Invocation and local fallback
OwnsCapture state and allowlisted local intents
Must not inferWake or transcript cannot invoke a tool
Natural conversation with deterministic automotive authority.
A model proposes a bounded plan; the orchestrator owns credentials; policy decides; the native app renders typed state that generated wording cannot advance.
Every layer exposes an authoritative responsibility and an explicit non-authority boundary.
OwnsCapture state and allowlisted local intents
Must not inferWake or transcript cannot invoke a tool
OwnsSchema-bound language proposal only
Must not inferNo credentials, entitlement or state authority
OwnsTyped tools, credentials, risk, moving policy and result validation
Must not inferCannot claim downstream vehicle/partner completion
OwnsConversation phase, exact confirmation and sourced cards
Must not inferGenerated text cannot advance lifecycle
Each transition names both the action and the identity or version evidence that makes it reproducible.
Start approved capture with visible/audible state and interruption.
method · capture policy · sessionReturn a schema-valid plan with no direct tool access.
prompt/model route · output schema · plan revisionResolve tool registry, entitlement, occupant, moving state, risk and freshness.
tool/policy revisions · decisionBind protected target, consequence, evidence, expiry and exact revisions.
method · turn/plan/context/policy · idempotencyRender typed terminal or uncertain result with source-bearing cards.
operation state · result source · trace/evaluatorOccupant, surface, moving state, capabilities and versions.
Model isolation, operations, risk, permission and policy.
Target, consequence, evidence, expiry and revision binding.
Redacted context, tool/result, latency and release evidence.
Use exact signed local grammar for supported intents or show unavailable.
Block protected confirmation and require refreshed evidence.
Reject before tool invocation and avoid attackable policy detail.
Expose uncertain/not-dispatched; never narrate success.
Each product can be bought and operated independently while sharing identity, context and lifecycle contracts.
Confirm target products, vehicle and cloud boundaries, source systems, contract versions, deployment, validation and lifecycle ownership.