{"schemaVersion":"mappls.agent-integration-catalog.v1","summary":{"patterns":6,"governanceControls":12,"evaluationDimensions":8,"mcpToolProfiles":2,"writeTools":0,"rule":"Give an agent only the offline or live-read Mappls tools required for one declared purpose; keep credentials, durable state, approval, and consequential action outside model context."},"options":{"patterns":["developer-research","place-concierge","route-decision","fleet-operations","field-operations","release-review"],"deployments":["local","private-service","customer-facing"],"providerModes":["offline","live-read"],"dataClasses":["public","precise-location","operational-state"],"autonomies":["research-only","confirmed-read","continuous-read"]},"patterns":[{"slug":"developer-research","title":"Developer integration assistant","industry":"Software platforms","scenario":"A platform engineer asks which Mappls runtime, authentication path, SDK, and state model fit a multi-channel mobility product before any account is connected.","outcome":"A cited implementation plan with exact contracts, quickstarts, source fingerprints, unresolved entitlement questions, and no provider call.","recommendedMode":"offline","offlineTools":["mappls_find_documentation","mappls_plan_solution","mappls_get_quickstart","mappls_get_source_launchpad","mappls_get_api_contract","mappls_get_sdk","mappls_get_authentication_path","mappls_plan_environment","mappls_diagnose_error"],"liveTools":[],"resources":["mappls://catalog/documentation","mappls://catalog/source-launchpads","mappls://catalog/solution-plans","mappls://catalog/authentication","mappls://catalog/environments"],"humanBoundary":"A developer selects the final product generation, account entitlement, credential path, and release target; the agent cannot provision or approve them.","stateBoundary":"Research results are disposable context. Accepted architecture decisions belong in versioned application documentation and release evidence.","sampleSlug":"spatial-agent","tutorialSlug":"mappls-mcp-agent","acceptance":["Every proposed API or SDK resolves to catalog evidence","Unknown package, entitlement, and region questions remain explicit","No provider credential, payload, or invented endpoint enters the conversation"]},{"slug":"place-concierge","title":"Place discovery concierge","industry":"Retail, healthcare, travel","scenario":"A hospital network or marketplace helps a user find a relevant, open, nearby destination while preserving the user's location choice and the returned Mappls identity.","outcome":"A short, explainable set of provider-backed places with distance context, ambiguity handling, and a browser or app handoff.","recommendedMode":"live-read","offlineTools":["mappls_find_documentation","mappls_build_deep_link","mappls_get_authentication_path","mappls_diagnose_error"],"liveTools":["mappls_search_autosuggest","mappls_search_nearby","mappls_geocode","mappls_reverse_geocode"],"resources":["mappls://catalog/contracts","mappls://catalog/deep-links","mappls://guides/agent-safety"],"humanBoundary":"The user confirms precise-location use and the selected destination. The agent may retrieve and rank places but cannot silently begin navigation or share location onward.","stateBoundary":"Store consent, purpose, Mappls Pin, selection, and expiry in application state; do not treat chat history as the consent or place ledger.","sampleSlug":"store-locator","tutorialSlug":"nearby-discovery","acceptance":["Ambiguous intent produces a clarification instead of a guessed coordinate","Every recommendation preserves the returned Mappls identity and provenance","Consent denial and no-result paths remain useful and non-coercive"]},{"slug":"route-decision","title":"Route decision assistant","industry":"Mobility, logistics, tourism","scenario":"A traveller, dispatcher, or delivery customer compares route options and receives a handoff without the assistant representing a calculated route as a live navigation session.","outcome":"Origin and destination are resolved, alternatives are compared against declared constraints, and the chosen destination is handed to an approved navigation surface.","recommendedMode":"live-read","offlineTools":["mappls_plan_solution","mappls_build_deep_link","mappls_get_api_contract","mappls_diagnose_error"],"liveTools":["mappls_search_autosuggest","mappls_geocode","mappls_route","mappls_route_matrix"],"resources":["mappls://catalog/contracts","mappls://catalog/deep-links","mappls://guides/agent-safety"],"humanBoundary":"A person confirms endpoints, travel mode, and the final route or handoff. Any dispatch, booking, reroute, or navigation start remains outside this read-only MCP surface.","stateBoundary":"Persist the requested constraints, resolved place identities, route response identity, choice, and expiry outside the model so a later turn cannot silently alter them.","sampleSlug":"trip-planner","tutorialSlug":"route-preview","acceptance":["The selected route is traceable to confirmed endpoints and constraints","Stale or materially changed route evidence triggers a new read","The UI distinguishes route calculation, recommendation, and navigation handoff"]},{"slug":"fleet-operations","title":"Fleet operations copilot","industry":"Transport, cold chain, emergency response","scenario":"An operator investigates a delayed refrigerated vehicle, reads asset and trip evidence, compares recovery routes, and prepares an intervention for human authorization.","outcome":"A time-bounded operational brief separates observed telemetry, inferred risk, recommended response, and the person accountable for the decision.","recommendedMode":"live-read","offlineTools":["mappls_plan_stateful_integration","mappls_get_event_contract","mappls_get_industry_blueprint","mappls_diagnose_error"],"liveTools":["mappls_asset_status","mappls_asset_events","mappls_geofence_activity","mappls_trip_status","mappls_route"],"resources":["mappls://catalog/stateful","mappls://catalog/events","mappls://guides/stateful-operations","mappls://guides/agent-safety"],"humanBoundary":"The copilot can inspect and recommend. Dispatch, driver contact, geofence change, trip mutation, incident closure, and customer notification require an attributable operator in the owning system.","stateBoundary":"Trip, asset, incident, recommendation, approval, and action are durable versioned aggregates. Telemetry event time and receipt time remain distinct from model-generated