Skip to content

Protocol Governance Framework

This directory governs Bluefly's conformance to upstream protocol authorities. It is the protocol-authority parallel to standards/platforms/ (Provider Governance).


Provider Governance vs Protocol Governance

Provider Governance Protocol Governance
Authority type Platform / runtime provider Protocol specification body
Examples Apple, GitLab, Drupal, Docker, Gas City AG-UI, MCP, A2A, OpenTelemetry, OIDC
Relationship Consumer modernizes toward the provider Consumer conforms to the protocol specification
Evolution driver Provider releases (WWDC, GitLab releases) Protocol spec versions (RFCs, spec updates)
Bluefly obligation Adopt current provider APIs; migrate superseded ones Implement spec surface; use thin adapters; no proprietary extensions
Score PCS + LOS Protocol Conformance Score (PCS) + Proprietary Extension Score (PES)

Protocol Invariant

A specialization of the Capability Invariant for protocol authorities.

Blu Studio SHALL NOT implement capabilities already defined by upstream protocol authorities. Bluefly code exists to implement business semantics, orchestration, and user experience — not protocol behavior.

Local implementation of a protocol capability is a defect unless: 1. The protocol specification explicitly designates the implementation as consumer-owned. 2. No conforming SDK or library exists for the target platform. 3. Evidence is produced and tracked in the protocol's governance family.


Protocol Authority Classes

Interaction Layer

Protocol Authority Owns Bluefly Responsibility
AG-UI AG-UI project Agent ↔ user interaction: events, state, streaming Expose AG-UI as canonical UI interaction protocol; use @ag-ui/client
MCP Anthropic Tool invocation protocol Thin adapter; never reimplement the protocol
A2A Google Agent ↔ agent federation Thin adapter; never reimplement the protocol

AG-UI, MCP, and A2A are complementary, not competing. AG-UI governs agent–UI interaction; MCP governs tool invocation; A2A governs agent–agent federation. All three operate simultaneously within the same Blu Studio runtime.

Observability Layer

Protocol Authority Owns Bluefly Responsibility
OpenTelemetry (OTLP) CNCF Traces, metrics, logs Emit OTLP; use SDK; never build custom telemetry pipeline

Identity Layer

Protocol Authority Owns Bluefly Responsibility
OAuth 2.0 IETF Authorization framework Consume tokens; never reimplement OAuth flows
OpenID Connect OpenID Foundation Identity and authentication Use OIDC provider (Keycloak); never reimplement identity

Transport Layer

Protocol Authority Owns Bluefly Responsibility
HTTP / SSE IETF Synchronous and event-stream transport Use platform HTTP; never build custom transport
WebSocket IETF Bidirectional streaming Use platform WebSocket; never build custom framing
Git wire protocol Git project Repository transport Use Git CLI / libgit; never reimplement

Protocol Standard Family Structure

Each protocol follows the same three-level family as provider standards:

Level Document Owns
001 Protocol Authority What the protocol owns, what the spec defines, what Bluefly must never reimplement
002 Conformance Rules How Bluefly implements the protocol correctly; ratchet rules; deviation tracking
003 Verification Gate Protocol Conformance Score (PCS), Proprietary Extension Score (PES), receipts

Protocol Family Roadmap

Protocol Family Status Priority
AG-UI AGUI-001 / 002 / 003 🔲 Planned High — Blu Studio primary interaction protocol
MCP MCP-001 / 002 / 003 🔲 Planned High — tool protocol
A2A A2A-001 / 002 / 003 🔲 Planned High — agent federation
OpenTelemetry OTEL-001 / 002 / 003 🔲 Planned Medium
OAuth 2.0 / OIDC OIDC-001 / 002 / 003 🔲 Planned Medium
HTTP / SSE HTTP-001 / 002 / 003 🔲 Planned Low
WebSocket WS-001 / 002 / 003 🔲 Planned Low

Protocol Convergence Matrix — Blu Studio / agent-chat

Current state of protocol ownership in Blu Studio. Derived from the Capability Invariant. Recompute when the codebase changes.

Concern Current Implementation Authority Target Retention Justified?
Agent ↔ UI events useSSE.ts (custom transport) AG-UI @ag-ui/client ❌ No — remove after AG-UI adoption
Tool invocation Custom bridge MCP MCP SDK ❌ No — remove after MCP adapter
Agent federation Custom A2A A2A SDK ❌ No — remove after A2A adapter
Telemetry Partial / none OpenTelemetry OTLP SDK ❌ No — emit OTLP
Authentication Keycloak (OIDC) OpenID Connect Already consuming upstream ✅ Yes — OIDC via Keycloak

Protocol Convergence Score: 1 conforming / 5 assessed = 20% (Authentication is the only item currently consuming the upstream protocol correctly)


Blu Studio Authority Architecture

Every layer maps to an upstream authority. Bluefly owns only the Business Layer and OSSA.

Layer                    │  Authority
─────────────────────────┼──────────────────────────────────────
Business Layer           │  Bluefly (OSSA, workflows, UX)
─────────────────────────┼──────────────────────────────────────
Interaction Layer        │  AG-UI
─────────────────────────┼──────────────────────────────────────
Agent Layer              │  OSSA Runtime
─────────────────────────┼──────────────────────────────────────
Interoperability Layer   │  MCP (tools) + A2A (agents)
─────────────────────────┼──────────────────────────────────────
Observability Layer      │  OpenTelemetry (OTLP)
─────────────────────────┼──────────────────────────────────────
Identity Layer           │  OpenID Connect (via Keycloak)
─────────────────────────┼──────────────────────────────────────
App Framework Layer      │  Next.js / SwiftUI / React
─────────────────────────┼──────────────────────────────────────
Platform Layer           │  Apple / Node.js / WebKit

The only Bluefly-owned layers are the Business Layer and OSSA Runtime. Every other layer has an identified upstream authority that Bluefly converges toward.


Capability × Authority × Responsibility

Capability Authority Bluefly Responsibility
React rendering Meta None — consume as-is
AG-UI event streaming AG-UI Conformance — implement spec, use @ag-ui/client
Tool protocol (MCP) Anthropic Thin adapter — never reimplement protocol
Agent federation (A2A) Google Thin adapter — never reimplement protocol
OSSA runtime Bluefly Full ownership — unique Bluefly contribution
Business workflows Bluefly Full ownership — unique Bluefly contribution
Telemetry protocol OpenTelemetry Conformance — emit OTLP via SDK
Identity / auth tokens OpenID Foundation Consume — use Keycloak as OIDC provider
SwiftUI rendering Apple None — consume as-is
Swift concurrency Apple None — consume actor, async/await