The orchestrator
The orchestrator turns a request into a plan, routes each step to a specialist agent, joins the results and surfaces conflicts. It never answers on its own.
Status: Early access.
What it does
- Detects the intent and classifies the request.
- Breaks it into steps and picks the agent for each.
- Builds a plan and resolves dependencies — steps with no dependency run in parallel.
- Passes each step the previous step’s result set, so agents narrow rather than re-discover.
- Aggregates the answers on one canonical resource identity.
- Surfaces conflicts between agents to you.
- If an action is needed, raises it for approval — and stops there.
The orchestrator has no access to estate data itself. An orchestrator that could read data would eventually answer a question on its own, unaudited and without evidence.
Kinds of request
| Kind | Produces | Example |
|---|---|---|
| Question | A direct answer from one agent | “How many production instances are in this account?” |
| Investigation | A plan and a joined answer | “Which exposed assets have critical findings, and who owns them?” |
| Action request | A plan, a proposal and an approval | “Close SSH from the internet on these instances.” |
| Workflow start | A workflow run | “Prepare this account for audit.” |
| Report | A synthesised document with evidence | “Give me the exposure summary for the board.” |
| Unsupported | A refusal with the reason | Anything outside cloud operations, or unsafe |
Conflicts are never auto-resolved
| Conflict | Example | What happens |
|---|---|---|
| Fact | Two sources disagree on an instance size | Both shown with sources and times; a declared precedence applies and is flagged |
| Judgement | Security says remove it; another agent says it is a recovery dependency | Escalated to you with both positions and their evidence |
| Recommendation | Downsize versus scale out | Shown as a trade-off; the orchestrator does not pick |
| Staleness | One source is hours older | The oldest time is reported as the answer’s freshness |
Failure handling
Permission denied is reported as “not authorised”, never as “no data”. A product that is down is named in the answer and the rest of the plan continues. A budget or loop limit stops the task and reports what is left undone. A failed validation after a change rolls back and is never retried with the same change.