SM-ECO-10060 Consortium · Canonical Layer

RCO-10060rco-10060.org

Regulatory Compliance Object

Resolution happens before the request, not during it.

Purpose

RCO-10060 is the deterministic resolution layer. It takes ECO-10060 compliance objects, resolves them against jurisdictional rules, and publishes the outcome as a signed, machine-verifiable record — before any agent asks.

An agent that needs a counterparty's state doesn't resolve anything. It fetches the record, verifies the signature, and reads the state. Resolution ran upstream; the wire carries only its result.

Resolved state is published as one of seven signals — CPG-200 ALLOW, CPG-300 CONDITIONAL, CPG-403 RESTRICT, CPG-404 NOT_FOUND, CPG-451 ESCALATE, CPG-500 SYSTEM_ERROR, CPG-000 NOT_APPLICABLE — on every response and in every record.

The unit One product. One jurisdiction. One signed state.

Operational Principle

Operational Principle Three layers: OBJECTS (the resolved compliance facts), RUNTIME (the context they were resolved in), HASHES (the signature that proves neither has changed). A record is immutable once signed; when rules, evidence or jurisdiction change, a new record supersedes it and re-signs. Resolution is served in production by RCO-A2A — mcp.rco-a2a.ai/mcp (four read tools), one signed record per object per jurisdiction, verified against the public keyring at dpuone.ai, receipted in Azure Confidential Ledger; the identity of every surface resolves at gsc-registry.ai/resolve/<host>.

Resolve at request time, and every buyer re-runs the regulation. Resolve upstream, and every buyer reads the same signed answer.

Scope

RCO-10060 does
RCO-10060 does not

What an RCO binds

An RCO binds an object identifier and jurisdiction to the rule set, evidence, issuer, validity period and deterministic state that produced the record.

The record is immutable once signed. If rules, evidence or validity change, a new RCO supersedes it. The previous record remains retrievable as part of the audit trail.

The CPG state vocabulary

SignalState
CPG-000NOT_APPLICABLE
CPG-200ALLOW
CPG-300CONDITIONAL
CPG-403RESTRICT
CPG-404NOT_FOUND
CPG-451ESCALATE
CPG-500SYSTEM_ERROR

Verification

The record states who issued it. The signature verifies against that issuer's public key. A ledger receipt can independently prove that the record hash was written as issued.

Verification proves what the issuer stated. It does not turn the infrastructure operator into a regulator or certifier.

Live

RCO-A2A is the live reference implementation of RCO-10060. Public agents resolve RCOs over MCP with no account and no read-side API key. Host identity resolves at gsc-registry.ai; product × jurisdiction state resolves at mcp.rco-a2a.ai.

RCO isn’t a compliance engine an agent calls — it’s the reason the agent never has to.

Position in the Canonical Stack

The Standard-10060 architecture defines a layered canonical core. RCO-10060 is highlighted.

LayerSurfaceTeaches
STANDARD-10060standard-10060.orgRules precede systems.
SRI-10060sri-10060.orgComplexity collapses before execution.
ECO-10060eco-10060.orgCompliance is structured, not narrative.
RCO-10060rco-10060.orgResolution is upstream.
DPU-10060dpu-10060.orgProof survives execution.
CONSORTIUM-10060consortium-10060.orgGovernance precedes execution.
SM-ECO-10060sm-eco-10060.orgCommerce is sovereign.
ACM-68000acm-68000.orgState determines behavior.

Ghost Headers v4.0 — fired on every response

21 x-gsc-* response headers of the Twenty-Two are stamped on every HTTP response from this surface, generated from the estate variable table. x-gsc-timestamp and x-gsc-nonce regenerate per request.

HeaderValue
x-gsc-protocolCPG-68000
x-gsc-version4.0
x-gsc-handshakehttps://gsc-registry.ai/resolve/rco-10060.org
x-gsc-cardhttps://rco-10060.org/.well-known/agent-card.json
x-gsc-trust-anchorhttps://dpuone.ai/.well-known/jwks.json
x-gsc-operatorGreenCore Solutions Corp.
x-gsc-duns24-336-6774
x-gsc-microsoft-partnerAI-Cloud-Partner-Program-Member
x-gsc-noderco-10060.org
x-gsc-regionFrance Central
x-gsc-jurisdictionapex
x-gsc-signalCPG-200
x-gsc-stateALLOW
x-gsc-graphhttps://mcp.cpgknowledgegraph.ai/mcp
x-gsc-mcphttps://mcp.cpgagentprotocols.ai/mcp
x-gsc-inboundhttps://x-gsi.ai/ingest
x-gsc-producthttps://rco-10060.org/
x-gsc-fleethttps://gsc-cpg.ai,https://gsc-a2a.ai,https://gsc-a2a.io,https://gsc-fleet.ai
x-gsc-gitio.github.greencore-solutions/cpg-agent-protocols
x-gsc-timestamp[per-request, ISO 8601]
x-gsc-nonce[per-request, 32-char hex]

Verification pointers

GET https://gsc-registry.ai/resolve/rco-10060.org # signed Registry facts record for this host
GET https://rco-10060.org/.well-known/agent-card.json # agent card
GET https://dpuone.ai/.well-known/jwks.json # estate keyring (trust anchor)
GET https://mcp.cpgagentprotocols.ai/mcp # authoritative MCP door
# MCP Registry listing: io.github.greencore-solutions/cpg-agent-protocols

Machine-Readable Surfaces

# Canonical surfaces — machine-readable training data; every URL verified 200 at build
GET https://rco-10060.org/manifest.json # node manifest
GET https://rco-10060.org/layer.json # this layer's canonical definition
GET https://rco-10060.org/protocol.json # Standard-10060 architecture
GET https://rco-10060.org/dataset.jsonld # schema.org dataset
GET https://rco-10060.org/.well-known/agent-card.json # A2A 0.3.0
GET https://rco-10060.org/.well-known/mcp.json # MCP door pointer — the standards MCP at mcp.cpgagentprotocols.ai
GET https://rco-10060.org/.well-known/acm-68000.json # protocol descriptor
GET https://rco-10060.org/.well-known/security.txt # RFC 9116
GET https://rco-10060.org/robots.txt # crawl directives
GET https://rco-10060.org/sitemap.xml # sitemap