAEG-FEDERATED-QUERY-R070 UNKNOWN — UQL execution budgets are enforced and reported in EXPLAIN/PROFILEEG-FEDERATED-QUERY-R071 BUILT — HTTP foreign sources support templated pagination and key placeholders
| |
| EG-FINANCE-PRIMITIVES | epistemic-graph | SPECIFIED | NOT AUDITED | 0/17 (0%)17 openEG-FINANCE-PRIMITIVES-R001 BUILT — Cross-host BacktestRun digest and Pine parity for finance-coreEG-FINANCE-PRIMITIVES-R002 BUILDING — Rehome generic finance evaluation kernels into eg-numericEG-FINANCE-PRIMITIVES-R003 BUILDING — Compute PBO from a BacktestRun's own CSCV splitsEG-FINANCE-PRIMITIVES-R004 SPECIFIED — finance-v1 asset, account, and strategy record typesEG-FINANCE-PRIMITIVES-R005 SPECIFIED — Deterministic fixed-point portfolio accountingEG-FINANCE-PRIMITIVES-R006 SPECIFIED — Point-in-time corporate actions and exchange session calendarsEG-FINANCE-PRIMITIVES-R007 SPECIFIED — Versioned StrategySpec evaluator with DCA, trend, rebalancingEG-FINANCE-PRIMITIVES-R008 SPECIFIED — Strategy backtests sealed through BacktestRunEG-FINANCE-PRIMITIVES-R009 SPECIFIED — Calibrated abstaining recommendations with scorecardsEG-FINANCE-PRIMITIVES-R010 SPECIFIED — Leverage risk module with margin, sizing, live-order boundaryEG-FINANCE-PRIMITIVES-R011 SPECIFIED — Finance alerts published through the finance outboxEG-FINANCE-PRIMITIVES-R012 SPECIFIED — Optional one-way Ghostfolio activity importEG-FINANCE-PRIMITIVES-R013 SPECIFIED — Golden accounting and risk fixtures with full provenanceEG-FINANCE-PRIMITIVES-R014 UNKNOWN — finance-v1 thin instrument and signal moduleEG-FINANCE-PRIMITIVES-R015 UNKNOWN — AnalysisSnapshot records with share.read control leasesEG-FINANCE-PRIMITIVES-R016 UNKNOWN — Incremental deterministic indicator kernels with Pine parityEG-FINANCE-PRIMITIVES-R017 UNKNOWN — BacktestRun provenance record with mandatory fields
| |
| EG-IDENTITY-001 | epistemic-graph | SPECIFIED | NOT AUDITED | 0/5 (0%)5 openEG-IDENTITY-R001 UNKNOWN — Multi-issuer OIDC trust list with per-issuer kind limitsEG-IDENTITY-R002 UNKNOWN — Identity and RBAC writes recompute roles and audit atomicallyEG-IDENTITY-R003 UNKNOWN — Identity mode is a durable singleton with CAS transitionEG-IDENTITY-R004 UNKNOWN — Generated scope registry classifies every capability scopeEG-IDENTITY-R005 UNKNOWN — Semantic workers use one identity across queue classes
| |
| EG-REPO-INGEST | epistemic-graph | SPECIFIED | NOT AUDITED | 2/11 (18%)9 openEG-REPO-INGEST-R001 UNKNOWN — Reconcile mode re-admits stranded semantic intentsEG-REPO-INGEST-R002 BUILDING — SourceIngest is sole owner of migrated ingestion capabilitiesEG-REPO-INGEST-R003 SPECIFIED — EG is sole home for remaining migrated ingestion modulesEG-REPO-INGEST-R004 BUILT — Derived series maintained incrementally with lineageEG-REPO-INGEST-R005 UNKNOWN — Replay-protection nonces commit in batches for throughputEG-REPO-INGEST-R006 BUILDING — Native ingestion commits fast; heavy enrichment deferredEG-REPO-INGEST-R007 BUILDING — Large ingestion batches refuse atomically with a stable codeEG-REPO-INGEST-R008 SPECIFIED — Oversized batches return a stable code for retryEG-REPO-INGEST-R009 BUILDING — Repository hydration links into the specification bridge
| |
| EG-TYPED-PACKS | epistemic-graph | SPECIFIED | NOT AUDITED | 27/96 (28%)69 openEG-TYPED-PACKS-R003 UNKNOWN — Import boundary enforces archive integrity, importer binding and G1-G21EG-TYPED-PACKS-R009 UNKNOWN — Projection readiness gates reader visibilityEG-TYPED-PACKS-R010 UNKNOWN — Import is a single atomic operation, not a staged protocolEG-TYPED-PACKS-R011 UNKNOWN — Incompatible Agent Library storage is refused, not upgradedEG-TYPED-PACKS-R012 UNKNOWN — Pack and agent-layer write methods are local-only in clustered modeEG-TYPED-PACKS-R013 UNKNOWN — Capability IRI validation distinguishes native errors from claimsEG-TYPED-PACKS-R014 UNKNOWN — Absent