Reference
What works today
A clear list of what works, what is limited to testers, and what is not ready yet.
Capability matrix
This table is generated from neo-capability-registry-v1. It describes code support and safety boundaries, not current deployment availability. The exact runtime truth is returned by /health and combines flags, immutable release observations, scenario evidence, and provider certification.
| Capability | Code | Required controls | Boundary |
|---|---|---|---|
| Published catalogue discovery | Implemented | Always available when deployed evidence agrees | Only published, active and in-stock catalogue facts are available. |
| Deterministic conversation policy | Implemented | ASSISTANT_DIALOGUE_POLICY_ENABLED | Planner-mediated turns retain deterministic safety and recovery boundaries. |
| Grounded response composition | Implemented | ASSISTANT_GROUNDED_RESPONSE_ENABLED | Generated copy is available only when the grounded composer flag and scenario evidence agree. |
| Buyer checkout Flow | Implemented | WHATSAPP_BUYER_CHECKOUT_FLOW_ENABLED | A signed checkout Flow stages data; only the separately confirmed action may write. |
| Payment initialization and confirmation | Implemented | AUTOMATED_COMMERCE_WRITES_ENABLED | Initialization is gated; only an authoritative callback confirms payment. |
| Refund execution | Implemented | AUTOMATED_COMMERCE_WRITES_ENABLEDPAYMENT_REFUNDS_ENABLED | Refund execution requires its kill switch, exact evidence and exact provider target. |
| Courier booking | Implemented | AUTOMATED_COMMERCE_WRITES_ENABLED | Booking requires the current accepted quote and exact logistics certification. |
| Seller catalogue import | Implemented | SELLER_CATALOG_IMPORT_ENABLED | Import remains preview-first, owner-bound and default off until exact Meta certification. |
| Seller payout transfer | Implemented | AUTOMATED_COMMERCE_WRITES_ENABLEDPAYOUT_TRANSFERS_ENABLED | Transfer requires explicit review, its kill switch and exact payout certification. |
| Seller attention | Implemented | RETENTION_SELLER_ATTENTION_ENABLED | Read-only seller attention remains independently switchable. |
| Post-purchase controls | Implemented | RETENTION_POST_PURCHASE_ENABLED | Post-purchase controls cannot mutate a provider without their existing action gate. |
| Cart-only reorder | Implemented | RETENTION_REORDER_ENABLED | Reorder creates a current cart only and never silently repeats payment or delivery. |
| Saved intents | Implemented | RETENTION_SAVED_INTENTS_ENABLED | Saved intent activation remains blocked unless the deployment and privacy prerequisites agree. |
| Consent-bound alerts | Implemented | RETENTION_ALERTS_ENABLED | Alerts require explicit purpose consent, current opt-out checks and delivery evidence. |
| Deterministic personalisation | Implemented | RETENTION_PERSONALIZATION_ENABLED | The current request wins; no sensitive or model-invented preference is accepted. |
| Privacy deletion fulfilment | Implemented | PRIVACY_FULFILMENT_EXECUTION_ENABLED | Completion requires every registered domain postcondition; destructive execution is independently default-off and provider records require reviewed evidence or an exact legal hold. |
Closed-beta boundary
Invite-only testers may be enrolled through an emergency phone allowlist or private signed share link. The secret-bearing first message is redacted before conversation storage. Access is phone scoped.
Sandbox logistics exercises state without a rider. Sandbox payouts exercise verification, review, transfer attempts, reconciliation, journals, and notifications without moving money. Test-mode checkout/refund does not prove live-money readiness.
Retention capability boundary
| Capability | Status | Boundary |
|---|---|---|
| Seller attention | Implemented / default off | Authoritative read only; closed-beta promotion is separate. |
| Post-purchase controls | Implemented / default off | Typed support requests cannot mutate a courier. |
| One-message reorder | Implemented / default off | Cart only; current price/stock and explicit reduced-cart choices. |
| Saved intents | Implemented / blocked | Cannot activate before complete privacy fulfilment. |
| Restock, price, and checkout alerts | Implemented / uncertified | Consent, template, target, opt-out, and reconciliation gates remain. |
| Personalisation | Implemented / default off | Current request dominates; no sensitive inference or model-created preference. |
These implementation states are not public acquisition claims. Loyalty, broad broadcasts, automatic recurring purchase, inferred refills, and automatic courier changes are excluded.
Known limitations
- No native mobile app.
- No general live payout, refund, or courier-booking claim.
- Privacy fulfilment execution is default off; provider work requires reviewed evidence or an exact legal hold before completion.
- Durable application lifecycle events and convergence scanners exist, but an external metrics and alert delivery service is not claimed.
- No item-level free-form conversational cart mutation.
- No seller team, broadcast, analytics, subscription, wishlist, gift, negotiation, supplier, or geospatial feature.
How this matrix changes
A runtime status changes only when implementation, reachability, deterministic scenario tests, immutable deployment evidence, enablement, and provider certification support the exact new wording. Roadmap placement and a successful sandbox run are not sufficient. Contradictory or missing evidence fails closed.
AGENTS.mddocs/NEO_OUTCOME_MESSAGING.mddocs/audits/neo-systemic-product-reliability-audit.mdsrc/capabilities.tssrc/capability-runtime.tssrc/provider-certification.ts
