{
  "schemaVersion": "1.0",
  "title": "Qualify the Hermes Agent connector",
  "description": "Use this page to decide whether one exact Hermes Agent connector artifact has enough evidence for a bounded release claim. It separates source-defined checks, deterministic provider fixtures, standalone-host behavior, path probes, and actua",
  "canonical": "https://getaip.org/docs/connectors/hermes-agent/qualification",
  "route": "/docs/connectors/hermes-agent/qualification",
  "source": "docs/connectors/hermes-agent/qualification/README.md",
  "protocol": "Agent Interoperability Protocol",
  "protocolVersion": "1.0",
  "section": "Connectors",
  "documentType": "Connector",
  "language": "en",
  "downloads": {
    "md": "/docs/download/connectors/hermes-agent/qualification.md",
    "txt": "/docs/download/connectors/hermes-agent/qualification.txt",
    "json": "/docs/download/connectors/hermes-agent/qualification.json",
    "pdf": "/docs/download/connectors/hermes-agent/qualification.pdf"
  },
  "content": {
    "format": "text/markdown",
    "markdown": "---\ntitle: Qualify the Hermes Agent connector\ndescription: >-\n  Evaluate deterministic, standalone-image, controlled-fleet, and\n  isolated-live evidence for one exact Hermes Agent connector artifact\nkind: qualification\naudience: evaluator\nappliesTo: \"1.x\"\nwritingStandard: \"aip-docs/1.0\"\nlastReviewedRevision: \"97be86e9efedf07ecf1783b03800f683f107fb04\"\nconnector: hermes-agent\n---\n\n# Qualify the Hermes Agent connector\n\nUse this page to decide whether one exact Hermes Agent connector artifact has\nenough evidence for a bounded release claim. It separates source-defined\nchecks, deterministic provider fixtures, standalone-host behavior, path\nprobes, and actual Hermes observations.\n\n**Current exact-artifact result: not established by this page.** The pinned\nsource contains test and qualification entry points, but this documentation\nreview did not execute them. A historical isolated-live report applies to a\ndifferent AIP artifact and cannot qualify the current standalone host.\n\n## Use evidence terms consistently\n\n| Term | Required evidence |\n|---|---|\n| Implemented | The behavior and contract exist in identified source |\n| Conformant | The exact artifact passed the applicable conformance scenarios with retained results |\n| Controlled-qualified | The exact artifact passed a named deterministic topology and failure matrix |\n| Path-verified | One identified native, MCP, chat, or operator path produced its expected observations |\n| Isolated-live verified | The exact artifact produced reviewed observations against identified Hermes and model-provider artifacts |\n| Production-observed | Deployment-specific records show the behavior under the stated production boundary |\n\nSource presence proves implementation only. A test function or smoke binary\nproves that a gate exists, not that it passed for the release under review.\n\n## Bind every claim to one identity set\n\nA qualification result is invalid unless its evidence binds all applicable\nvalues:\n\n| Identity class | Required values |\n|---|---|\n| AIP source | Commit, tree or complete dirty-source snapshot, and clean or dirty status |\n| Connector artifact | Immutable image ID, component, version, source label, entrypoint, and architecture |\n| Contract | Manifest digest, 35-capability catalogue digest, schemas, and implementation-support map |\n| Hermes upstream | Commit, tree, immutable image ID, API configuration, and state migrations |\n| Model route | Provider, model identifier, credential scope, and relevant generation settings |\n| Harness | Source digest, runner image, configuration digest, and selected cases |\n| Runtime | Container engine, databases, trust policy, endpoint set, and network topology |\n| Run | UTC interval, unique run ID, operator or CI identity, and evidence-root digest |\n\nThe pinned source identities for this review are:\n\n| Source | Commit | Git tree |\n|---|---|---|\n| AIP | `97be86e9efedf07ecf1783b03800f683f107fb04` | `2d83a382a312c601ecbbf5ed03f8af2b0218bdae` |\n| Hermes Agent | `7426c09beee73bdff94d916015bac71384f6bc92` | `583423a976e761d3f076d2cf7f7859c13e40cc29` |\n\nThese source identities do not identify a built image or a completed run. A\nmutable tag, branch, filename, or successful command exit is not an immutable\nartifact identity.