entries become reversible Withdrawn, not retiredEG-TYPED-PACKS-R015 UNKNOWN — Importer authority is admin-bound, with environment value as bootstrap onlyEG-TYPED-PACKS-R016 UNKNOWN — Server pin follows declared contract, not package versionEG-TYPED-PACKS-R017 UNKNOWN — Release scope excludes an offline Agent Library upgrade pathEG-TYPED-PACKS-R018 UNKNOWN — Body reads use AgentComponent.Content, not a pack-specific methodEG-TYPED-PACKS-R020 UNKNOWN — A tenant-profile administrative capability defect is out of EG scopeEG-TYPED-PACKS-R021 UNKNOWN — Cross-cutting import-safety defects are release-gate obligationsEG-TYPED-PACKS-R022 UNKNOWN — Pack index well-formedness validationEG-TYPED-PACKS-R023 UNKNOWN — Pack size bounds across index, entries, archive and bodyEG-TYPED-PACKS-R024 UNKNOWN — Archive presence, length and digest integrityEG-TYPED-PACKS-R025 UNKNOWN — Archive section layout and offset correctnessEG-TYPED-PACKS-R026 UNKNOWN — Section, entry and pack digest recomputationEG-TYPED-PACKS-R027 UNKNOWN — Text body UTF-8 validity without a byte-order markEG-TYPED-PACKS-R030 UNKNOWN — Tool entries require an input schemaEG-TYPED-PACKS-R031 UNKNOWN — Empty description falls back to the entry nameEG-TYPED-PACKS-R032 UNKNOWN — Capability, cost, latency and model annotation validationEG-TYPED-PACKS-R034 UNKNOWN — Shape blank-node scoping and SPARQL-backed constraint rejectionEG-TYPED-PACKS-R035 UNKNOWN — Step-bounded SHACL cross-validation against the ontologyEG-TYPED-PACKS-R036 UNKNOWN — Sibling reference resolution without cyclesEG-TYPED-PACKS-R038 UNKNOWN — Import requires a matching bound importer identityEG-TYPED-PACKS-R039 UNKNOWN — Mass-withdrawal guard requires an explicit admin overrideEG-TYPED-PACKS-R040 UNKNOWN — Validation stops at a bounded violation countEG-TYPED-PACKS-R043 UNKNOWN — Modality annotations on pack entriesEG-TYPED-PACKS-R044 UNKNOWN — EG-computed tool schema digestsEG-TYPED-PACKS-R045 UNKNOWN — MCP ToolAnnotations hints captured as pack factsEG-TYPED-PACKS-R046 UNKNOWN — Cost annotation on pack entriesEG-TYPED-PACKS-R047 UNKNOWN — Latency annotation on pack entriesEG-TYPED-PACKS-R048 UNKNOWN — ModelProfile cost, latency, modality and capability factsEG-TYPED-PACKS-R049 UNKNOWN — contract_pin is carried as an opaque SDK claimEG-TYPED-PACKS-R050 UNKNOWN — Per-entry contract_version replaces package-version pinningEG-TYPED-PACKS-R051 UNKNOWN — Composable per-graph schema source setsEG-TYPED-PACKS-R052 UNKNOWN — No pack-specific stand-in for pending schema authorityEG-TYPED-PACKS-R053 UNKNOWN — Visible-staleness snapshot for non-pack schema attachEG-TYPED-PACKS-R054 UNKNOWN — One topic per Agent Library outbox consumerEG-TYPED-PACKS-R055 UNKNOWN — Outbox retry never collateral dead-letters unrelated eventsEG-TYPED-PACKS-R057 UNKNOWN — Ontology withdrawal removes a whole source, not per-tripleEG-TYPED-PACKS-R058 UNKNOWN — One shared derivation-step budget bounds EL+/RL reasoningEG-TYPED-PACKS-R059 UNKNOWN — Schema attach validates only newly introduced dataEG-TYPED-PACKS-R060 UNKNOWN — Manifest-read refusal precedes dependent import pathsEG-TYPED-PACKS-R062 UNKNOWN — GraphSchema replicates through the existing GraphState routeEG-TYPED-PACKS-R063 UNKNOWN — Agent-layer row types affected by a schema bump are enumeratedEG-TYPED-PACKS-R064 UNKNOWN — Output-schema digest recorded on tool pinsEG-TYPED-PACKS-R065 UNKNOWN — EG does not recompute the SDK's contract-pin normalizationEG-TYPED-PACKS-R066 UNKNOWN — OWL/rule classification over model and capability factsEG-TYPED-PACKS-R067 UNKNOWN — Coordinated contract regeneration for new library methodsEG-TYPED-PACKS-R071 UNKNOWN — Generated core ontology corpus as GraphSchema authorityEG-TYPED-PACKS-R073 UNKNOWN — Raise the core schema source bound to 64 and split world_modelEG-TYPED-PACKS-R074 UNKNOWN — Least-privilege, per-pack projection