The normative shapes. Each doc is scoped to one primitive so a module can be
checked against them one at a time. canon/ says why; these say exactly what.
| Doc | Primitive | Status |
|---|---|---|
module-surface.md | the HTTP routes and shapes every module exposes, with the conformance checklist | written 2026-08-17 |
job.md | the job envelope: fields, who sets them, correlation | planned (folded into module-surface.md and canon/03 for now) |
outcome.md | the four outcome types and their fields | planned (same) |
caller.md | the caller context, token claims, verifier port | planned (in canon/02 for now) |
usage-event.md | one metering event: fields, standard meters, guarantees | written 2026-08-17 |
manifest.md | the capability manifest, requirements, and the field registry (seed) | written 2026-08-17 at the session's default effort (high); xhigh pass wanted |
runner-verbs.md | the runner-to-payload interface: run(item, ctx) and every verb on Context, each with its witness | written 2026-08-17 |
caller-keys.md | per-module caller keys (option C): format, storage, expiry, rotation, transport, conformance rows | written 2026-08-18 |
conformance.md | the smoke suite a module runs against itself, measured against live services-api | landed 2026-08-18 (gcp-opus) |