Protocol Governance Framework¶
This directory governs Bluefly's conformance to upstream protocol authorities.
It is the protocol-authority parallel to standards/platforms/ (Provider Governance).
Provider Governance vs Protocol Governance¶
| Provider Governance | Protocol Governance | |
|---|---|---|
| Authority type | Platform / runtime provider | Protocol specification body |
| Examples | Apple, GitLab, Drupal, Docker, Gas City | AG-UI, MCP, A2A, OpenTelemetry, OIDC |
| Relationship | Consumer modernizes toward the provider | Consumer conforms to the protocol specification |
| Evolution driver | Provider releases (WWDC, GitLab releases) | Protocol spec versions (RFCs, spec updates) |
| Bluefly obligation | Adopt current provider APIs; migrate superseded ones | Implement spec surface; use thin adapters; no proprietary extensions |
| Score | PCS + LOS | Protocol Conformance Score (PCS) + Proprietary Extension Score (PES) |
Protocol Invariant¶
A specialization of the Capability Invariant for protocol authorities.
Blu Studio SHALL NOT implement capabilities already defined by upstream protocol authorities. Bluefly code exists to implement business semantics, orchestration, and user experience — not protocol behavior.
Local implementation of a protocol capability is a defect unless: 1. The protocol specification explicitly designates the implementation as consumer-owned. 2. No conforming SDK or library exists for the target platform. 3. Evidence is produced and tracked in the protocol's governance family.
Protocol Authority Classes¶
Interaction Layer¶
| Protocol | Authority | Owns | Bluefly Responsibility |
|---|---|---|---|
| AG-UI | AG-UI project | Agent ↔ user interaction: events, state, streaming | Expose AG-UI as canonical UI interaction protocol; use @ag-ui/client |
| MCP | Anthropic | Tool invocation protocol | Thin adapter; never reimplement the protocol |
| A2A | Agent ↔ agent federation | Thin adapter; never reimplement the protocol |
AG-UI, MCP, and A2A are complementary, not competing. AG-UI governs agent–UI interaction; MCP governs tool invocation; A2A governs agent–agent federation. All three operate simultaneously within the same Blu Studio runtime.
Observability Layer¶
| Protocol | Authority | Owns | Bluefly Responsibility |
|---|---|---|---|
| OpenTelemetry (OTLP) | CNCF | Traces, metrics, logs | Emit OTLP; use SDK; never build custom telemetry pipeline |
Identity Layer¶
| Protocol | Authority | Owns | Bluefly Responsibility |
|---|---|---|---|
| OAuth 2.0 | IETF | Authorization framework | Consume tokens; never reimplement OAuth flows |
| OpenID Connect | OpenID Foundation | Identity and authentication | Use OIDC provider (Keycloak); never reimplement identity |
Transport Layer¶
| Protocol | Authority | Owns | Bluefly Responsibility |
|---|---|---|---|
| HTTP / SSE | IETF | Synchronous and event-stream transport | Use platform HTTP; never build custom transport |
| WebSocket | IETF | Bidirectional streaming | Use platform WebSocket; never build custom framing |
| Git wire protocol | Git project | Repository transport | Use Git CLI / libgit; never reimplement |
Protocol Standard Family Structure¶
Each protocol follows the same three-level family as provider standards:
| Level | Document | Owns |
|---|---|---|
| 001 | Protocol Authority | What the protocol owns, what the spec defines, what Bluefly must never reimplement |
| 002 | Conformance Rules | How Bluefly implements the protocol correctly; ratchet rules; deviation tracking |
| 003 | Verification Gate | Protocol Conformance Score (PCS), Proprietary Extension Score (PES), receipts |
Protocol Family Roadmap¶
| Protocol | Family | Status | Priority |
|---|---|---|---|
| AG-UI | AGUI-001 / 002 / 003 | 🔲 Planned | High — Blu Studio primary interaction protocol |
| MCP | MCP-001 / 002 / 003 | 🔲 Planned | High — tool protocol |
| A2A | A2A-001 / 002 / 003 | 🔲 Planned | High — agent federation |
| OpenTelemetry | OTEL-001 / 002 / 003 | 🔲 Planned | Medium |
| OAuth 2.0 / OIDC | OIDC-001 / 002 / 003 | 🔲 Planned | Medium |
| HTTP / SSE | HTTP-001 / 002 / 003 | 🔲 Planned | Low |
| WebSocket | WS-001 / 002 / 003 | 🔲 Planned | Low |
Protocol Convergence Matrix — Blu Studio / agent-chat¶
Current state of protocol ownership in Blu Studio. Derived from the Capability Invariant. Recompute when the codebase changes.
| Concern | Current Implementation | Authority | Target | Retention Justified? |
|---|---|---|---|---|
| Agent ↔ UI events | useSSE.ts (custom transport) |
AG-UI | @ag-ui/client |
❌ No — remove after AG-UI adoption |
| Tool invocation | Custom bridge | MCP | MCP SDK | ❌ No — remove after MCP adapter |
| Agent federation | Custom | A2A | A2A SDK | ❌ No — remove after A2A adapter |
| Telemetry | Partial / none | OpenTelemetry | OTLP SDK | ❌ No — emit OTLP |
| Authentication | Keycloak (OIDC) | OpenID Connect | Already consuming upstream | ✅ Yes — OIDC via Keycloak |
Protocol Convergence Score: 1 conforming / 5 assessed = 20% (Authentication is the only item currently consuming the upstream protocol correctly)
Blu Studio Authority Architecture¶
Every layer maps to an upstream authority. Bluefly owns only the Business Layer and OSSA.
Layer │ Authority
─────────────────────────┼──────────────────────────────────────
Business Layer │ Bluefly (OSSA, workflows, UX)
─────────────────────────┼──────────────────────────────────────
Interaction Layer │ AG-UI
─────────────────────────┼──────────────────────────────────────
Agent Layer │ OSSA Runtime
─────────────────────────┼──────────────────────────────────────
Interoperability Layer │ MCP (tools) + A2A (agents)
─────────────────────────┼──────────────────────────────────────
Observability Layer │ OpenTelemetry (OTLP)
─────────────────────────┼──────────────────────────────────────
Identity Layer │ OpenID Connect (via Keycloak)
─────────────────────────┼──────────────────────────────────────
App Framework Layer │ Next.js / SwiftUI / React
─────────────────────────┼──────────────────────────────────────
Platform Layer │ Apple / Node.js / WebKit
The only Bluefly-owned layers are the Business Layer and OSSA Runtime. Every other layer has an identified upstream authority that Bluefly converges toward.
Capability × Authority × Responsibility¶
| Capability | Authority | Bluefly Responsibility |
|---|---|---|
| React rendering | Meta | None — consume as-is |
| AG-UI event streaming | AG-UI | Conformance — implement spec, use @ag-ui/client |
| Tool protocol (MCP) | Anthropic | Thin adapter — never reimplement protocol |
| Agent federation (A2A) | Thin adapter — never reimplement protocol | |
| OSSA runtime | Bluefly | Full ownership — unique Bluefly contribution |
| Business workflows | Bluefly | Full ownership — unique Bluefly contribution |
| Telemetry protocol | OpenTelemetry | Conformance — emit OTLP via SDK |
| Identity / auth tokens | OpenID Foundation | Consume — use Keycloak as OIDC provider |
| SwiftUI rendering | Apple | None — consume as-is |
| Swift concurrency | Apple | None — consume actor, async/await |