grant with recorded failureEG-TYPED-PACKS-R077 UNKNOWN — GraphSchemaClasses exposes canonical class and property namesEG-TYPED-PACKS-R078 UNKNOWN — Proven retrieval plan templates keyed by task class and digestEG-TYPED-PACKS-R079 UNKNOWN — Typed OHLCV bar-series contractEG-TYPED-PACKS-R080 UNKNOWN — Exhaustive OpKind/PredKind printer and parser contractEG-TYPED-PACKS-R081 SPECIFIED — Ontology object model migrated into EG's kg/ontology packageEG-TYPED-PACKS-R082 BUILDING — EG-generated types replace hand-written graph-schema DTOsEG-TYPED-PACKS-R083 UNKNOWN — Schema-drift SHACL rendering and contract store move into EGEG-TYPED-PACKS-R084 UNKNOWN — Request deadlines propagate into long-running pack operationsEG-TYPED-PACKS-R085 UNKNOWN — Identity domain operations with Argon2id and redacted viewsEG-TYPED-PACKS-R086 BUILT — Planted derivation-budget and malformed-path cases are refusedEG-TYPED-PACKS-R087 UNKNOWN — Stable error codes for auth-boundary refusalsEG-TYPED-PACKS-R088 BUILDING — Embedded engine enforces graph-level access controlEG-TYPED-PACKS-R090 UNKNOWN — Canonical ontology and SHACL artifacts generated from RustEG-TYPED-PACKS-R093 UNKNOWN — Turtle parser blank-node identities do not collideEG-TYPED-PACKS-R096 UNKNOWN — Connector-pack reprojection with bounded, isolated aggregates
| |
| EG-UNIFIED-DATA-PLANE | epistemic-graph | SPECIFIED | NOT AUDITED | 1/36 (2%)35 openEG-UNIFIED-DATA-PLANE-R001 SPECIFIED — Record attached-source and native-hosting architecture decisionsEG-UNIFIED-DATA-PLANE-R002 SPECIFIED — Unify attached-source registration into one owner-scoped registryEG-UNIFIED-DATA-PLANE-R003 SPECIFIED — Extract typed, hashed catalog graphs per dialectEG-UNIFIED-DATA-PLANE-R004 SPECIFIED — Infer schema structure deterministically from attached catalogsEG-UNIFIED-DATA-PLANE-R005 SPECIFIED — Compile approved relational mappings to named R2RML virtual graphsEG-UNIFIED-DATA-PLANE-R006 SPECIFIED — Push down virtual-graph queries to source SQLEG-UNIFIED-DATA-PLANE-R007 SPECIFIED — Federate attached tables as DataFusion table providersEG-UNIFIED-DATA-PLANE-R008 SPECIFIED — Normalize change capture into a durable, replayable frameworkEG-UNIFIED-DATA-PLANE-R009 SPECIFIED — Drive consumers from change capture idempotentlyEG-UNIFIED-DATA-PLANE-R010 SPECIFIED — Maintain an accelerated local copy of attached dataEG-UNIFIED-DATA-PLANE-R011 SPECIFIED — Route queries by freshness across native, live, and accelerated pathsEG-UNIFIED-DATA-PLANE-R012 SPECIFIED — Govern write-back to attached sourcesEG-UNIFIED-DATA-PLANE-R013 SPECIFIED — Implement the Postgres attached-source adapterEG-UNIFIED-DATA-PLANE-R014 SPECIFIED — Implement the MySQL and MariaDB attached-source adaptersEG-UNIFIED-DATA-PLANE-R015 SPECIFIED — Implement the SQLite file attached-source adapterEG-UNIFIED-DATA-PLANE-R016 SPECIFIED — Implement the Microsoft SQL Server attached-source adapterEG-UNIFIED-DATA-PLANE-R017 SPECIFIED — Implement the ClickHouse attached-source adapterEG-UNIFIED-DATA-PLANE-R018 SPECIFIED — Implement the Oracle and Db2 attached-source adaptersEG-UNIFIED-DATA-PLANE-R019 SPECIFIED — Implement the MongoDB and DocumentDB attached-source adapterEG-UNIFIED-DATA-PLANE-R020 SPECIFIED — Federate Snowflake, BigQuery, DuckDB, and Iceberg sourcesEG-UNIFIED-DATA-PLANE-R021 SPECIFIED — Bridge Debezium Kafka events into ChangeEnvelopeEG-UNIFIED-DATA-PLANE-R022 SPECIFIED — Build a per-dialect conformance harnessEG-UNIFIED-DATA-PLANE-R023 SPECIFIED — Operate a shared CloudNativePG and MariaDB platformEG-UNIFIED-DATA-PLANE-R024 SPECIFIED — Admit applications to the shared platform with rollbackEG-UNIFIED-DATA-PLANE-R025 SPECIFIED — Evaluate a pgrx companion extension through a spikeEG-UNIFIED-DATA-PLANE-R026 SPECIFIED — Run the Gramps native-hosting pilot phases P0 through P5EG-UNIFIED-DATA-PLANE-R027 SPECIFIED — Fix Postgres