System One capability plan

Core contracts: Capability services and shared inference bridge.

Capability contract: system-one:v1, exposed as system-one.v1 to consumers. Provider plugin: plugins/systemone (current System One decision model jev-latest). First consumer: NR's event classifier. Browser may adopt the same contract in a later phase; browser actions remain owned by Browser.

Settings-only review revision

Review: NR's previous Jev key was plaintext in nr_settings. PPQ already uses src/security/encrypted-secret.ts; System One follows that established encryption pattern. NR legacy keys are unused by this provider.

Shared inference bridge

Core owns one client-facing Bearer key, HTTP authentication, endpoint discovery, and bounded body reading. Core inference and installed apps explicitly register inference-endpoint:v1 providers. System One's HTTP adapter invokes its existing system-one:v1 decision contract; upstream credentials remain encrypted and separate from the bridge key. Internal capabilities are not automatically exposed over HTTP.

HTTP model defaulting correction

Structured choice criteria compatibility

The user's direct TypeSafe connection-test request includes object-valued choice criteria, such as "1": { "element": "[1] More information" }. Preserve these JSON values through the shared decision contract and HTTP adapter instead of requiring string/null descriptions.

Provider output must be checked against the caller's offered question IDs/types/candidates. A provider may not return unknown answer IDs or choices, mismatched answer types, out-of-range probability/confidence values, or non-finite scores. The API request carries caller-supplied state to the configured provider; consumers remain responsible for minimizing sensitive content.