CAPELLA AFEPCapella Agentic Full-Stack Engineering Platform for SAPAsk CAPELLA

PUBLIC PRODUCT TRUTH LEDGER

Inspect the claim before you believe it.

CAPELLA AFEP V0.7 exposes public-safe release truth, authority, evidence, limitations and verification boundaries. It is a transparency surface, not a marketing page.

CURRENT RELEASE

CAPELLA AFEP 0.7.4 / RELEASED

Released product commit d9c02ef163c5ff0cfd2e7efcfdd20daa82dbfa57 and current engineering main reviewed 5626baa41a9abcc3207c1691cf36fb0fca4940a8 are deliberately separate.

v0.7.4Release tag
0.13.1SFC
1.0.0A4Layer
2026-09-26Last website truth reconciliation

Claim → authority → evidence → limitation → verification

Major claims carry proof and invalidation conditions.

Unknown evidence remains unknown; no claim is promoted by code presence alone.

VERIFIEDCAPELLA AFEP 0.7.4 is RELEASED.Verify
Authority
Release provenance and website truth reconciliation
Source / provenance
d9c02ef163c5ff0cfd2e7efcfdd20daa82dbfa57
What proves this
The public product boundary is release 0.7.4 at tag v0.7.4.
What this does not prove
Post-release engineering main changes are not automatically 0.7.4 release features.
Release boundary
RELEASED_PRODUCT
What would make this false?
release commit changed; tag provenance changed; post-release main were presented as original release
Inspect source
DECISIONERCC_CONTRACT_HASH is not the executable mutation/config hash.Verify
Authority
CAPELLA authority model
Source / provenance
/architecture?focus=ercc
What proves this
ERCC owns the reasoning contract and bounded projection only.
What this does not prove
ERCC authorization, SAP execution or a runtime outcome.
Release boundary
CURRENT_MAIN_REVIEWED
What would make this false?
ERCC contract were used as execution authorization; GOVERN did not bind the executable configuration
Inspect source
VERIFIEDGOVERN binds approval to the exact executable configuration.Verify
Authority
GOVERN
Source / provenance
/architecture?focus=govern
What proves this
Qualified output cannot silently become a different authorized write.
What this does not prove
SAP will accept, activate or run the deployed artifact.
Release boundary
CURRENT_MAIN_REVIEWED
What would make this false?
bound execution contract changed; authorization expired; authorization was consumed; authorization provenance were stale
Inspect source
VERIFIEDRAP-04 runtime remained PLATFORM_BLOCKED and not runtime verified.Verify
Authority
SAP/runtime evidence classification
Source / provenance
CAPELLA_AFEP_0_7_4_RAP04
What proves this
Backend and deployment evidence can be verified while runtime verification remains false.
What this does not prove
End-user runtime execution.
Release boundary
CURRENT_GENERATION_CASE
What would make this false?
only deployment existence were observed; only AppIndex registration existed; runtime was platform blocked but shown as verified; execution proof was unavailable
Inspect source

Evidence lineage graph

ERCC contract hash is not the executable mutation/config hash.

The lineage shows how intent becomes evidence without collapsing reasoning, qualification, authorization, execution, SAP truth and claim publication into one authority.

