๐Ÿ“– English documentation
ๆ—ฅๆœฌ่ชž โ†’

๐Ÿ“–Glossary

When to use fail-safe / fail-open / fail-closed, plus Phase C terminology. Bilingual (JA/EN).

Aligned with aegis-sip-bridge/docs/glossary.md. The three easily-confused fail-* terms are illustrated first. Each term key is shared across languages, so this page serves as the JA/EN parallel reference.

fail-safe / fail-open / fail-closed (most important)

fail-safe
If judged as spam, hang up (block).
Adopted (defense against spam)
verdict=spam โ†’ Hangup(21)
fail-open
Fall back to business continuity โ€” route legitimate calls to a human.
Adopted (Aegis default)
verdict=unknown/empty/unexpected โ†’ Dial(PJSIP/${HUMAN_PEER})
fail-closed
Cut everything off (let no one through).
Not adopted
The legacy dialplan's unknownโ†’Hangup (retired in C-2(b))
verdict
The AI's decision from classify_call (classification / spam_score / should_terminate, etc.). In the current code it is recorded and steers the AI toward taking a message; it is not an instruction to cut the call (neither the old Plan A AstDB path nor Plan B AMI Hangup fires; slated for removal).
AstDB
Asterisk's built-in key-value store. The old Plan A had the bridge write the verdict via AMI DBPut for the dialplan to read; it was rejected. Only a DB_DELETE(aegis_verdict/โ€ฆ) in the dialplan h extension remains, with no writer (slated for removal).
AudioSocket
The TCP audio protocol of Asterisk chan_audiosocket: [type:1][len:2 BE][payload]. The bridge listens on 127.0.0.1:9092. type: 0x00=hangup / 0x01=UUID / 0x10=audio (slin = 16-bit PCM, 8 kHz, 20 ms = 320 bytes; not ฮผlaw โ€” measured 2026-08-03).
AMI
Asterisk Manager Interface (127.0.0.1:5039). The bridge's hangup_by_uuid (Status lookup of AEGIS_UUID โ†’ Hangup) exists but nothing in the current code calls it from the in-call verdict, so it never fires; slated for removal. No code sends DBPut.
HUMAN_PEER
A legacy placeholder (not in the current dialplan). Today the hand-off target is HUMAN_EXTEN (set in kitted; empty = the called extension), via Dial(PJSIP/${HUMAN_DIAL_EXTEN}@hgw-trunk,30). Undecidable, unreachable bridge and end of the AI leg all converge here.
ALLOW_DESTINATION
A legacy placeholder (not in the current dialplan). Legitimate calls also go to the single hand-off point (exec_dial) using HUMAN_EXTEN.
classify_call
An OpenAI Realtime tool (function calling) that classifies a call and returns a classification (spam/allow/unknown), should_terminate, and related data.
should_terminate
A classify_call return value. Even when true, the current bridge does not hang up (conversation_may_terminate() is always False); the platform forces it to false on explicit_human_request. The final design never uses it to cut a call.
Aegis Cloud
The aegis-platform backend. The bridge forwards tool calls to /api/realtime/tools/{tool_name} (AegisCloudProxy).
HGW
The home gateway (e.g. for Hikari Denwa fiber phone). Asterisk REGISTERs to it as an extension to receive inbound calls.
commodity ็ฎฑ
A generic package containing only the Asterisk wiring and deployment steps (the bridge itself is not included).
Item A (strict_approval_mode)
A per-client non-bypassable gate. It rejects direct loosening writes with 409 and allows only the proposeโ†’approveโ†’apply flow.
4-eyes
Two-person approval that forces the proposer and approver to be different people; applied via strict_approval / change_approval.
voice-edge
The main repo holding the Pi's Asterisk 22 + chan_pjsip + dialplan and the connection points to the HGW, the bridge, and human extensions. The current main line for real phone numbers.
AI_ROUTE
A mechanism that routes inbound calls between a human and the AI: registered numbers go to a human, everything else goes to AI reception.
route-decision
An aegis-platform API (GET /api/realtime/route-decision) that takes a caller number and returns block / human / ai. The decision reuses the existing blocklist / whitelist / protection logic.
RDS
Arrowfone Redirect Server โ€” the server that handles Rhodium's call redirection.
Arrowfone
Rhodium's presence service and the protocol for its smartphone app.
RTS
A conceptual name that appears in Rhodium-related configuration/DB; not a standalone executable program.
ChatVoice
An external JV partner responsible for on-device testing. Current operations (v1) have also been set up via ChatVoice.
arc score
A conversation-level risk measure: instead of scoring single turns, it combines Peak (maximum instantaneous risk) and Accumulation (built-up risk). Core of gray-zone sales detection in the business MVP. Stage 1 (shadow recording only) is implemented; not used in live decisions.
arc_peak
The maximum turn score observed during a conversation. Preserves 'was a clearly dangerous request ever made?' so it cannot be averaged away. Recorded in shadow columns.
arc_accumulation
The accumulated total of below-threshold suspicion that keeps recurring โ€” this is where persistence is captured. Recorded in shadow columns.
persistence
The 'thin but relentless' attack pattern. Averaging keeps it under any threshold forever, so Accumulation captures it instead. Legitimate callers can be persistent too, which is why the arc score remains a suspicion signal and never directly triggers a hangup on its own.
โœ…Aegis defaults

Reliably cut only listed numbers at Gate 1 (fail-safe), and route everything else to a human (fail-open). The path that cuts a call on the mid-call verdict (spam) does not fire in the current code (slated for removal, 2026-09-16). Even if the bridge / AMI / OpenAI go down, we never โ€œcut everything off (fail-closed)โ€ (verdict=unknown โ†’ hand to a human).

โ„น๏ธPhase C terms

verdict / AstDB / AudioSocket / AMI / HUMAN_PEER / ALLOW_DESTINATION / classify_call / should_terminate / Aegis Cloud / HGW / commodity box / Item A / 4-eyes โ€” definitions are shown in the list above (GlossaryView).