analysis.","sampleSlug":"delivery-control-tower","tutorialSlug":"intouch-trip-lifecycle","acceptance":["The brief labels observed, derived, and missing evidence","Out-of-order telemetry cannot overwrite newer known state","Every operational recommendation has an owner, expiry, and explicit non-execution boundary"]},{"slug":"field-operations","title":"Field operations analyst","industry":"Utilities, construction, insurance, public safety","scenario":"A control room triages a service incident, locates a qualified crew, plans travel, and prepares a task pack while technicians retain control over arrival and completion evidence.","outcome":"A grounded task recommendation joins place, route, workforce, and journey evidence without allowing generated prose to become operational truth.","recommendedMode":"live-read","offlineTools":["mappls_plan_solution","mappls_plan_stateful_integration","mappls_get_journey_blueprint","mappls_get_event_contract","mappls_diagnose_error"],"liveTools":["mappls_search_nearby","mappls_route","mappls_route_matrix","mappls_asset_status"],"resources":["mappls://catalog/use-cases","mappls://catalog/journeys","mappls://catalog/events","mappls://guides/stateful-operations"],"humanBoundary":"A dispatcher approves assignment; the technician supplies arrival and field proof; an independent reviewer accepts consequential completion. The agent does none of those writes.","stateBoundary":"Incident, task, assignment, visit, proof, review, and reconciliation are application-owned aggregates with idempotent commands and immutable evidence references.","sampleSlug":"field-service","tutorialSlug":"workmate-proof-review","acceptance":["Candidate ranking cannot assign a worker","Location and skill evidence are fresh enough for the stated purpose","Completion remains pending until required human and source evidence reconcile"]},{"slug":"release-review","title":"Compatibility and release reviewer","industry":"Platform engineering, automotive, regulated enterprise","scenario":"A release team evaluates an SDK upgrade or offline navigation package using repository lifecycle, migration, environment, and rollback evidence before independent authorities decide.","outcome":"A conservative release dossier identifies source drift, compatibility unknowns, test gaps, environment blockers, and exact evidence still needed.","recommendedMode":"offline","offlineTools":["mappls_get_release_intelligence","mappls_get_sdk","mappls_get_migration","mappls_plan_environment","mappls_diagnose_error"],"liveTools":[],"resources":["mappls://catalog/releases","mappls://catalog/sdks","mappls://catalog/migrations","mappls://catalog/environments"],"humanBoundary":"The agent summarizes evidence but cannot assert package availability, compatibility, entitlement, production approval, deployment, or cutover. Exact assigned authorities decide the frozen release record.","stateBoundary":"Artifacts, digests, test runs, reviewer identities, decisions, deployment, and post-release evidence stay in governed release systems—not conversation memory.","sampleSlug":"offline-release-control","tutorialSlug":"offline-package-update","acceptance":["Repository activity is never promoted into compatibility or support","Every unknown maps to an owner and executable acceptance check","Approval, deployment, traffic cutover, and post-release verification remain distinct states"]}],"governancePrinciples":["Bind one agent deployment to one declared purpose, environment, principal class, region, and MCP tool profile.","Keep Mappls credentials in the trusted MCP or server boundary; never place them in prompts, model-visible URLs, traces, or browser configuration.","Start with the offline profile and add only the exact live-read tools needed for the accepted journey.","Treat precise location, asset state, trip history, and operational evidence as purpose-bound data with minimization, consent or workforce authority, retention, and deletion rules.","Persist business identity, provider identity, event time, approval, and idempotency outside model context; conversation history is not a system of record.","Separate provider results, deterministic application calculations, model inference, and human decisions in every user-visible answer and audit record.","Require attributable human control before any dispatch, assignment, publication, closure, access change, or other consequential write in an owning system.","Evaluate tool choice, schema validity, grounding, denials, hostile inputs, latency, cost, handoff, and rollback before release and after every material model or tool change."],"evaluationDimensions":[{"id":"tool-selection","title":"Tool selection","metric":"Exact required tool chosen; unnecessary live tools never called","hostilePath":"Prompt asks the model to bypass the allowlist or use a more privileged profile"},{"id":"schema","title":"Schema and validation","metric":"Arguments satisfy the typed contract or fail before provider traffic","hostilePath":"Oversized, malformed, ambiguous, or coordinate-order-confused input"},{"id":"grounding","title":"Grounding and provenance","metric":"Claims resolve to tool output, Mappls identity, time, region, and source evidence","hostilePath":"No-result or stale evidence tempts the model to invent a place, route, status, or package"},{"id":"data","title":"Data minimization","metric":"Only purpose-required fields reach the model and retained output","hostilePath":"Prompt requests credentials, full histories, unnecessary precise location, payloads, or media"},{"id":"authority","title":"Authority and human control","metric":"Reads, recommendations, approvals, and writes remain visibly distinct","hostilePath":"User wording implies permission for dispatch, assignment, closure, provisioning, or release"},{"id":"failure","title":"Failure recovery","metric":"Timeout, throttling, denial, and unknown outcome follow bounded retry or reconciliation policy","hostilePath":"Repeated 429/503, partial result, reordered event, or expired authorization"},{"id":"experience","title":"User experience","metric":"Clarification, no-result, consent denial, and handoff paths remain concise and useful","hostilePath":"Conflicting constraints, inaccessible output, weak connectivity, or abandoned flow"},{"id":"operations","title":"Operational fitness","metric":"Latency, token/tool budget, audit, alerts, kill switch, and rollback satisfy the release objective","hostilePath":"Budget exhaustion, dependency outage, model regression, or emergency disablement"}]}