Tasks, offers, bids, evidence
Robots, services, skills and knowledge move between independent owners. Publish → qualify → bid → award → run → verify → record → propose → review.
UMP lets a skill be written once and run on any machine whose body can physically do it. It has two levels: an exchange where tasks, skills, offers and evidence move between owners, and a machine layer that translates a skill to one body and admits it only when physics allows.
The exchange carries what to do. Each machine decides how, on board. Nobody standardizes why.
Judgment and planning stay in each operator's own stack. Mixing these levels is how protocols grow out of control: a skill that also decides whether to act becomes a planner, and a planner cannot be certified.
Robots, services, skills and knowledge move between independent owners. Publish → qualify → bid → award → run → verify → record → propose → review.
Per machine, in real time, offline if needed. The safety path is local (hot); governance and distribution are remote (cold).
A skill packet describes a physical action without naming a body: "apply 5 N", never "turn motor 3".
| Axis | Carries | Status |
|---|---|---|
| S | Sensing: what must be perceived, and how well | Specified |
| K | Kinematics: positions, paths and tolerances in a named frame | Demonstrated (sim), reach |
| F | Force: targets and limits; a coupled impedance mode for contact with unknown stiffness | Specified, untested |
| T | Time and logic: sequence, timeouts, hold or abort per step | Specified |
Example, the reach skill used in run E3
skill: reach fkst_version: 0.1 K: target: cartesian_position frame: world value_m: [0.40, 0.00, 0.50] tolerance_mm: 20 T: on_refusal: hold_state_safe
Every machine declares what its body can do in numbers. The tool tip is a mandatory, verified frame.
In simulation, measuring from the last joint instead of the tip silently hid one degree of freedom from every check. The fix became a protocol rule.
| Field | Meaning |
|---|---|
| workspace_envelope | Where the tool can reach |
| max_force_per_actuator | Force and torque limits |
| degrees_of_freedom | Joints that move the tool |
| precision_class | Repeatability |
| end_effector_capabilities | Grippers, tools |
| sensing_modalities | What it can perceive |
| reaction_time_ms | How fast it responds |
| mobility_class | Fixed, wheeled, legged |
| environmental_restrictions | Where it may not operate |
Mandatory since run E3
end_effector_reference_frame: frame_type: fixed_tip_joint link_ref: tip_link verified_dof_coverage: true # perturb each declared DOF; # the reference point must move
Cheap checks run before expensive ones, and nothing moves until the robot itself admits it.
Three end states are always kept apart: rejected before running, failed while trying, and unverified when the result cannot be shown.
| Stage | What it does | Result | Status |
|---|---|---|---|
| 1 | Read the skill's requirements and the capability manifest | capability match | Demonstrated (sim) |
| 2a | Geometric reachability: distance to the target against declared reach. Necessary, not sufficient | reachable | geometric_infeasible | Demonstrated (sim) |
| 2b | Solver convergence, only if 2a passes (damped least squares) | converged | non_convergent | Converged (sim) |
| 3 | Translation into this body's joint targets; learned models allowed inside if the result still passes 4 and 5 | full | partial | rejected | Demonstrated (sim) |
| 4 | Admission against the physical validity envelope, re-checked during the run | admit | refuse | Joint limits only |
| 5 | Translation fidelity certificate: the translator qualified on 3 or more categorically different bodies | full | partial | provisional | Not demonstrated |
Physics cannot be voted on. A valid signature proves who sent a skill, not that it can be done.
Every limit is tagged with its class, so a contract, price or governance vote can never make something physically impossible allowed.
| Envelope part | Contents |
|---|---|
| Stability certificate | Dynamics class: hold a point, steady cycle, or fixed-duration manoeuvre |
| Safety certificate | Mapped to ISO 10218 and ISO/TS 15066 parameters; a mapping, not compliance |
| Actuation constraints | Actuator limits |
| Environmental assumptions | Quantitative values, not tags |
| Temporal validity | Maximum state age, latency, revalidation interval |
| Invariant class | Who can change it |
|---|---|
| physics_enforced | Nobody: a law of nature or a measured fact |
| protocol_negotiated | Governance, by renegotiation |
| hybrid | Only the negotiated margin on a physical quantity |
Ten objects carry a job from request to verified outcome, and carry what was learned back to the next machine.
| Object | Purpose | Good |
|---|---|---|
| TaskContract | Outcome, acceptance criteria, constraints, site and safety context, evidence required, bid rules | Services |
| CapabilityAndStateOffer | Certified capability plus live state: health, energy, availability, location, uncertainty, state age | Robots |
| ExecutionBid | Method, predicted time, cost, energy and risk with uncertainty; evidence from comparable jobs | Services |
| AwardAndExecutionContract | Accepted obligations, plan, evidence plan, abort rights | Services |
| AdmissionDecision | The robot's own permit or refusal, with a reason | All |
| ExecutionTrace | Timestamped measured events, changes and aborts | Knowledge |
| OutcomeEvidence | Verified, failed or unverified, with uncertainty and proofs | Knowledge |
| VariantProposal | An improved skill: lineage, metric changes, scope, negative results, review status | Skills |
| TaskPattern | A reusable way to break down and coordinate a task | Knowledge |
| RobotAssetRecord | Identity, manifest, wear state, ownership and a verified track record | Robots |
UMP composes existing standards through profiles instead of competing with them.
What stays ours: admission before award across owners, evidence as a tradable asset, governed reuse that pays skill authors, and one loop linking robots, services, skills and knowledge.
| Profile | Uses | Where UMP differs |
|---|---|---|
| Skill payload | RFL skill instruction set, SkillCrate packages, qualified learned policies | Market, many owners, settlement, evidence reuse |
| Compatibility | ECM contract dimensions | Physical admission, outcome evidence |
| Verification | RFL certificates, independent evaluation gates | Field data from real jobs |
| Execution inside a site | Open-RMF bridge, VDA 5050 | Between sites, with money, contracts and proof |
| Industrial integration | OPC UA, ISA-95, Asset Administration Shell (IEC 63278) | — |
| Safety | ISO 10218, ISO/TS 15066, ISO 13849 | Admission stays local and never depends on payment |