Capability Status
This page is generated from user-docs/static/capabilities.json. It is the public status surface for capabilities that remain limited, preview, planned, or otherwise outside the narrow Phase 1 workload boundary.
Current capability status
| Capability | Request family | Transport | Deployment mode | Availability | Last verification date | Evidence tier | Limitations |
|---|---|---|---|---|---|---|---|
CAP-ACCESS-LIVE | chat_completions, responses, messages | json, sse | self_hosted, hosted, saas | planned | Not yet verified | mock_verified | Unified Access live enforcement is not reconciled for the Phase 1 public scope. Public copy must not imply live wallet reservation or settlement. |
CAP-BUDGET-LIVE | chat_completions, responses, messages | json, sse | self_hosted, hosted, saas | planned | Not yet verified | mock_verified | Live hard-budget enforcement is not Phase 1 GA and must stay off primary surfaces. Capability status may describe the current budget-policy state only with limitations. |
CAP-GW-AUDIT-DURABILITY | chat_completions, responses | json, sse | self_hosted, air_gapped | limited | Not yet verified | mock_verified | Decision evidence is available for governed gateway traffic, but immutable every-decision durability remains a tracked gap. Phase 1 capability status must disclose current WAL, ingestion, and continuity limits. No primary surface may imply complete Trail durability until later phases close the gap. |
CAP-GW-CHAT-POLICY | chat_completions | json, sse | self_hosted, air_gapped | limited | Not yet verified | mock_verified | Phase 1 covers the documented Chat Completions gateway path only. Anthropic Messages, WebSocket, and MCP parity remain outside the initial wedge. GA remains blocked until live-provider and post-deploy evidence is current. |
CAP-GW-RESPONSES-POLICY | responses | json, sse | self_hosted, air_gapped | limited | Not yet verified | mock_verified | Phase 1 covers the documented Responses gateway path only. Streaming parity is limited to the documented JSON and SSE flow. GA remains blocked until live-provider and post-deploy evidence is current. |
CAP-KMS-HOSTED | kms_hosted | internal | hosted, saas | planned | Not yet verified | mock_verified | Hosted external KMS integration remains blocked until region, rotation, and readiness evidence exists. Primary surfaces must not imply hosted KMS support. |
CAP-MCP-ACTION-POLICY | mcp | streamable_http | self_hosted, hosted | preview | Not yet verified | mock_verified | Live MCP tool-action governance remains preview-only and must not be marketed as GA. |
CAP-MESSAGES-POLICY | messages | json, sse | self_hosted, air_gapped | preview | Not yet verified | mock_verified | Anthropic Messages policy parity remains outside the initial GA wedge. |
CAP-OAUTH-BEARER | oauth_bearer | http, browser | hosted, saas | preview | Not yet verified | mock_verified | OAuth bearer access remains preview-only and must not be marketed as a supported public bearer flow. |
CAP-ROUTER-AUTO | chat_completions, responses, messages | json, sse | self_hosted, hosted, saas | planned | Not yet verified | mock_verified | Automatic model routing remains non-GA and must stay off primary surfaces until deterministic selection evidence exists. |
CAP-SCIM | scim | http | hosted, saas | planned | Not yet verified | mock_verified | SCIM provisioning remains non-GA and unadvertised on primary surfaces until provisioning, deprovisioning, and rotation lanes pass. |
CAP-SIEM-STREAM | siem_delivery | http | self_hosted, hosted, saas | preview | Not yet verified | mock_verified | Durable SIEM outbox delivery and replay guarantees are not Phase 1 GA. Primary surfaces must not imply production-ready SIEM streaming. |
CAP-SSO-OIDC | browser_sign_in | browser, redirect | hosted, saas | planned | Not yet verified | mock_verified | OIDC SSO remains non-GA and unadvertised on primary surfaces until browser, API, and recovery lanes pass. |
CAP-SSO-SAML | browser_sign_in | browser, redirect | hosted, saas | planned | Not yet verified | mock_verified | SAML SSO remains non-GA and unadvertised on primary surfaces until browser, API, and recovery lanes pass. |
CAP-WS-FRAME-POLICY | chat_completions_ws, responses_ws | websocket | self_hosted, air_gapped | planned | Not yet verified | mock_verified | Per-frame governance and binary-frame rejection remain planned. Primary surfaces must not imply WebSocket policy parity. |
How to read this page
gameans the manifest-declared positive, negative, and freshness gates are all satisfied.betameans a fresh sandbox or runtime verification exists, but the capability is still outside the GA contract.limited,preview, andplannedstay here until the owning phase closes their gaps.