\n\n## Evaluate five independent gates\n\n| Gate | Source-owned entry point | What it can prove | What it cannot prove |\n|---|---|---|---|\n| Q1: connector conformance | `tests/frozen_conformance.rs` | Deterministic Hermes connector semantics through public connector and runtime boundaries | Container, fleet, or actual Hermes behavior |\n| Q2: standalone image | `verify-product-images.sh` | Exact image identity, runtime user, entrypoint, labels, inspect, history, and SBOM | Provider compatibility, image signature, vulnerability policy, or admission |\n| Q3: controlled product fleet | `run-product-qualification.sh` and `verify-product-fleet.sh` | Admission, selected operations, approval, replay, routing, fail-closed behavior, and recovery against fixtures | Actual Hermes or model-provider compatibility |\n| Q4: bounded path probes | Five Hermes smoke binaries | The exact native, MCP, chat, operator, or delegation path selected by a retained run | Broad conformance or unobserved capabilities |\n| Q5: isolated live | `aipd-hermes-operator-smoke` plus a campaign manifest | Selected behavior against identified Hermes and model-provider artifacts | Arbitrary models, every capability, scale, or production readiness |\n\nRecord a result for every gate required by the release claim. One gate cannot\nsilently substitute for another. A release may omit an external-provider gate\nonly when its claim states that exclusion.\n\n## Review deterministic conformance evidence\n\nThe frozen driver returns 13 scenario results. It exercises:\n\n- authenticated actor, tenant, correlation, and opaque credential projection;\n- input and delegated-output schema rejection;\n- concurrent replay suppression, input-collision rejection, and stable\n  delivery identity;\n- retry classification, backoff, exhaustion, and dead-letter settlement;\n- pre-dispatch, in-flight, and late cancellation boundaries;\n- ordered chunks, one terminal chunk, and bounded stream truncation;\n- read retry fields, unsafe uncertainty, and secret redaction;\n- independent approval authority, quorum, retained evidence, and one resume;\n- delegation receipts, correlation, and removal of raw secrets;\n- restart recovery, an outcome-unknown start, and cursor-based reconnect.\n\nTransactions and webhooks are explicitly not applicable in this driver. The\nsource test accepts only a passing report with 13 checks, but that assertion is\nnot a result artifact. Retain the report, selected binary identity, process\nstatus, timestamps, and redacted diagnostics from the exact run.\n\nThe connector also has focused operator tests for:\n\n- exactly one Hermes run under concurrent replay;\n- rejection when one Action ID is reused with changed input;\n- generation-bound and idempotent approval resume;\n- no replay of an unbound start after process restart;\n- cancellation confirmed by terminal Hermes state;\n- server-assigned child Action IDs and exact native child contracts;\n- delegated-result contract, tenant, and transport-owner verification;\n- delegation that remains disabled until explicitly allowlisted.\n\nThose tests strengthen the deterministic gate. They do not replace the frozen\nreport, standalone topology, or real provider observations.\n\n## Review the standalone image gate\n\nThe image verifier builds `aip-host-hermes-agent` with the common host\nDockerfile. It runs the help surface under read-only, capability-dropped, and\nno-new-privileges controls, then requires:\n\n- an immutable `sha256` image ID;\n- runtime user `10001:10001`;\n- entrypoint `/usr/local/bin/aip-connector-host`;\n- exact source revision, version, and component labels;\n- retained image inspect, full history, and SPDX JSON SBOM artifacts.\n\nReview the Hermes image artifacts rather than relying on the shared six-host\nsummary. An SBOM is an inventory. It is not an image signature, vulnerability\ndecision, license decision, provenance attestation, or provider qualification.