Proof Ledger

Every MarketingOS claim should be visible in a run record.

The current source state has a complete specialist route record for both runtimes. OpenClaw 2026.6.10 executes eleven named specialists. The Hermes route record uses a dedicated local 0.18.2 proof build with one deliberately carried compatibility commit. Its exact identity is recorded in the hash bound receipt. It executes eleven installed roles through native delegate_task leaf sessions and retains partial runtime parity. Both runs produce eleven matching actions, receipts and evidence records, make SiteOne available to every route, reject 55 invalid variants each and keep externalWrites at 0. This is not a publicly signed customer release or an impact record.

CURRENT

Stock Hermes loads the native plugin

An inspection with stock Hermes Agent 0.18.2 loaded the dedicated MarketingOS profile. Eleven tools were expected and exactly eleven were observed. This record also verifies transactional uninstall. Inspection used no external network and exposed no token.

CURRENT

The native data tool surface is narrow

The plugin exposes MarketingOS context, sources, goals, SiteOne, actions, receipts, observations and outcomes. It exposes no terminal, filesystem, browser, web access, general execution, memory, skill management, Tool Search, MCP or foreign plugin tool.

INSTALLED

Hermes keeps a separate role layer

Twelve skills, twelve slash commands and one team bundle carry the orchestrator and specialist role logic. The delegate_task mapping targets native leaf sessions. The current agent surface contains the eleven plugin data tools plus delegate_task and nothing broader.

CURRENT

A local Hermes proof build executes all eleven specialist roles

The isolated Hermes 0.18.2 proof build with one deliberately carried compatibility commit binds every installed specialist role to a native delegate_task leaf session. Its exact build identity is recorded in the hash bound receipt. All eleven routes read a bounded synthetic source and produce a matching action, receipt and evidence record. The roles are not persistent named agents, so runtime parity remains partial.

BOUNDARY

Hermes Direct is not process containment

The tool allowlist accepts trusted local workloads only. Hermes Secure is unavailable and stops before mutation with hermes-secure-whole-process-unavailable. This is not untrusted or production approval.

CURRENT

OpenClaw executes all eleven named specialists

An isolated OpenClaw 2026.6.10 run installs the current orchestrator and all eleven specialists. Every route binds the installed role contract, context, source, action, receipt and evidence. SiteOne is available throughout. Fifty five invalid variants are rejected. externalWrites remains 0.

BOUNDARY

A source record is not a customer release

The run uses an isolated test mode with the current source and a synthetic .example source. It proves neither a publicly signed package nor installation on a separate customer machine or business impact.

BUILT

The installed product path understands workspace boundaries

Acquisition Verification and product installation come before onboarding and runtime attachment. The host agent supplies its exact runtime paths to the stable MarketingOS-Manage launcher. Product and runtime bind transactionally to the configured workspace.

BUILT

SiteOne has one model entry point

The installer verifies SiteOne 2.5.1, hides its binary path and process options from the model, and exposes marketingos_siteone_crawl only. This proves integration, not the state of a customer website.

BUILT

The managed Google review candidate has a narrow contract

Policy Authority, Capability Broker, Secret Broker, Audit Service and Secure Executor separate responsibilities. Exactly eight GSC, GA4 and GTM groups are selected incrementally. Three reads may run after authorization. The five writes are never autonomous and bind an exact target and payload, one-time approval, at most one provider attempt, a receipt, provider post-check and rollback or recovery. Google tokens remain outside the browser, Local Agent, OpenClaw, Hermes and models.

TESTED

Thirteen adversarial tests for the Audit Witness

The Witness maintains its own signed ledger and accepts only the next sequence from the last witnessed Audit head. All thirteen tests passed. The dedicated reviewer deployment runs it under a second operating system identity; that live evidence is not general customer release evidence.

OPEN

The public Windows release record is still open

A local Windows x64 development candidate has been verified with manifests, an SBOM, provenance, installer flows and extracted package tests. It is not a published, publicly signed customer package and has not been tested on a fresh customer machine. That real release lifecycle therefore remains open.

OPEN

The public release artifact is missing

There is no green receipt yet for a published commit and final signed customer artifact. SEO/GEO remains a Founding Partner Preview until that gate closes.

OPEN

Google review, general writes and customer outcomes

The managed Google connector is undergoing live validation only on dedicated reviewer infrastructure. This is neither Google approval nor a generally available customer release; Google review and general customer release remain open. General CMS, Bing and other external writes stay closed without their own connector contract. Claims about time saved, visibility, leads or revenue also require measurements from the right period.

Continue

From technical evidence to release

All eleven specialist routes are verified in current OpenClaw and Hermes source runs. A publicly signed customer release remains open. The managed Google connector is only a review candidate; general CMS, Bing and other writes stay closed.

Read the roadmap