Onam Security

Concepts: agents, skills, tools, tasks and approvals

The words Onam Operations uses, each with one meaning. Permissions are only reasonable when these are never used interchangeably.

The vocabulary

TermMeaningExample
AgentA specialist with a declared purpose, level, skills, tools and permissions — a versioned definition, not a promptSecurity Agent, L1
SkillA declared, versioned capability with typed input and output, a risk level and an evidence contractfind_public_exposure
ToolA concrete integration that touches something outside the platformcei.query
PermissionAuthority for one agent to perform one action on one class of resource through one toolSecurity Agent may read findings
PolicyA rule, held as data, that decides whether something may happen and how many approvals it needsProduction security-group changes are high risk
TaskOne unit of work with a lifecycle, an owner and a resultInvestigate exposure of one instance
WorkflowA versioned multi-step procedure that can outlive a requestPrepare an account for audit
ActionA single attempted change to the outside worldReplace one ingress rule
ApprovalA recorded human decision authorising one specific change at one versionApproved by a named person, bound to the change’s hash
EvidenceThe data behind a claim, retained and addressableQuery, 14 rows, scan ID, time observed
MemoryWhat an agent keeps between turns, deliberately narrow“This organisation treats staging as production for data classification”

How they relate

  • A person creates a task; the orchestrator assigns its steps to agents.
  • An agent invokes skills; skills use tools; only the tool gateway runs a tool.
  • Every tool call is gated by permission; policy classifies the risk.
  • Skills produce evidence. A change needs an approval before an action can exist.

Two rules follow and are enforced everywhere:

  1. The only path to your cloud runs through an approval. There is no route from an agent to your cloud.
  2. Agents never call tools. The skill layer exists so capability can be governed as data.

Agent levels

LevelNameReadsWritesApproval
L1InvestigatorAny estate domain it is grantedIts own investigation notesNone — it cannot change anything
L2ProposerAny estate domain it is grantedChange proposals onlyEvery proposal needs a human decision before anything is applied
L3ActorAny estate domain it is grantedThe customer cloud, scoped to one approved changeMandatory, per action. Starts only from an approval record
L4OrchestratorNo estate data at allNothingRoutes work; never answers or acts itself

An agent’s level is fixed in its definition. Promotion needs re-certification; it is never a runtime decision.

Memory never holds a fact about your estate

Estate facts change; a remembered fact goes stale silently. Agents read the current estate on every turn, with its observed time. Memory holds preferences and context you give them — and never a secret.