\n\n## Review the controlled product-fleet gate\n\nThe source-owned product fleet uses deterministic upstream fixtures. Its Hermes\nbaseline requires:\n\n- exactly 35 admitted capabilities for the identified connector version;\n- one `models` read and one `jobs_list` read through the gateway;\n- one approval-governed `job_create` with stable Action and idempotency\n  identities;\n- replay of the completed mutation through the same governed lifecycle;\n- fixture audit records for `GET /v1/models`, `GET /api/jobs`, and\n  `POST /api/jobs`;\n- authorization and idempotency markers at the fixture boundary.\n\nThe outer matrix includes the Hermes host in graceful restart, `SIGKILL`,\nexpired-lease fail-closed, restart recovery, shared PostgreSQL outage, and\ndatabase recovery cases. It also checks that the Hermes runtime database has\nan independent owner and the required runtime tables.\n\nThis gate exercises three Hermes capability IDs against a controlled fixture.\nIt does not exercise the other 32 capabilities, a real Hermes deployment,\nmodel inference, streams, sessions, operator work, first-class delegation, or\nprovider-version drift. Label it controlled product-fleet qualification.\n\n## Review each bounded path probe\n\nUse a path probe only for the claim it actually observes:\n\n| Entry point | Required retained observation |\n|---|---|\n| `aip-hermes-smoke` | Direct endpoint health plus AIP handshake and endpoint-qualified health actions |\n| `aip-hermes-chat-smoke` | One endpoint health check and one non-empty chat result through the in-process AIP path |\n| `aipd-hermes-chat-smoke` | Deployed manifest exposure, native handshake, health, and exact prompted chat content |\n| `aipd-hermes-mcp-smoke` | MCP tool discovery plus structured health and exact prompted chat content |\n| `aipd-hermes-operator-smoke` | Independent approval, operator stream evidence, exactly one child action, scope denial, and exact delegated result |\n\nRecord the endpoint set, tool and capability IDs, prompt marker, Action IDs,\napproval identity, provider handles, terminal state, and raw result references.\nDo not combine separate runs into one apparently continuous result.\n\nA chat marker proves the selected route returned expected content once. It\ndoes not prove model quality, deterministic generation, every transport,\nprovider durability, or the other capability families.\n\n## Review isolated-live evidence\n\nA current isolated-live campaign needs actual Hermes and model-provider\nartifacts, not fixture-compatible routes. Use at least two independently named\nHermes endpoints when the claim includes endpoint isolation.\n\nThe operator campaign should verify:\n\n1. unauthenticated profile access fails at the intended boundary;\n2. every endpoint discovers only its allowlisted AIP tools;\n3. an operator Action enters pending approval before execution;\n4. an independent authenticated principal approves the immutable request;\n5. structured run chunks contain the expected tool start and completion;\n6. exactly one protocol-assigned child Action performs the downstream work;\n7. the child result matches an independently read expected record;\n8. an out-of-scope delegation fails closed;\n9. the allowed delegation returns the same child Action and durable result;\n10. cancellation, restart, or uncertainty cases required by the claim settle\n    under their original identities.\n\nHermes must not receive credentials for the downstream business system. The\nauthoritative delegated result comes from the native AIP lifecycle, not model\nprose.\n\nThe retained 11 July 2026 report describes a historical pass for two endpoints.\nIt used a different AIP artifact, has no complete machine-readable result or\ncleanup record, and cannot establish a current pass. Preserve it as\n`historical` and review its exact limits in the dedicated record.