Skip to main content

Agent Mesh

V2 and above. Part of the invite-only hosted editions, not the free self-hosted V1. See the editions.

The problem this solves​

There are useful agents on the internet that aren't yours. Some are excellent. Some are broken. Some are actively hostile, and the polite ones are indistinguishable from the hostile ones until the moment they aren't.

Agent Mesh lets you use them anyway. You register an agent, hand it a task, and it works with authority that is narrow, short-lived and revocable — while AI Partner watches what it actually does and pulls the plug the instant its behaviour stops matching its story.

It works in both directions:

DirectionWhat it means
OutboundYour AI Partner hires external agents and supervises them
InboundYour AI Partner accepts work from external orchestrators — including another AI Partner

Both are off by default. Turn them on in Settings → Agent Mesh.


How an external agent is kept honest​

Four things happen around every delegation, without you arranging any of them.

Authority that expires

Each delegation gets its own credential, valid for minutes, scoped to only the actions that task needs. Nothing long-lived is ever handed out.

A tripwire

A decoy credential is planted alongside the real one. It has no legitimate use — so if it's ever presented back, that agent has tried something it shouldn't. There is no innocent explanation, and none is assumed.

Behaviour watched live

What the agent actually does is compared against what it advertised it does. Reaching outside its declared abilities is what gets noticed.

Instant revocation

A tripped tripwire, a failed verification or a hostile classification kills all of that agent's authority immediately — not at the end of the task.

AI Partner also refuses to talk to addresses that shouldn't be reachable from a server — your internal network, loopback, cloud metadata endpoints — so registering a hostile URL can't be used to make your own instance attack itself.


Trust classes​

Every registered agent carries a class, and it's earned by observed behaviour rather than claims:

ClassWhat it means
UnclassifiedRegistered, not yet observed doing anything
FriendlyBehaviour has matched what it advertises
ConfusedMalformed responses, or straying slightly outside its declared abilities — unreliable rather than malicious
RogueVerification failures, or reaching for sensitive capabilities it never declared
HostileThe tripwire fired, or you said so

Classification is rule-based and deterministic — the same behaviour always produces the same class. A model is used only to write the human-readable explanation of why, never to decide it. You're never in the position of an agent being trusted because something found it persuasive.

You can override any classification by hand in the Triage tab.


The five tabs​

Register an agent by pasting its URL. AI Partner probes it and shows what it found: whether it speaks the full standard or only a basic fallback, its current trust class, and whether it's reachable right now.

An agent that repeatedly fails is taken out of rotation automatically rather than being retried forever.


Delegating inside a goal​

External agents aren't only for manual delegation. A goal can hand part of its work to a registered agent mid-run — "ask Acme's agent for their current pricing and return it as structured data" — with the same expiring authority, the same watching, and the same audit trail. The result comes back into the goal and the run carries on.


Accepting work from others​

The inbound direction turns your instance into something other orchestrators can delegate to. Turn on Accept inbound tasks in the same settings card.

Once on, your instance advertises itself as available for streaming work, and compatible orchestrators pick that up on their own. Each caller runs as its own isolated, metered consumer. See the Agent API guide for the consumer model and billing.


Two instances working together​

The most common use of the inbound direction is two AI Partner instances in tandem — one coordinating, one specialising.

  1. 1
    On the executing instance

    An administrator turns on Inbound Agent API and creates a consumer for the coordinating instance. Copy its key — shown once.

  2. 2
    On the coordinating instance

    Agent Mesh → Registry → register the executing instance's address. It's probed automatically and recognised as fully capable, so delegations to it stream live.

  3. 3
    Delegate

    Agent Mesh → Delegate → pick it, write the goal. Watch it run in Delegations with live status, and the result when it lands.

The executing instance is classified like any other external agent. Being another AI Partner earns it no special trust.


Turning it off​

Switch the main toggle off and the Agent Mesh section disappears — no new delegations can be issued. Existing audit records are kept. Turning off supervision never erases the history of what was supervised.