Operate Agents

Inspect Agent identity, follow Resource bindings, and understand which revision a Run executes.

Before you begin

You need agent:read access to the namespace. For Run inspection, also request run:read and ledger access. Know whether the Agent uses fixed Resource CRNs or scoped selectors resolved from tenant, customer, or principal authority.

Steps

  1. Open the Agent detail page or call GET /v1/namespaces/:namespace/agents/:agent. Confirm its CRN, version, mode, deployment revision, and enabled state.
  2. Compare the current model, Resource, Policy, Toolset, and limits with the release manifest. Follow linked CRNs rather than relying on display names.
  3. Inspect Recent runs. This list is a bounded analytics snapshot, so open an individual Run when exact state matters.
  4. Review status, queue and execution timing, customer identity, Policy hash, Resource snapshot, journal, waits, controls, usage, and committed facts. Page the journal or ledger when the bounded initial snapshot has more data.
  5. If the package is wrong, redeploy the corrected package using the same Agent id. A version bump is not required. Existing Runs continue on their accepted deployment.
  6. Apply pause, resume, interrupt, cancel, Policy, rebind, truncate, or branch controls at the Run boundary; Agent SDK code does not administer itself.
  7. Disable new admission only after reviewing Policy and operational impact. Disabling never rewrites accepted Run history.

Verify

A valid Agent has a resolvable canonical CRN, a complete binding snapshot, a bounded Tool catalog, positive limits, and a current executable revision. Existing Runs must continue to report the exact revision accepted at their boundary even after a newer Agent is deployed.

Next steps

Read Run operations for safe-point controls and durable history, or Channel operations for ingress routing.