Product proof

Can an agent approve a discount?
No.

That refusal is a product property, not a promise. Follow the question through policy, demonstration, evidence and limitation.

  1. Agent asks
  2. Discount
  3. Policy blocks
  4. Human decides
  5. Audit records
  6. Flow resumes

Buyer questions

What can the system establish independently?

Numeric benchmark results appear only after a protocol, environment, version, date, limitation and reproduction path exist.

Can policy reject an invalid decision?

Commercial policy is deterministic code, not a model's judgement: a renewal at or above the threshold stops and waits for a named human.

Benchmark dimension: Invalid-decision refusal

Limit: Proven for the built-in renewal object and its single value threshold. A general policy engine over arbitrary custom objects does not exist.

Inspect evidence

Can a human gate stay outside agent authority?

The agent cannot approve on the human's behalf. A test asserts the refusal, so the boundary is a property of the system rather than a promise in a README.

Benchmark dimension: Human authority boundary

Limit: In local-development mode the actor is asserted, not authenticated: no authentication ships, so an actor header there is not an identity. This holds a boundary against an honest agent, not against an attacker with network access.

Inspect evidence

Can the application describe itself?

One command tells an agent what an application actually is — packages, capabilities, resources, actions, policies, providers — read from checked-in source, in a single deterministic JSON report.

Benchmark dimension: Independent composition inspection

Limit: Source-only and read-only. It never opens the database, contacts a provider, reads a secret, or reports runtime, CI or authorization state — and it lists those blind spots as machine-readable limitations in its own output.

Inspect evidence

Can the result run without a hosted vendor runtime?

SQLite is Node's built-in node:sqlite. PostgreSQL requires one pinned runtime driver, pg@8.23.0. There is no ORM, no query builder, no build step and no framework underneath your framework.

Benchmark dimension: Source portability and hosted-runtime independence

Limit: Applications that select PostgreSQL carry pg@8.23.0. The SQLite path still needs no third-party driver. This is not a production-readiness claim and not shared-database tenancy; composition is dedicated-database, not row tenancy.

Inspect evidence
Implementation truth stays separate. Current proof and limitations come from the generated claims ledger, not from this product description.

Benchmark architecture

Product, agent and engineering benchmarks stay distinct.

A synthetic run is never presented as customer evidence. Where no equivalent baseline exists, comparisons cover architecture, responsibility and verification rather than invented competitor numbers.