compatibility gaps proven by captured trafficEG-UNIFIED-DATA-PLANE-R028 SPECIFIED — Build the Postgres-equivalence differential harnessEG-UNIFIED-DATA-PLANE-R029 SPECIFIED — Expose a schema_context query surfaceEG-UNIFIED-DATA-PLANE-R030 SPECIFIED — Resolve entities across attached applicationsEG-UNIFIED-DATA-PLANE-R031 SPECIFIED — Enforce consolidation safety across attached applicationsEG-UNIFIED-DATA-PLANE-R032 SPECIFIED — Run the Immich connector pilot phases I0 through I6EG-UNIFIED-DATA-PLANE-R033 SPECIFIED — Cut over Gramps to EG-backed storage in productionEG-UNIFIED-DATA-PLANE-R035 UNKNOWN — Share the compiled ontology cache with attached-schema graphsEG-UNIFIED-DATA-PLANE-R036 UNKNOWN — Derive HealthAnomaly and Incident facts with conformance checking
| |
| GRAPHOS-A2A-001 | graph-os | SPECIFIED | NOT AUDITED | 0/8 (0%)8 openGRAPHOS-A2A-R001 SPECIFIED — A2A facade over the engine and agent servicesGRAPHOS-A2A-R002 UNKNOWN — Inbound task routing with caller-filtered tool exposureGRAPHOS-A2A-R003 UNKNOWN — No duplicate skill or prompt harvesting in the multiplexerGRAPHOS-A2A-R004 UNKNOWN — Served MCP bridge runs FastMCP 4, matching its declared versionGRAPHOS-A2A-R005 BUILDING — Durable, fail-closed A2A approval exchange for tool callsGRAPHOS-A2A-R006 SPECIFIED — Operation invoke and plan-confirm methods for A2AGRAPHOS-A2A-R007 BUILDING — Pre-effect audit reservation for every governed writeGRAPHOS-A2A-R008 BUILDING — First-party A2A facade, not a vendored wrapper
| |
| GRAPHOS-CAPACITY-001 | graph-os | SPECIFIED | NOT AUDITED | 0/2 (0%)2 openGRAPHOS-CAPACITY-R001 UNKNOWN — AIMD error-budget throttling that only narrows automaticallyGRAPHOS-CAPACITY-R002 BUILDING — Capacity status and mode operations
| |
| GRAPHOS-DATA-MARKET-001 | graph-os | SPECIFIED | NOT AUDITED | 0/6 (0%)6 openGRAPHOS-DATA-MARKET-R001 BUILT — Durable, deduplicated flip alert deliveryGRAPHOS-DATA-MARKET-R002 BUILT — Scheduled finance backfill, scan, and explanation jobsGRAPHOS-DATA-MARKET-R003 BUILDING — Server-side finance and markets reads and paper order submissionGRAPHOS-DATA-MARKET-R004 SPECIFIED — One-at-a-time application admission with rollbackGRAPHOS-DATA-MARKET-R005 SPECIFIED — schema_context query surface for tables and ontology mappingsGRAPHOS-DATA-MARKET-R006 SPECIFIED — Recurring DCA plans with deterministic, non-duplicating proposals
| |
| GRAPHOS-DEPLOY-001 | graph-os | SPECIFIED | NOT AUDITED | 0/15 (0%)15 openGRAPHOS-DEPLOY-R001 UNKNOWN — Worker topology manifest is digest-pinnedGRAPHOS-DEPLOY-R002 UNKNOWN — Executable release-qualification runbookGRAPHOS-DEPLOY-R003 UNKNOWN — Pre-push hooks always run the full gate suiteGRAPHOS-DEPLOY-R004 BUILT — mypy hook type-checks the test suiteGRAPHOS-DEPLOY-R005 BUILT — Web UI rename cutover across GraphOSGRAPHOS-DEPLOY-R006 SPECIFIED — gateway-widgets extra pins a compatible connector floorGRAPHOS-DEPLOY-R007 SPECIFIED — GraphOS hosts deployment doctor and skill certificationGRAPHOS-DEPLOY-R008 SPECIFIED — GraphOS hosts its own boundary modulesGRAPHOS-DEPLOY-R009 SPECIFIED — GraphOS owns hosting/deployment configuration settingsGRAPHOS-DEPLOY-R010 UNKNOWN — Ecosystem and repository development skills are publishedGRAPHOS-DEPLOY-R011 UNKNOWN — Deployment layout test suite passes in fullGRAPHOS-DEPLOY-R012 BUILT — Pipelines dependency is referenced at main, never pinnedGRAPHOS-DEPLOY-R013 BUILT — Development and production deployment profilesGRAPHOS-DEPLOY-R014 UNKNOWN — Agent runtime split into connector SDK, GraphOS and engineGRAPHOS-DEPLOY-R015 UNKNOWN — AVX2 guard test runs on any hosted runner
| |
