Record format
@flashyos/aao
The AAO charter standard: named roles, a human accountable by email, and approval thresholds an agent cannot cross alone. The manifest spec, its JSON Schema, and the validators every checker in the estate imports.
version 0.4.2 · audit of 2026-10-04 · source: flashyos/packages/aao
npm i @flashyos/aaoAn Agentic Autonomous Organization publishes one charter at /.well-known/flashyos-charter.json — and the conformance suite reads it there and nowhere else. The charter names roles (governance labels), each with a family, a purpose, a measure, and the approval threshold above which a human must sign.
Two vocabularies are deliberately linked rather than merged: a role name is a governance label, a capability is a discovery tag, and every advertised capability must be answered for by some role — by name or through that role’s x-capability.
Commands
| Command | Does |
|---|---|
| npx @flashyos/conformance <domain> | audit a live domain against the charter it serves |
| npx @flashyos/conformance init | scaffold the charter, both well-known surfaces, and the test |
Edge cases — each one paid for once
One unknown top-level key fails all five static questions
The suite stops at the first invalid manifest, so a stray key that is neither a spec field nor x- prefixed makes a fully-populated roster read as an org that declared nothing. One _comment did exactly this to two rosters.
Role names cap at 24 characters
A role whose function has a longer name carries x-capability rather than a truncation. The vendored pre-install checker could not see this rule until the differential test compared it to the spec.
An empty family beats an invented role
The standard exists to stop roster inflation, not to reward it. Pre-revenue orgs honestly declare empty growth/revenue/support families.