\n\n## Account for all 35 capabilities\n\nMaintain one generated or machine-validated row per published capability:\n\n| Field | Required value |\n|---|---|\n| Capability ID | Exact endpoint-qualified admitted identifier |\n| Contract evidence | Schema, method, route, risk, approval, retry, streaming, and transaction mapping |\n| Deterministic evidence | Scenario and result artifact, or an explicit gap |\n| Controlled-fleet evidence | Case and artifact, or `not_run` |\n| Native and MCP evidence | Path probe and artifact, or `not_run` |\n| Isolated-live evidence | Provider identities, case, and artifact, or `not_run` |\n| Failure evidence | Auth, validation, rejection, uncertainty, cancellation, restart, and recovery cases exercised |\n| Side-effect control | Action, idempotency, approval, provider handle, reconciliation, and cleanup as applicable |\n| Review decision | Accepted scope, limitation, owner, reviewer, and time |\n\nEvery row needs contract evidence. Live mutation of all operations is not a\ndefault requirement and may create unsafe model, session, job, or operator\neffects. Select live cases by unique risk and behavior, then publish every\nunobserved capability as a gap.\n\n## Retain a complete evidence set\n\nA current qualification record should contain:\n\n1. immutable AIP source, host image, manifest, schema, Hermes, model-route,\n   harness, dependency, topology, and run identities;\n2. a gate manifest naming every required case and invariant;\n3. raw process exits, structured per-case results, and redacted diagnostics;\n4. admission, catalogue, implementation-support, assignment, and route\n   snapshots;\n5. image inspect, history, SBOM, and separate supply-chain decisions;\n6. native envelopes, MCP tool metadata, provider requests, and correlations\n   without credentials or sensitive prompt content;\n7. durable Action, approval, idempotency, lifecycle, chunk, operator-binding,\n   child-action, and provider-state observations;\n8. failure and recovery ordering, including process, lease, database, and\n   provider events;\n9. a generated 35-row capability coverage matrix;\n10. checksums for every retained artifact and one evidence-root checksum;\n11. verified cleanup, residual-resource inventory, and retained exceptions;\n12. a summary that states scope, result, exclusions, reviewer, and UTC time.\n\nA summary file's presence is not a pass. Review every referenced artifact and\nensure that later recovery did not hide an earlier failed invariant.\n\n## Assign results without ambiguity\n\n| Result | Use when |\n|---|---|\n| `passed` | Every required invariant passed for the exact identity set, artifacts are complete and redacted, gaps match the claim, and cleanup was verified |\n| `failed` | A required invariant failed, identity mismatched, evidence was corrupted or leaked, or cleanup violated the campaign contract |\n| `blocked` | A required dependency or authority was unavailable before the invariant could be evaluated |\n| `not_run` | The gate was not executed for this identity set |\n| `historical` | A prior result belongs to a different source, artifact, topology, or evidence standard |\n\nDo not collapse `blocked`, `not_run`, or `historical` into `passed`. One gate\ncan pass while the broader release claim remains unestablished.\n\n## Publish only the supported claim\n\nAcceptable result language names the evidence boundary:\n\n> At the recorded time, the identified AIP, Hermes Agent, and model-route\n> artifacts passed the listed deterministic, standalone-fleet, and selected\n> isolated-live cases in the retained topology. The coverage matrix lists\n> every unobserved capability and excluded production property.\n\nDo not publish `fully compatible`, `all 35 capabilities live verified`,\n`exactly once`, or `production-ready` unless the retained campaign defines and\nproves each phrase under the stated deployment.\n\n## Reviewer checklist\n\n- [ ] Every source, image, manifest, Hermes, model-route, harness, and run\n  identity is immutable and mutually consistent.\n- [ ] Required gates are explicit; no fixture result is labeled live.\n- [ ] The 35-row coverage matrix matches the admitted catalogue.\n- [ ] Frozen-conformance and standalone-fleet reports are complete.\n- [ ] Native and MCP path results name their exact route and endpoint.\n- [ ] Operator and delegation evidence binds approval, child identity,\n  lifecycle state, provider handle, and authoritative result.\n- [ ] Cancellation and uncertain outcomes are reconciled without replay.