Everything around it is the hard part. Eight layers we build minimal, but right.
01/08Orchestration & runtime
Agent logic belongs in a persistent, resumable process, not in a chat session. For long-running flows with waits, approvals and retries we rely on durable execution.
- Claude Agent SDK
- OpenAI Agents SDK
- Google ADK
- LangGraph
- Temporal
- Inngest
02/08Integration via MCP
We connect tools and data via the Model Context Protocol. An MCP gateway centrally controls which agent sees which tools, with authentication, rate limits and an audit log.
03/08Identity & permissions
Every agent has its own identity in the identity provider. It acts on behalf of a person with their permissions, or with narrowly scoped permissions of its own. Never through a shared superuser.
- Entra ID
- Okta
- OAuth on-behalf-of
- Human-in-the-loop
04/08Security
No filter reliably stops prompt injection. We solve it in the architecture: separate capabilities, control outbound connections, allowlist tools, sandbox code execution.
- Egress control
- Tool allowlist
- Sandbox
05/08Context & knowledge
Retrieval inherits the permissions of the source systems. An agent only finds what the person it works for may see. For numbers we use defined metrics instead of free-form SQL on raw tables.
- Permission-aware RAG
- Semantic layer
- Memory
06/08Model layer
A gateway in front of the models enables multi-model operation, fallbacks and cost control per team. Large models plan, small ones handle routine. With EU data residency on request.
- LiteLLM
- Portkey
- Bedrock
- Vertex AI
- Microsoft Foundry
07/08Observability & evals
Every run is fully traced, including tool calls, context, cost and latency. Evals built from real cases run as regression tests on every change. Without evals, every model switch is flying blind.
- OpenTelemetry
- Langfuse
- LangSmith
- Arize
- Cost per run
08/08Governance & operations
An agent registry shows which agents exist, who owns them and what they may do. Plus audit logs, a kill switch, risk classification under the EU AI Act, GDPR and, where needed, the works council.
- Agent registry
- Audit log
- Kill switch
- EU AI Act
- GDPR