| GRAPHOS-FLEET-001 | graph-os | SPECIFIED | NOT AUDITED | 0/24 (0%)24 openGRAPHOS-FLEET-R001 BUILDING — Typed pack publisher replaces placeholder ContentPackGRAPHOS-FLEET-R002 SPECIFIED — Tool schema fingerprints recomputed from served schemasGRAPHOS-FLEET-R003 BUILDING — D18 write-back exposed only as a typed, previewed operationGRAPHOS-FLEET-R004 UNKNOWN — Pack annotations carry capability, digest, modality, cost, latencyGRAPHOS-FLEET-R005 UNKNOWN — A2A task routing with typed work-item and lease operationsGRAPHOS-FLEET-R006 UNKNOWN — Multiplexer skill and prompt harvest path removedGRAPHOS-FLEET-R007 UNKNOWN — Bridge upgraded to FastMCP 4GRAPHOS-FLEET-R008 UNKNOWN — RUM, security-audit and CI/CD feeds join the catalogGRAPHOS-FLEET-R009 UNKNOWN — Run admission evaluates, commits and publishes with capacity controlGRAPHOS-FLEET-R010 BUILT — Assembly result parsing reads the full agents listGRAPHOS-FLEET-R011 BUILT — Registry core computes a canonical digest and authorized findGRAPHOS-FLEET-R012 BUILT — EG-direct binding generator with reviewed exclusionsGRAPHOS-FLEET-R013 BUILDING — MCP projection exposes the six verbs with typed schemasGRAPHOS-FLEET-R014 BUILT — Resolver ranks catalog items with partitioned feedbackGRAPHOS-FLEET-R015 BUILDING — Typed operations cover agents, browser and fleet callsGRAPHOS-FLEET-R016 BUILDING — Automated gates catch API surface and compatibility driftGRAPHOS-FLEET-R017 BUILDING — Authority-parity oracle validates principal, operation and surfaceGRAPHOS-FLEET-R018 BUILDING — Multiplexer exposes four resident fleet tools over one catalogGRAPHOS-FLEET-R019 SPECIFIED — Eunomia narrows authority at discover, load and callGRAPHOS-FLEET-R020 SPECIFIED — Multiplexer meta-tools register as the four resident toolsGRAPHOS-FLEET-R021 BUILT — Fleet capability checks require exact scopes, deny unknown toolsGRAPHOS-FLEET-R022 BUILDING — Catalog reconciliation re-ingests via durable replayPA-12 SPECIFIED — Catalog reload rejects invalid candidates, proves replica convergenceGRAPHOS-FLEET-R023 UNKNOWN — Connector count pins stay consistent across the fleet
| |
| GRAPHOS-HOST-001 | graph-os | SPECIFIED | NOT AUDITED | 1/16 (6%)15 openGRAPHOS-HOST-R001 SPECIFIED — Cross-repository composition boundary assignmentGRAPHOS-HOST-R002 UNKNOWN — Graph engine client exposes the session/discovery surfaceGRAPHOS-HOST-R003 BUILT — Web UI rename cutover across GraphOSGRAPHOS-HOST-R004 BUILDING — Single gateway implementation under graph_os/gatewayGRAPHOS-HOST-R005 SPECIFIED — graph_os.mcp_server.runtime serves retired MCP actionsGRAPHOS-HOST-R006 SPECIFIED — graph_os.fleet is the sole multiplexer and host ownerGRAPHOS-HOST-R007 SPECIFIED — Agent runtime imported only through its public APIGRAPHOS-HOST-R008 SPECIFIED — GraphOS hosts its own boundary modulesGRAPHOS-HOST-R009 BUILDING — GraphOS hosts the agent HTTP server and A2A/ACP endpointsGRAPHOS-HOST-R010 SPECIFIED — GraphOS owns hosting/deployment configuration settingsGRAPHOS-HOST-R011 BUILDING — GraphOS serves the messaging channel and routing layerGRAPHOS-HOST-R012 SPECIFIED — Component registry carries GraphOS and SDK boundary entriesGRAPHOS-HOST-R013 SPECIFIED — Front ends import only public GraphOS/agent-runtime surfacesGRAPHOS-HOST-R014 UNKNOWN — Agent runtime split into connector SDK, GraphOS and engineGRAPHOS-HOST-R015 SPECIFIED — Layered agent capability model with a harness abstraction
| |
| GRAPHOS-IDENTITY-001 | graph-os | SPECIFIED | NOT AUDITED | 0/24 (0%)24 openGRAPHOS-IDENTITY-R001 BUILT — Elevation request, approve, and revoke surfacesGRAPHOS-IDENTITY-R002 UNKNOWN — Domain scopes consume the generated scope registryGRAPHOS-IDENTITY-R003 BUILDING — Persistent local token issuer with secret-backed keyGRAPHOS-IDENTITY-R004 UNKNOWN — Loopback bootstrap principal with origin guardingGRAPHOS-IDENTITY-R005 UNKNOWN — Local account lifecycle with server-side sessionsGRAPHOS-IDENTITY-R006 BUILDING — Optional MFA with TOTP, WebAuthn, and recovery codesGRAPHOS-IDENTITY-R007 UNKNOWN — Admin console tabs with mapping dry-run and mode wizardGRAPHOS-IDENTITY-R008 UNKNOWN — API keys and service accounts replace