\n- [ ] Image inventory is not presented as signature, scan, or provenance.\n- [ ] Artifacts are redacted, checksummed, access-controlled, and retained for\n  the claim lifetime.\n- [ ] Cleanup and residual resources are independently recorded.\n- [ ] Final wording states time, scope, result, gaps, and exclusions.\n\n## Related documentation\n\n- [Conformance and qualification](../../../reference/conformance.md)\n- [Connector fleet qualification](../../../testing/connector-fleet-qualification.md)\n- [Live-product qualification](../../../testing/live-product-e2e.md)\n- [Historical Hermes Agent isolated-live result](../../../testing/hermes-agent-isolated-live.md)\n- [Hermes Agent capability index](../capabilities/README.md)\n- [Release artifacts and verification](../../../reference/release-artifacts.md)\n",
    "text": "Qualify the Hermes Agent connector\n\nUse this page to decide whether one exact Hermes Agent connector artifact has\nenough evidence for a bounded release claim. It separates source-defined\nchecks, deterministic provider fixtures, standalone-host behavior, path\nprobes, and actual Hermes observations.\n\nCurrent exact-artifact result: not established by this page. The pinned\nsource contains test and qualification entry points, but this documentation\nreview did not execute them. A historical isolated-live report applies to a\ndifferent AIP artifact and cannot qualify the current standalone host.\n\nUse evidence terms consistently\n\n| Term | Required evidence |\n\n| Implemented | The behavior and contract exist in identified source |\n| Conformant | The exact artifact passed the applicable conformance scenarios with retained results |\n| Controlled-qualified | The exact artifact passed a named deterministic topology and failure matrix |\n| Path-verified | One identified native, MCP, chat, or operator path produced its expected observations |\n| Isolated-live verified | The exact artifact produced reviewed observations against identified Hermes and model-provider artifacts |\n| Production-observed | Deployment-specific records show the behavior under the stated production boundary |\n\nSource presence proves implementation only. A test function or smoke binary\nproves that a gate exists, not that it passed for the release under review.\n\nBind every claim to one identity set\n\nA qualification result is invalid unless its evidence binds all applicable\nvalues:\n\n| Identity class | Required values |\n\n| AIP source | Commit, tree or complete dirty-source snapshot, and clean or dirty status |\n| Connector artifact | Immutable image ID, component, version, source label, entrypoint, and architecture |\n| Contract | Manifest digest, 35-capability catalogue digest, schemas, and implementation-support map |\n| Hermes upstream | Commit, tree, immutable image ID, API configuration, and state migrations |\n| Model route | Provider, model identifier, credential scope, and relevant generation settings |\n| Harness | Source digest, runner image, configuration digest, and selected cases |\n| Runtime | Container engine, databases, trust policy, endpoint set, and network topology |\n| Run | UTC interval, unique run ID, operator or CI identity, and evidence-root digest |\n\nThe pinned source identities for this review are:\n\n| Source | Commit | Git tree |\n\n| AIP | 97be86e9efedf07ecf1783b03800f683f107fb04 | 2d83a382a312c601ecbbf5ed03f8af2b0218bdae |\n| Hermes Agent | 7426c09beee73bdff94d916015bac71384f6bc92 | 583423a976e761d3f076d2cf7f7859c13e40cc29 |\n\nThese source identities do not identify a built image or a completed run. A\nmutable tag, branch, filename, or successful command exit is not an immutable\nartifact identity.