Card snapshot
fo.flocore.tech
·
2026-09-30 05:32:52 UTC
·
0427fc0901267bdab2ba14707b7fecdbadbb221e509996ef80e1780b33230e9d
This is a frozen copy of the agent's agent-card.json as we observed it at the timestamp above. We capture a new snapshot every time the card's content hash changes. Useful for: forensic drift analysis, verifying downstream callers see the right version, reproducing routing decisions made historically.
{
"protocolVersion": "1.0",
"name": "FLOCORE",
"description": "AI-native operational intelligence platform - ontology + declarative workflow engine + agent mesh. The agent-readiness layer is the public face of a real multi-tenant operational platform, not a standalone gateway.",
"url": "https://fo.flocore.tech",
"preferredTransport": "JSONRPC",
"provider": {
"organization": "FLOCORE",
"url": "https://fo.flocore.tech"
},
"version": "flocore.agent-manifest/v1",
"documentationUrl": "https://fo.flocore.tech/.well-known/agent-manifest",
"capabilities": {
"streaming": false,
"pushNotifications": false,
"stateTransitionHistory": true
},
"defaultInputModes": [
"application/json"
],
"defaultOutputModes": [
"application/json"
],
"skills": [
{
"id": "identity",
"name": "Identity & Access",
"description": "OTP\u2192JWT \u00b7 introspect \u00b7 revoke \u00b7 service-tokens \u00b7 RBAC",
"tags": [
"identity"
]
},
{
"id": "events",
"name": "Event Backbone",
"description": "ingest/route/replay events across systems (loose-coupling bus) + audit",
"tags": [
"events"
]
},
{
"id": "sentinels",
"name": "Sentinel Fleet",
"description": "9-sentinel fleet under 5 Guardians (Drift\u00b7Freshness\u00b7Fraud\u00b7User-Behaviour\u00b7AEGIS\u00b7Availability\u00b7Exposure\u00b7Compliance\u00b7Visibility); observe\u2192signal\u2192auto-ticket\u2192score",
"tags": [
"observability"
]
},
{
"id": "operational_trust_score",
"name": "Operational Trust Score",
"description": "fuses every Guardian's signal into one 0-100; rolls up site\u2192customer\u2192tenant; the Orchestrator conducts a fleet sweep (many signals in, one number out)",
"tags": [
"observability"
]
},
{
"id": "aegis",
"name": "AEGIS, AI Counter-Intelligence",
"description": "self-learning AI guardian: prompt-injection/exfil pre-flight on /ai/gateway; 4 watch-domains (human-intrusion, exposure/drift, AI-adversary, OSINT self-recon); defensive-only, human-gated, watch-the-watchers",
"tags": [
"ai"
]
},
{
"id": "advatar",
"name": "Advatar, the Governed Front Door for Agents",
"description": "the free aegis_inspect screen, then the Human Gate, then a signed receipt, as one machine-readable rail any agent can discover and self-serve onboard to; every world-affecting step is human-gated, no autonomous rung",
"tags": [
"governance"
]
},
{
"id": "resilience",
"name": "Resilience & DR",
"description": "daily backup + off-box sync + automated restore-test (passing) + host watchdog + DR runbook, site back online within the hour",
"tags": [
"infrastructure"
]
},
{
"id": "visibility",
"name": "AEO/SEO Visibility Engine",
"description": "answer-engine + search visibility for tenants and sub-tenants: page audit (13 checks), fix generator (JSON-LD/FAQ/llms.txt), first-party POPIA-safe beacon",
"tags": [
"observability"
]
},
{
"id": "waste",
"name": "Waste Intelligence (W52)",
"description": "SA-compliance-native waste capture\u2192classify\u2192rollup\u2192report (SAWIS/EPR/ESG/accreditation/chargeback); Phase 2 report projections LIVE at GET /waste/reports over waste.captured/waste.disposed events",
"tags": [
"modules"
]
},
{
"id": "compliance_grounding",
"name": "Compliance & SOP Grounding",
"description": "per industry\u00d7country law + SOP packs; citation enforcement; safe-use ladder",
"tags": [
"governance"
]
},
{
"id": "notification",
"name": "Notification Relay",
"description": "transactional OTP/notifications from trusted khanyisa.net sender (DKIM)",
"tags": [
"content"
]
},
{
"id": "observation",
"name": "Observation / Distillation Signal",
"description": "auto-emit role.decision signal (bottom-up training + benefit signal)",
"tags": [
"observability"
]
}
],
"securitySchemes": {
"bearer": {
"type": "http",
"scheme": "bearer",
"description": "W32 service token, scoped per tenant (scope 'tenant:<slug>')."
}
},
"security": [
{
"bearer": []
}
],
"x_flocore": {
"governance": {
"human_approval": "every world-affecting action is gated on a human approval; the approver is server-bound and distinct from the requesting agent",
"tenant_silo": "per-(tenant\u00d7customer) isolation; a token may only act on its scope",
"audit": "every agent action is recorded in a durable event log"
},
"receipts": {
"algorithm": "Ed25519 + HMAC-SHA256 (legacy)",
"signer": "flocore",
"public_key": "GOaNNi8HguxI1-OZY1HPsjffWACXXTlCaV0rriZxdjw",
"verify": "verify `signature_ed25519` over `canonical` against `public_key` \u2014 offline, no secret, no call to FLOCORE. That is the point: you do not have to trust us.",
"legacy": "`signature` (HMAC) is symmetric and cannot be verified by a third party; kept for existing verifiers only.",
"key_status": "persistent"
},
"protocol_support": {
"a2a_agent_card": "implemented (this document)",
"a2a_task_lifecycle": "implemented (unverified against a real A2A client) \u2014 POST /a2a: message/send, tasks/get, tasks/cancel. A world-affecting ask returns an `auth-required` task; poll tasks/get until a HUMAN decides -> completed | rejected. A credential is required for every skill but the free screen, and only the asking agent can read its task. tasks/cancel is not supported yet: a parked task stays pending until a person decides or it expires, and cancel says so instead of claiming otherwise.",
"mcp": "implemented \u2014 POST /mcp (JSON-RPC 2.0, MCP 2025-11-25). READ tools answer directly; WRITE tools are gated on a HUMAN approval and return APPROVAL_REQUIRED rather than executing."
},
"alias": "https://fo.flocore.tech/.well-known/agent-manifest (the original, non-standard sibling)",
"generated_at": "2026-09-30T05:32:50.612278+00:00"
}
}