What the ceiling buys.
31 July 2026 · the launch journal
A procurement-class agent does not evaluate the way a human evaluator does. It arrives with a checklist and a spend ceiling, and it runs a three-step algorithm: match the surface against its checklist, verify the claims it can check mechanically, then spend or escalate. It does not read positioning. It does not book a call. It cannot be persuaded, because persuasion is not an input to any of its three steps. This entry is the surface that algorithm reads, written down in the order it reads it.
Step one: match
The agent's first question is whether this property serves its class at all. The answer is published, not inferred: /agent-classes.json is the single enumeration of agent classes, and /icp.json selects the ids this door serves — coding, integration, verifier, procurement — with the classification ladder (self-declared hint, then user-agent face, then declared fallback) stated as the contract a runtime selector actually executes. A procurement agent finds its class published at the door it arrived at, with the routes this property serves enumerated. Match is a lookup, not a judgment.
Step two: verify
The checklist's substance is conformance, and conformance here is stated as checkable fact. The conforms_to block of /icp.json, verbatim:
"epcis": "2.0.1 (pinned)" "schema_provenance": "validators precompiled over pinned official GS1 schemas; sha256 PINS.json" "gated_against": "OpenEPCIS reference vectors"
Each clause is mechanically verifiable, and the agent verifies rather than trusts. The pinned digests are on the conformance page — the official EPCIS 2.0.1 JSON schema pins at sha256 0f46ff694efffd8d8ce840a33dfde84228add11b516b8b258f3200740ae210af, retrieval date and source URL recorded, changes only by journaled human ruling. POST /validate on this origin returns that same digest inside every verdict, so the schema the validator ran is the schema the pin names — no trust bridge between the claim and the check. And the honesty constraint is published in the same file: no conformance attestation has ever been issued. A surface that states its negative space is one an agent can rely on; a surface that only states positives is one it must discount entirely.
Step three: spend — and what the ceiling buys
Here is the fact table the spend decision reads. The free zone is everything pure or bounded, published in no_ask_zone:
| verb | price | status |
|---|---|---|
| translate | free | live on this origin, no key |
| validate | free | live on this origin, no key |
| hash | free | live on this origin, no key |
| capture | $0/event | see the status line below |
The $0/event line carries its own status, quoted verbatim because quoting it is the point:
"INTENT, NOT TERMS (canon §0.13). Our intent is that recording an event never costs money. Until published terms bind it, that is a commitment we make, not a contract you hold. When prices are published this document will carry them in terms — or it will say we changed our mind."
A procurement agent parses that exactly right: capture-at-zero is a published intention with a named condition for becoming binding, not a price it can contract against today. Most surfaces would hide that distinction; this one types it, because an agent that discovers the distinction later is an agent that never returns. What the ceiling actually buys sits past the free zone, where the gates are declared: durable statefulness (retention, traces, custody evidence), authority (grants, seats), licensed data — and never compute. The reasoning behind that placement is The gate is never on compute.
The fourth step nobody designs for: escalate
When the ask exceeds the ceiling, the agent does not negotiate — negotiation is a human act, and simulating it produces the worst of both. It escalates with evidence: the contract for the deputized case, verbatim from /icp.json, is "the ask goes to the deputizing human; the agent carries realised value as proof." The escalation artifact is concrete: the corpus it translated and the per-job fidelity reports, the validation verdicts with the pinned schema digest cited, the §8.9 hashes computed, and the ask with its price. The human upstream receives realized value plus a bounded request — which makes the agent the internal champion, carrying better evidence than any sales deck, because every line of it is re-runnable.
That handoff only works if the evaluation was free — an agent cannot carry realized value it was never allowed to realize. The free zone earns the escalation.
Where the gates open
The evaluation surface described above is live on this origin today: the machine face, the pinned digests, the free engine doors, and npx epcis.dev on your own bench. The spend side — capture keys, seats, retention, and the published terms that would turn intent into contract — rides the dated ledger at /what-ships-today/. If your organization is the one deputizing a procurement agent: the key list takes your address first, asks a short branching set of questions about how you buy today, and locks. Keys are provisioned from that list, in order — one email when yours is ready.
We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.