Operate governed agents with clear, shared visibility.
Browser and CLI workflows give platform engineers, reviewers, and tenant operators access to the information they need while data stores and service credentials remain behind server-side boundaries.
Usage evidence#
Usage Center projects tenant-scoped calls, failures, tokens, estimated USD cost, average latency, and p95 latency from payload-free model-call audit events.
Dashboards#
An optional profile packages Prometheus, Grafana, and ClickHouse into the install, with two dashboards provisioned automatically — no manual import. It is a local evaluation and demo aid, not a production observability platform.
helm upgrade agentfleet ./agentfleet \
--namespace agentfleet-system \
-f agentfleet/profiles/local-light.yaml \
-f agentfleet/profiles/demo-observability.yaml \
-f agentfleet-images.values.json
kubectl -n agentfleet-system port-forward svc/agentfleet-demo-grafana 13000:3000
Open http://localhost:13000. The local demo credentials are admin /
agentfleet-demo — change or remove them before any shared use.
| Dashboard | Source | Shows |
|---|---|---|
| AgentFleet Operations | Prometheus | Gateway request rate and p95 latency, route failures, policy decisions, A2A delegation and MCP tool-call outcomes, model call outcomes/latency/tokens/estimated cost, and comparison and audit delivery outcomes. |
| AgentFleet Audit | ClickHouse | Request volume by tenant, outcomes, policy decisions, degraded modules, top invoked agents, gateway audit latency percentiles, recent audit events with raw event lookup, and model comparison evidence. |
Send a request while the dashboards are open to see it appear — follow the governed-request step in the sandbox demo. Prometheus itself is reachable directly if you want to query metrics without Grafana:
kubectl -n agentfleet-system port-forward svc/agentfleet-demo-prometheus 9090:9090
This profile does not enable bundled or external PostgreSQL — registry, approval, and context storage stay in-memory, and policy stays off at the gateway even though the profile ships rules for it. See Profiles to compose in durability and enforcement. ClickHouse itself does persist, backed by a PersistentVolumeClaim.
Approval Inbox#
Authorized reviewers can inspect approval records, view immutable events, and approve or deny pending requests. Request fingerprints and workflow metadata are stored without governed prompt or input payloads.
Protected path operations#
The protected-path profile adds per-agent workload identity, credential-free pods, operator-owned egress policy, Registry-backed identity checks, optional Guard inspection, and a suspension kill switch. Enable it only where the cluster CNI passes the Helm network-policy enforcement probe.
kubectl label namespace team-agents agentfleet.io/protection=managed
kubectl patch agent refund-agent -n team-agents --type=merge \
-p '{"spec":{"suspended":true}}'
Retain protected-path verification results with your organization’s deployment records. See Protected model path for the security boundary.
Expert CLI#
The onboarding bundle includes agentfleetctl for operators who prefer terminal workflows.
agentfleetctl --server http://127.0.0.1:8089 \
--tenant retail --actor platform-user status