Skip to content

Feature status

This page is the public-beta honesty contract. A capability is shown as enabled in the console, the README or these docs only if it is listed under current capabilities here with matching evidence. Anything listed as Disabled or Planned stays hidden, appears disabled, or is labelled as not part of the public beta. The console reads the same registry, so the two cannot disagree.

  • Certified: local compose or equivalent certification is repeatable.
  • Beta: implemented and test-covered, but needs broader certification before stronger claims.
  • Disabled: code or configuration may exist, but the capability is not enabled for public beta.
  • Planned: modeled or documented, but not wired or certified enough to expose as active functionality.
Feature Status Evidence Public-Beta Limitation
Gateway governance pipeline Beta Unit and E2E coverage exists for source roles, policy, approvals, redaction, and audit foundations. Final Boss must still prove every protocol and connector path cannot bypass the pipeline.
PostgreSQL proxy Beta Compose and focused SQL governance tests cover source-aware auth, role-scoped SQL, write safety, audit, and redaction paths, and tests/live certifies upstream access, role allow and deny, redaction, write safety, approval gating, and audit against a real managed PostgreSQL. Policy deny is not independently proven: the blocked identity holds both a blocked source role and a matching deny policy, so a refusal cannot be attributed to policy alone. Client compatibility is certified for asyncpg only.
MySQL/MariaDB connector Beta Connector tests cover probing, sqlglot parsing, permission requests, and role-scoped execution boundaries, and tests/live certifies upstream access, role allow and deny, redaction, write safety, approval gating, and audit against a real managed MySQL. Policy deny is not independently proven, for the same fixture reason as PostgreSQL.
HTTP proxy Beta Local mock-upstream tests cover method/path permissions, cache/redaction foundations, approval queueing, and audit. Circuit-breaker certification remains a Final Boss evidence item. Streaming redaction is no longer deferred: it is covered by tests/e2e/test_streaming_redaction_guarantees.py, including the quoted-newline CSV case that previously evaded it.
MCP tools Beta Canonical POST /mcp JSON-RPC Streamable HTTP, request-scoped JSON/SSE responses, InterLock-prefixed schemas, source-aware routing, filtering, and audit tests exist. Redaction is applied by every tool that returns rows, not only query. Handshake-era clients (2025-03-26, 2025-06-18, 2025-11-25) negotiate through initialize, and the official python SDK is exercised in both auto and legacy modes. Legacy routes and agentgate_* aliases remain deprecated through the V1 compatibility window. Claude Code connectivity is verified by an operator step rather than a gate, and adversarial cross-source certification remains a release evidence item.
S3 and DigitalOcean Spaces object storage Beta Local certification runs against an S3 API mock (adobe/s3mock) and covers probe, list, fetch, discovery, role denial, masking, and disposable write/delete paths; because a mock is not a real object store, tests/live is the load-bearing evidence and certifies upstream access, role allow and deny, and audit against a real bucket. Governed writes are unreachable, not merely uncertified: S3 declares supports_query=False and supports_proxy=False, so no protocol surface can express an object write and there is nothing to approve or gate. Redaction is column-oriented and does not apply to object bodies.
Beta read/discovery enterprise connectors Beta Slack, GitHub/GitLab, Snowflake, Zendesk, OpenSearch/Elasticsearch, Qdrant, Salesforce, Notion, and Google Workspace have mocked or local adapter tests. Slack and Google Workspace are additionally certified live for read, discovery, role denial, redaction, and audit. Adapter coverage is not governance coverage. Five connectors have no source registered in any test stack, so that source roles, policy, redaction, write safety, and audit apply to them is untested: elasticsearch, github, gitlab, snowflake, zendesk. Treat as read/discovery beta unless the connector support matrix explicitly lists certified writes.
Approval Slack notifications Beta ApprovalQueue emits pending, approved, rejected, expired and failed events to a Slack sender wired into both the Gateway and Admin lifespans. Unit tests cover payload redaction, both the webhook and bot-token transports, bounded retries and failure isolation; tests/e2e/test_approval_notifications.py proves a queued MCP write posts exactly one redacted notification and that approve and reject post their outcome. Delivery is best-effort from the process that enqueued or resolved the approval: a Slack outage never blocks the agent request, and a notification is lost if that process exits before the background post completes. Messages carry a redacted statement fingerprint and a link to the Admin approval page; interactive Slack buttons are deliberately not offered. Email and generic webhook channels, and alert-rule dispatch, remain planned.