\n\nEvaluate five independent gates\n\n| Gate | Source-owned entry point | What it can prove | What it cannot prove |\n\n| Q1: connector conformance | tests/frozenconformance.rs | Deterministic Hermes connector semantics through public connector and runtime boundaries | Container, fleet, or actual Hermes behavior |\n| Q2: standalone image | verify-product-images.sh | Exact image identity, runtime user, entrypoint, labels, inspect, history, and SBOM | Provider compatibility, image signature, vulnerability policy, or admission |\n| Q3: controlled product fleet | run-product-qualification.sh and verify-product-fleet.sh | Admission, selected operations, approval, replay, routing, fail-closed behavior, and recovery against fixtures | Actual Hermes or model-provider compatibility |\n| Q4: bounded path probes | Five Hermes smoke binaries | The exact native, MCP, chat, operator, or delegation path selected by a retained run | Broad conformance or unobserved capabilities |\n| Q5: isolated live | aipd-hermes-operator-smoke plus a campaign manifest | Selected behavior against identified Hermes and model-provider artifacts | Arbitrary models, every capability, scale, or production readiness |\n\nRecord a result for every gate required by the release claim. One gate cannot\nsilently substitute for another. A release may omit an external-provider gate\nonly when its claim states that exclusion.\n\nReview deterministic conformance evidence\n\nThe frozen driver returns 13 scenario results. It exercises:\n• authenticated actor, tenant, correlation, and opaque credential projection;\n• input and delegated-output schema rejection;\n• concurrent replay suppression, input-collision rejection, and stable\n  delivery identity;\n• retry classification, backoff, exhaustion, and dead-letter settlement;\n• pre-dispatch, in-flight, and late cancellation boundaries;\n• ordered chunks, one terminal chunk, and bounded stream truncation;\n• read retry fields, unsafe uncertainty, and secret redaction;\n• independent approval authority, quorum, retained evidence, and one resume;\n• delegation receipts, correlation, and removal of raw secrets;\n• restart recovery, an outcome-unknown start, and cursor-based reconnect.\n\nTransactions and webhooks are explicitly not applicable in this driver. The\nsource test accepts only a passing report with 13 checks, but that assertion is\nnot a result artifact. Retain the report, selected binary identity, process\nstatus, timestamps, and redacted diagnostics from the exact run.\n\nThe connector also has focused operator tests for:\n• exactly one Hermes run under concurrent replay;\n• rejection when one Action ID is reused with changed input;\n• generation-bound and idempotent approval resume;\n• no replay of an unbound start after process restart;\n• cancellation confirmed by terminal Hermes state;\n• server-assigned child Action IDs and exact native child contracts;\n• delegated-result contract, tenant, and transport-owner verification;\n• delegation that remains disabled until explicitly allowlisted.\n\nThose tests strengthen the deterministic gate. They do not replace the frozen\nreport, standalone topology, or real provider observations.\n\nReview the standalone image gate\n\nThe image verifier builds aip-host-hermes-agent with the common host\nDockerfile. It runs the help surface under read-only, capability-dropped, and\nno-new-privileges controls, then requires:\n• an immutable sha256 image ID;\n• runtime user 10001:10001;\n• entrypoint /usr/local/bin/aip-connector-host;\n• exact source revision, version, and component labels;\n• retained image inspect, full history, and SPDX JSON SBOM artifacts.\n\nReview the Hermes image artifacts rather than relying on the shared six-host\nsummary. An SBOM is an inventory. It is not an image signature, vulnerability\ndecision, license decision, provenance attestation, or provider qualification.\n\nReview the controlled product-fleet gate\n\nThe source-owned product fleet uses deterministic upstream fixtures. Its Hermes\nbaseline requires:\n• exactly 35 admitted capabilities for the identified connector version;\n• one models read and one jobslist read through the gateway;\n• one approval-governed jobcreate with stable Action and idempotency\n  identities;\n• replay of the completed mutation through the same governed lifecycle;\n• fixture audit records for GET /v1/models, GET /api/jobs, and\n  POST /api/jobs;\n• authorization and idempotency markers at the fixture boundary.\n\nThe outer matrix includes the Hermes host in graceful restart, SIGKILL,\nexpired-lease fail-closed, restart recovery, shared PostgreSQL outage, and\ndatabase recovery cases. It also checks that the Hermes runtime database has\nan independent owner and the required runtime tables.