# Mesh identity files

What AnalystOS publishes so a FlashyOS conformance check (or any agent) can
discover it, and what it deliberately does not.

| URL (once deployed at analystos.dev) | File in this repo | Format | Purpose |
|---|---|---|---|
| `/.well-known/flashyos.json` | `site/.well-known/flashyos.json` | `flashyos/1` handshake | Level 1: discoverable |
| `/.well-known/flashyos-charter.json` | `site/.well-known/flashyos-charter.json` | AAO 0.1 charter | Level 2: chartered |
| `/flashyos.roles.json` | `site/flashyos.roles.json` | same charter, legacy path | some estates serve both; a test keeps the bytes identical |
| `/.well-known/api-catalog` | `site/.well-known/api-catalog` | RFC 9727 linkset | points agents at the OpenAPI document and the API guide (generated by `tools/build_site_machine.py`) |

`vercel.json` serves these with the right content type (JSON, or
`application/linkset+json` for the catalog), `Access-Control-Allow-Origin: *` and a
5-minute cache. Other machine-facing files (`/llms.txt`, `/llms-full.txt`, `/docs/*.md`,
`/sitemap.xml`, `/robots.txt`) are generated from `docs/` by
`tools/build_site_machine.py`.

## The charter in one screen

Slug `analystos`; accountable human `30eventures@gmail.com`; escalation goes to
`verification`. Three standing roles, each with one number it moves. Every
measure must be computable from what the API's audit log records
(`docs/api.md`), so nothing is published that cannot be measured.

| Role | Family | Approval at or above | Measure |
|---|---|---|---|
| `analysis` | data | MEDIUM | reports delivered at the written tier, both gates passed, as a share of reports delivered |
| `verification` | risk | HIGH | facts refused for failing verification, as a share of facts proposed |
| `evidence` | governance | HIGH | delivered reports whose seal re-verifies offline, as a share of reports delivered |

## The handshake

```json
{ "mesh": "flashyos/1",
  "org": { "slug": "analystos", "name": "AnalystOS", "profile": "https://analystos.dev" } }
```

No `capabilities`: a capability is a claim that something is callable. Add
`"capabilities": ["document-analysis"]` only after `docs/api.md`'s endpoints are
deployed and an agent token exists.

## Check it

```
python3 -m analystos.aao site/.well-known/flashyos-charter.json     # ours (docs/aao.md)
npx @flashyos/conformance analystos.dev --level 2                   # FlashyOS's
```

To check a whole deployment (every advertised URL and content type, the charter,
the API's rewrites and that it fails closed), run one command:

```
python3 tools/smoke.py https://analystos.dev           # add --json, or --no-post
```

If Python reports a certificate error, the machine's Python has no CA bundle (the
python.org macOS build): use `SSL_CERT_FILE=/etc/ssl/cert.pem python3 tools/smoke.py`.
Run against analystos.dev on 2026-09-27 it passed 54 of 54 checks.

**Result, 2026-09-26:** the second command was run against the deployed site
(`@flashyos/conformance` 0.2.3, run with install scripts disabled) and exited 0:
Level 1 (Discoverable) and Level 2 (Chartered) both passed, every check ticked.
The package's published code was read before it was run: it makes only GET
requests to the domain (and, at Level 3, to `api.flashyos.com`'s public
conformance record), reads no local files for the check, and has no install
scripts. The source repository is private, so the published code was read, not
its source. Level 3 (the mark) is granted from FlashyOS's register and needs a
running agent; it is not attempted here. To repeat the run:

```
npm_config_ignore_scripts=true npx @flashyos/conformance@0.2.3 analystos.dev --level 2
```

## Deliberately not served

| File | Why not |
|---|---|
| `/.well-known/frontdoor.json` | `frontdoor/1` requires a working `endpoint` and a person who reads what arrives. Neither exists. |
| `/directory.fragment.json` | asserts people and relationships on someone's authority; the owner's decision. |
| `/.well-known/canon.json`, `backlog.json` | nothing to pin or publish yet. |

## Ownership and contact (stated by the owner, 2026-09-26)

30E Ventures owns AnalystOS and the `analystos` org on the FlashyOS network, and
`30eventures@gmail.com` is the accountable email. This is the owner's statement;
the public directory does not list org owners, so it is confirmed for real when
someone signs in at app.flashyos.com as that org.

## Open decisions before deploying

1. ~~Who owns the existing `analystos` org?~~ Answered above: 30E Ventures.
   Still worth confirming by signing in as that org before the handshake goes live.
2. ~~Is `30eventures@gmail.com` the right accountable human?~~ Yes, per the owner.
3. **Are the measures right?** They are computable, not yet computed.

## Not verified

Verified against the deployed site on 2026-09-26: Vercel serves `.well-known`
and the headers apply (JSON, `application/linkset+json`, CORS); our checker and
FlashyOS's Level 2 check both pass the live charter.

Still not verified:

- A real upload through `/api/v1/analyses` or the upload page's new download
  buttons (needs an access code or API key, and spends real model calls).
- That the `analystos` org is controlled by 30E Ventures on the FlashyOS network
  (the owner's statement; confirm by signing in at app.flashyos.com).