  1. 01IntentCAPELLA
    Input
    Engineering request
    Output
    Bounded mission intent
    Claim class
    DEMONSTRATED
    Evidence
    Mission state and context boundary
    Boundary
    Intent is not authorization.
    Next authority
    ERCC reasoning contract
  2. 02ERCC reasoning contractERCC
    Input
    Intent + verified context
    Output
    ERCC_CONTRACT_HASH
    Claim class
    DECISION
    Evidence
    Frozen Engineering Task Contract
    Boundary
    Not executable mutation authority.
    Next authority
    SFC qualification
  3. 03SFC qualificationSFC 0.13.1
    Input
    Bounded SFC projection
    Output
    Qualified candidate
    Claim class
    VERIFIED
    Evidence
    Qualification and diagnostics
    Boundary
    Qualification is not approval.
    Next authority
    Executable mutation manifest
  4. 04Executable mutation manifestCAPELLA/SFC handoff
    Input
    Qualified candidate
    Output
    EXECUTION_CONFIG_OR_MUTATION_HASH
    Claim class
    VERIFIED
    Evidence
    Canonical physical artifact identity
    Boundary
    Different from ERCC_CONTRACT_HASH.
    Next authority
    GOVERN authorization
  5. 05GOVERN authorizationGOVERN
    Input
    Exact executable configuration
    Output
    Bound authorization state
    Claim class
    VERIFIED
    Evidence
    Approval provenance
    Boundary
    Stale or changed config blocks execution.
    Next authority
    Execution
  6. 06ExecutionA4Layer
    Input
    Approved configuration
    Output
    Execution result
    Claim class
    DEMONSTRATED
    Evidence
    Carrier result and operation record
    Boundary
    Provider capability is not SAP authority.
    Next authority
    SAP realization
  7. 07SAP realizationSAP
    Input
    Bounded execution
    Output
    Target-system state
    Claim class
    VERIFIED
    Evidence
    Readback, ATC, service/AppIndex evidence
    Boundary
    SAP remains final authority.
    Next authority
    Runtime classification
  8. 08Runtime classificationSAP/runtime
    Input
    Runtime access attempt
    Output
    VERIFIED / FAILED / PLATFORM_BLOCKED / UNVERIFIED
    Claim class
    VERIFIED
    Evidence
    Runtime observation vocabulary
    Boundary
    Deployment verified does not mean runtime verified.
    Next authority
    Evidence claim
  9. 09Evidence claimObservatory
    Input
    Observed proof
    Output
    Public claim + limitation
    Claim class
    VERIFIED
    Evidence
    Claim evidence record
    Boundary
    Unknown evidence stays unknown.
    Next authority
    Human review

Authority microscope

Seven authority layers. No hidden eighth layer.

CAPELLA

Product shell

Owns
Mission state, operator truth domains, role lens and evidence navigation.
Does not own
SAP authorization, SFC compiler authority, GOVERN approval authority or target-system truth.
Input
Engineering intent and public-safe context.
Output
Bounded mission state, selected next authority and evidence route.
Can block
Unsupported scope, missing context, unsafe transition or incomplete evidence.
Cannot authorize
SAP writes or runtime execution.
ERCC

Context & engineering contract

Owns
Reasoning contract, Current Context, assumptions, unknowns and bounded SFC projection.
Does not own
Executable mutation manifest, GOVERN authorization, A4Layer execution or SAP runtime authority.
Input
Mission intent plus verified context.
Output
ERCC_CONTRACT_HASH and bounded Engineering Task Contract.
Can block
Context contradiction, unknown authority, unsafe widening or unsupported scope.
Cannot authorize
SAP writes, Fiori deployment or live execution.
SFC

Compile and qualify

Owns
Compilation, qualification and SAP preflight evidence for supported candidates.
Does not own
Human authorization, execution approval or target SAP realization.
Input
Bounded engineering contract or supported delivery candidate.
Output
Qualified artifact set and qualification result.
Can block
Qualification failure, unsupported source shape or SAP preflight failure.
Cannot authorize
Execution or SAP/BTP writes.
GOVERN

Human approval

Owns
Authorization decision bound to the exact executable configuration.
Does not own
SAP runtime authority or A4Layer execution.
Input
Qualified artifact plus EXECUTION_CONFIG_OR_MUTATION_HASH.
Output
Approved, rejected, stale or consumed authorization state.
Can block
Stale authorization, changed execution identity, expired approval or missing owner decision.
Cannot authorize
A different execution configuration than the one approved.
A4LAYER

Governed execution

Owns
Bounded carrier execution after approval.
Does not own
SAP authorization outcome, target-system activation truth or runtime verification.
Input
Approved execution configuration.
Output
Execution result and SAP-facing delivery attempt evidence.
Can block
Provider capability unavailable, system carrier unavailable or missing approved config.
Cannot authorize
Its own execution without GOVERN approval.
SAP

