Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

What ships today

What governs this page

This page is an inventory, not a promise. It answers one question — what is available right now, and on what evidence — and it answers it from a machine-readable source rather than from prose.

SourceWhat it decides for this page
The capability and evidence manifest (AAASM-5531), in the agent-assembly repositoryEvery row in every table below. Nothing inside a generated block is hand-written
ADR 0033 §6The eleven words for what the product did to an action. This page prints them and does not define them — Check a published claim names them and links their definitions
Product promiseThe approved wording, the default-posture table, and which term each mechanism reaches. This page does not restate any of the three
Source of truth & statusWhich repository owns an area of documentation, and how finished that area is

Ticket references on this page are plain text, not links: the tracker is not publicly readable, so a link would only reach a login wall — and a link checker scores that wall as reachable, which makes the reference look verified when it is not.

Every table below is generated from governance/capability-manifest.yaml in the ai-agent-assembly/agent-assembly repository — the capability and evidence manifest defined by AAASM-5531 — through the pinned extract capability-surface.toml in this repository.

Manifest version 1.0.0 · 80 capability rows · taken at commit e2730ddaf · the manifest’s own evidence tree 299de3883, dated 2026-08-06 · declared fix version agent-assembly v0.0.1-rc.7.

The extract is refreshed by hand, so it can lag the manifest. What this repository’s CI proves is that the generated tables on these pages match the extract — prose outside the generated blocks is not checked, and proving the extract itself matches the manifest needs a cross-repository check, which is AAASM-5600.

Two different words are spelled Planned, and this page prints one of them. In the tables below it is ADR 0033 §6’s term, about an action: decided but not implemented, carrying a ticket reference and no capability claim. The 🗺️ Planned beside a page title in the sidebar is a documentation-area label from the status map, about how finished an area of this documentation is. Neither licenses a conclusion about the other: a 🧪 Release candidate area can be Unsupported on a platform, and a shipped feature can be Unmeasured on a path.

Level 1 — one sentence

Agent Assembly ships a governance decision point and an evidence trail for actions you have routed onto a governed path, on Linux and macOS, and this page lists what each area reaches and where it stops.

Level 3 — for an evaluator

What each claim term covers today

Every manifest row carries exactly one ADR 0033 §6 term. Two of §6’s eleven have no row at all, and that is shown rather than left out — their absence is a fact about the manifest, not a hole in this table.

ADR 0033 §6 termRowsAreasCapability ids
Observed5Developer-tool launch, Host actions, Platform host-level interception, SDK and framework seamsS3 S4 H4 L5 P2
Detected2Credentials, Host actionsH2 C6
Evaluated11Degraded and failure modes, Identity and attribution, Network traffic, SDK and framework seamsS6 S9 S13 N4 I1 I2 I3 I5 I7 G5 G8
Denied before execution13Degraded and failure modes, Developer-tool launch, Host actions, MCP, Network traffic, SDK and framework seamsS1 S2 S5 S8 H5 N1 N2 N3 M1 M3 L1 G1 G3
Redacted5Credentials, Degraded and failure modes, MCP, Network trafficN7 M9 C1 C2 G4
Approval required0no row in the manifest carries this term
Degraded1Degraded and failure modesG6
Unmeasured36Credentials, Degraded and failure modes, Developer-tool launch, Host actions, Identity and attribution, MCP, Network traffic, SDK and framework seamsS7 S10 S11 S12 H1 H3 H6 H7 H8 N5 N6 N9 N10 N12 N13 M2 M4 M5 M6 M7 M10 L2 L3 L6 L7 L8 C3 C4 C5 I4 I6 G2 G7 G9 G10 G11
Experimental1Platform host-level interceptionP1
Planned0no row in the manifest carries this term
Unsupported6Developer-tool launch, MCP, Network traffic, Platform host-level interceptionN8 N11 M8 L4 P3 P4
Total80

Approval required having no row does not mean approvals are absent from the product; it means no capability row’s outcome is recorded as that term. Planned having no row is what §6 asks for: the term carries a ticket reference and no capability claim, so it belongs beside a ticket rather than in an inventory of what exists.

Where those outcomes sit

AreaRowsOutcomes its rows reach today
SDK and framework seams (sdk)13Observed 2 · Evaluated 3 · Denied before execution 4 · Unmeasured 4
Network traffic (network)13Evaluated 1 · Denied before execution 3 · Redacted 1 · Unmeasured 6 · Unsupported 2
MCP (mcp)10Denied before execution 2 · Redacted 1 · Unmeasured 6 · Unsupported 1
Host actions (host_action)8Observed 1 · Detected 1 · Denied before execution 1 · Unmeasured 5
Developer-tool launch (devtool_launch)8Observed 1 · Denied before execution 1 · Unmeasured 5 · Unsupported 1
Credentials (credentials)6Detected 1 · Redacted 2 · Unmeasured 3
Identity and attribution (identity)7Evaluated 5 · Unmeasured 2
Degraded and failure modes (degraded_mode)11Evaluated 2 · Denied before execution 2 · Redacted 1 · Degraded 1 · Unmeasured 5
Platform host-level interception (platform)4Observed 1 · Experimental 1 · Unsupported 2

Host actions are shell and subprocess, files, browser automation and database queries. The other area names carry their scope on their face; the manifest’s own enum value is printed beside each so a rename cannot hide in a display label.

