Reference
Flow, provenance, HITL, guardrails, capabilities, memory, and supervisor.
Every state transition is journaled to durable storage before it happens. When a wait fires, compute is released — not blocked. Retry, timeout, concurrency key, and priority are first-class per-edge properties.
// task graph — declarative, versioned, journaled { "id": "claims-triage.turn", "version": "1.4.0", "nodes": [ { "id": "classify", "kind": "agent", "ref": "intent-classifier" }, { "id": "retrieve", "kind": "tool", "ref": "precedents.search" }, { "id": "extract", "kind": "agent", "ref": "fact-extractor" }, { "id": "reason", "kind": "agent", "ref": "risk-analyzer" }, { "id": "cite", "kind": "check", "ref": "must-cite" }, { "id": "review", "kind": "review", "ref": "senior-adjuster" }, { "id": "respond", "kind": "agent", "ref": "draft-generator" } ], "edges": [ { "from": "classify", "to": "retrieve", "policy": { retry: "3x-backoff", timeout: "30s" } }, { "from": "classify", "to": "extract", "policy": { parallel: true } }, { "from": "retrieve", "to": "reason", "policy": { join: "all" } }, { "from": "extract", "to": "reason", "policy": { join: "all" } }, { "from": "reason", "to": "cite" }, { "from": "cite", "to": "review", "policy": { on: "risk>0.7" } }, { "from": "cite", "to": "respond", "policy": { else: true } } ] }
Every output traces back to every input that influenced it — cryptographically.
Prompts, retrieved chunks, tool results, model version, reviewer decisions, tenant policy in effect — all edges in a directed acyclic graph. Cryptographically signed and independently verifiable with any standard crypto library. The signed DAG is the audit artifact.
An operational surface with reviewer classes, queues, and escalation paths.
Approval queues, batched review, junior/senior reviewer routing, escalation paths, signed audit-bundle exports. Reviews are first-class kernel state — resumable across deploys, auditable end-to-end, exportable for regulator inspection.
Declare what the agent must never do, and what it must always do.
Guardrails evaluate at every turn — before tool calls, before responses, before human handoff. On failure, the runtime captures the input, the offending output, the specific check that fired, and the enforcement action taken; all signed into the audit trail.
defineAgent({ id: "claims-triage", guardrails: [ mustCite({ min: 1 }), neverCallTool("delete_claim"), outputMatches(ClaimSchema), maxToolCalls({ n: 50 }), cost({ max: "$0.05", on: "escalate" }), ], // same object · prod runtime + CI });
Agents declare what they need, not which model they use.
The router matches capability declarations to models that satisfy them, under per-tenant policy and per-run budget. Per-tenant provider allow/deny lists are enforced at the kernel on every call. Bring-your-own-model providers plug in through the same routing interface.
needs: [ "structured_output", "context >= 200k", "thinking", "cost <= $0.05/call", ] // tenant policy: no OpenAI · US regions only // budget remaining: $0.043 / $0.100 → route: claude-sonnet-4-6 (us-east-1) reason: satisfies all · under budget · policy-clean
Two primitives. Semantic recall, cross-conversation history, and working-memory context are views derived from both.
An append-only log of turns, tool calls, tool results, agent messages. Typed, versioned facts with declared retrieval hints — semantic, recency, exact, or graph. Every fact write is causally linked to the log entry that produced it, which feeds provenance.
Bounded fixes proposed against an immutable ground layer.
The supervisor observes runs, detects guardrail violations, proposes fixes in bounded artifact tiers, dry-runs proposals against held-out evals, and routes surviving proposals to your reviewers. It cannot modify its own guardrails or evaluation criteria — that's the immutable ground layer, human-authored, versioned through normal engineering flow.
Additional Use Grant: internal enterprise use is granted without restriction. Change Date: Apache-2.0 four years after each release.