Skip to main content
Glama

RCO-A2A - Regulatory Compliance Objects

Server Details

Signed, deterministic compliance state per object per jurisdiction, resolved upstream.

If you are the author of this connector, you can claim ownership with GitHub, an HTTP challenge, or a DNS record. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Healthy
Last Tested
Transport
Streamable HTTP
URL
Repository
greencore-solutions/rco-a2a
GitHub Stars
0

Tool Definition Quality

Score is being calculated. Check back soon.

Available Tools

5 tools
get_recordGet record by id
Read-onlyIdempotent
Inspect

Return any RCO by record_id, including superseded records - the audit trail, retained byte-identical.

ParametersJSON Schema
NameRequiredDescriptionDefault
record_idYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
stateYes
issuerYes
key_idYes
signalYes
eco_refYes
rule_setYes
object_idYes
record_idYes
signatureYesDetached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json.
case_studyNo
conditionsNo
supersedesYes
rco_versionYes
resolved_atYes
valid_untilYes
jurisdictionYes
evidence_refsYes
verification_urlYes
list_issuersList issuers
Read-onlyIdempotent
Inspect

Return the signed consortium issuer registry document, verbatim as published at consortium-10060.org/issuers.json.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

Output Schema

ParametersJSON Schema
NameRequiredDescription
key_idYes
issuersYes
updatedYes
signatureYes
trust_anchorNo
registry_versionYes
verification_urlYes
list_rule_setsList rule sets
Read-onlyIdempotent
Inspect

List the versioned rule sets in force and formerly in force for a jurisdiction: id, version, hash, effective dates, artifact URL. Never the regulation text.

ParametersJSON Schema
NameRequiredDescriptionDefault
jurisdictionYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
rule_setsYes
jurisdictionYes
publish_recordPublish record (issuer)
Idempotent
Inspect

Publish a signed Regulatory Compliance Object to the partner rail (rco-a2a-cpg.ai). The ONLY write path in the suite, and it accepts only what already verifies: the record must be schema-valid RCO v1.3, its issuer must be a cpg-rail issuer active in the signed consortium registry, its verification_url must equal that issuer's registry JWKS URL, its detached JWS must verify against that JWKS, and its record_id (and any supersession) must be consistent. GSC never authors a partner record and never holds a partner private key: GSC verifies, receipts to Azure Confidential Ledger, and serves. A submitted record is never modified. Idempotent: republishing a byte-identical record returns the same receipt. Typed errors only.

ParametersJSON Schema
NameRequiredDescriptionDefault
recordYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
noteNo
slotYes
ledgerYes
card_urlNo
publishedYes
record_idYes
idempotentNo
record_urlYes
resolve_complianceResolve compliance state
Read-onlyIdempotent
Inspect

Return the current signed Regulatory Compliance Object for an object in a jurisdiction. Deterministic. Inside the resolved universe (SPEC v1.2 pairs.json + the jurisdiction doors' own objects) an unknown object returns a pre-resolved, signed CPG-404 record; outside it the typed error record_not_found is returned - nothing is signed at request time. Never narrative.

ParametersJSON Schema
NameRequiredDescriptionDefault
object_idYes
jurisdictionYes

Output Schema

ParametersJSON Schema
NameRequiredDescription
stateYes
issuerYes
key_idYes
signalYes
eco_refYes
rule_setYes
object_idYes
record_idYes
signatureYesDetached JWS Compact Serialization (RFC 7515) with unencoded payload (RFC 7797): BASE64URL(protected header {alg:ES256, b64:false, crit:[b64], kid}) '..' BASE64URL(ES256 raw R||S). Signing input = ASCII(BASE64URL(protected header) '.') || RFC 8785 canonical JSON of the record with this member removed. Test vectors: signature-test-vectors.json.
case_studyNo
conditionsNo
supersedesYes
rco_versionYes
resolved_atYes
valid_untilYes
jurisdictionYes
evidence_refsYes
verification_urlYes

Frequently Asked Questions

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Connectors

  • Multi-jurisdictional AI compliance readiness scoring with sourced penalty math.

  • Signed verification attestations for agent decisions: business, price, freshness, claim checks.

  • Dated, signed compliance-evidence packs: gov-fact-grounded claims + exclusion screens + trap-facts.

  • Append-only decisions with provenance, supersession, retrieval, and audited MCP actions.

View all MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    B
    maintenance
    Provides cryptographic signing and verification for AI decisions to generate verifiable, Ed25519-signed receipts for compliance and auditing. It automatically maps AI actions to regulatory frameworks like HIPAA and SOX with high-performance, sub-3ms signing.
    4
    MIT
  • A
    license
    A
    quality
    C
    maintenance
    Source-verified regulatory and compliance intelligence: 10,000+ obligations across 39 pillars, each grounded in a primary legal source with a content hash. Covers the EU AI Act, GDPR, DORA, NIS2, HIPAA, Basel III and the MITRE ATT&CK/ATLAS families.
    25
    1
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Computes multi-jurisdictional AI compliance readiness scores with sourced penalty math, enabling gap analysis and audit tier recommendations.
    MIT

View all MCP Servers

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.