Read the counts as counts of manifest rows, not of features and not of code paths. A row is one question the manifest asked and answered; an area with more rows was examined in more places, not necessarily covered in more places. The per-mechanism version of this question — which term each named mechanism reaches — is Product promise’s, and is not repeated here.

Platforms

Host-level interception is per platform, and a platform without an adapter has none. There is no lower mechanism that picks up what an absent one would have done, and eBPF is one Linux mechanism rather than a cross-platform floor.

PlatformCapability rows released on itHost-level interception todayReachability of that row
Linux x86_6471Experimental (P1)shipped on crates.io only
Linux aarch6470Observed (P2)shipped on crates.io only
macOS64Unsupported (P3)shipped on crates.io only
Windows13Unsupported (P4)no mechanism exists

The authoritative platform matrix — including what transport mediation reaches on each platform, and the macOS row, which ends with an instruction not to read it as no host enforcement on macOS — is ADR 0033 §5.3. The table above is the manifest’s view of the same question and defers to it.

Where the artifacts come from

Distribution is per channel and per platform: a capability can ship on one channel and not another, and absent from a list is not the same statement as not shipped there. The manifest can record the second only for the container-image channel today. That mechanism was added by AAASM-5680 and has not been extended to the other seven.

ChannelRows delivered on itRows recorded as not published thereRows recorded as not surveyed
GitHub Release assets (github_release)50not recordednot recorded
Homebrew tap (homebrew)50not recordednot recorded
Install script (install_script)50not recordednot recorded
crates.io (crates_io)73not recordednot recorded
PyPI (pypi)13not recordednot recorded
npm (npm)13not recordednot recorded
Go modules (go_modules)13not recordednot recorded
GHCR container images (ghcr)243217
No distribution question (not_applicable)7not recordednot recorded

Channels the manifest surveyed: github_release, homebrew, install_script, crates_io, pypi, npm, go_modules, ghcr, not_applicable. Channels it did not survey: none.

So on every channel except ghcr, a row that does not list a channel is telling you only that it does not list it. Do not read a not recorded cell as a zero. Which container images exist, and how their tags move, is Docker & containers’s.

What stands behind the rows

A capability row is worth what its evidence is worth. The manifest separates a test it can point at from a test it was told exists but could not locate, and separates both from a recorded gap — then separates all three from whether that evidence actually runs.

What stands behind the rowRows
At least a located test26
No located test, but a test asserted but not locatable from the manifest’s repository10
A recorded gap — no test44
Does that evidence run?Rows
It runs on every push to main42
It is path-gated, with a schedule5
It does not run33

A recorded gap is not a silence. It is the manifest saying, in the row itself, that no test backs this and why. To take any single published sentence to the evidence behind it, start at Check a published claim.

What this page does not answer

  • Whether a control is on. Shipping, buildable and activated are three separate questions. A capability can be in an artifact you installed and still be off, or reachable only when an environment variable names a process.
  • Whether your agent is on a governed path. Coverage is a per-host, per-launch fact rather than a property of the architecture. Start at Choose your enforcement path.
  • What a term means. ADR 0033 §6 defines the vocabulary; this page prints it.
  • How finished an area of documentation is. That is the status map’s maturity label, on a different axis from anything here.
  • Whether the extract is current with the manifest. This repository’s CI proves the pages match the extract. Nothing here proves the extract matches upstream; that check is AAASM-5600.

The managed service is not in these numbers

The Cloud control plane and the Enterprise operations features are documented as intent. Their documentation areas carry the status map’s 🗺️ Planned label, they have no rows in the capability manifest, and nothing on this page should be read as saying that either can be provisioned or operated today. What is written about them describes a design. Where the line between the open and the commercial side falls is the Open core boundary’s to state.

Deeper

The implementation-level answer — which crate does what, at which source line, and the highest term each mechanism can legitimately reach — is ADR 0033 in the Core documentation. The manifest this page is generated from is governance/capability-manifest.yaml.

Generated content on this page is rendered by docs/scripts/generate_capability_surface.py from capability-surface.toml. Do not hand-edit between the BEGIN/END GENERATED markers — AAASM-5609.


Last reviewed: 2026-08-13 — AI Agent Assembly Team


Last updated: 2026-08-20 by AI Agent Assembly Team