AsiBackbone Product Documentation
This section organizes the Accountable Systems Infrastructure documentation for the stable 7.x release line around product implementation, API use, operations, compatibility, and release evidence.
AsiBackbone is a .NET governance package family for accountable software decision flow. See Project Boundaries and Non-Claims for the canonical boundary reference.
Documentation ownership
This repository is authoritative for concrete AsiBackbone package, API, configuration, runtime, integration, security, operations, compatibility, release, and maintainer behavior. See Documentation Ownership for the cross-repository ownership matrix.
General architectural education belongs in ASI Backbone Learning (source). Former conceptual URLs in this repository are retained as short product-mapping stubs for bookmark and inbound-link continuity; the left navigation now points directly to the canonical Learning treatments.
Current stable package posture
Stable 7.x package family. The current release is 7.0.0.
7.0.0 binds acknowledgment responses to the challenged actor and makes
unconfigured DLP failure behavior and risk levels fail explicitly instead of
inheriting a permissive zero value. Package IDs and the net10.0 target remain
unchanged. Four public namespaces move from the Handshakes and
CapabilityTokens vocabulary to Acknowledgments and CapabilityGrants; the
binary assembly identity advances to 7.0.0.0.
Released stable package surfaces include Core, DependencyInjection, Storage.InMemory, EntityFrameworkCore, AspNetCore, Testing, Templates, Analyzers, OpenTelemetry, Signing.LocalDevelopment, and Signing.ManagedKey.
Consumers upgrading from 4.0.0 must review the
5.0.0 Migration Guide. Hosts that persist the affected
enums as integers need a data migration, and call sites that relied on
permissive validation defaults now have to state what they are validating
against.
Event Hubs, Purview, Azure-specific non-signing SDK adapters, Aspire runtime packages, robotics, immutable storage, and additional non-signing provider packages remain design-only, strategy-only, sample-only, host-owned, or future-provider work unless a later stable release explicitly ships them.
The release process includes explicit Release Cadence and Readiness guidance for patch, minor, and major release selection, package metadata, Source Link, SBOM/provenance, documentation links, and future package identity or namespace changes. The current verification evidence is the 7.0.0 Consumer Verification Guide. Consumers moving from the previous stable line must also follow the Upgrade from 6.x to 7.0 guide.
Search and navigation
Use the header search box for package names, API concepts, and article titles. Search is enabled for the published DocFX site; if a newly merged page is missing from results, wait for the documentation publish workflow to finish and refresh the browser cache. Source files live under docs/ in the repository, and the site header includes a Repository link for source review or edits.
Overview
Use these pages to establish the product boundary before integrating the packages.
- Project Boundaries and Non-Claims
- Package and Integration Boundaries
- Target Framework Support
- Documentation Ownership
- 6.0 Product Terminology
- AsiBackbone API Terminology Map
- AsiBackbone API Glossary
- Core Governance Flow Diagrams
Get started
- Implementation-First Adoption Path
- First 15 Minutes: Standard API Gating
- AddAsiBackbone Builder Facade
- Getting Started
- Progressive Adoption Ladder
- dotnet new Templates
- Reference Deployment: Plain ASP.NET Core Host Evidence
Packages & API
Use the Generated API Reference for public types and members. These guides explain package-level integration boundaries and supported extension surfaces.
- Core API Domain Model
- ASP.NET Core Integration Boundary
- ASP.NET Core Endpoint Governance
- EF Core Integration Boundary
- EF Core JSON Metadata Storage
- EF Core Host Ownership and Migration Guidance
- Testing Harness
- Roslyn Analyzers
- OpenTelemetry Governance Emission Provider
- Signing Provider Package Boundary
- Managed-Key Signing Provider
- Schema Versioning
- API Compatibility and SemVer
Implementation guides
These pages describe what the runtime does and how hosts participate in the governed decision flow.
- Policy Evaluator Pipeline
- Threat Model Contributors
- Threat Outcome Reason Selection
- Threat Metadata Provenance
- Constraint Exception Policy
- Strict Governance Profile
- Regulated Governance Profile
- Custom Decision Policy Examples
- Acknowledgment Workflow
- Host-Owned Execution Enforcement
- Host Mutation Accountability
- Actor-Type Claim Trust Boundary
- Evaluator Concurrency Contract
- High-Throughput Host Service Guidance
- Endpoint Governance Development Diagnostics
Security & operations
These pages cover production hardening, durable audit/outbox behavior, observability, DLP, signing, verification, capability proof, and regulated-system concerns.
- Production Hardening: Evaluator and Outbox Configuration
- Durable Audit and Outbox Persistence
- Governance Outbox Delivery Semantics
- Hosted Governance Outbox Drain
- Outbox Multi-Worker Concurrency
- Outbox Drain Reliability and Alerting
- Governance Outbox Poison-Message Controls
- Observability and Governance Emission Architecture
- Governance Emission Contract
- Safe Audit and Telemetry Data
- DLP and Classification Failure Policy
- DLP and Classification Scanner Integration
- Signing-Ready Receipts and Key Handling
- Signed Audit and Outbox Records
- Verification Policy and Result Handling
- Key Rotation and Retired-Key Verification
- Capability Grant Hardening
- Capability Proof Trust Pinning
- Cryptographic Security Posture and Production Guidance
- Production Managed-Key Integration Guide
- Regulated Storage and Signing Verification Checklist
- NuGet Package Signing Decision Record
Samples & scenarios
- Plain ASP.NET Core Host Sample
- Aspire AppHost Sample
- NetCoreApplicationTemplate Host Validation
- NCAT Audit Completion Adapter
- AI Agent Gateway
- Human Approval Before AI Tool Execution
- High-Risk Administrative Action
- Sensitive Data Access Request
- Deployment or Infrastructure Change Gate
- Robotics Operational Gateway
Releases & compatibility
Start with the current release and compatibility rules. Older release notes, consumer-verification guides, and upgrade records are preserved under Releases & Compatibility so they remain easy to find without dominating the implementation navigation.
- 7.0.0 Release Notes
- 6.0.0 Release Readiness Record
- 6.0.0 Consumer Verification Guide
- Upgrade from 6.x to 7.0
- API Compatibility and SemVer
- Schema Versioning
- Target Framework Support
- Release and Upgrade History
Maintainer / quality evidence
Release-readiness records, benchmark reviews, coverage/mutation/concurrency evidence, documentation-claim validation, and maintainer checklists are published under Maintainer & Quality Evidence. They remain searchable and public, but are intentionally outside the normal consumer implementation path.
Historical records
Superseded design proposals, alpha-era package/readiness records, and historical API reviews are preserved under Historical and Superseded Records. These records are retained for traceability and should not be read as current package behavior.
Learn the architecture
For general architecture concepts, tutorials, comparisons, tradeoffs, labs, and broader governed-execution education, use ASI Backbone Learning.
Former conceptual URLs remain searchable as short continuity stubs, but canonical educational navigation points directly to Learning. Product-specific implementation, API, security, operations, compatibility, and release content remains authoritative here.