Skip to content
Back to FLOCORE

Card snapshot

fo.flocore.tech · 2026-09-30 05:32:52 UTC · 0427fc0901267bdab2ba14707b7fecdbadbb221e509996ef80e1780b33230e9d

This is a frozen copy of the agent's agent-card.json as we observed it at the timestamp above. We capture a new snapshot every time the card's content hash changes. Useful for: forensic drift analysis, verifying downstream callers see the right version, reproducing routing decisions made historically.

{
  "protocolVersion": "1.0",
  "name": "FLOCORE",
  "description": "AI-native operational intelligence platform - ontology + declarative workflow engine + agent mesh. The agent-readiness layer is the public face of a real multi-tenant operational platform, not a standalone gateway.",
  "url": "https://fo.flocore.tech",
  "preferredTransport": "JSONRPC",
  "provider": {
    "organization": "FLOCORE",
    "url": "https://fo.flocore.tech"
  },
  "version": "flocore.agent-manifest/v1",
  "documentationUrl": "https://fo.flocore.tech/.well-known/agent-manifest",
  "capabilities": {
    "streaming": false,
    "pushNotifications": false,
    "stateTransitionHistory": true
  },
  "defaultInputModes": [
    "application/json"
  ],
  "defaultOutputModes": [
    "application/json"
  ],
  "skills": [
    {
      "id": "identity",
      "name": "Identity & Access",
      "description": "OTP\u2192JWT \u00b7 introspect \u00b7 revoke \u00b7 service-tokens \u00b7 RBAC",
      "tags": [
        "identity"
      ]
    },
    {
      "id": "events",
      "name": "Event Backbone",
      "description": "ingest/route/replay events across systems (loose-coupling bus) + audit",
      "tags": [
        "events"
      ]
    },
    {
      "id": "sentinels",
      "name": "Sentinel Fleet",
      "description": "9-sentinel fleet under 5 Guardians (Drift\u00b7Freshness\u00b7Fraud\u00b7User-Behaviour\u00b7AEGIS\u00b7Availability\u00b7Exposure\u00b7Compliance\u00b7Visibility); observe\u2192signal\u2192auto-ticket\u2192score",
      "tags": [
        "observability"
      ]
    },
    {
      "id": "operational_trust_score",
      "name": "Operational Trust Score",
      "description": "fuses every Guardian's signal into one 0-100; rolls up site\u2192customer\u2192tenant; the Orchestrator conducts a fleet sweep (many signals in, one number out)",
      "tags": [
        "observability"
      ]
    },
    {
      "id": "aegis",
      "name": "AEGIS, AI Counter-Intelligence",
      "description": "self-learning AI guardian: prompt-injection/exfil pre-flight on /ai/gateway; 4 watch-domains (human-intrusion, exposure/drift, AI-adversary, OSINT self-recon); defensive-only, human-gated, watch-the-watchers",
      "tags": [
        "ai"
      ]
    },
    {
      "id": "advatar",
      "name": "Advatar, the Governed Front Door for Agents",
      "description": "the free aegis_inspect screen, then the Human Gate, then a signed receipt, as one machine-readable rail any agent can discover and self-serve onboard to; every world-affecting step is human-gated, no autonomous rung",
      "tags": [
        "governance"
      ]
    },
    {
      "id": "resilience",
      "name": "Resilience & DR",
      "description": "daily backup + off-box sync + automated restore-test (passing) + host watchdog + DR runbook, site back online within the hour",
      "tags": [
        "infrastructure"
      ]
    },
    {
      "id": "visibility",
      "name": "AEO/SEO Visibility Engine",
      "description": "answer-engine + search visibility for tenants and sub-tenants: page audit (13 checks), fix generator (JSON-LD/FAQ/llms.txt), first-party POPIA-safe beacon",
      "tags": [
        "observability"
      ]
    },
    {
      "id": "waste",
      "name": "Waste Intelligence (W52)",
      "description": "SA-compliance-native waste capture\u2192classify\u2192rollup\u2192report (SAWIS/EPR/ESG/accreditation/chargeback); Phase 2 report projections LIVE at GET /waste/reports over waste.captured/waste.disposed events",
      "tags": [
        "modules"
      ]
    },
    {
      "id": "compliance_grounding",
      "name": "Compliance & SOP Grounding",
      "description": "per industry\u00d7country law + SOP packs; citation enforcement; safe-use ladder",
      "tags": [
        "governance"
      ]
    },
    {
      "id": "notification",
      "name": "Notification Relay",
      "description": "transactional OTP/notifications from trusted khanyisa.net sender (DKIM)",
      "tags": [
        "content"
      ]
    },
    {
      "id": "observation",
      "name": "Observation / Distillation Signal",
      "description": "auto-emit role.decision signal (bottom-up training + benefit signal)",
      "tags": [
        "observability"
      ]
    }
  ],
  "securitySchemes": {
    "bearer": {
      "type": "http",
      "scheme": "bearer",
      "description": "W32 service token, scoped per tenant (scope 'tenant:<slug>')."
    }
  },
  "security": [
    {
      "bearer": []
    }
  ],
  "x_flocore": {
    "governance": {
      "human_approval": "every world-affecting action is gated on a human approval; the approver is server-bound and distinct from the requesting agent",
      "tenant_silo": "per-(tenant\u00d7customer) isolation; a token may only act on its scope",
      "audit": "every agent action is recorded in a durable event log"
    },
    "receipts": {
      "algorithm": "Ed25519 + HMAC-SHA256 (legacy)",
      "signer": "flocore",
      "public_key": "GOaNNi8HguxI1-OZY1HPsjffWACXXTlCaV0rriZxdjw",
      "verify": "verify `signature_ed25519` over `canonical` against `public_key` \u2014 offline, no secret, no call to FLOCORE. That is the point: you do not have to trust us.",
      "legacy": "`signature` (HMAC) is symmetric and cannot be verified by a third party; kept for existing verifiers only.",
      "key_status": "persistent"
    },
    "protocol_support": {
      "a2a_agent_card": "implemented (this document)",
      "a2a_task_lifecycle": "implemented (unverified against a real A2A client) \u2014 POST /a2a: message/send, tasks/get, tasks/cancel. A world-affecting ask returns an `auth-required` task; poll tasks/get until a HUMAN decides -> completed | rejected. A credential is required for every skill but the free screen, and only the asking agent can read its task. tasks/cancel is not supported yet: a parked task stays pending until a person decides or it expires, and cancel says so instead of claiming otherwise.",
      "mcp": "implemented \u2014 POST /mcp (JSON-RPC 2.0, MCP 2025-11-25). READ tools answer directly; WRITE tools are gated on a HUMAN approval and return APPROVAL_REQUIRED rather than executing."
    },
    "alias": "https://fo.flocore.tech/.well-known/agent-manifest (the original, non-standard sibling)",
    "generated_at": "2026-09-30T05:32:50.612278+00:00"
  }
}