No agent is unrestricted. Every agent possesses explicit identity, scope, whitelist, and risk profile.
| Agent | Model | Status | Risk Profile | Allowed Actions | Allowed Tools | Memory Scope |
|---|
High-risk actions require explicit server-side authorization. Cannot be bypassed by frontend.
| ID | Agent | Action | Risk Level | Reasons | Requester | Status | Actions |
|---|
Full execution history through Scope โ Permission โ Risk โ Execution โ Observation โ Verification.
| Task ID | Agent | Goal | Status | Plan Steps | Verified | Evidence SHA-256 | Timestamp |
|---|
Tool registry and capability sandbox. No tool can be invoked without explicit agent permission.
| Tool ID | Name | Description | Required Level | Side Effect Safe | Credentials Boundary |
|---|
Defines what agents can and cannot do across domains, resources, actions, and targets.
Scoped memory store with provenance, sensitivity, and cross-agent boundary isolation.
| ID | Scope | Key | Sensitivity | Provenance | Timestamp |
|---|
Cryptographically verifiable execution trail. Proves WHO, WHAT, WHY, WHEN, UNDER WHICH POLICY with WHAT EVIDENCE.
| Audit ID | Task ID | Actor / Agent | Action | Policy Verdict | Risk | Verification | Evidence SHA-256 |
|---|
Failure capture, retry budget, state preservation, compensation, and escalation trajectories.
Execution evaluation and feedback loop. Proposes rule and prompt improvements without automatic privilege escalation.
| Event ID | Task ID | Agent | Status | Learning Signal | Proposed Improvement | Timestamp |
|---|
FlyTrustAgent is model-agnostic. Foundation models sit beneath the Harness Control Layer.