Intentionally bounded
Action capability
AUX calls authoritative evidence sources, verifies attestations, evaluates certification policy, and issues signed receipts and non-executing handoffs. It never executes a downstream payment, onboarding, or other consequential action.
Domain-specific
Autonomy
Given a complete caller-initiated request and selected profile, AUX independently resolves supported public sources and reaches a bounded terminal state. It does not invent goals, broaden the requested action, or self-start consequential workflows.
Deterministic contract
Planning and reasoning
AUX sequences declared evidence requirements and returns exact machine-readable remediation for outstanding requirements. It is deliberately not a general planner or conversational reasoning agent.
Automatic bounded recovery
Adaptation and recovery
Durable attempts reuse a deterministic attempt ID and automatically retry temporary source failures with bounded backoff, without caller resubmission. Missing data, adverse evidence, and temporary source failures remain distinct states.
Durable, privacy-bounded state
State and continuity
Active attempts persist for at most 24 hours. The request is deleted on terminal state; terminal status and result remain available for at most 24 additional hours, then are deleted. AUX does not claim long-lived cross-project memory.
Continuously smoke-tested
Reliability
Scheduled external production smoke tests cover health, durable bindings, profiles, Agent Card, OpenAPI, retry and retention, public discovery, example-client syntax, measurement intake, and the synthetic-only boundary. AUX does not publish a formal SLA or uptime percentage.
Open machine interfaces
Interoperability
AUX publishes OpenAPI, A2A 1.0 JSON-RPC, Agent Card 0.9.0, ARD, llms.txt, JWKS, portable verification endpoints, domain-owned policies, and signed agent-to-agent handoffs.
Fail-closed and auditable
Safety and observability
CERTIFIED requires every bounded requirement. Other outcomes preserve missing, adverse, and temporary-source distinctions. Signed receipts bind evidence, policy, version, and time; single-use handoff consumption prevents replay and states action_executed=false.
Caller-controlled
Operator sovereignty
The caller chooses the profile and acceptance policy, independently verifies signatures, and retains control of the final consequential action. AUX does not approve vendors or compel execution.
Deliberate limits
AUX does not set its own goals, perform open-ended planning, execute payments, approve vendors, make legal or comprehensive sanctions-clearance determinations, or replace operator judgment. Those limits are safety properties, not missing documentation.