Skip to main content
An agent is an LLM worker that reacts to events. When an event reaches its inbox, the platform loads the agent’s prompt and tools; the agent reasons and calls tools; and it emits events. It never writes entity state directly: it emits, and a system node decides what to persist.

The agent contract

An agent is declared as a map entry in agents.yaml. The key is the agent’s id (its address) and, by default, the role name it fulfills (used to resolve prompts/<role>.md and to match required_agents in schema.yaml), so you usually do not write id: or role: inside the entry.
Memory scope is derived from the flow’s instance model — one conversation per flow instance, so in a mode: template flow that means one per instance/entity. memory: true on a flow with no per-instance identity (a plain root flow) fails at boot with an error explaining why: there is no flow-instance owner to scope the conversation to.

What an agent can call

You list only declared tools in tools. Beyond those, every agent automatically gets:
  • Universal tools: agent_message, mailbox_send.
  • Emit tools: emit_{event_name} for each entry in emit_events.
  • Role-scoped entity tools: read_*, save_*, update_*, generated from the entity contract and entity_writes.
  • read_flow_data: generated only when a flow-scoped agent declares flow_data_access, to read deploy-time reference files shipped with the flow.
Host capabilities (bash, web_search, file_io) are gated separately by the native_tools field, a channel independent of tools and permissions. See Tools.

Prompts

Each agent has a markdown prompt at prompts/{agent-id}.md. Prompts use {{variable}} placeholders, substituted at session creation from four sources, in priority order:
  1. Instance variables
  2. Policy values
  3. Entity-state fields
  4. A small runtime-token allowlist (current_date, agent_id, flow_instance_path)
Substitution is plain string replacement with no logic, and a variable that resolves nowhere is left as-is.
The platform appends a short environment postamble (the workspace mount paths) to every prompt. It does not list tools; the model sees those through the tool definitions.

Keeping reviewers independent

To stop two agents from sharing context, give a role two pools — separate agent entries for the same role with different subscriptions — and route originals to one and appeals to the other. Same prompt, separate sessions, no shared context.
The older model_tier and conversation_mode/session_scope fields are retired; model and memory replace them.