Versioned against MLflow's Prompt Registry, with aliases and a per-prompt test workspace.
Definitions run in a bounded subprocess: separate interpreter, empty environment, private working directory, and hard time, memory, and output limits.
Named capabilities with selection logic; preview which skills resolve for an input.
Registered Model Context Protocol servers — including a first-party database server — exposed as tools under command and host allowlists.
Hybrid retrieval (BM25 + dense RRF, tri-hybrid with graph) plus retrieval calibration.
Agentic graphs composed in Studio, preview-run, published, and traced end to end.
Humans and the Aria copilot resolve the same server-validated identity — password accounts, revocable sessions, and four scopes. Each asset follows the lifecycle it actually implements, and the audit trail records actor, action, and entity.
Only 28% of organizations can trace an agent's actions back to a human across all environments — ~72% cannot (Cloud Security Alliance, 2025). CALIBER ties every change to an actor in one audit trail.
61% of executives required a human in the loop when surveyed (KPMG, Q3 2025). Runtime approvals honour the node's required role and a quorum of distinct approvers, and by default whoever triggered the run cannot approve it.
EU AI Act high-risk obligations phase in from 2 August 2026; penalties reach €35M or 7% of global annual turnover (Article 99). Apache 2.0 and self-hostable — no lock-in, data and lineage stay in your own environment.
Mounts at /caliber inside MLflow, or runs as a standalone ASGI service connected to vanilla MLflow over HTTP.
Aria runs a permissioned tool loop on OpenAI and Claude — read state, execute, observe, iterate — inside the product.
Evaluation scorecards, prompt refinement with regression checks, and deterministic tool calibration connect proposals to recorded evidence.
Server-validated identity and shared RBAC scopes, a bounded and swappable tool execution boundary, SSRF-checked workflow HTTP, and explicit operator apply or publish.
MLflow tracing with per-tool-call spans, dependency readiness, queue and worker health, and operator-declared objectives that open durable incidents.
Apache 2.0 · Python 3.10–3.12 · SQLAlchemy 2.0 · React SPA · local/S3 storage · No vendor lock-in.