Final authority

Owns
Target-system authorization, realized object state, AppIndex/service registration and runtime truth.
Does not own
CAPELLA public claim wording or website classification.
Input
Bounded execution request or runtime access attempt.
Output
Realized state, readback, registration, failure or platform-blocked runtime classification.
Can block
Authorization failure, runtime authentication requirement or unavailable target service.
Cannot authorize
CAPELLA to overstate evidence.
OBSERVATORY

Evidence

Owns
Evidence timeline, claim provenance and public proof classification.
Does not own
Permission, execution or SAP runtime authority.
Input
Qualification, approval, execution, readback and runtime records.
Output
Claim evidence, limitations and public truth ledger entries.
Can block
Claim promotion when evidence is missing or contradictory.
Cannot authorize
A write, retry or deployment.

Verified engineering cases

Current and historical evidence stay separate.

VERIFIED

Managed RAP Creation

A validated managed RAP mission moved through SFC 0.13.1 qualification, explicit human authorization, A4Layer 1.0.0 execution, SAP realization, SAP readback and ATC with 0 findings.

CAPELLA_MULTI_OBJECT_NAMING_CORRECTED_LIVE_REALIZATION_R1
CLAIM_SCOPED

Governed FullStack deployment with platform-limited runtime

RAP-04 records a current-generation FullStack case where backend delivery and deployed content were verified, while runtime execution remained platform-blocked and was not represented as runtime-verified.

CAPELLA_AFEP_0_7_4_RAP04

Capability ledger

Public states avoid binary marketing checkmarks.

Current Context and ERCC

VERIFIED

Authoritative context, assumptions, unknowns and ERCC Engineering Task Contract projection are inspectable before SFC.

Typed field projection

VERIFIED

Typed field fidelity and grounded projection checks prevent silent widening before qualification.

SFC qualification and SAP preflight

VERIFIED

SFC 0.13.1 qualifies candidates while SAP preflight and canonical artifact identity remain separate gates.

Canonical physical artifact identity

VERIFIED

The executable mutation manifest and physical artifact identity are frozen before governed execution.

Bound SAP-write authorization

VERIFIED

Human approval remains explicit, single-use and bound to the exact execution configuration.

Fiori deployment authorization

DEMONSTRATED

Fiori deployment authorization is distinct from SAP-write authorization and does not silently inherit it.

Backend realization

VERIFIED

Governed carrier execution, SAP generation, activation, ATC, backend readback, service publication and OData validation are represented as separate proof points.

Fiori delivery

VERIFIED

UI5 validation/build, BSP deployment, deployment reconciliation and deployed-content verification are exposed without equating deployment with runtime execution.

Runtime verification

DEMONSTRATED

Runtime registration and execution verification are classified as VERIFIED, FAILED, PLATFORM_BLOCKED or UNVERIFIED.

Evidence and recovery

VERIFIED

Operator truth, backend truth, safe resume, evidence timeline and post-realization correction keep machine activity separate from verified delivery.

Generic existing RAP modification

NOT SUPPORTED

Generic modification of arbitrary existing RAP applications remains outside current source-proven support.

Multi-environment qualification

NOT SUPPORTED

Broader target-environment qualification remains roadmap until evidence supports it.

Known limitations

What CAPELLA refuses to overstate.

Claim classes are fixed: VERIFIED, DEMONSTRATED, EXPERIMENTAL, ROADMAP, DECISION. Evidence gaps do not become claims.

  • 01RUNTIME_VERIFIED remains false when runtime evidence is PLATFORM_BLOCKED.
  • 02Deployment verification does not equal runtime verification.
  • 03SAP registration or AppIndex evidence alone does not prove runtime execution.
  • 04Historical verified evidence is not silently promoted into a current-release SAP outcome.
  • 05Post-release engineering main is reviewed separately from the released 0.7.4 product boundary.
  • 06Effectiveness telemetry for agent/skill/MCP outcome influence is not yet measured.

Role lens

Same evidence, different emphasis.

No personal role profile is stored. The lens only changes the recommended path.