InOrbit RFCs
Platform
Every public RFC in this space, the open ones first.
The RFCs and studies are in English only.
Taken from the RFCs product on 2026-10-09.
Open
0040Chaos as a service, our test bench in the customer's networkopenThe chaos tool we test this platform with, rebuilt around the agent and run against this platform continuously - surface checks on every protocol, tests that must fail, honest load, budgeted faults, findings that replay - so the autonomous work we build has a bench that says what it broke; customers later, on the same parts.2026-10-03
0040.2Surface checks on every protocolopenGeneric checks for HTTP, gRPC, SSE, WebSocket, MQTT, GraphQL and MCP that ask each surface three questions (does it answer, does it answer in the declared shape, does it refuse a caller it cannot identify), run from our cloud for verified public hosts and from the agent for everything else.2026-10-030040.3Honest load through the agentopenThe open-loop pacer moves into the agent, drives operations read from the target's own OpenAPI document or protos, reports what was asked beside what was measured and what was sent beside what was counted, and stops at hard ceilings the plan and the agent's policy both set.2026-10-030040.4Faults through the agent's proxyopenThe agent becomes a reverse proxy in front of a service and injects latency, a share of errors and dropped connections from a small menu, each fault paid from a budget, ended by the agent itself when its lifetime runs out, and judged by an objective stated before it starts.2026-10-030040.5Scenarios as codeopenThe scenario file (targets, load, a timeline of faults and the assertions that decide pass or fail) lives in the repository beside the code it tests, names connections instead of addresses, is checked by iohr and the console before it runs, and runs from CI or an autonomous agent with a token that can only start runs.2026-10-030040.6Findings that replayopenAssertions on a service's own contract (status, shape, retried writes with an Idempotency-Key, pagination, refusals), each broken one kept as a finding with what was expected, what happened and the steps that led there, grouped by signature, shrunk to the fewest steps and replayed against another environment.2026-10-030040.7CapacityopenA sweep raises one parameter of a load run step by step, repeats every step, puts 95 % confidence intervals on p50 and p99, judges the contract at every point and names the knee in a sentence a person can act on, all inside the load ceilings.2026-10-030040.8Runs, schedules and the live viewopenEvery check, load, fault, scenario, sweep and replay becomes a run of an account that an autonomous agent or a person can start and read through the API, MCP and iohr, queued per account and per agent, scheduled, streamed live, compared before and after a change, announced as events and kept for a stated time.2026-10-030040.9Vantage points that do not share our fateopenSeveral agents per environment, each declaring the machine, network, power and provider it shares fate with, so a monitor counts as covered only when someone outside the target's fate watches it, goes down only when independent vantage points agree, and a bench that goes quiet is raised as an alert by a path that does not run on the platform.2026-10-030040.10Hosts and clusters, read firstopenThe agent reads what an engineer checks by hand on a machine and a cluster (disk, inodes, memory, clocks, certificates, units, node pressure, pods, restarts, warning events), each as a check kind with thresholds in checks.toml, read-only and named in the policy, with every action treated as a fault under its rules and no shell offered.2026-10-030040.11Who may see whatopenProbes on every public route of the OpenAPI document that one account's token never reads another account's objects, a token without the route's scope is refused, revoked and expired tokens stop working within the stated window, limits answer 429 with a time, and CORS, security headers, TLS and URL-fetching guards hold; reported as findings with the route and the expected and actual status, never a body.2026-10-030040.12Consistency across surfaces and dataopenThe same read over REST, gRPC, GraphQL, the WebSocket mux and the event stream gives the same answer, compared by normalised shape and ids in memory; a write is read back on every surface within a stated window, lists agree with their totals, events for a write arrive with exactly its ids, and retries are idempotent across surfaces; contract-level, writes only in probe accounts.2026-10-030040.13Journeys in a browseropenThe agent runs a headless Chromium under its policy and bounded in CPU, memory and time, plays journeys declared as steps (open, click by role, fill from a secret reference, expect, wait), times every step and the page's vitals, signs in through our own identity pages with a probe account and its second factor, and keeps a screenshot only on failure, only where the policy allows, for seven days.2026-10-030040.14The change verdict, for people and AI assistantsopenOne answer per change (pass, fail, regressed or incomplete), computed by rules over the per-claim verdict of RFC 0047 together with the repository's own CI result, the bench runs before and after, new findings and the guard checks, posted on the pull request with its evidence; required of our autonomous agents before they ask for a merge and after they roll; and the bench offered as MCP tools on the server RFC 0050 opened to every assistant, with thin plugins kept in a separate public repository that publishes nothing until the owner has read a review of each assistant vendor's terms.2026-10-03
Decided