\n\nThis gate exercises three Hermes capability IDs against a controlled fixture.\nIt does not exercise the other 32 capabilities, a real Hermes deployment,\nmodel inference, streams, sessions, operator work, first-class delegation, or\nprovider-version drift. Label it controlled product-fleet qualification.\n\nReview each bounded path probe\n\nUse a path probe only for the claim it actually observes:\n\n| Entry point | Required retained observation |\n\n| aip-hermes-smoke | Direct endpoint health plus AIP handshake and endpoint-qualified health actions |\n| aip-hermes-chat-smoke | One endpoint health check and one non-empty chat result through the in-process AIP path |\n| aipd-hermes-chat-smoke | Deployed manifest exposure, native handshake, health, and exact prompted chat content |\n| aipd-hermes-mcp-smoke | MCP tool discovery plus structured health and exact prompted chat content |\n| aipd-hermes-operator-smoke | Independent approval, operator stream evidence, exactly one child action, scope denial, and exact delegated result |\n\nRecord the endpoint set, tool and capability IDs, prompt marker, Action IDs,\napproval identity, provider handles, terminal state, and raw result references.\nDo not combine separate runs into one apparently continuous result.\n\nA chat marker proves the selected route returned expected content once. It\ndoes not prove model quality, deterministic generation, every transport,\nprovider durability, or the other capability families.\n\nReview isolated-live evidence\n\nA current isolated-live campaign needs actual Hermes and model-provider\nartifacts, not fixture-compatible routes. Use at least two independently named\nHermes endpoints when the claim includes endpoint isolation.\n\nThe operator campaign should verify:\n1. unauthenticated profile access fails at the intended boundary;\n2. every endpoint discovers only its allowlisted AIP tools;\n3. an operator Action enters pending approval before execution;\n4. an independent authenticated principal approves the immutable request;\n5. structured run chunks contain the expected tool start and completion;\n6. exactly one protocol-assigned child Action performs the downstream work;\n7. the child result matches an independently read expected record;\n8. an out-of-scope delegation fails closed;\n9. the allowed delegation returns the same child Action and durable result;\n10. cancellation, restart, or uncertainty cases required by the claim settle\n    under their original identities.\n\nHermes must not receive credentials for the downstream business system. The\nauthoritative delegated result comes from the native AIP lifecycle, not model\nprose.\n\nThe retained 11 July 2026 report describes a historical pass for two endpoints.\nIt used a different AIP artifact, has no complete machine-readable result or\ncleanup record, and cannot establish a current pass. Preserve it as\nhistorical and review its exact limits in the dedicated record.\n\nAccount for all 35 capabilities\n\nMaintain one generated or machine-validated row per published capability:\n\n| Field | Required value |\n\n| Capability ID | Exact endpoint-qualified admitted identifier |\n| Contract evidence | Schema, method, route, risk, approval, retry, streaming, and transaction mapping |\n| Deterministic evidence | Scenario and result artifact, or an explicit gap |\n| Controlled-fleet evidence | Case and artifact, or notrun |\n| Native and MCP evidence | Path probe and artifact, or notrun |\n| Isolated-live evidence | Provider identities, case, and artifact, or notrun |\n| Failure evidence | Auth, validation, rejection, uncertainty, cancellation, restart, and recovery cases exercised |\n| Side-effect control | Action, idempotency, approval, provider handle, reconciliation, and cleanup as applicable |\n| Review decision | Accepted scope, limitation, owner, reviewer, and time |\n\nEvery row needs contract evidence. Live mutation of all operations is not a\ndefault requirement and may create unsafe model, session, job, or operator\neffects. Select live cases by unique risk and behavior, then publish every\nunobserved capability as a gap.