Evaluator-first capability summary

AUX is a pre-action trust control for AI agents.

AUX independently resolves bounded evidence before consequential action and returns machine-readable outcomes plus signed, portable records. It is not a general autonomous agent, payment rail, vendor approver, or action-execution system. Downstream owners and agents establish authority, decision boundaries, and how AUX outcomes are used.

The public counterparty journey is available without an account, API key, payment, subscription, or package installation. Trust here means inspectable evidence for a specific action at a specific moment—not permanent counterparty trustworthiness, guaranteed real-world truth, or “safe to pay.” Caller assertions alone never satisfy an independent requirement.

AUX distinguishes CERTIFIED, REQUIREMENTS_OUTSTANDING, NOT_CERTIFIABLE, and SOURCE_TEMPORARILY_UNAVAILABLE. Durable attempts automatically retry temporary source failures. Active requests are retained only while needed, deleted on terminal state, and terminal results expire after the bounded retrieval window.

Primary-source capability evidence

Nine dimensions, with deliberate limits.

High autonomy is not the product objective. AUX gathers and verifies bounded evidence, recovers from temporary source failures, and produces portable proof while the caller keeps control of the consequential action.

Intentionally bounded

Action capability

AUX calls authoritative evidence sources, verifies attestations, evaluates certification policy, and issues signed receipts and non-executing handoffs. It never executes a downstream payment, onboarding, or other consequential action.

Domain-specific

Autonomy

Given a complete caller-initiated request and selected profile, AUX independently resolves supported public sources and reaches a bounded terminal state. It does not invent goals, broaden the requested action, or self-start consequential workflows.

Deterministic contract

Planning and reasoning

AUX sequences declared evidence requirements and returns exact machine-readable remediation for outstanding requirements. It is deliberately not a general planner or conversational reasoning agent.

Automatic bounded recovery

Adaptation and recovery

Durable attempts reuse a deterministic attempt ID and automatically retry temporary source failures with bounded backoff, without caller resubmission. Missing data, adverse evidence, and temporary source failures remain distinct states.

Durable, privacy-bounded state

State and continuity

Active attempts persist for at most 24 hours. The request is deleted on terminal state; terminal status and result remain available for at most 24 additional hours, then are deleted. AUX does not claim long-lived cross-project memory.

Continuously smoke-tested

Reliability

Scheduled external production smoke tests cover health, durable bindings, profiles, Agent Card, OpenAPI, retry and retention, public discovery, example-client syntax, measurement intake, and the synthetic-only boundary. AUX does not publish a formal SLA or uptime percentage.

Open machine interfaces

Interoperability

AUX publishes OpenAPI, A2A 1.0 JSON-RPC, Agent Card 0.9.0, ARD, llms.txt, JWKS, portable verification endpoints, domain-owned policies, and signed agent-to-agent handoffs.

Fail-closed and auditable

Safety and observability

CERTIFIED requires every bounded requirement. Other outcomes preserve missing, adverse, and temporary-source distinctions. Signed receipts bind evidence, policy, version, and time; single-use handoff consumption prevents replay and states action_executed=false.

Caller-controlled

Operator sovereignty

The caller chooses the profile and acceptance policy, independently verifies signatures, and retains control of the final consequential action. AUX does not approve vendors or compel execution.

Deliberate limits

AUX does not set its own goals, perform open-ended planning, execute payments, approve vendors, make legal or comprehensive sanctions-clearance determinations, or replace operator judgment. Those limits are safety properties, not missing documentation.