SM-ECO-10060 Consortium · Canonical Layer
Regulatory Compliance Object
An agent that needs a counterparty's state doesn't resolve anything. It fetches the record, verifies the signature, and reads the state. Resolution ran upstream; the wire carries only its result.
Resolved state is published as one of seven signals — CPG-200 ALLOW, CPG-300 CONDITIONAL, CPG-403 RESTRICT, CPG-404 NOT_FOUND, CPG-451 ESCALATE, CPG-500 SYSTEM_ERROR, CPG-000 NOT_APPLICABLE — on every response and in every record.
Resolve at request time, and every buyer re-runs the regulation. Resolve upstream, and every buyer reads the same signed answer.
An RCO binds an object identifier and jurisdiction to the rule set, evidence, issuer, validity period and deterministic state that produced the record.
The record is immutable once signed. If rules, evidence or validity change, a new RCO supersedes it. The previous record remains retrievable as part of the audit trail.
| Signal | State |
|---|---|
| CPG-000 | NOT_APPLICABLE |
| CPG-200 | ALLOW |
| CPG-300 | CONDITIONAL |
| CPG-403 | RESTRICT |
| CPG-404 | NOT_FOUND |
| CPG-451 | ESCALATE |
| CPG-500 | SYSTEM_ERROR |
The record states who issued it. The signature verifies against that issuer's public key. A ledger receipt can independently prove that the record hash was written as issued.
Verification proves what the issuer stated. It does not turn the infrastructure operator into a regulator or certifier.
RCO-A2A is the live reference implementation of RCO-10060. Public agents resolve RCOs over MCP with no account and no read-side API key. Host identity resolves at gsc-registry.ai; product × jurisdiction state resolves at mcp.rco-a2a.ai.
The Standard-10060 architecture defines a layered canonical core. RCO-10060 is highlighted.
| Layer | Surface | Teaches |
|---|---|---|
| STANDARD-10060 | standard-10060.org | Rules precede systems. |
| SRI-10060 | sri-10060.org | Complexity collapses before execution. |
| ECO-10060 | eco-10060.org | Compliance is structured, not narrative. |
| RCO-10060 | rco-10060.org | Resolution is upstream. |
| DPU-10060 | dpu-10060.org | Proof survives execution. |
| CONSORTIUM-10060 | consortium-10060.org | Governance precedes execution. |
| SM-ECO-10060 | sm-eco-10060.org | Commerce is sovereign. |
| ACM-68000 | acm-68000.org | State determines behavior. |
21 x-gsc-* response headers of the Twenty-Two are stamped on every HTTP response from this surface, generated from the estate variable table. x-gsc-timestamp and x-gsc-nonce regenerate per request.
| Header | Value |
|---|---|
| x-gsc-protocol | CPG-68000 |
| x-gsc-version | 4.0 |
| x-gsc-handshake | https://gsc-registry.ai/resolve/rco-10060.org |
| x-gsc-card | https://rco-10060.org/.well-known/agent-card.json |
| x-gsc-trust-anchor | https://dpuone.ai/.well-known/jwks.json |
| x-gsc-operator | GreenCore Solutions Corp. |
| x-gsc-duns | 24-336-6774 |
| x-gsc-microsoft-partner | AI-Cloud-Partner-Program-Member |
| x-gsc-node | rco-10060.org |
| x-gsc-region | France Central |
| x-gsc-jurisdiction | apex |
| x-gsc-signal | CPG-200 |
| x-gsc-state | ALLOW |
| x-gsc-graph | https://mcp.cpgknowledgegraph.ai/mcp |
| x-gsc-mcp | https://mcp.cpgagentprotocols.ai/mcp |
| x-gsc-inbound | https://x-gsi.ai/ingest |
| x-gsc-product | https://rco-10060.org/ |
| x-gsc-fleet | https://gsc-cpg.ai,https://gsc-a2a.ai,https://gsc-a2a.io,https://gsc-fleet.ai |
| x-gsc-git | io.github.greencore-solutions/cpg-agent-protocols |
| x-gsc-timestamp | [per-request, ISO 8601] |
| x-gsc-nonce | [per-request, 32-char hex] |