Authority: Normative summary · Status: E3.1 control candidate implemented; selected-origin retrieval blocked · Applies to: E3 · Verified against: current checkout · Source:spec/atlas/ATLAS_CONTROL_PLANE_0_1.md,schemas/json/atlas-selection.schema.json,schemas/json/atlas-policy-set.schema.json,schemas/json/atlas-registry.schema.json
Purpose
The Atlas control plane makes breadth and depth independently inspectable. Its committed selection contains exactly 500 A0 candidates. A candidate is not a cataloged, policy-approved, profiled, observed, compiled, semantic, or live origin.review_required; its scheduler is disabled and its dry-run decision is
access_not_allowed. No candidate origin is contacted by these commands.
Data model
Policy and robots rules
An A2 origin must reproduce a dated human policy record covering robots, terms, attribution, authentication, rate, retention, and risk.allow,
deny, and review_required are distinct; absence and uncertainty do not
authorize access. The exact policy-set bytes are SHA-256 bound from the
registry.
The offline RFC 9309 evaluator is bounded at 500 KiB and has conformance,
malformed, percent-encoding, wildcard, longest-match, and fuzz tests. It has no
HTTP client. Robots rules inform crawler behavior but are not publisher
authorization or a factual claim about content.
Dry-run frontier
The frontier requires an explicit UTC planning time and emits only origin IDs, bounded budgets, due times, and visible decisions. It never emits a destination URL and carriesnetwork_access: disabled. A job requires an A2-or-higher
allow decision and active per-origin scheduler state; cooldown, policy denial,
review-required state, and disabled scheduling fail closed.
Read-only API
The implemented API is loopback-only:family, maturity, limit, and cursor are the only list filters. There is
no URL parameter, invocation route, write route, crawler, browser, model, or
HTTP client in this process.
Failure behavior and security
Duplicate keys, unknown fields, trailing JSON, duplicate origins, non-HTTPS or credentialed identities, quota drift, maturity skips, missing policy binding, unsafe scheduler state, incomplete attestations, and unbounded API queries fail closed. The server accepts only a literal loopback listener. Selected-origin observation remains disabled until the applicable policy changes toallow
and a separately admitted public-origin egress gate passes.