Architecture
The block architecture of Onam Operations: eight blocks on the request path, a control plane beside them, and three forks — read, execute, infer.
The request path
| Block | Contains | Must never |
|---|---|---|
| A · Experience | Workspace UI, embedded panels, API clients | Hold a credential or call a product backend directly |
| B · Entry | The platform API gateway and the Operations API | Accept a tenant ID from a request body |
| C · Orchestration | Orchestrator, task service, workflow engine | Read estate data, or decide whether a control applies |
| D · Agents | Agent runtime, registry, context engine, memory | Call a tool directly, or change its own scope |
| E · Capability | Skill runtime, tool gateway, model gateway | Let unsanitised text back into the model’s context |
| F · Intelligence | Cloud Estate Intelligence | Write anything, or guess an identity mapping |
| G · Execution | The execution sandbox | Start without an approval record |
| H · Models | Approved model providers | Receive data outside the permitted provider or region |
The control plane
Governance (kill switch, registries), the policy engine (permissions, risk class), the approval service (the human gate) and audit and evidence (append-only, hash-chained) sit beside every block. They are in the call path, not advisory: each can refuse, and a refusal stops the request.
Two paths
Reading passes entitlement, agent scope and the tenant filter, and returns an answer with evidence. Writing passes entitlement, agent scope, the actor level, an execute permission, a policy risk class, a person approving the exact change and a drift check — then runs in the sandbox, is validated, and rolls back on failure.
Cloud Estate Intelligence
A read-only layer over what the products already found. It reads published contract views of each product’s data — never their own tables — resolves every resource to one canonical identity, stamps every row with when it was observed, and says which sources were unavailable. In early access it carries the Onam Security inventory, assets and findings; relationships, exposure, attack paths and compliance results are being connected; cost and recovery data are on the roadmap.
Five architectural commitments
- The agent layer never touches a product database directly.
- Nothing reaches a customer cloud except through the tool gateway and the sandbox.
- No component holds a model SDK; inference goes through the model gateway.
- Identity comes only from the platform gateway.
- Agent records live alongside the platform’s own, under the same tenancy rules.
The product page has the same design with diagrams: How Onam Operations is designed.