Agent Mesh
V2 and above. Part of the invite-only hosted editions, not the free self-hosted V1. See the editions.
The problem this solves
There are useful agents on the internet that aren't yours. Some are excellent. Some are broken. Some are actively hostile, and the polite ones are indistinguishable from the hostile ones until the moment they aren't.
Agent Mesh lets you use them anyway. You register an agent, hand it a task, and it works with authority that is narrow, short-lived and revocable — while AI Partner watches what it actually does and pulls the plug the instant its behaviour stops matching its story.
It works in both directions:
| Direction | What it means |
|---|---|
| Outbound | Your AI Partner hires external agents and supervises them |
| Inbound | Your AI Partner accepts work from external orchestrators — including another AI Partner |
Both are off by default. Turn them on in Settings → Agent Mesh.
How an external agent is kept honest
Four things happen around every delegation, without you arranging any of them.
Each delegation gets its own credential, valid for minutes, scoped to only the actions that task needs. Nothing long-lived is ever handed out.
A decoy credential is planted alongside the real one. It has no legitimate use — so if it's ever presented back, that agent has tried something it shouldn't. There is no innocent explanation, and none is assumed.
What the agent actually does is compared against what it advertised it does. Reaching outside its declared abilities is what gets noticed.
A tripped tripwire, a failed verification or a hostile classification kills all of that agent's authority immediately — not at the end of the task.
AI Partner also refuses to talk to addresses that shouldn't be reachable from a server — your internal network, loopback, cloud metadata endpoints — so registering a hostile URL can't be used to make your own instance attack itself.
Trust classes
Every registered agent carries a class, and it's earned by observed behaviour rather than claims:
| Class | What it means |
|---|---|
| Unclassified | Registered, not yet observed doing anything |
| Friendly | Behaviour has matched what it advertises |
| Confused | Malformed responses, or straying slightly outside its declared abilities — unreliable rather than malicious |
| Rogue | Verification failures, or reaching for sensitive capabilities it never declared |
| Hostile | The tripwire fired, or you said so |
Classification is rule-based and deterministic — the same behaviour always produces the same class. A model is used only to write the human-readable explanation of why, never to decide it. You're never in the position of an agent being trusted because something found it persuasive.
You can override any classification by hand in the Triage tab.
The five tabs
Register an agent by pasting its URL. AI Partner probes it and shows what it found: whether it speaks the full standard or only a basic fallback, its current trust class, and whether it's reachable right now.
An agent that repeatedly fails is taken out of rotation automatically rather than being retried forever.
Delegating inside a goal
External agents aren't only for manual delegation. A goal can hand part of its work to a registered agent mid-run — "ask Acme's agent for their current pricing and return it as structured data" — with the same expiring authority, the same watching, and the same audit trail. The result comes back into the goal and the run carries on.
Accepting work from others
The inbound direction turns your instance into something other orchestrators can delegate to. Turn on Accept inbound tasks in the same settings card.
Once on, your instance advertises itself as available for streaming work, and compatible orchestrators pick that up on their own. Each caller runs as its own isolated, metered consumer. See the Agent API guide for the consumer model and billing.
Two instances working together
The most common use of the inbound direction is two AI Partner instances in tandem — one coordinating, one specialising.
- 1On the executing instance
An administrator turns on Inbound Agent API and creates a consumer for the coordinating instance. Copy its key — shown once.
- 2On the coordinating instance
Agent Mesh → Registry → register the executing instance's address. It's probed automatically and recognised as fully capable, so delegations to it stream live.
- 3Delegate
Agent Mesh → Delegate → pick it, write the goal. Watch it run in Delegations with live status, and the result when it lands.
The executing instance is classified like any other external agent. Being another AI Partner earns it no special trust.
Turning it off
Switch the main toggle off and the Agent Mesh section disappears — no new delegations can be issued. Existing audit records are kept. Turning off supervision never erases the history of what was supervised.