Product field guide

From idea to governed fleet.

Kordana manages AI agents the way a company manages its people: every agent holds a position, is hired with a business case, passes certification and a trial period, works inside a governed flow, gets its performance review and its payroll line — and every important decision is signed by a person.

01·The journey at a glance

Four stages, one thread.

The position is designed and signed; the agent is proposed against it with its business case; it is certified with evidence and graduated to production; it operates inside its lane, escalating to humans when it must; and everything is measured, audited and can be retired with evidence. Every human signature on the map is a decision only an identified person can make — never a machine credential, no matter its permissions.

The official lifecycle

Uppercase states are the agent's official lifecycle; the lock marks the human-signature gates.

SOLICITADA

Decide the business casehuman signature

rejectRECHAZADAterminal
EN_DISENO

Compile the candidate version and sign the certification planhuman signature

CERTIFICADA

Trial period — canary runs that build the evidence

EN_PRUEBA

Graduation — favorable scorecard + human signaturehuman signature

ACTIVA

Freeze ⇄ resume — lifecycle commands

Verified retirement — scorecard evidence + human signaturehuman signature

ARCHIVADAterminal
  • Flywheel: every structured return hardens the next version's certification.
  • The scorecard gates graduation: no favorable verdict, no production.

The verdict is deterministic

Promoting, retiring or declaring a winning version depends on scorecards Kordana computes with fixed rules — never on an AI model's opinion.

The signature is human

Approving, signing, graduating and retiring require an identified person. Automated engines provide evidence, never authority.

02·Actors

Who uses Kordana

Fleet operator

Watches the control room, handles escalations, reviews performance and cost, exercises the lifecycle.

Role author & signer

Designs the positions, connects tools and signs contracts, plans and promotions.

Platform staff

Maintains the global catalogs (models, integrations) behind the scenes; never decides for the customer.

API integrations

Customer systems that query inventory and results. They never sign nor launch runs.

03·Before you start

Administration: getting the house ready

What a workspace needs before onboarding its first agent.

Sign in as a human

Corporate SSO or email + one-time code. Both identify the person — the condition for crossing any signature gate. Integrations use API keys, which only read and operate signature-free surfaces.

The fleet org chart

Fleet → domains → groups → units. It's not decorative: metrics aggregate, and policies and budgets inherit down that tree.

Default-deny access

Nobody does anything an access role doesn't explicitly grant; sensitive permissions (sign, write units, execute, manage escalations) are granted one by one, today at full-workspace scope.

subtree scoping · on the roadmap

04·Stage 1

Onboard: from position to ready agent

The position comes first. Every agent is proposed to fill an existing Role, so designing and signing the Role precedes enrollment.

  1. 01

    Design the Role

    /build · /library

    The Role is the position: mission, limits, allowed tools, knowledge, escalation rules, budget and model tier (economy · standard · premium — never a specific model). You can request an assisted proposal, start from a Library template, and draw the workflow in the editor: early triage, multiple decisions, branches that reconverge — with a topology preview before signing. Every branch must be able to terminate, and what's not allowed doesn't even exist in the flow.

  2. 02human signature

    Sign the Role contract

    The signature turns the design into a contract: it validates the flow, materializes least-privilege access and leaves the snapshot in the ledger. The design proposes; the Role owner signs.

  3. 03

    Propose the Unit

    /lifecycle · /register if external

    Against the signed Role, you propose who will fill it. A native agent is enrolled from the lifecycle; one built outside is inventoried in Register with scoped management. Enrollment creates the agent and its business case in a single act: there is no agent without a value justification.

    State: REQUESTED · business case under review

  4. 04human signature

    Decide the business case

    /lifecycle

    Approving moves the agent to design in the same operation; rejecting ends the journey right there, with a record of why.

    State: IN_DESIGN · REJECTED

  5. 05

    Connect tools

    /connect

    Only the curated catalog (Gmail, Slack, CRM…) — never the raw universe. The connection is per workspace (guided OAuth or API key, encrypted credential, health probe); access is per agent, with the exact list of allowed actions. Knowledge lives apart: registered by reference and queried live; its health is watched in Freshness.

    binding enrollment from console · on the roadmap (API today)

  6. 06

    Set the position's limits

    Budget per period with an action on exhaustion (alert, degrade or halt — enforced on every call, not at month-end), inheritable policies and, if the workspace brings its own model keys (BYOAI), they are encrypted and provisioned with the platform. Control and metering charges never go to customer keys: measurement doesn't depend on who is measured.

  7. 07human signature

    Compile the candidate version

    The exact snapshot (contract + flow + access + configuration) that will be certified. No candidate version, no path to production.

05·Stage 2

Certify & trial: evidence, not trust

Nothing reaches production because it “looks good”: it gets there because it passed measurable tests and a person signed it.

  1. 01signs the plan

    Executable certification

    An eval bank (versioned, immutable test cases) + a signed plan that sets thresholds. The engine runs the bank and returns per-case results: it provides evidence, it never signs. With the evidence approved, a person executes the transition to certified.

