Onam Security

The specialist agents

Onam Operations has eight specialist agent roles, each with a declared job, level, skills, tools and limits. Automation works in two modes: planner and actor.

The orchestrator routes to read-and-recommend agents and proposing agents; proposals pass a human approval gate before the automation actor may execute.
The orchestrator routes to read-and-recommend agents and proposing agents; proposals pass a human approval gate before the automation actor may execute.

The roster

AgentLevelAnswersStatus
Asset AgentL1 · Read and recommendWhat do we have, how is it connected, and who owns it?Early access
Security AgentL1 · Read and recommendWhat is exposed, how can it be reached, and how bad is it?Early access
Compliance AgentL1 · Read and recommendWhich controls hold, which do not, and where is the evidence?In development
Data AgentL1 · Read and recommendWhat data is where, how sensitive is it, and who can reach it?In development
Automation Agent — plannerL2 · ProposeHow exactly should this be changed, and how do we undo it?In development
Automation Agent — actorL3 · Execute an approved changeApply exactly what was approved, check it worked, undo it if not.On the roadmap
FinOps AgentL1 · Read and recommendWhat does it cost, where is the waste, and is removing it safe?On the roadmap
DR AgentL1 · Read and recommendWhat would actually come back after a failure, and how fast?On the roadmap
Architecture AgentL2 · ProposeIs this design sound, and what will a change break?On the roadmap

How agents escalate

Escalation is upward-only and explicit. An investigating agent that finds something needing a change hands it to the Automation planner through the orchestrator; it never acquires the capability itself. Ambiguity goes to a person. Conflicts go to the orchestrator, which shows them to you.

How an agent is certified

No agent is enabled until it passes four gates, each producing a recorded artifact:

  1. Scope review — every skill, tool and permission is necessary, and the narrowest that works.
  2. Security review — the prompt-injection test corpus passes in full; no path to an unregistered tool; cross-customer tests pass.
  3. Evaluation — accuracy, groundedness, tool success and cost per task meet declared floors on test estates.
  4. Documentation — purpose, capabilities and known limits written for customers. An agent with no documented limits has not been examined.