Platform Ontology · Revision
An agent is not a program you configure. It is an entity with a constitution, senses, memory, and a brain to reason with — everything it is, bounded by a single membrane of trust.
The one idea to keep
The revision turns on a single distinction that your original sketch already had right: the MCP data source is not a tool the agent picks up — it is a sense the agent is born with.
In Uderia the user's MCP server is configured in Configuration → MCP Servers, a permanently separate namespace from Platform Connectors. So it already belongs to the DNA, not to Components. That placement isn't an accident of the UI — it's the truth of the architecture.
And it's the truth of the capability. Because the OPTIM / tool_enabled class runs the entire Fusion Optimizer over MCP tools — strategic and tactical planning, twelve rewrite passes, orchestrators, plan hydration, RAG champion cases, self-correction — the MCP server is not a generic, swappable connector. The agent's reasoning apparatus is co-designed with it. A generic tool you bolt on. A sense, you're born with. That is exactly the line between DNA and Components — and it's a line no generic agent platform draws.
What the agent is born with: the brain that reasons and the senses it natively perceives its data world through. Constitutional; the reasoning engine is built around them.
→ MCP data source · LLM (the brain) · IFOC classCapabilities layered on top and shared across agents. Chart, canvas, dashboard, flow — and the Platform Connectors (browser, files, web, Google/M365).
→ Components · Platform ConnectorsThe five faculties
The star stays — it's the right hero for an agent-centric platform. Each point is a distinct faculty: what the agent is, what it perceives, what it remembers, what it knows, and what it can do. Together they make one identity — and the brain that reasons over them is born into the DNA, not bolted on. And no agent is truly alone: the faint constellation around the membrane is Coordination, one agent composing many.
Configuration
What the agent is born with: its brain (the LLM & provider), its profile class, and — critically — the MCP data source, its primary sense. Inherited, defining, differentiating.
Session
What the agent perceives right now. The current context, isolated per session — the percept, distinct from the sensory organ that produces it.
Memory
What the agent remembers across sessions. Per-agent (local) facts and shared (global) facts about the user — recalled, governed, inspectable.
Intelligence
What the agent knows — its semantic layer, split by origin: acquired knowledge (Knowledge repositories, the ontology/KGs, domains) and learned expertise (Planner repositories — proven strategies from successful runs).
Components
What the agent can do. Chart, canvas, dashboard, flow, scheduler — plus Platform Connectors. Shared, pluggable instruments, not part of the body.
Genie · Coordination
An agent can compose other agents. The star draws one identity; a coordinator is a star made of stars — now the faint constellation framing the membrane. Genie mode, made visible.
The two foundations
Grounding and Guardrails are the load-bearing floor — the agent's principles, not its parts. One keeps it honest about what it knows; the other keeps it safe in what it does.
truth · faithfulness
The agent may only claim what its trusted scope supports. Answers stay faithful to the KG-declared, deployed knowledge — no confident drift into databases it was never grounded in.
Tier 1.1 · grounding gate · pass / annotate / blockrules · safety
The rules the agent must never break: no PII leaking outbound, no toxic output, no prompt-injection reaching the model. Policy, enforced at the request path.
Tier 1.3 · outbound redaction · inbound blockGrounding's role is Truth / Faithfulness, not Values — "values" reads as ethics, which is what Guardrails carry. Grounding is about factual fidelity: the sharpest, most defensible claim the platform makes. And both foundations are graduated, not binary — each runs on the same ladder: off → observe (measure, never alter — the default) → annotate → review (withhold, but keep the original for a human) → enforce. You climb it deliberately, per agent.
The boundary
Your dashed membrane is the right perimeter — but its most novel property isn't that it encloses the agent. It's that a trusted agent is made of trusted ingredients: the identity is 🟢 only when its ontology, its skills, its configuration each verify. A consumer reads one badge; the composition is what earns it.
So the membrane isn't just a box drawn around the star. Each point carries its own trust state, and the agent's trust is their sum — signable, cryptographically verifiable, and portable across instances. That is the claim the diagram should make out loud, because it's the one competitors can't casually copy.
The membrane breathes
A signature proves an agent is unchanged. It cannot prove it is behaving. The end-to-end approach closes that gap: measured conduct changes trust, trust can change enforcement, and every step is visible and verifiable. The membrane is not stamped once — it breathes.
