Inspect the execution-authorization boundary before relying on it.
RLSOK checks whether the exact approved software release is still eligible to cause a robot command now. Deployment alone is not authorization.
Product boundary
Shadow evaluates the real authorization path with no dispatcher: Hardware dispatch: NO. RLSOK is not an E-stop, safety PLC, certified controller, motion planner, functional-safety system, generic cybersecurity product, or replacement for SROS2 and existing safeguards.
Failure behavior
Missing Cloud authority, expired or revoked approval, stale/mismatched state, malformed input, and unknown transport outcomes do not create authorization. Restart recovery and replay checks remain fail-closed. Cloud outages never cause a local permissive billing fallback.
Data handling
Cloud stores account and organization identities, memberships and sessions; registered Runtime, robot, controller, binding and release metadata; approvals, revocations, Permits and Evidence; audit events; and minimal billing identifiers when commerce is configured. Metadata-only Zero-to-Shadow stores artifact digest and size rather than policy bytes. Managed artifact flows may store uploaded artifact content. RLSOK does not provide a general robot-telemetry platform. Evidence may contain the execution facts submitted by Runtime; command payloads are not copied into commercial analytics.
Open source and portability
The robot Runtime is Apache-2.0 and available on GitHub. Evidence can be exported and the Runtime can be uninstalled. Billing does not rewrite historical Evidence.
Release provenance
The public release manifest currently reports product v1.3.0, Runtime 1.4.5, and Cloud 1.3.0. Unreleased candidate SHAs are not presented as production facts. See downloads and checksums and the repository changelog.
Security and reviewers
See the security reporting process and Technical Contributors & Reviewers. Attribution is not endorsement, partnership, certification, integration, or customer status.