Every card below maps to source that already exists in the sealed ActionGate lineage. “Engineering ready” means there is source-backed engineering material and testable contracts. It does not mean a legal customer has connected the integration, that an external vendor has certified it, or that StableMind has exercised it in a live customer environment.
Agent & Tool RuntimeMCP Governance
Govern Model Context Protocol tool calls as semantic action requests before consequential tool execution. Exact tool, arguments, target and authority bindings remain subject to ActionGate policy.
- SOURCE
- AG35
- STATE
- ENGINEERING_READY
- PROTOCOL
- MCP
- TRUTH
- ENGINEERING
Boundary: MCP connectivity does not grant tool authority. A reachable tool still requires current delegated authority and an exact decision.
Enterprise SaaSMicrosoft Enterprise
Source-backed Microsoft enterprise action evaluation with exact profile and authority binding. Designed to govern semantic enterprise actions without equating tenant access, app registration or token possession with permission.
- SOURCE
- AG38
- STATE
- ENGINEERING_READY
- PROTOCOL
- Microsoft enterprise adapter
- TRUTH
- ENGINEERING
Boundary: Tenant access and Microsoft credentials are capability inputs, never delegated machine authority.
Enterprise SaaSSalesforce Enterprise
Evaluate Salesforce actions against exact tenant, operation, object and authority bindings before execution. The adapter preserves semantic-action boundaries instead of treating an OAuth scope as permission to perform every reachable mutation.
- SOURCE
- AG39
- STATE
- ENGINEERING_READY
- PROTOCOL
- Salesforce enterprise adapter
- TRUTH
- ENGINEERING
Boundary: OAuth scopes constrain technical reach; they do not manufacture authority for a consequential Salesforce action.
Enterprise SaaSServiceNow Enterprise
Govern ServiceNow enterprise operations with exact instance, domain, role and operation profiles. Source contracts reject encoded-query expansion, dot-walk drift, role supersets and session identifiers at the authority boundary.
- SOURCE
- AG40
- STATE
- ENGINEERING_READY
- PROTOCOL
- ServiceNow enterprise adapter
- TRUTH
- ENGINEERING
Boundary: ServiceNow role membership or API reach does not authorize an agent to exercise every available operation.
Execution InfrastructureStableMind Connector Host
A bounded connector-host contract for running certified connector processes with deterministic handshakes, request binding, deadlines and receipts. It is the runtime boundary between an exact permit and an implementation-specific integration.
- SOURCE
- AG41
- STATE
- ENGINEERING_READY
- PROTOCOL
- actiongate.connector/1.0
- TRUTH
- ENGINEERING
Boundary: The host cannot broaden the Action Permit, invent a semantic action or retain credential material as standing capability.
Execution InfrastructureConnector Certification
Source-backed certification machinery checks connector packages, publisher signatures, subprocess behavior, credential redaction and deterministic receipts against the StableMind Connector Standard.
- SOURCE
- AG42
- STATE
- DEVELOPMENT_CERTIFICATION
- PROTOCOL
- StableMind Connector Standard v1
- TRUTH
- ENGINEERING
Boundary: A passing connector certificate proves package conformance to a scoped engineering contract. It never grants tenant-local action authority.
DeveloperConnector SDKs
Go, Python and TypeScript SDKs implement actiongate.connector/1.0 framing, invocation binding, credential redaction and deterministic result receipts for custom connectors.
- SOURCE
- AG42
- STATE
- ENGINEERING_READY
- PROTOCOL
- Go · Python · TypeScript
- TRUTH
- ENGINEERING
Boundary: SDK adoption makes integration easier; it does not bypass connector admission, authority checks, permits or customer policy.
Credential InfrastructureCredential Broker
Materialize short-lived technical capability only after an exact permit exists. Profiles bind route, target, credential type, scope, TTL and use count, with volatile handling and explicit revocation.
- SOURCE
- AG21
- STATE
- ENGINEERING_READY
- PROTOCOL
- JIT credential lease/injection
- TRUTH
- ENGINEERING
Boundary: Credential availability is downstream of authority. The broker cannot issue permission and cannot upgrade a commercial identity into machine authority.
Financial ActionPayment Connector
A payment-specific connector contract with preflight, exact action binding, JIT credential handling and reconciliation semantics for consequential financial workflows.
- SOURCE
- AG23
- STATE
- ENGINEERING_READY
- PROTOCOL
- Payment preflight + execution receipt
- TRUTH
- ENGINEERING
Boundary: Payment rails and bank credentials remain execution capability. Destination, amount and authority must still be independently governed.
Enterprise DataSupplier Connector
A source-backed supplier-information boundary emphasizing upstream identity, field minimization, freshness and a direct-mutation prohibition. Useful for authority and target resolution without turning read access into mutation power.
- SOURCE
- AG21
- STATE
- ENGINEERING_READY
- PROTOCOL
- Read-minimized supplier data
- TRUTH
- ENGINEERING
Boundary: The connector is read-oriented by contract and does not create supplier-change authority.
EcosystemExtension Gallery
Signed extension manifests, publisher identity, SBOM/provenance digests and declared capabilities support a governed extension ecosystem for connectors and evidence verifiers.
- SOURCE
- AG63
- STATE
- DEVELOPMENT_ECOSYSTEM
- PROTOCOL
- Signed extension manifests
- TRUTH
- ENGINEERING
Boundary: Gallery publication, publisher verification and extension installation create no standing authority and bundle no credentials.
EcosystemOpen Authority Ecosystem Lab
An open lab certification bundle exercises authority-aware ecosystem interoperability and conformance without promoting synthetic lab success into third-party production proof.
- SOURCE
- PT08
- STATE
- LAB_VERIFIED
- PROTOCOL
- Open conformance bundle
- TRUTH
- ENGINEERING
Boundary: Open ecosystem verification is engineering evidence only. It cannot certify a customer workflow or create action authority.