\n\nRetain a complete evidence set\n\nA current qualification record should contain:\n1. immutable AIP source, host image, manifest, schema, Hermes, model-route,\n   harness, dependency, topology, and run identities;\n2. a gate manifest naming every required case and invariant;\n3. raw process exits, structured per-case results, and redacted diagnostics;\n4. admission, catalogue, implementation-support, assignment, and route\n   snapshots;\n5. image inspect, history, SBOM, and separate supply-chain decisions;\n6. native envelopes, MCP tool metadata, provider requests, and correlations\n   without credentials or sensitive prompt content;\n7. durable Action, approval, idempotency, lifecycle, chunk, operator-binding,\n   child-action, and provider-state observations;\n8. failure and recovery ordering, including process, lease, database, and\n   provider events;\n9. a generated 35-row capability coverage matrix;\n10. checksums for every retained artifact and one evidence-root checksum;\n11. verified cleanup, residual-resource inventory, and retained exceptions;\n12. a summary that states scope, result, exclusions, reviewer, and UTC time.\n\nA summary file's presence is not a pass. Review every referenced artifact and\nensure that later recovery did not hide an earlier failed invariant.\n\nAssign results without ambiguity\n\n| Result | Use when |\n\n| passed | Every required invariant passed for the exact identity set, artifacts are complete and redacted, gaps match the claim, and cleanup was verified |\n| failed | A required invariant failed, identity mismatched, evidence was corrupted or leaked, or cleanup violated the campaign contract |\n| blocked | A required dependency or authority was unavailable before the invariant could be evaluated |\n| notrun | The gate was not executed for this identity set |\n| historical | A prior result belongs to a different source, artifact, topology, or evidence standard |\n\nDo not collapse blocked, notrun, or historical into passed. One gate\ncan pass while the broader release claim remains unestablished.\n\nPublish only the supported claim\n\nAcceptable result language names the evidence boundary:\n\nAt the recorded time, the identified AIP, Hermes Agent, and model-route\nartifacts passed the listed deterministic, standalone-fleet, and selected\nisolated-live cases in the retained topology. The coverage matrix lists\nevery unobserved capability and excluded production property.\n\nDo not publish fully compatible, all 35 capabilities live verified,\nexactly once, or production-ready unless the retained campaign defines and\nproves each phrase under the stated deployment.\n\nReviewer checklist\n• [ ] Every source, image, manifest, Hermes, model-route, harness, and run\n  identity is immutable and mutually consistent.\n• [ ] Required gates are explicit; no fixture result is labeled live.\n• [ ] The 35-row coverage matrix matches the admitted catalogue.\n• [ ] Frozen-conformance and standalone-fleet reports are complete.\n• [ ] Native and MCP path results name their exact route and endpoint.\n• [ ] Operator and delegation evidence binds approval, child identity,\n  lifecycle state, provider handle, and authoritative result.\n• [ ] Cancellation and uncertain outcomes are reconciled without replay.\n• [ ] Image inventory is not presented as signature, scan, or provenance.\n• [ ] Artifacts are redacted, checksummed, access-controlled, and retained for\n  the claim lifetime.\n• [ ] Cleanup and residual resources are independently recorded.\n• [ ] Final wording states time, scope, result, gaps, and exclusions.\n\nRelated documentation\n• Conformance and qualification (../../../reference/conformance.md)\n• Connector fleet qualification (../../../testing/connector-fleet-qualification.md)\n• Live-product qualification (../../../testing/live-product-e2e.md)\n• Historical Hermes Agent isolated-live result (../../../testing/hermes-agent-isolated-live.md)\n• Hermes Agent capability index (../capabilities/README.md)\n• Release artifacts and verification (../../../reference/release-artifacts.md)\n"
  },
  "integrity": {
    "algorithm": "sha256",
    "sourceDigest": "77163a5ad9aee540bf43a2edb81a411ffa3317d8206e254c62e6c71b3c7e7808"
  }
}
