CEO
Set the agent infra standard before every team picks a different stack. Private first. Govern usage. Distribute what becomes durable.
Governed agent execution at production scale. Identity, separate microsandbox code execution, scoped authority, files, approvals, receipts, replay — one platform, enterprise controls.
Internal agents stay private. Promote selected ones to partner or public surfaces when ready.
Agents run as services with isolated execution, readiness checks, release history, and infra ownership.
Sandboxed runtime keeps code-running work behind a hardened boundary and explicit file grants.
Files, memory, artifacts persist. Inspect exactly what changed.
Human gates for file expansion, sensitive actions, bounty selection, production handoff.
Receipts, traces, replay data, scores, review notes tied to each agent.
Expose agents to tools, other agents, Claude Code, Cursor, APIs, customer workflows.
Usage, receipts, pricing, monetization paths for partner-facing agents.
Set the agent infra standard before every team picks a different stack. Private first. Govern usage. Distribute what becomes durable.
Move agent work out of notebooks into services with deploy history, runtime boundaries, observability, files, approvals, reproducibility.
Turn repeatable customer work into agents with proof: inputs, artifacts, scores, receipts, review notes, pricing.
Fastest credible proof is not a marketplace launch. It is one production-grade private agent with real files, real approvals, real artifacts, signed event history you can inspect.
CTO, CIO, Head of AI, Head of Platform, Head of Security — here are the answers, with deep links to the architecture pages.
Grant-backed delegation and managed workspace operations can use ephemeral, audience-bound, glob-filtered authority. Hosted agent processes may also have separately configured secrets and local runtime access. Approval records remain distinct from signed execution receipts.
Zero Trust runtime →Hosted skill code runs in a Knative or Kubernetes container. Code sent explicitly through ctx.sandbox runs behind a separate libkrun virtualization boundary, with grant-aware workspace paths enforcing scoped patterns. Per-agent secrets may be projected into the hosted process, and the repository does not claim absolute no-network or no-escape guarantees.
Isolation model →The control plane signs and persists authenticated Agent API calls, while trusted ingress signs public /invoke and standard MCP tools/call executions. Agent API receipts bind user:{id}; gateway caller values are conservative anonymous, credential-present, or verified grant-issuer classifications. Gateway replay is a minimal transport timeline, not a full internal event trace.
Replay architecture →Receipts are cryptographically tied to the observations supplied by their sealing path. The schema supports input hashes, grant IDs, file ops, tool calls, eval scores, and review notes; optional fields may be empty. Verified records are queryable and exportable for SOC2 / ISO 42001 / EU AI Act evidence packs.
Receipt anatomy →One command — `a2a deploy`. Source is packaged, built, pushed to a managed registry, released to a hosted endpoint with health checks. Versioned, rollbackable, release history preserved. Private agents stay behind org auth.
Deploy lifecycle →Each agent publishes an AgentCard at /.well-known/ and resolves through a platform-managed deployment identity. Supported delegated calls can carry signed grants; formal A2A routes remain protocol state. Users authenticate to the dashboard and API through account identity and org-scoped sessions.
Identity model →