Diligence

Technical capability register

Complete catalogue for technical diligence. Buyer overview remains on Capabilities. States use production availability; staging-only surfaces appear as Roadmap or Integration required.

64 of 64

CapabilityDomainStateBoundaryLink

Organisation / Workspace

Workspace tenancy, isolation, membership, and client lifecycle.

AdminOperationalWorkspace lifecycle and onboarding are operational with logical isolation. Dedicated residency is roadmap.Open

Human Principal / Ownership

Users, roles, and ownership of agents within a workspace.

GovernOperationalRoles, invite, role change and revoke are operational. SSO and OIDC login require customer identity configuration.Open

Agent Registry

Register, identify, scope and revoke agents. Discover estate systems and promote into identity.

ObserveOperationalNot a full enterprise CMDB. Discovery promote is separate from authorisation.Open

Authority / Mandate

Delegated authority profiles and limits for agents.

GovernOperationalFinancial authority deepest; non-financial templates limited.Open

Action Gateway

ALLOW / ESCALATE / DENY before sensitive actions reach execution systems.

ControlOperationalValarIQ does not execute payments or hold funds.Open

Policy Engine

Policies and controls evaluated at decision time.

GovernOperationalCore refund defaults are operational via the Action Gateway. Expanded governance catalogues deepen with customer programmes.Open

Human Decision / Approval

Named approvers resolve ESCALATE outcomes.

ControlOperationalAdvanced dual-control patterns limited.Open

Evidence Envelopes

Signed evidence on decisions within implemented scope.

EvidenceOperationalSigned decision evidence is operational within implemented scope. Broader relationship traversal is provided by Evidence Graph.Open

Agent Flight Recorder

Chronological, evidence-linked agent record: identity, authority, context, policy, decision, approval and outcomes within tenant scope.

EvidenceOperationalOperational chronological record within tenant scope. Execution outcome remains unknown without verified provider confirmation. Independent timestamping is roadmap.Open

Evidence Graph

Relational governed graph over decisions, agents, context, evidence and controls with tenant-isolated traversal.

EvidenceOperationalOperational as a tenant-isolated relational graph over decisions, agents, context and controls. Not a dedicated graph database. Mapping is not certification.Open

Temporal Evidence Assurance

Preserves what was known and authorised at the time of an autonomous action, then tracks whether later changes make supporting assurance stale or require re-verification — without rewriting historical decisions.

EvidenceOperationalHistorical decisions stay fixed. Current assurance is assessed separately. External evidence providers, payment-rail confirmation, hardware key custody, independent timestamping and third-party verification remain separate capabilities. See Evidence Lifecycle for claim-scoped applicability.Open

Evidence Lifecycle

Keeps the historical truth of a control decision intact while assessing whether that evidence still supports a specific claim today — including when authority or context has changed — with re-verification and clear lineage.

EvidenceOperationalOperational for signed decision evidence. Completeness depends on what was captured when the decision was sealed. Confirming that a payment rail actually executed remains a separate capability. Re-authorisation after change requires a complete agent and policy setup.Open

Control Intelligence

Finance-first templates, deployment playbooks, control mappings, tenant-specific patterns and deterministic recommendations.

ExecutiveOperationalTemplates require tenant adoption. Playbooks do not self-certify readiness. Mappings do not imply compliance. Recommendations are SUGGESTED — not predicted ROI. Patterns are tenant-specific observations — no benchmarks. Provider reliability and execution outcomes remain Configurable without activated providers.Open

Context Assurance

Context Assurance verifies provenance, integrity, freshness, completeness and consistency of evidence used in autonomous-action decisions.

VerifyOperationalDeterministic core is operational. External evidence providers require integration. Does not independently guarantee that source facts are true.Open

Client Tenancy & Onboarding

Platform-operator client workspaces, lifecycle, invitations, and phased onboarding deliverables.

AdminOperationalPlatform admin does not access client business data. Bulk invite up to 50 per request. High-volume load testing not verified.Open

SMTP invitation delivery

Email delivery of workspace invitations when Resend or SMTP credentials are configured.

AdminOperationalInvitation delivery uses configured transactional email. Link-only fallback applies if email delivery is unavailable.Open

Consumption metering

Usage meters for control decisions, agents, and exports with included allowances.

AdminConfigurableFactual counters and overflow estimates only. Non-enforcing until meters verified. No service interruption on overflow.Open

Tenant data export

Workspace export requests with signed manifest checksums.

AdminConfigurableJSON archive with domain payloads (row-capped). Key hashes and invite tokens omitted. Object-storage delivery Roadmap.Open

Intent and Action Plan

First-class intent and action-plan objects in the autonomous-action chain.

VerifyOperationalIntent + Action Plan objects in the autonomous-action chain.Open

Authority Graph

Delegated authority edges, continuous re-evaluation, historical reconstruction.