    State: IN_DESIGN → CERTIFIED

  2. 02

    Trial period

    The phase to observe performance under bounded conditions before production. Canary runs launch exactly like production ones — from the agent's page, humans only — and they're what builds the period's evidence; exit requires a favorable scorecard.

    State: IN_TRIAL

  3. 03human signature

    Graduation to production

    Two keys turn together: a favorable scorecard (the deterministic verdict) and a human signature (a person owns the decision). The candidate version becomes the only active version.

    State: ACTIVE · operational life begins

06·Stage 3

Operate: the fleet's day to day

Watch, execute, intervene and measure — with the human always in command of what matters.

Watch the Control room

/

The panoramic view: the org chart with its groups, every agent with its health signal (healthy · attention · intervention), aggregates by fleet/domain/group and recent runs. At a glance you know where to look.

Launch runs

humans only

/units/:id

Only a person launches a run — an API key gets a no, whatever its permissions. The agent receives, plans, acts with its allowed tools and verifies before closing. Intelligence drives inside the signed lane: what's not allowed doesn't exist in its topology. Every call passes through model tier, budget and metering.

Handle escalations

/escalations

When the agent hesitates or hits a limit, it doesn't improvise: it stops and escalates with the context packaged. The answer is a structured return — decision, reason and labels, not a loose “ok” — that resumes it exactly where it was. Every return is captured knowledge: the raw material of the flywheel.

Measure performance & cost

/scorecards · /payroll

Each period, every agent receives its scorecard (cases closed, escalations, violations, SLA, cost vs. budget — with a clear verdict) and its line in the fleet payroll. Agents stop being a fuzzy cost: each one is accountable like any member of the team.

07·Stage 4

Govern: control for the entire life

And the loop closes: every human intervention makes the fleet better.

Lifecycle

/lifecycle + agent page

The full pipeline in one view; freeze ⇄ resume and retire are exercised from the agent's page, and each command is enabled only when legal from the current state.

re-versioning a live agent · on the roadmap

Guardrails & edge enforcement

/guardrails

The hard limits no agent crosses; for customers with their own gateway, Kordana pushes the signed policy to the edge and verifies its obedience without touching data traffic.

Knowledge freshness

/freshness

Probes the sources, measures their age against thresholds and alerts before it shows in the answers.

Immutable audit

Every approval, signature, transition and revocation lands in a ledger that can't be edited or deleted, not even with privileged access.

The flywheel — how the fleet improves

  1. 1An agent escalates; the operator answers with a structured return.
  2. 2That return is promoted to a test case with its lineage.
  3. 3A curator adds it to the eval bank (new version, immutable).
  4. 4The next version certifies against a bank that already includes exactly the cases where the previous one needed help.
  5. 5The scorecard proves the improvement (or not) — with a human signature at every gate.

Nothing is lost as stale conversation: operations train the measuring stick.

The ending is governed too

Retirement requires scorecard evidence and a human signature; archiving takes the final snapshot and revokes all of the agent's credentials — no way back and no orphan credentials.

human signature RETIRED → ARCHIVED

08·Annex

Quick reference

StageWhereWhat you doGate
Administration/iam · /settingsAccess, users, API keysAdmin permissions
Onboard/build · /libraryDesign the Role and its flowSession
Onboard/buildSign the Role contractSign permission + human signature
Onboard/lifecycle · /registerAgent enrollment + business caseSession
Onboard/lifecycleDecide the business caseWrite + human signature
Onboard/connectConnect workspace toolsSession
CertifyEvals API and lifecycleBank, signed plan, certification and transitionsHuman signature + evidence
Operate/Watch the fleetSession
Operate/units/:idLaunch a runExecute permission + humans only
Operate/escalationsReturn (structured)Registered human
Operate/scorecards · /payrollMeasure performance & costSession
Govern/units/:idFreeze / resume / retireWrite + human signature
Govern/guardrails · /freshnessHard limits and freshnessSession

Mini-glossary

Unit / agent
The managed agent: the entity that travels this journey end to end.
Role (the position)
Mission, limits, tools, knowledge, escalation, budget and model tier. The Role is signed; the agent executes it.
Business case
The value justification every agent must pass before entering design. No case, no agent.
Candidate version
The exact snapshot of the agent that gets certified and trialed; on graduation it becomes the only active version.
Escalation & structured return
The governed halt: the agent hands the case to a person with full context; the typed response resumes it and feeds the flywheel.
Scorecard
The deterministic per-period performance review — the only signal that gates graduations and backs retirements.
Payroll
Cost per agent and period, against budget: FinOps for the fleet.
Flywheel
Return → test case → eval bank → certification of the next version: operations improve measurement, and measurement improves the fleet.
Human signature
Every sensitive decision is made by a registered person who signed in as a human (SSO or email+code). Machines provide evidence, never authority.

Ready to onboard your first agent?

Start with a 14-day trial and walk the full journey: from signed position to governed fleet.