Protocol · v0.50.0
Protocol contracts are the authority model; adapters are not
@ruleoak/protocol defines shared contracts and validators. MCP, HTTP and application adapters map external requests into those canonical semantics.
Core sequence
Intent / proposed action
↓
Capability context
↓
Authority Grant / Authority Envelope
↓
Policy decision
↓
Approval when required
↓
One-use ExecutionLease
↓
Adapter invocation
↓
Observed effect
↓
EffectReceipt + observation quality
↓
Evidence graph / bundle
Adapter isolation
MCP is a first-class RuleOak adapter, not the RuleOak authority model. The v0.50.0 MCP path recognizes protocol generation 2026-07-28 and retains a compatibility codec for 2025-06-18 session-oriented deployments. Protocol-specific fields remain isolated from canonical RuleOak principal, action, resource, authority, lease and effect semantics.
Important distinctions
- An allowed policy decision is not proof that an external effect completed.
- An
ExecutionLeasegrants one bounded execution opportunity; replay is rejected. - An
EffectReceiptrecords what RuleOak observed and the quality/scope of that observation. - Unknown or ambiguous effects remain explicit; a successful transport response is not automatically remote-world confirmation.
- Extension metadata and capability discovery never grant runtime authority.
Verification vocabulary
Integrity, citation/evidence binding, semantic support, workload qualification, human review and effect confirmation are separate facts and must not silently promote one another.