{
  "schema_version": 1,
  "canonical_page": "/capabilities/",
  "reviewed_on": "2026-07-14",
  "evidence_note": "Rows are manually reviewed and statically validated; source changes can still make a row stale. Public release references remain pending.",
  "rows": [
    {
      "id": "cap-self-hosting",
      "capability": "Self-hosted memory store",
      "lifecycle_state": "Implemented",
      "verified_scope": "The default self-hosted product path keeps stored product data on operator-controlled machines.",
      "evidence_link": "/proof/#claim-self-hosted-boundary",
      "evidence_status": "Verified 2026-07-14",
      "last_reviewed": "2026-07-14",
      "known_limitation": "Implemented in ax0s-memory 0.5.0; a public release record is pending. The scope applies to default product storage, not optional product egress or website services.",
      "consequence": "The operator is responsible for the machines that run and retain the memory store.",
      "safe_workaround": "Review optional product egress and website egress separately before deployment.",
      "next_validation_gate": "Publish a release record with date, artifact, supported environments, interface contract, and acceptance receipt."
    },
    {
      "id": "cap-agent-surfaces",
      "capability": "Named agent surfaces",
      "lifecycle_state": "Implemented",
      "verified_scope": "Connection paths are implemented separately for Claude Code, Codex, ChatGPT, and Hermes; a dated same-store four-surface receipt is pending.",
      "evidence_link": "/proof/#claim-agent-surface-paths",
      "evidence_status": "Verified 2026-07-14",
      "last_reviewed": "2026-07-14",
      "known_limitation": "Separate implementation paths do not establish simultaneous operation against one store, current runtime health, or any additional surface.",
      "consequence": "Treat each named path as a separate implementation until a combined operational receipt is published.",
      "safe_workaround": "Validate the selected path in the operator's own environment before relying on it.",
      "next_validation_gate": "Publish a dated same-store four-surface operational receipt."
    },
    {
      "id": "cap-supersession",
      "capability": "Supersession and addressable history",
      "lifecycle_state": "Implemented",
      "verified_scope": "Stale facts can be superseded without deletion, and superseded history remains addressable.",
      "evidence_link": "/proof/#claim-supersession-history",
      "evidence_status": "Verified 2026-07-14",
      "last_reviewed": "2026-07-14",
      "known_limitation": "Implemented and test-covered in ax0s-memory 0.5.0, with one recorded 2026-07-14 product round trip; a public release record is pending. This row does not claim that every contradiction is resolved automatically.",
      "consequence": "A correction can become current while the prior record remains available for inspection.",
      "safe_workaround": "Inspect the addressable history when the prior state matters.",
      "next_validation_gate": "Publish a release record and broader compatibility, concurrency, and durability receipts."
    },
    {
      "id": "cap-per-user-controls",
      "capability": "Principal and scoped access controls",
      "lifecycle_state": "Implemented",
      "verified_scope": "Per-principal tokens and slug/capability grants, expiry, revocation, rate limits, default-deny enforcement, and access-audit records are implemented; record-level authorization, hardened multi-tenant isolation, and externally validated identity controls are not established.",
      "evidence_link": "/security/#auth-title",
      "evidence_status": "Verified 2026-07-14",
      "last_reviewed": "2026-07-14",
      "known_limitation": "Record-level authorization, hardened multi-tenant isolation, and externally validated identity controls are not established. Legacy shared-bearer compatibility remains until registry cutover.",
      "consequence": "Do not rely on the current product where record-level authorization, hardened tenant isolation, or externally validated identity controls are required.",
      "safe_workaround": "No public workaround is claimed for the unestablished controls.",
      "next_validation_gate": "Publish record-level authorization, tenant-isolation, and external identity-validation artifacts before extending this scope."
    },
    {
      "id": "cap-causal-hypergraph",
      "capability": "Causal-hypergraph and N-ary discovery",
      "lifecycle_state": "Roadmap",
      "verified_scope": "This is a research direction only; it is not a shipped product capability.",
      "evidence_link": "/data/capabilities-public.json",
      "evidence_status": "Roadmap",
      "last_reviewed": "2026-07-14",
      "known_limitation": "Causal and N-ary discovery are not available in the current product.",
      "consequence": "Current workflows must not depend on causal or N-ary discovery.",
      "safe_workaround": "Use only the implemented memory and supersession behavior described in this matrix.",
      "next_validation_gate": "Publish an approved implementation artifact before changing the lifecycle state."
    }
  ]
}
