Onam Security

Automation Agent

The Automation Agent works in two modes: a planner that turns a recommendation into a reversible change proposal, and an actor that may execute only from an approval.

Every agent in Onam Operations is a versioned definition — purpose, level, skills, tools and permissions held as data — certified through scope review, security review, an evaluation suite and documentation before it can be enabled. See how agents work and the full roster.

Automation Agent — planner

Status: In development. Proposal flow is built; blast-radius inputs are being connected.

LevelL2 · Proposer
AuthorityPropose
AnswersHow exactly should this be changed, and how do we undo it?

Turns an accepted recommendation into a precise, reversible change proposal: the exact change, its rollback, its blast radius and a dry run — writing nothing outside the proposal.

What it does

  • Builds the exact change artifact and its rollback artifact
  • Assesses blast radius from recorded dependencies and recent activity
  • Simulates the change with no side effect
  • Raises the proposal to the approval queue

Skills it may invoke

generate_remediation_plan · build_change_artifact · build_rollback_artifact · assess_blast_radius · simulate_change

Tools its skills may use

cei.query · cei.graph_traverse · engine.policy · cloud.config.read · cloud.audit.read · cloud.change.plan

What it must never do

  • Apply a change
  • Approve anything — agents cannot hold approval authority

Known limits

Blast radius comes from recorded dependencies and recent activity and may miss traffic the platform does not observe.


Automation Agent — actor

Status: On the roadmap. Built and tested in the platform; not enabled for any customer.

LevelL3 · Actor
AuthorityExecute an approved change
AnswersApply exactly what was approved, check it worked, undo it if not.

Executes an approved change against an unchanged target inside an isolated sandbox, validates the result, rolls back on failure and produces the evidence package.

What it does

  • Re-reads the target and aborts if it changed since approval
  • Applies the approved artifact — nothing wider — with short-lived, scoped credentials
  • Validates the result and rolls back automatically on failure
  • Stores the before state, the commands and the after state as evidence

Skills it may invoke

execute_change · validate_change · rollback_change · produce_execution_evidence

Tools its skills may use

cloud.*.write (scoped, one hour) · repo.pull_request · cloud.change.plan · evidence.store

What it must never do

  • Start from chat — only from an approval record
  • Widen a change beyond the approved artifact
  • Continue past a failed validation

Known limits

Requires you to create a write role in your own cloud account and to raise your autonomy ceiling past “propose”.

Status labels mean exactly what Availability says. Nothing marked “On the roadmap” is offered today.