static MCP tokensGRAPHOS-IDENTITY-R009 UNKNOWN — Multi-provider OIDC with mapping rules and JIT policyGRAPHOS-IDENTITY-R010 UNKNOWN — LDAPS bind with nested group syncGRAPHOS-IDENTITY-R011 UNKNOWN — SCIM 2.0 provisioning serverGRAPHOS-IDENTITY-R012 UNKNOWN — SAML sign-in brokered through an OIDC providerGRAPHOS-IDENTITY-R013 UNKNOWN — Identity CLI commands and doctor diagnosticsGRAPHOS-IDENTITY-R014 BUILDING — Shared RBAC decision oracle across identity modesGRAPHOS-IDENTITY-R015 BUILT — Identity operations documentation and cutover runbookGRAPHOS-IDENTITY-R016 UNKNOWN — Optional SMTP adapter for identity emailGRAPHOS-IDENTITY-R017 SPECIFIED — Remove the unauthenticated opt-out once clients migrateGRAPHOS-IDENTITY-R018 BUILDING — Identity administration operations for self, admin, configGRAPHOS-IDENTITY-R019 BUILDING — Access operations for elevation and approval decisionsGRAPHOS-IDENTITY-R020 BUILDING — Domain scope registry covers finance, fleet, loops, opsGRAPHOS-IDENTITY-R021 BUILDING — Identity wiring depends only on identity portsGRAPHOS-IDENTITY-R022 BUILT — Fleet authorization fails closed on exact scopesGRAPHOS-IDENTITY-R023 SPECIFIED — Native, self-refreshing credentials for MCP clientsGRAPHOS-IDENTITY-R024 SPECIFIED — Committed browser and Keycloak SSO probe
| |
| GRAPHOS-INGRESS-001 | graph-os | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openGRAPHOS-INGRESS-R001 SPECIFIED — Public ingress rename with Keycloak and OpenBao cutover
| |
| GRAPHOS-OPS-001 | graph-os | SPECIFIED | NOT AUDITED | 0/38 (0%)38 openGRAPHOS-OPS-R001 SPECIFIED — Native MCP/REST facade with A2A unary operations then streamingGRAPHOS-OPS-R002 UNKNOWN — Scoped A2A task routing and fleet tool exposureGRAPHOS-OPS-R003 UNKNOWN — Remove multiplexer skill/prompt harvest pathGRAPHOS-OPS-R004 UNKNOWN — FastMCP 4 bridge for the MCP serverGRAPHOS-OPS-R005 SPECIFIED — Stable auth error codes from the engine contractGRAPHOS-OPS-R006 SPECIFIED — Consume the engine's packaged wire-callable contractGRAPHOS-OPS-R007 BUILT — Immutable operation registry with digest and authorizationGRAPHOS-OPS-R008 BUILT — Generated engine-bound operations with exclusionsGRAPHOS-OPS-R009 BUILT — Single invoke pipeline for authority, effect, and auditGRAPHOS-OPS-R010 BUILDING — Closed error enum and one response envelopeGRAPHOS-OPS-R011 BUILDING — Six resident MCP verbs with typed discoveryGRAPHOS-OPS-R012 BUILT — Bounded resolver for natural-language operation lookupGRAPHOS-OPS-R013 BUILT — Generated HTTP API for every registry operationGRAPHOS-OPS-R014 BUILDING — Identity self-service and admin operationsGRAPHOS-OPS-R015 BUILDING — Access elevation, approval, and lease operationsGRAPHOS-OPS-R016 BUILDING — Capacity status and throttle mode operationsGRAPHOS-OPS-R017 BUILDING — Finance and markets operations with tenant isolationGRAPHOS-OPS-R018 SPECIFIED — Query, search, ontology, and analytics operationsGRAPHOS-OPS-R019 BUILDING — Federation source registration and sharing operationsGRAPHOS-OPS-R020 BUILDING — Ingest operations through a typed SDK runner facadeGRAPHOS-OPS-R021 BUILDING — Decision, retrieval, and policy operationsGRAPHOS-OPS-R022 BUILDING — Work and evolution loop operationsGRAPHOS-OPS-R023 BUILDING — Agent, browser, RLM, and fleet call operationsGRAPHOS-OPS-R024 BUILDING — Telemetry, security, usage, and admin operationsGRAPHOS-OPS-R025 BUILDING — Generated registry, OpenAPI, and client artifactsGRAPHOS-OPS-R026 BUILDING — API surface and compatibility drift gatesGRAPHOS-OPS-R027 BUILDING — Authority-parity test across principals and surfacesGRAPHOS-OPS-R028 BUILDING — Exported domain scope classesGRAPHOS-OPS-R029 BUILDING — Single resident-tool server cutoverGRAPHOS-OPS-R030 BUILT — Accurate MCP server and API documentationGRAPHOS-OPS-R031 SPECIFIED — Published tool-to-operation parity inventoryGRAPHOS-OPS-R032 BUILDING — Identity dependency inversion via portsGRAPHOS-OPS-R033 BUILDING — Dynamic multiplexer discovery, load, and callGRAPHOS-OPS-R034 SPECIFIED — Eunomia narrowing-only policy enforcementGRAPHOS-OPS-R035 SPECIFIED — Multiplexer registration reduced to four resident toolsGRAPHOS-OPS-R036 BUILDING — Pre-dispatch audit reservation for governed effectsGRAPHOS-OPS-R037 BUILDING — Native first-party A2A facadeGRAPHOS-OPS-R038 UNKNOWN — Generated OpenAPI served through Swagger UI