GovernOperationalDelegated authority edges with draft/approve/activate/revoke and simulate.Open

Decision Contract v2

Extended outcomes with ALLOW_WITH_CONDITIONS; compat ALLOW/ESCALATE/DENY retained.

ControlOperationalControl API /api/v1/action-authority. Compat ALLOW/ESCALATE/DENY retained on /api/v1/decisions.Open

Execution authorisation

Short-lived single-use signed execution tokens. Authorised is not executed.

ControlOperationalEdDSA file-backed signing (not KMS/HSM). Single-use tokens; authorised is not executed.Open

MCP control adapter

Tool filter and tool-call authorisation adapter. Not a full MCP host.

ControlOperationalValarIQ MCP control adapter only (initialize/tools/list/tools/call). Not a full MCP host, generic orchestrator, or complete gateway platform.Open

A2A control adapter

Agent Card validation and task authorisation. Not an A2A orchestrator.

ControlOperationalValarIQ A2A control adapter only (Agent Card + task authorisation). Not an A2A orchestrator, generic orchestration layer, or complete gateway platform.Open

On-Behalf-Of identity

OBO claim validation. Customer IdP JWKS Integration required.

GovernIntegration requiredWithout a configured customer IdP, OIDC/OBO is Integration required — not Operational.Open

Deterministic rogue-agent detection

Explainable detectors (rate, deny streak, replay, mismatch). Not ML.

MonitorOperationalDeterministic explainable detectors only. Low-confidence alerts do not auto-contain.Open

ValarIQ-side scoped containment

Request/session/agent/workspace pause, quarantine, emergency stop. External kill Integration required.

MonitorOperationalValarIQ-side pause/quarantine/resume only unless externally confirmed. External process kill and enforcement connectors (MuleSoft/Kong) remain Integration required. No certified MuleSoft, Microsoft, Salesforce or Kong integrations.Open

Decision Ledger

Append-only hashed decision events. Not a blockchain.

VerifyOperationalTenant-scoped hash chain. Not a blockchain. No absolute immutability claim. Independent timestamping remains Integration required.Open

Agent Network visualisation

Workspace-scoped declared/observed graph with UNKNOWN telemetry labels.

ObserveOperationalWorkspace-scoped graph. Capped/paginated. No cross-tenant inference.Open

Execution confirmation

Authorised is not executed. Webhooks remain unverified until a provider is activated.

VerifyConfigurableStaging Operational: provider-neutral framework + Stripe test-mode adapter. Genuine customer Stripe accounts and production rails remain Configurable / MANUAL ACTION REQUIRED. No certified MuleSoft, Microsoft, Salesforce or Kong integrations.Open

Customer activation wizard

Guided controlled-deployment activation with finance packs and programme workflow.

AdminOperationalAvailable for configured customer deployments. Finance packs require tenant adoption and approval before enforcement. No certification claim.Open

Controlled Deployment Programme

Discover → Observe → Model → Review → Enforce → Assure with named enforcement approval.

AdminOperationalControlled deployment programme with named enforcement approval. Enforcement never auto-approves.Open

Policy simulation console

SYNTHETIC/SIMULATION observe-style policy replay without mutating history or issuing tokens.

ControlConfigurableNever issues execution tokens. Labelled SYNTHETIC.Open

Auditor evidence pack

One-click signed JSON evidence pack with redaction profiles and UNKNOWN fields.

AssureConfigurableSigned JSON canonical; ZIP optional later. Independent timestamping Roadmap.Open

AI asset discovery

Signed manifests, synthetic fixtures, and configured credentialed scanners for common cloud and repository sources.

ObserveOperationalSigned manifests, synthetic fixtures and configured credentialed scanners are available. Discovered assets are never auto-trusted. External integration is required before provider-confirmed execution can be claimed.Open

Ops Chat (Insights)

Grounded, read-only Q&A over workspace agents, Discover inventory, Decide queue, policy mode and decision pressure.

ObserveOperationalDeterministic answers from control-plane records only — not an LLM copilot. No writes, no payment execution, no invented estate state.Open

External vault / KMS references

Secret-reference interface. File-based signing remains active.

TrustIntegration requiredSecret-reference interface is present. File-based signing remains active. External vault or KMS integration is required before provider-backed key custody can be claimed.Open

Runtime

Runtime event ingestion and observation APIs.

ObserveOperationalIdempotent ingest and ops controls Operational; real external connectors not activated.Open

Assurance

Evidence vault, findings and assurance workflows.

EvidenceConfigurableNot certification. Vault and findings foundation Operational; full assurance programme depth continuing.Open

Monitoring / Response

Incidents, anomalies and ValarIQ-side containment.

ObserveOperationalExternal SIEM/containment deferred. ValarIQ-side containment only.Open

Executive Intelligence

Priority, decisions required, board packs — factual rollups.

