Agentcess

Documentation

Agentcess documentation: passports, capabilities, policies, zones, the gate, budgets, approvals, evidence and delegation.

Everything in Agentcess revolves around one idea: an agent is a governed actor. The concepts below are the whole model; once they make sense, every page in the app does too.

Core concepts

  • Passport — the agent's portable identity: purpose, owner, status and a permanent identity history. Every change is a numbered record.
  • Capabilities — named abilities bound to an agent, each with a risk tier: read, write, destructive or consequential.
  • Access grants — exactly which data assets an agent may reach, and at which classification.
  • Policies and policy packs — versioned rules, bundled into reusable packs, that gate actions in observe, warn, approval or block mode.
  • Zones — where data must live and what may leave it. The gate refuses or escalates actions that would breach a zone's egress terms.

Running agents

  • Runs — give an agent a task and a dollar budget. It executes on the server and keeps going if you close your phone.
  • The gate — every action passes identity, capability, policy, zone and budget checks in a fixed order, and the decision is recorded.
  • Approvals — actions needing a person land in Approvals, bound to the exact action and resource, verified by passkey.
  • Delegation — an agent may hand part of its authority to another agent, but never more than it holds.

Evidence and oversight

  • Evidence ledger — every interaction is recorded and attributable.
  • Record book — history is folded into a hash-chained book you can export and verify independently.
  • Behaviour monitor — refusal rates, spend and anomalies per agent, with automatic hold on repeated refusals.
  • Security scan — a workspace-wide check for over-powered agents, open-ended clearances and risky tools.

Need a hand?