Capability, maturity, and evidence
These status labels are intentionally narrow:
- Released means the bytes exist in the current regular release.
- Locally validated means reproducible local evidence exists; it does not establish live-system or production fitness.
- Planned means design or roadmap only.
- External evidence required means the repository cannot prove the claim without a real provider, tenant, environment, or independent operation.
| Capability | Status | Evidence | Boundary |
|---|---|---|---|
| Governed synthetic CRM → ERP effect | Released / locally validated | CM-SEC-007 evidence and command, Quickstart | One pinned loopback flow with fictional records; no live integration or production claim |
| SAFE_GUIDED authority default | Released / locally validated | Closed proof manifest and negative probes | Declared local path only; no hostile-host or complete-mediation claim |
| Verification Fabric and Shadow planner | Released / locally validated | Verification Fabric guide, CM-REL-004 release binding | Deterministic contracts and Shadow planning; no production deployment proof |
| Update, migration, and Doctor contracts | Released / locally validated | Contract freeze guide, CM-REL-005 release binding | Six-axis immutable locks, compatibility, preview plans and read-only reports; no discovery, apply, migration, repair or owner-state mutation |
| Builder contracts | Released / locally validated | Builder guide, current-release byte binding, BLD-001 local PDCA source | Typed target-neutral planning and synthetic two-system reuse; no live-system builder, automatic adapter generator or production UI. The historical PDCA's pre-release status describes its dated checkpoint, while current release governance owns byte status. |
| Resource-plane profiles M0 | Released / locally validated | Resource-plane guide, CM-REL-012 release binding | Declarative plan for exactly seven closed planes with SAFE_GUIDED/CUSTOM/FULL_CONTROL diff only; no runtime activation, host authority change, resource access or production claim |
| ADD → REPLACE adaptability benchmark M0 | Released / locally validated | Benchmark, method and measured record, CM-REL-013 release binding | Two local in-process synthetic contracts reuse one unchanged Builder core and consumer; AI-blind input is prepared but not run. No live-provider, universal-adaptability, engineering-time or speed claim |
| Extension assurance profiles | Released / locally validated | Assurance profile guide, CM-REL-014 release binding | Closed local-synthetic evidence assessment with eight hard-fail gates and private security routing; no scan, badge, acceptance, installation, activation, authority, certification or production claim |
| Minimized agent-work event contract | Released / locally validated | AWI-01 contract guide, CM-REL-015 release binding | Pseudonymous, digest-bound synthetic contract with consent, finite retention and payload-free tombstones; no collection, telemetry, training, dashboard, ingestion or production claim |
| Universal Knowledge Envelope | Locally validated / default-off synthetic slice | AWI-03 contract guide, CM-REL-021 evidence binding | Strict attributable envelopes, governed taxonomy generations, exact curated/exploratory selection and read-only explanation; no truth, production corpus/storage or authority claim |
| Local file knowledge corpus | Locally validated / not in current regular release | LKC-FILES-01 guide, Issue #54 PDCA source | Closed read-only UTF-8 Markdown/Text editions, exact line citations, lexical receipts and LKG rollback only; no PDF/OCR, Kiwix/Wikipedia, download, LLM, semantic-quality or production-capacity claim |
| External Video Service boundary | Released contract / optional external artifact | External video service contract, CM-REL-016 release binding | SHA-256-pinned external cm.video/v1 artifact readback only; no embedded production/Docker renderer, Docker ownership, upload, publication, worker activation or universal studio claim |
| Synthetic CPU video package reference | Released / locally validated synthetic slice | Bounded local reference, CM-REL-023 release binding | Linux-local strict contract/conformance and canonical package-index assembly over fixed PNG/PCM fixtures only; no playable/encoded video, production renderer, Docker hardening, codec, GPU, TTS, model, provider, network, publication, deployment, production media or external-artifact equivalence |
| ASF-INTAKE-2 signal release intake | Released / locally validated | CM-REL-017 release binding, contract | Pure nine-gate pre-candidate decision with stable rejections; no monitoring, posting, merge, release, deployment or runtime authority |
| ASF-01 Skill Bundle canonical contracts | Locally validated / not in current regular release | Skill Bundle contract guide, contract | Strict manifest, immutable lock tuple, exact-file verification and v1/OpenClaw compatibility fence only; no generator, live registry, installation, activation, marketplace release, auto-update or authority claim |
| INT-PROFILE-001 integration profiles | Released / locally validated | Integration profile guide, CM-REL-018 release binding | Five local-synthetic description variants and nine denial probes; no real tenant/provider/credential, connector activation, external write, production or universal-compatibility claim |
| CAP-CELL-ERP-01 ERP order provider replacement | Released / locally validated | Synthetic ERP order capability cell, current-release byte binding | Exactly two local-synthetic semantically compatible bindings for erp.order.create v1; no live ERP/provider, migration, arbitrary provider/accounting equivalence, external call, production or L4 claim |
| External KaleidoSphere service boundary v2 | Released contract / optional external subsystem | External BI service contract, CM-REL-022 release binding, 13 focused CM fail-closed probes and cross-repo clean-room runner | CM stores only the stable SBA URL boundary, exact v0.8.0/2.0.0 pins and timeout; KaleidoSphere alone owns BI logic/runtime. Direct Superset/database routes, credentials, SQL, raw rows and mutation intents are denied. |
| HMI/Harness multitool and contribution preflight | Released / locally validated | CM-REL-006 HMI/Harness release evidence, contribution-preflight PDCA | Authority-free local-synthetic generation, discover/explain and digest-bound preparation only; no submission, publication, external write, credential, route or production UI |
| Microsoft Entra identity profile | Released / external evidence required | CM-REL-007 Azure/Entra release evidence, identity PDCA | Closed single-tenant Authorization Code + PKCE contract using exactly cm.discovery.read; no live tenant, registration, consent, token validation or production identity proof |
| Power Platform five-read connector | Released / external evidence required | CM-REL-008 Power Platform release evidence, read-connector PDCA | Exactly five authority-free operations, all bound to cm.discovery.read; no import, live Gateway/tenant, consent, DLP, certification or production behavior. cm.operator.read remains a future separate administrative-read profile. |
| Arbitrary-system onboarding and writes | Planned | Connection blueprint | Not an executable path beyond the bundled synthetic fixture |
| Knowledge-driven Operating System | Current product category; broad live realization planned | Documentation scope, root architecture story | The category and released local-synthetic contract foundation are current; arbitrary live-system adaptation, autonomous outcome learning and production fitness remain planned/unproven |
The machine-readable release record is release/governance.json. The root README owns orientation; Security Assurance owns scoped security claims; Known Limitations owns current non-claims. The curated roadmap links planned work to live issues without making it a second maturity source.