ExecutiveConfigurableNo fabricated benchmarks or financial value claims. Keston Pulse disabled.Open

Enterprise / Portfolio

Hierarchy and portfolio aggregates with explicit grants.

EnterpriseConfigurableHierarchy does not grant access. OIDC login Configurable (activate per SAML metadata + SCIM Users/Groups scaffolding Integration required — not enforced IdP.Open

SDK / Gateway package

Node client wrapTool / decide / confirm / redeem / webhook verify helpers.

RuntimeConfigurableGateway client is available for integration programmes. Not distributed as a public package-registry release.Open

Webhooks

Outbound event delivery to customer systems.

RuntimeRoadmapNot operational in production. Customer webhook destinations remain roadmap until a controlled release.Open

MCP / A2A

Model Context Protocol and agent-to-agent control surfaces.

RuntimeRoadmapNot operational in production. Protocol control surfaces remain roadmap until a controlled release.Open

Billing & payments

Plan catalogue, usage meters, overflow estimates, and future invoicing for ValarIQ itself.

AdminConfigurableMetering UI and plan catalogue only. Stripe, invoicing, and payment collection inactive. customer programmes billing offline. No public fixed prices or contractual SLA. Operational Stripe activation:.Open

Independent penetration testing

Third-party security assessment of the production control plane.

TrustRoadmapNot scheduled. Vendor-ready scope in Required before regulated customer programmes diligence.Open

Universal Action Contract

Versioned vendor-neutral contract for consequential autonomous actions with ADE compatibility.

GovernConfigurableConfigurable for customer programmes. Not a payment rail. ValarIQ does not execute payments.Open

Continuous authorisation checkpoints

Append-only checkpoints from intent to post-execution with material-change invalidation.

GovernConfigurableFail-closed in Enforce; observable in Observe. Configurable until sustained Operational evidence (.Open

Context Assurance expansion

Provenance, freshness, corroboration and contradiction factors — no trust score.

GovernConfigurableExtends Context Assurance; does not demote existing CA Operational. Production Roadmap until verified.Open

Execution truth reconciliation

Authorised versus executed mismatch detection. Never moves money.

VerifyConfigurableStripe test-mode / fixtures only. Production Roadmap until verified. No real payment execution.Open

Delegated authority helpers

Delegation ceiling, non-delegable permissions, self-approval prohibition extending Authority Graph.

GovernConfigurableExtends Authority Graph; does not demote existing authority_graph Operational. Production Roadmap until verified.Open

Finance control packs

Versioned finance-first templates; tenant adoption required; Observe before Enforce.

GovernConfigurableAdoption is not certification. Production Roadmap until verified. Templates never auto-activate.Open

Policy interoperability adapters

Constrained IR import for Cedar/Rego/IAM/Entra. Never executes customer policy code.

GovernConfigurableConfigurable bounded adapter on staging. Production Roadmap until verified. Imported ≠ compliant.Open

Agent Passport

Governed portable record of agent identity, authority and assurance state.

GovernConfigurableNot an Entra identity or regulatory certification. Production Roadmap until verified.Open

Deployment assurance gates

Approval-to-operate states with evidence-backed gates. Not regulatory certification.

AssureConfigurableApproval to operate only. Production Roadmap until verified.Open

Counterfactual control simulation

SYNTHETIC replay against proposed policies without mutating historical evidence.

ControlConfigurableAlways SYNTHETIC for fixture replay. Configurable until bounded historical scale + Operational evidence pack signed (.Open

Action evidence chain projection

Causal Human→…→Evidence projection for Action Records. Not a blockchain.

VerifyConfigurableExtends Evidence Graph / Flight Recorder. Does not demote existing Operational. Production Roadmap until verified.Open

Control effectiveness measurement

Factual numerator/denominator effectiveness with SYNTHETIC excluded by default.

AssureConfigurableNever inferred from configuration alone. Production Roadmap until verified.Open

Offline verification toolkit

Standalone digest/signature/chain checks without DB or private keys.

VerifyRoadmapLocal RC only. Not published. Not certified. Production Roadmap until verified.Open

Tenant control intelligence

Tenant-only explainable analysis. Cross-customer benchmarking disabled.

MonitorConfigurableDoes not demote existing control_intelligence Operational. New tenant ATP surface is Roadmap in production until verified. Cross-customer disabled.Open

Provider reliability observations

Tenant-specific confirmation/mismatch rates with INSUFFICIENT_DATA below threshold.

VerifyRoadmapNo cross-customer rankings. Production Roadmap until verified with non-synthetic samples.Open

Control-pack catalogue foundation

Governed catalogue for ValarIQ/tenant/future partner packs. No marketplace payments.

GovernConfigurableNo commercial marketplace. No partner certification. Production Roadmap until verified.Open

Interoperability and partner adapters

Bounded reference adapters/fixtures for gateways, IdP and execution providers.

GovernRoadmapNo formal partnerships or certified connectors. Production Roadmap until verified.Open