askedAsked
A stable run records the user's objective, scenario, actor, tenant, purpose, and bounded inputs before any provider access.
Turn a natural-language spatial objective into an inspectable plan, obtain an exact least-privilege approval, execute allow-listed Mappls tools, and cite provider evidence without exposing credentials to the model.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
askedA stable run records the user's objective, scenario, actor, tenant, purpose, and bounded inputs before any provider access.
plannedA schema-valid allow-listed dependency graph, risk class, scopes, argument bounds, and canonical plan hash are available for inspection.
approvedAn attributable person approved the exact plan hash, every required scope, purpose, data boundary, policy version, and expiry.
executingA service-side lease owns execution and calls each Mappls tool only after dependencies and authorization are satisfied.
completedterminalThe grounded answer, structured outputs, exact tool evidence, provenance, citations, cost, and terminal audit event are committed.
rejectedterminalA named approver denied the proposed plan with an attributable reason and no provider calls occurred.
failedterminalExecution stopped with a typed, secret-safe error and retained evidence for every completed step.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
askApplication useragent.question_receivedUse a client-generated run command ID across network retries.
create_planAgent planneraskedagent.plan_createdCanonical objective, policy, planner version, and normalized plan produce one immutable hash.
approve_planHuman approverplannedagent.plan_approvedBind approver decision to run version, exact plan hash, scopes, purpose, and expiry.
reject_planHuman approverplannedagent.plan_rejectedPersist the review decision and reason under one command identity.
start_executionExecution serviceapprovedagent.execution_startedAcquire one lease only after recalculating plan hash and rechecking approval, scopes, expiry, and policy.
complete_executionExecution serviceexecutingagent.execution_completedCommit terminal result, citations, audit, and outbox against the execution attempt identity.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Durable objective, lifecycle, version, risk, actor, tenant, and purpose boundary.
runIdstateversiontenantIdquestionriskCanonical tool graph, dependencies, arguments, requested scopes, and integrity identity.
planVersionplanHashplannerVersionstepsrequiredScopespolicyVersionIndependent attributable authority for one exact plan and bounded time window.
planHashapprovedByapprovedScopespurposeapprovedAtexpiresAtResolved arguments, structured response, provider provenance, status, timing, and stable request identity.
toolCallIdstepIdtoolrequestIdprovenancecompletedAtAnswer and machine-readable outputs with per-step citations and inference labels.
runIdanswercitationsgeneratedAtmodelVersionThe model never receives Mappls or customer credentials.
Only schema-valid allow-listed tools and bounded arguments can enter a plan.
Approval names the canonical immutable plan hash and every required scope.
An expired, superseded, partially scoped, or self-approved plan cannot execute.
Every factual provider claim is traceable to retained Mappls provenance.
Tool failures and persisted evidence never expose secrets.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
The proposed tool, scope, host, or argument is absent from the validated plan policy.
Reject the plan or stop execution and surface the exact policy denial for human review.
Recomputed canonical hash differs from the approved plan hash.
Refuse execution, append a tamper or supersession event, and require a new review.
Execution lease expires with an ambiguous step and stable request identity.
Reconcile by provider or application request identity before retrying, especially for side-effecting tools.
Response-envelope validation or redaction policy fails.
Quarantine the output, stop the run safely, rotate any exposed secret, and retain only a sanitized incident record.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenarios/api/places/search/json/api/places/nearby/json/{REST_KEY}/{resources}/{profile}/{geopositions}/devicesmappls-rest-apismappls-intouch-rest-apis15 verified tests