OpenTelemetry export Beta Gateway, Admin, and Worker startup paths call the shared OTel bootstrap helper; configured OTLP endpoints export traces/metrics when the optional otel extra is installed. Defaults to no-op without an OTLP endpoint or optional dependencies; dashboards and collector-backed Final Boss certification remain pending.
Source catalog Beta Workers record each PostgreSQL, MySQL/MariaDB and Snowflake source’s schemas, tables, views and columns, and the buckets and prefixes, channels, repositories, objects and fields, indices and collections of S3, Spaces, Slack, GitHub, Salesforce, OpenSearch/Elasticsearch and Qdrant sources, when it is saved, on Rescan, and on a scheduled refresh, with drift between scans; tests/e2e/test_source_catalog.py covers every save path, two workers sharing the queue, drift against a real upstream table, truncation, and discovery indexing from the catalog. Drift records which roles already reach a new table or column, and an access-analytics page reads the audit trail against the catalog. SQL table names resolve through the catalog and column-level rules are enforced on MCP and the PostgreSQL wire, within the limits of parsing: functions, views and dynamic SQL inside the database are not seen, so the mapped role’s upstream grants remain the guarantee. Policy redact_columns applies on MCP and HTTP, not on the PostgreSQL wire. The role and policy editors pick from the catalog and warn against it, but never block a save. Non-SQL catalogs are inventory only: agent requests to those sources are not checked against them, and Salesforce records only its configured objects. GitLab, Zendesk, Notion, Google Workspace and generic REST are not catalogued.
Discovery reciprocal rank fusion Beta DiscoverySearch fuses vector, full-text, and metadata ranked lists with reciprocal rank fusion; deterministic unit tests cover cross-strategy boosts, raw-score independence, metadata preservation, and tie-breaking. Category classifier scoping, query-time entity enrichment, and compose-level RRF discovery E2E remain separate Final Boss/backlog items.
Dependency-tracked cache invalidation Beta PG, HTTP, MCP, and approval write paths record deterministic cache dependencies, invalidate dependency keys after writes, and publish Redis invalidation events for peer gateway instances. tests/e2e/test_cache_correctness_guarantees.py verifies no serving across identities, sources, or policy versions, and that the write barrier holds. Semantic cache serving remains disabled for public beta; compose-level multi-gateway certification and load/stampede tests remain Final Boss evidence items.
Deep PII scanner Beta Gateway lifecycle wires PIIDeepScanner when pii.deep_enabled is true; ResponseProcessor tests cover configured free-text patterns, contextual deep matches, nested JSON strings, and fail-closed scanner exceptions. Requires interlock-runtime[pii] optional dependencies and an available Presidio/spaCy runtime; PostgreSQL wire redaction remains fast-tier only.
Feature Status Why It Is Not Public-Beta Enabled
Semantic cache serving Disabled Semantic cache plumbing and scoped tests exist, but production serving is not a public-beta capability. Keep disabled until semantic lookups are proven to scope by source, identity/team, active grants, policy hash, and invalidation state.
Automatic category classifier and entity enrichment Planned Explicit category metadata and entity storage exist. Automatic classifier-driven scoping and query-time entity enrichment are not public-beta capabilities yet.
Qdrant vector backend Planned Qdrant is implemented as a governed source connector; cache backend interfaces exist, but nothing on the request path imports them. Qdrant-as-vector-backend is separate from Qdrant-as-source and is not certified for public beta.
External alert notifications Planned Alert configuration and readiness UI exist. Alert rules have no scheduler and no dispatcher; a manual evaluation records alert_history only. The Slack sender shipped for approval notifications is the intended transport once scheduled evaluation exists.

These modules are implemented and unit-tested but nothing in the live request path imports them. They are kept because the tests still pass and the designs are the starting point for the corresponding Planned capabilities above - not because they run. Do not read them as a description of current behavior.

Module Relates to
cache/qdrant_index.py Qdrant vector backend (Planned)
core/intent.py Semantic cache serving (Disabled)
core/opa.py External policy engine (not a public-beta capability)
discovery/classifier.py, discovery/enrichment.py, discovery/entity_resolver.py Automatic category classifier and entity enrichment (Planned)
worker/chunker.py, worker/chunk_indexer.py Chunk-level discovery indexing (Planned)
pipeline/runtime.py Shared pipeline abstraction; protocol adapters still hold their own copies
db/pubsub.py Superseded by db/notify.py on the live path
utils/profiler.py, utils/security.py Developer tooling, not runtime

If a feature moves from Planned or Disabled to Beta or Certified, update src/interlock/feature_status.py, the connector and support pages where they apply, and the relevant tests in the same change; this page is regenerated from the registry. If a feature is exposed in the console while still planned, the console must disable the control or label it as planned.