Trust in Uderia is a composite of four axes. The star is the first; the membrane, the second; and two more make the picture end-to-end:
who the agent is
The Profile itself — the star. Its IFOC class, its brain, its senses, memory, and components. The @TAG profile is the agent.
the five facultiesis it what was signed?
The Trust Membrane — compositional, tamper-evident, offline-verifiable. Static integrity: 🟢 only when every ingredient is. And dynamic: a Behavioral Trust Score fuses that signature with measured conduct, so the badge earns trust and honestly withdraws it as behaviour declines.
Trust Membrane · Behavioral Trust Score · circuit breakerwhat may it do, on whose behalf
Agent Authority. When an agent acts on its own — a scheduled task, a coordinator's expert, a flow step — it runs as a strict subset of its owner, checked fail-closed at every tool, every action attributed to the agent. Trust ≠ access: a checked thing is not an authorised one.
Agent Authority · autonomous principalcan it be proven, later
The provenance chain. Every turn is sealed into an Ed25519-signed, tamper-evident record — and every answer carries a verifiable receipt the consumer can export and check offline. Even the quality verdicts are signed and bound to the trajectory they grade.
Execution Provenance Chain · answer receiptsThese four turn on one turn of the loop. A user request is screened (inbound guardrail), the acting principal is set (authority), the trusted scope is stamped (grounding), every tool call is enforced, the answer is guarded and grounded on the way out, the turn is scored, and the whole thing is sealed. What that loop measures then feeds back: an agent that drifts is caught by evaluation; sustained bad conduct trips a circuit breaker that can freeze its unattended use; a risky answer can be held for a human instead of discarded; and no path is silent — a poisoned memory, document, or tool result is defused at the door, and every incident becomes a worked item in an Assurance Inbox. Before you tighten any of it, you can backtest the policy over real history or red-team the agent — deciding on evidence, not faith.
Most platforms sell trust as filtering (guardrails that block) or as reporting (dashboards that observe). Uderia sells it as closed-loop, verifiable trust: measured behaviour changes the trust state, the trust state can change enforcement, and every step of that loop — down to the individual answer — is cryptographically provable. That is the whole membrane, breathing.
Changelog
| Point | Before | After & why |
|---|---|---|
| DNA | DNA (Basic Senses) | Kept & promoted — now the anchor idea. MCP-as-sense is stated on the diagram as the differentiator. |
| Brain | unnamed | named inside the DNA. You're born with a unique DNA, brain and basic senses — the LLM is the brain, part of Configuration, not a separate center. |
| Intelligence | Intelligence = Intelligence | Knowledge & Expertise → Intelligence. Covers the whole semantic layer — acquired knowledge (repos/KGs) + learned expertise (planner repos), not just the learned half. |
| Memory | Lcoal / Globa | Local / Global Remembrance. Typo fix; reworded — memory named as remembrance. |
| Grounding | Values | Truth · Faithfulness. Values reads as ethics — that's Guardrails' job. |
| Kinds | five equal spokes | each point tagged constitution / state / knowledge / capability. They aren't the same kind of thing. |
| Membrane | a container | compositional trust. Trusted agent = trusted ingredients. |
| Coordination | absent | drawn as the outer constellation. Genie mode — a star made of stars framing the membrane. |
| Foundations | binary floor | graduated ladder. off → observe → annotate → review → enforce, per agent — including the new HITL "review" that withholds but keeps the original for a human. |
| Membrane | a signed stamp | a breathing loop. Static integrity + dynamic Behavioral Trust Score: the badge earns and withdraws trust as conduct is measured; a circuit breaker responds. |
| Axes | identity + assurance | four axes. Identity · Assurance · Access (Agent Authority) · Audit (provenance + verifiable answer receipts) — the end-to-end picture. |
| Grounding | SQL scope only | two lanes, one gate. The same gate now grounds answers built from retrieved knowledge — a corpus-support trigger with second-chance retrieval, escalating to the groundedness judge, with unsupported claims marked in the answer itself; plus a sufficiency-honesty check so weak retrieval never becomes a confident specific answer. |
| Intelligence | trusted ingredient, unscreened | the knowledge lane made trustworthy. An ingest firewall screens documents at the source; a corpus's signature is now earned (fully screened, critical findings resolved); every answer shows its source's integrity, staleness and sensitivity; a poisoned document is one click from reversible quarantine — plus beyond-par retrieval-anomaly monitoring, sensitivity ceilings, and a source-consistency judge. |