๐Glossary
When to use fail-safe / fail-open / fail-closed, plus Phase C terminology. Bilingual (JA/EN).
Aligned with aegis-sip-bridge/docs/glossary.md. The three easily-confused fail-* terms are illustrated first.
Each term key is shared across languages, so this page serves as the JA/EN parallel reference.
fail-safe / fail-open / fail-closed (most important)
verdict=spam โ Hangup(21) verdict=unknown/empty/unexpected โ Dial(PJSIP/${HUMAN_PEER}) The legacy dialplan's unknownโHangup (retired in C-2(b)) - verdict
- The AI's decision from classify_call (classification / spam_score / should_terminate, etc.). In the current code it is recorded and steers the AI toward taking a message; it is not an instruction to cut the call (neither the old Plan A AstDB path nor Plan B AMI Hangup fires; slated for removal).
- AstDB
- Asterisk's built-in key-value store. The old Plan A had the bridge write the verdict via AMI DBPut for the dialplan to read; it was rejected. Only a DB_DELETE(aegis_verdict/โฆ) in the dialplan h extension remains, with no writer (slated for removal).
- AudioSocket
- The TCP audio protocol of Asterisk chan_audiosocket: [type:1][len:2 BE][payload]. The bridge listens on 127.0.0.1:9092. type: 0x00=hangup / 0x01=UUID / 0x10=audio (slin = 16-bit PCM, 8 kHz, 20 ms = 320 bytes; not ฮผlaw โ measured 2026-08-03).
- AMI
- Asterisk Manager Interface (127.0.0.1:5039). The bridge's hangup_by_uuid (Status lookup of AEGIS_UUID โ Hangup) exists but nothing in the current code calls it from the in-call verdict, so it never fires; slated for removal. No code sends DBPut.
- HUMAN_PEER
- A legacy placeholder (not in the current dialplan). Today the hand-off target is HUMAN_EXTEN (set in kitted; empty = the called extension), via Dial(PJSIP/${HUMAN_DIAL_EXTEN}@hgw-trunk,30). Undecidable, unreachable bridge and end of the AI leg all converge here.
- ALLOW_DESTINATION
- A legacy placeholder (not in the current dialplan). Legitimate calls also go to the single hand-off point (exec_dial) using HUMAN_EXTEN.
- classify_call
- An OpenAI Realtime tool (function calling) that classifies a call and returns a classification (spam/allow/unknown), should_terminate, and related data.
- should_terminate
- A classify_call return value. Even when true, the current bridge does not hang up (conversation_may_terminate() is always False); the platform forces it to false on explicit_human_request. The final design never uses it to cut a call.
- Aegis Cloud
- The aegis-platform backend. The bridge forwards tool calls to /api/realtime/tools/{tool_name} (AegisCloudProxy).
- HGW
- The home gateway (e.g. for Hikari Denwa fiber phone). Asterisk REGISTERs to it as an extension to receive inbound calls.
- commodity ็ฎฑ
- A generic package containing only the Asterisk wiring and deployment steps (the bridge itself is not included).
- Item A (strict_approval_mode)
- A per-client non-bypassable gate. It rejects direct loosening writes with 409 and allows only the proposeโapproveโapply flow.
- 4-eyes
- Two-person approval that forces the proposer and approver to be different people; applied via strict_approval / change_approval.
- voice-edge
- The main repo holding the Pi's Asterisk 22 + chan_pjsip + dialplan and the connection points to the HGW, the bridge, and human extensions. The current main line for real phone numbers.
- AI_ROUTE
- A mechanism that routes inbound calls between a human and the AI: registered numbers go to a human, everything else goes to AI reception.
- route-decision
- An aegis-platform API (GET /api/realtime/route-decision) that takes a caller number and returns block / human / ai. The decision reuses the existing blocklist / whitelist / protection logic.
- RDS
- Arrowfone Redirect Server โ the server that handles Rhodium's call redirection.
- Arrowfone
- Rhodium's presence service and the protocol for its smartphone app.
- RTS
- A conceptual name that appears in Rhodium-related configuration/DB; not a standalone executable program.
- ChatVoice
- An external JV partner responsible for on-device testing. Current operations (v1) have also been set up via ChatVoice.
- arc score
- A conversation-level risk measure: instead of scoring single turns, it combines Peak (maximum instantaneous risk) and Accumulation (built-up risk). Core of gray-zone sales detection in the business MVP. Stage 1 (shadow recording only) is implemented; not used in live decisions.
- arc_peak
- The maximum turn score observed during a conversation. Preserves 'was a clearly dangerous request ever made?' so it cannot be averaged away. Recorded in shadow columns.
- arc_accumulation
- The accumulated total of below-threshold suspicion that keeps recurring โ this is where persistence is captured. Recorded in shadow columns.
- persistence
- The 'thin but relentless' attack pattern. Averaging keeps it under any threshold forever, so Accumulation captures it instead. Legitimate callers can be persistent too, which is why the arc score remains a suspicion signal and never directly triggers a hangup on its own.
Reliably cut only listed numbers at Gate 1 (fail-safe), and route everything else to a human (fail-open). The path that cuts a call on the mid-call verdict (spam) does not fire in the current code (slated for removal, 2026-09-16). Even if the bridge / AMI / OpenAI go down, we never โcut everything off (fail-closed)โ (verdict=unknown โ hand to a human).
verdict / AstDB / AudioSocket / AMI / HUMAN_PEER / ALLOW_DESTINATION / classify_call / should_terminate / Aegis Cloud / HGW / commodity box / Item A / 4-eyes โ definitions are shown in the list above (GlossaryView).