| |
| GRAPHOS-RELEASE-001 | graph-os | SPECIFIED | NOT AUDITED | 0/3 (0%)3 openGRAPHOS-RELEASE-R001 SPECIFIED — Dependency-ordered, digest-verified release promotionGRAPHOS-RELEASE-R002 UNKNOWN — Local Kubernetes validation gates every pushGRAPHOS-RELEASE-R003 UNKNOWN — Exit-criteria matrix maps readiness to tests
| |
| PIPE-IDENTITY-001 | pipelines | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openPIPE-IDENTITY-R001 UNKNOWN — Commit author identity is restricted to an allowlist
| |
| PIPE-PAGES-001 | pipelines | SPECIFIED | NOT AUDITED | 2/11 (18%)9 openPIPE-PAGES-R001 SPECIFIED — Repository switcher kept in sync with the core repo listPIPE-PAGES-R002 UNKNOWN — Layered documentation from overview to referencePIPE-PAGES-R003 UNKNOWN — Present-tense docs with accessible embedded startPIPE-PAGES-R004 UNKNOWN — One progressively disclosed skill-graph corpusPIPE-PAGES-R005 UNKNOWN — Generate architecture and reference pages from registriesPIPE-PAGES-R006 UNKNOWN — Rehome generated docs out of the legacy docs directoryPIPE-PAGES-R008 UNKNOWN — Correct ownership and quick start in consumer parity checksPIPE-PAGES-R009 UNKNOWN — HTML/CSS architecture views, no ASCII or Mermaid diagramsPIPE-PAGES-R010 UNKNOWN — Generate API contract docs from the contract registry
| |
| PIPE-RELEASE-001 | pipelines | SPECIFIED | NOT AUDITED | 0/3 (0%)3 openPIPE-RELEASE-R001 SPECIFIED — Pipelines publishes images in dependency order with digest pinsPIPE-RELEASE-R002 UNKNOWN — Release tags point to the exact qualified commitPIPE-RELEASE-R003 UNKNOWN — Release build job sources environment values safely
| |
| RM-CONNECTOR-001 | repository-manager | SPECIFIED | NOT AUDITED | 0/6 (0%)6 openRM-CONNECTOR-R001 UNKNOWN — Migrate connector imports to the public SDK boundaryRM-CONNECTOR-01 SPECIFIED — Classify every import from the orchestration packageRM-CONNECTOR-02 SPECIFIED — Route connector transport imports through the public SDKRM-CONNECTOR-03 SPECIFIED — Keep governance imports under repository-manager authorityRM-CONNECTOR-04 SPECIFIED — Preserve MCP/CLI contract during connector migrationRM-CONNECTOR-05 SPECIFIED — Remove dead connector adapters after cutover
| |
| RM-GOVERNANCE-001 | repository-manager | SPECIFIED | NOT AUDITED | 0/29 (0%)29 openRM-GOVERNANCE-R001 BUILT — repository-manager hosts the Git development-governance modulesRM-GOVERNANCE-01 SPECIFIED — Single authority for Git development governanceRM-GOVERNANCE-02 SPECIFIED — Branch allocation tracks ownership, lease, and lifecycle stateRM-GOVERNANCE-03 SPECIFIED — Isolated checkouts never corrupt shared Git configRM-GOVERNANCE-04 SPECIFIED — Commits stage only reviewed paths and verified gate identityRM-GOVERNANCE-05 SPECIFIED — Merge-queue promotion rechecks identity before reporting successRM-GOVERNANCE-06 SPECIFIED — Cleanup proves containment before deleting a branch checkoutRM-GOVERNANCE-07 SPECIFIED — Concept reservations are scoped and cannot be silently reusedRM-GOVERNANCE-R002 UNKNOWN — readme-deploy-block hook must not silently skipRM-GOVERNANCE-R003 UNKNOWN — Cleanup removes isolated checkouts and scratch only after mergeRM-GOVERNANCE-R004 UNKNOWN — Workspace check refuses credential-embedded remote URLsRM-GOVERNANCE-R005 UNKNOWN — Complexity gate scores exhaustive-dispatch functions correctlyRM-GOVERNANCE-R006 UNKNOWN — Clone-duplication gate enforces zero new pairs before