Reference
The core record, core.json v1.
core.json is the signature of a delivered repository: the record the client owns with the code. It names the framework services installed, their versions, the guardrail patch level and the support channel, so the tools know what to do. It also names the helpers the compiler needs to upgrade, migrate and patch the repository.
01
Readable by anyone, owned with the code.
It moves no data, holds no secrets and is plain JSON anyone can read. The client may set it aside and develop the code freely; while it is kept current, security patches and support updates reach the repository from the framework's official release, and the OS tools and support services remain Agentization Core products.
Readable, not encrypted.
Plain JSON, human and machine readable. No cipher, no hidden fields.
Compile, don't transfer.
The record tells the compiler and the OS tools what the repository carries. Nothing in it is client data.
In service, or out.
The record lists which services and which files the framework relies on. Changing those is the client's right and takes the repository out of service until re-signed; everything else is free to change.
Updates from one source.
Guardrail security patches and support updates are pushed only to the officially released repository; a diverged repository receives none until it is re-signed.
The published shape is the public one: it shows what a record declares, never the full internal document. v1 only ever gains fields, so a reader written against it keeps working. The core record in the glossary →
02
What the record declares.
Fifteen top-level fields. Four of them are required; the rest are written when they apply.
| Field | Shape | What it says |
|---|---|---|
| subject | "core" | "app" · required | What the record describes: a whole core, or one application delivered into a core. |
| id | string · required | The identifier of the subject: a core identifier such as core-014, or an application slug. |
| framework | { version } · required | The framework release the repository was compiled from, as a semantic version. Patches and support are matched against it. |
| custody | "client" | "consultancy" · required | Who holds the repository and the data it works on. Custody is the client's after handover. |
| host | "on-premise" | "cloud" | "single-machine" | Where the core runs, in the three delivery targets the framework supports. |
| tier | "operate" | "build" | "build-support" | The OS tier of the engagement. Accounts and wizard flows follow it. |
| image | { id, version, branch_of } | The deployable image the OS produced from the repository, and the branch it was taken from when the client branched. |
| targets | [ { id, kind, name } ] | The hosts the OS deploys to: dedicated, own-server or cloud. |
| helpers | [ { id, version, for } ] | The versioned helpers the compiler needs to upgrade, migrate or patch this repository. |
| patches | { hooks, ml, applied_at } | The hook and ML-guardrail patch levels applied to the image, and when. |
| services | [ { id, version, in_service, protected_paths } ] | The framework services the repository carries: the version each one runs, whether it is still in service, and the paths that service relies on. |
| guardrails | { patch_level, layers } | The guardrail patch level the repository is at, and which of the three layers are switched on. |
| support | { channel, level, consultancy } | The audit channel support requests are raised on, the support level the contract grants, and the consultancy that answers first. |
| apps | [ { id, kind, version, flows } ] | The applications delivered into the core, their kind and version, and the wizard flows each one was generated from. |
| signature | { issued_by, issued_at, digest } | Who issued the record, when, and a content hash of the canonical record. The digest detects change; it is a hash, not an encryption. |
draft 2020-12 · $id https://agentization-core.com/schemas/core.json/v1 · additive within v1 · a breaking change becomes core.json/v2
03
One record, filled in.
A demonstration core for a fictional insurer: two applications, three framework services, one support channel.
{
"$schema": "https://agentization-core.com/schemas/core.json/v1",
"subject": "core",
"id": "core-014",
"framework": { "version": "1.4.0" },
"custody": "client",
"host": "on-premise",
"tier": "build-support",
"image": { "id": "img-0142", "version": "2.4", "branch_of": null },
"targets": [
{ "id": "hv-stg-02", "kind": "own-server", "name": "staging" },
{ "id": "hv-prd-01", "kind": "own-server", "name": "production" }
],
"helpers": [
{ "id": "migrate-retrieval", "version": "v2", "for": "migrate" },
{ "id": "patch-hooks", "version": "v3", "for": "patch" }
],
"patches": { "hooks": "gr-115", "ml": "ml-021",
"applied_at": "2026-09-18T09:20:00Z" },
"services": [
{ "id": "audit-channel", "version": "v3", "in_service": true,
"protected_paths": ["generated/audit/", "agents/audit-channel/"] },
{ "id": "retrieval", "version": "v2", "in_service": true,
"protected_paths": ["generated/retrieval/"] },
{ "id": "task-queue", "version": "v2", "in_service": false,
"protected_paths": ["generated/queue/"] }
],
"guardrails": { "patch_level": "gr-115", "layers": ["hooks", "ml", "agents"] },
"support": { "channel": "CH-4", "level": 1, "consultancy": "exceed-solutions" },
"apps": [
{ "id": "claims-intake", "kind": "application", "version": "v2",
"flows": [{ "id": "intake-triage", "version": "v4" },
{ "id": "policy-lookup", "version": "v2" }] },
{ "id": "halvard-dev", "kind": "cli", "version": "v1",
"flows": [{ "id": "arch-check", "version": "v3" }] }
],
"signature": {
"issued_by": "agentization-core",
"issued_at": "2026-09-18T09:20:00Z",
"digest": "sha256:4f2b9c1d7a83e05f6b41cc9d20ae7318f5c6b0d4a91e2f7c83b5d6e0a142f9cb"
}
}
One service reads out of service here: the repository changed files that service relies on, so it takes no framework updates until it is re-signed. Everything outside those paths stayed the client's to change. The raw schema →
Where to go next
Read the vocabulary the record is written in, the protocols the compiler targets, or the delivery chapter that binds a repository to its framework release.