Concepts: agents, skills, tools, tasks and approvals
The words Onam Operations uses, each with one meaning. Permissions are only reasonable when these are never used interchangeably.
The vocabulary
| Term | Meaning | Example |
|---|---|---|
| Agent | A specialist with a declared purpose, level, skills, tools and permissions — a versioned definition, not a prompt | Security Agent, L1 |
| Skill | A declared, versioned capability with typed input and output, a risk level and an evidence contract | find_public_exposure |
| Tool | A concrete integration that touches something outside the platform | cei.query |
| Permission | Authority for one agent to perform one action on one class of resource through one tool | Security Agent may read findings |
| Policy | A rule, held as data, that decides whether something may happen and how many approvals it needs | Production security-group changes are high risk |
| Task | One unit of work with a lifecycle, an owner and a result | Investigate exposure of one instance |
| Workflow | A versioned multi-step procedure that can outlive a request | Prepare an account for audit |
| Action | A single attempted change to the outside world | Replace one ingress rule |
| Approval | A recorded human decision authorising one specific change at one version | Approved by a named person, bound to the change’s hash |
| Evidence | The data behind a claim, retained and addressable | Query, 14 rows, scan ID, time observed |
| Memory | What an agent keeps between turns, deliberately narrow | “This organisation treats staging as production for data classification” |
How they relate
- A person creates a task; the orchestrator assigns its steps to agents.
- An agent invokes skills; skills use tools; only the tool gateway runs a tool.
- Every tool call is gated by permission; policy classifies the risk.
- Skills produce evidence. A change needs an approval before an action can exist.
Two rules follow and are enforced everywhere:
- The only path to your cloud runs through an approval. There is no route from an agent to your cloud.
- Agents never call tools. The skill layer exists so capability can be governed as data.
Agent levels
| Level | Name | Reads | Writes | Approval |
|---|---|---|---|---|
| L1 | Investigator | Any estate domain it is granted | Its own investigation notes | None — it cannot change anything |
| L2 | Proposer | Any estate domain it is granted | Change proposals only | Every proposal needs a human decision before anything is applied |
| L3 | Actor | Any estate domain it is granted | The customer cloud, scoped to one approved change | Mandatory, per action. Starts only from an approval record |
| L4 | Orchestrator | No estate data at all | Nothing | Routes work; never answers or acts itself |
An agent’s level is fixed in its definition. Promotion needs re-certification; it is never a runtime decision.
Memory never holds a fact about your estate
Estate facts change; a remembered fact goes stale silently. Agents read the current estate on every turn, with its observed time. Memory holds preferences and context you give them — and never a secret.