Skip to main content
The qxctl knowledge session ... grammar opens noncanonical authenticated sessions through one exact bound coordinator and one TOPS-scoped SSIAG endpoint. A separate session features ... grammar drives the persistent SSFV maintenance stream.

Base session grammar

Session lifecycle
Every call requests a fresh exact grant and validates:
  • Subject and target identity
  • Policy and configuration state
  • Expiry
  • Caller-class neutrality
  • Non-transferability
  • Canonical-apply disablement
  • Capability binding
Session evidence authorizes only the named protected noncanonical operation. Keep session and reconciliation journals separate; use context references only to associate them.

SSFV maintenance stream

Features stream
The features stream is a separate persistent SSFV maintenance context. Mutations require:
  • An open authenticated base session
  • Exact coordinator and SSFV bindings
  • Stable operation identifiers
  • Exact compare-and-swap
  • Fresh SSIAG evidence
Preserve the baseline snapshot and its original engine identity across compatible upgrades or rollbacks. Optional Maestro evidence must be a complete authenticated inventory; when Maestro is intentionally absent, record the explicit not-configured reason. review_required is evidence for caller review, not ratification.

SSIAG

Issues the fresh grants each session request validates.

Session coordinator

The engine backing session and features journals.

qxctl reconcile

Reconciliation contexts that pair with sessions.

SSFV

The feature vector the features stream maintains.
Last modified on September 24, 2026