@fabric-harness/agent-registry
v0.2.2
Published
Vertical-neutral agent governance contracts: registration, enrollment, capability grants, budgets, decision boundary, and identity bindings.
Readme
@fabric-harness/agent-registry
Vertical-neutral agent governance contracts, extracted per the Fabric Agent
Contracts Reconciliation ADR (techfabric vault) from the family's origin
vertical packages. This package knows nothing about the applications that
integrate with it — no vertical vocabulary, no product names, CI-guarded in
both src/ and test/. Origin-equivalence tests live in each vertical's own
repository beside its re-export shim.
What lives here:
- registry — agent definitions, hash-pinned versions with hard model
budgets (
resolveAgentRunTokenBudget), tenant registrations, capability grants with the read/propose/execute separation, runs, execution principals. - enrollment — the external-runtime onboarding state machine (invites with
hashed tokens, request/approve with request-hash + envelope-hash fencing,
encrypted credential reveals, operator dispatches/admissions, mutation
fences) and
approvalIsSubset— approval can only narrow, never widen. Runtime kindgeneric-mcpis the channel-hosted ACP agent kind. - decisions —
ActionRouterouting vocabulary, per-actionPolicyDecision/PolicyHint, theclampRouteautonomy ceiling, theApprovalRequestentity, decision events,SignalPendingStep, and the D16 decision boundary:validateExternalDecision(pure — refusals, expiry, verification floor, capability, receipt pins) returning the decision record +SignalOutboxIntentthe vertical action persists atomically with its pending→terminal compare-and-set, andcreateSignalOutboxReconciler(idempotent delivery with CAS checkpointing; receiving workflows dedupe onapprovalRequestId). No neutral code records a decision and then performs an uncheckpointed inline signal. - identity — revocable external identity bindings (
nostr,slack,email, …) between surface identities and Fabric principals. - evidence / skills / envelope / ports / kinds — outcome-evidence and
skill-contract factories, the
X-Fabric-Signature: v1=signed envelope, neutral ports, namespaced kind primitives.
Scope rule (CI-guarded): nothing here names a vertical's domain. Verticals
attach scope via zod .extend() and factory literals in their own packages,
which keeps persisted wire shapes byte-identical through the extraction.
Layering: channel adapters (@fabric-harness/channels/*) carry candidate
identities and never authorize; only a vertical's governed decision-ingress
action — composed from createDecisionIngress — resolves bindings, checks
capabilities, and signals durable workflows.
