The verdict is deterministic
Promoting, retiring or declaring a winning version depends on scorecards Kordana computes with fixed rules — never on an AI model's opinion.
Product field guide
Kordana manages AI agents the way a company manages its people: every agent holds a position, is hired with a business case, passes certification and a trial period, works inside a governed flow, gets its performance review and its payroll line — and every important decision is signed by a person.
01·The journey at a glance
The position is designed and signed; the agent is proposed against it with its business case; it is certified with evidence and graduated to production; it operates inside its lane, escalating to humans when it must; and everything is measured, audited and can be retired with evidence. Every human signature on the map is a decision only an identified person can make — never a machine credential, no matter its permissions.
Uppercase states are the agent's official lifecycle; the lock marks the human-signature gates.
Decide the business casehuman signature
Compile the candidate version and sign the certification planhuman signature
Trial period — canary runs that build the evidence
Graduation — favorable scorecard + human signaturehuman signature
Freeze ⇄ resume — lifecycle commands
Verified retirement — scorecard evidence + human signaturehuman signature
Promoting, retiring or declaring a winning version depends on scorecards Kordana computes with fixed rules — never on an AI model's opinion.
Approving, signing, graduating and retiring require an identified person. Automated engines provide evidence, never authority.
02·Actors
Watches the control room, handles escalations, reviews performance and cost, exercises the lifecycle.
Designs the positions, connects tools and signs contracts, plans and promotions.
Maintains the global catalogs (models, integrations) behind the scenes; never decides for the customer.
Customer systems that query inventory and results. They never sign nor launch runs.
03·Before you start
What a workspace needs before onboarding its first agent.
Corporate SSO or email + one-time code. Both identify the person — the condition for crossing any signature gate. Integrations use API keys, which only read and operate signature-free surfaces.
Fleet → domains → groups → units. It's not decorative: metrics aggregate, and policies and budgets inherit down that tree.
Nobody does anything an access role doesn't explicitly grant; sensitive permissions (sign, write units, execute, manage escalations) are granted one by one, today at full-workspace scope.
subtree scoping · on the roadmap
04·Stage 1
The position comes first. Every agent is proposed to fill an existing Role, so designing and signing the Role precedes enrollment.
/build · /library
The Role is the position: mission, limits, allowed tools, knowledge, escalation rules, budget and model tier (economy · standard · premium — never a specific model). You can request an assisted proposal, start from a Library template, and draw the workflow in the editor: early triage, multiple decisions, branches that reconverge — with a topology preview before signing. Every branch must be able to terminate, and what's not allowed doesn't even exist in the flow.
The signature turns the design into a contract: it validates the flow, materializes least-privilege access and leaves the snapshot in the ledger. The design proposes; the Role owner signs.
/lifecycle · /register if external
Against the signed Role, you propose who will fill it. A native agent is enrolled from the lifecycle; one built outside is inventoried in Register with scoped management. Enrollment creates the agent and its business case in a single act: there is no agent without a value justification.
State: REQUESTED · business case under review
/lifecycle
Approving moves the agent to design in the same operation; rejecting ends the journey right there, with a record of why.
State: IN_DESIGN · REJECTED
/connect
Only the curated catalog (Gmail, Slack, CRM…) — never the raw universe. The connection is per workspace (guided OAuth or API key, encrypted credential, health probe); access is per agent, with the exact list of allowed actions. Knowledge lives apart: registered by reference and queried live; its health is watched in Freshness.
binding enrollment from console · on the roadmap (API today)
Budget per period with an action on exhaustion (alert, degrade or halt — enforced on every call, not at month-end), inheritable policies and, if the workspace brings its own model keys (BYOAI), they are encrypted and provisioned with the platform. Control and metering charges never go to customer keys: measurement doesn't depend on who is measured.
The exact snapshot (contract + flow + access + configuration) that will be certified. No candidate version, no path to production.
05·Stage 2
Nothing reaches production because it “looks good”: it gets there because it passed measurable tests and a person signed it.
An eval bank (versioned, immutable test cases) + a signed plan that sets thresholds. The engine runs the bank and returns per-case results: it provides evidence, it never signs. With the evidence approved, a person executes the transition to certified.
State: IN_DESIGN → CERTIFIED
The phase to observe performance under bounded conditions before production. Canary runs launch exactly like production ones — from the agent's page, humans only — and they're what builds the period's evidence; exit requires a favorable scorecard.
State: IN_TRIAL
Two keys turn together: a favorable scorecard (the deterministic verdict) and a human signature (a person owns the decision). The candidate version becomes the only active version.
State: ACTIVE · operational life begins
06·Stage 3
Watch, execute, intervene and measure — with the human always in command of what matters.
/
The panoramic view: the org chart with its groups, every agent with its health signal (healthy · attention · intervention), aggregates by fleet/domain/group and recent runs. At a glance you know where to look.
/units/:id
Only a person launches a run — an API key gets a no, whatever its permissions. The agent receives, plans, acts with its allowed tools and verifies before closing. Intelligence drives inside the signed lane: what's not allowed doesn't exist in its topology. Every call passes through model tier, budget and metering.
/escalations
When the agent hesitates or hits a limit, it doesn't improvise: it stops and escalates with the context packaged. The answer is a structured return — decision, reason and labels, not a loose “ok” — that resumes it exactly where it was. Every return is captured knowledge: the raw material of the flywheel.
/scorecards · /payroll
Each period, every agent receives its scorecard (cases closed, escalations, violations, SLA, cost vs. budget — with a clear verdict) and its line in the fleet payroll. Agents stop being a fuzzy cost: each one is accountable like any member of the team.
07·Stage 4
And the loop closes: every human intervention makes the fleet better.
/lifecycle + agent page
The full pipeline in one view; freeze ⇄ resume and retire are exercised from the agent's page, and each command is enabled only when legal from the current state.
re-versioning a live agent · on the roadmap
/guardrails
The hard limits no agent crosses; for customers with their own gateway, Kordana pushes the signed policy to the edge and verifies its obedience without touching data traffic.
/freshness
Probes the sources, measures their age against thresholds and alerts before it shows in the answers.
Every approval, signature, transition and revocation lands in a ledger that can't be edited or deleted, not even with privileged access.
Nothing is lost as stale conversation: operations train the measuring stick.
Retirement requires scorecard evidence and a human signature; archiving takes the final snapshot and revokes all of the agent's credentials — no way back and no orphan credentials.
human signature RETIRED → ARCHIVED
08·Annex
| Stage | Where | What you do | Gate |
|---|---|---|---|
| Administration | /iam · /settings | Access, users, API keys | Admin permissions |
| Onboard | /build · /library | Design the Role and its flow | Session |
| Onboard | /build | Sign the Role contract | Sign permission + human signature |
| Onboard | /lifecycle · /register | Agent enrollment + business case | Session |
| Onboard | /lifecycle | Decide the business case | Write + human signature |
| Onboard | /connect | Connect workspace tools | Session |
| Certify | Evals API and lifecycle | Bank, signed plan, certification and transitions | Human signature + evidence |
| Operate | / | Watch the fleet | Session |
| Operate | /units/:id | Launch a run | Execute permission + humans only |
| Operate | /escalations | Return (structured) | Registered human |
| Operate | /scorecards · /payroll | Measure performance & cost | Session |
| Govern | /units/:id | Freeze / resume / retire | Write + human signature |
| Govern | /guardrails · /freshness | Hard limits and freshness | Session |
Start with a 14-day trial and walk the full journey: from signed position to governed fleet.