pushRM-GOVERNANCE-R007 UNKNOWN — Routine cleanup prunes merged branches and build cachesRM-GOVERNANCE-R008 UNKNOWN — KISS hook resolves test module path declarations correctlyRM-GOVERNANCE-R009 UNKNOWN — Duplication gate fails closed on an empty-change commitRM-GOVERNANCE-R010 UNKNOWN — Reviewed-distinct clone pairs are tracked in a registryRM-GOVERNANCE-R011 UNKNOWN — Status page stays in sync with capability and reservation docsRM-GOVERNANCE-R012 UNKNOWN — Build verification on extracted trees uses content hashesRM-GOVERNANCE-R013 UNKNOWN — A fast rebase must not silently skip the hook suiteRM-GOVERNANCE-R014 UNKNOWN — Completion claims require full hook-run logs as proofRM-GOVERNANCE-R015 UNKNOWN — Continuous review-and-merge replaces batch integrationRM-GOVERNANCE-R016 UNKNOWN — Cleanup removes leftover backup references and build scratchRM-GOVERNANCE-R017 UNKNOWN — Build submission is asynchronous, not polling-basedRM-GOVERNANCE-R018 UNKNOWN — Dependency-readiness hook works from any checkout locationRM-GOVERNANCE-R019 UNKNOWN — A fix is accepted only when all quality gates pass togetherRM-GOVERNANCE-R020 UNKNOWN — Duplication gate distinguishes real new duplication from movesRM-GOVERNANCE-R021 UNKNOWN — Secret-history exceptions are digest-pinned and self-checkingRM-GOVERNANCE-R022 UNKNOWN — The repository passes its own full local gate suite
| |
| RM-IDENTITY-001 | repository-manager | SPECIFIED | NOT AUDITED | 0/9 (0%)9 openRM-IDENTITY-R001 SPECIFIED — Rewrite commit identities across public repositories with approval and rollbackRM-IDENTITY-01 SPECIFIED — Complete ref and tag discovery before rewriteRM-IDENTITY-02 SPECIFIED — Deterministic dry-run identity rewrite planRM-IDENTITY-03 SPECIFIED — Signed approval required before any rewriteRM-IDENTITY-04 SPECIFIED — Byte-identical trees and preserved history topologyRM-IDENTITY-05 SPECIFIED — Quarantined staging with backup refs before ref updateRM-IDENTITY-06 SPECIFIED — Lease-protected per-remote publication receiptsRM-IDENTITY-07 SPECIFIED — Coordinated merge-queue pause and resync during rewriteRM-IDENTITY-R002 UNKNOWN — Reconcile diverged history before identity rewrite
| |
| RM-MATERIALIZE-001 | repository-manager | SPECIFIED | NOT AUDITED | 0/7 (0%)7 openRM-MATERIALIZE-R001 UNKNOWN — Repository-manager materializes an approved proposal into a commitRM-MATERIALIZE-01 SPECIFIED — Approval verification gates every Git materialization requestRM-MATERIALIZE-02 SPECIFIED — Patch application is isolated and restricted to approved pathsRM-MATERIALIZE-03 SPECIFIED — Validation gates and explicit staging precede every commitRM-MATERIALIZE-04 SPECIFIED — Merge queue submission never claims landing before verificationRM-MATERIALIZE-05 SPECIFIED — An immutable receipt binds every materialization outcomeRM-MATERIALIZE-06 SPECIFIED — No caller has a direct Git fallback when the service is unavailable
| |
| RM-RELEASE-001 | repository-manager | SPECIFIED | NOT AUDITED | 0/7 (0%)7 openRM-RELEASE-R001 BUILDING — Dependency-ordered fleet release planningRM-RELEASE-01 SPECIFIED — Complete per-repository dependency censusRM-RELEASE-02 SPECIFIED — Acyclic, typed dependency graph per release scopeRM-RELEASE-03 SPECIFIED — Immutable, content-addressed release plan digestRM-RELEASE-04 SPECIFIED — Dependency-ordered execution with trusted gatingRM-RELEASE-05 SPECIFIED — One shared admission contract across release routesRM-RELEASE-06 SPECIFIED — Per-stage receipts with retry and rollback evidence
| |
| TM-INVENTORY-001 | tunnel-manager | SPECIFIED | NOT AUDITED | 0/1 (0%)1 openTM-INVENTORY-R001 SPECIFIED — One canonical host inventory path across surfaces
| |
| US-PAGES-001 | universal-skills | SPECIFIED | NOT AUDITED | 0/2 (0%)2 openUS-PAGES-001 SPECIFIED — Consolidate published documentationUS-PAGES-R001 UNKNOWN — Shared documentation hierarchy across the fleet's sites
| |