Gateway and routing
The single entry point for agent traffic, and the sequence it runs for every request.
Why a gateway#
If applications call agents directly there is no place to apply policy, no consistent audit trail, and no way to change which agent serves a capability without changing the caller. Putting one governed entry point in front of the fleet gives all three.
What happens to a request#
- The gateway normalises the request and resolves the tenant and actor.
- The registry returns agents that declare the capability and are healthy.
- Policy evaluates the request against the candidate.
- The scheduler ranks the remaining candidates and explains its choice.
- The gateway invokes the agent, over a Kubernetes Service or an external endpoint.
- Context is optionally recorded, and audit evidence is emitted.
Every stage is separately switchable. A module that is off reports skipped in the response
metadata rather than silently doing nothing, so you can always tell whether policy actually ran.
Reading the response metadata#
Responses carry the decisions that produced them:
"metadata": {
"agentfleet.policy.mode": "enforce",
"agentfleet.policy.decision": "allow",
"agentfleet.policy.participation": "evaluated",
"agentfleet.scheduler.status": "ok",
"agentfleet.audit.mode": "async"
}
participation is the field to check when you are unsure whether a module took part.
skipped means the module was off, not that it approved.
Tool calls come back as intents#
When an agent wants to take an external action — charge a card, write to a system of record — the gateway returns it as an intent rather than executing it. The action is recorded, governed, and made available for approval, but the control plane does not perform it as a side effect of a model deciding it should happen.
Failure policy#
Each dependency has a configurable failure policy. A governance dependency that is unreachable should normally fail the request rather than be skipped — a policy service that is down must not become an implicit allow. Set this deliberately per module in values.