Governance and versioning
Kill switches
Section titled “Kill switches”Robotics can be paused at any moment, at three independent levels:
| Who | Scope |
|---|---|
| Restaurant owner | Their filial, from Sitora Biz. |
| Branch manager | Their filial, from Sitora Pro. |
| The platform freeze | Every filial at once, from Sitora Console — the emergency stop. |
A paused or frozen filial refuses claims with 409 (robotics_paused /
platform_frozen) and stops issuing offers. Your controller must comply
immediately: park, finish nothing new, keep heartbeating. Kill-switch
compliance is one of the five certification scenarios
— an integration that fights the kill switch does not get certified.
Sitora staff hold a fourth lever, and it is a stand-down rather than a pause: Console can suspend your vendor everywhere, or revoke one filial’s activation. Both kill the credential rather than parking it, and both are described under authentication.
Certification lifecycle
Section titled “Certification lifecycle”Certification attaches to a recorded passing conformance run and is a
prerequisite for every activation of your fleet, at every restaurant. It can
be revoked by Sitora; a revoked vendor’s filials show
vendor_not_certified in blocked_reasons and receive no offers until
re-certification. Breaking controller revisions you declare under contract
re-run certification before they go live.
Data boundaries
Section titled “Data boundaries”Exactly three things cross to your fleet:
- The task manifest — order display number, item names and quantities, and the destination. On a courier leg the destination is the customer’s free-text delivery address, which is personal data; handle it accordingly. The manifest is withheld once a task is terminal.
- The fleet snapshot — your activation’s operating configuration, your
own liveness, and
blocked_reasons. - Webhook notifications — task identifiers and state only, never the manifest.
No customer record, phone number, order note, price, or payment data is ever exposed to a robot credential, and no staff identity is either: you are never told which person loaded a tray or confirmed a serve. The contract prohibits attempting to obtain any of it through a side channel, and prohibits retaining manifest data beyond the run it describes.
Versioning
Section titled “Versioning”The surface is URL-versioned at /api/robotics/v1/.
- Changes within
v1are additive only — new fields and endpoints may appear; existing ones never change meaning or disappear. Ignore fields you do not recognize. - Breaking changes ship as
/v2/with a published deprecation window forv1. - The live contract is always available at
GET /api/robotics/v1/openapi.json(anonymous); the API reference section of this site is generated from that document.