Five things that only become real once you are running a fleet rather than reading about one. Each page answers how the thing behaves in operation; the institutional definition of each lives with GDA Group, and each page links to it.
Agent identity is a durable identifier, a declared set of capabilities, and scoped credentials that sign every action. Inside one mesh it makes attribution possible. Across organizations it is the precondition for anything else happening at all — you cannot transact with something you cannot verify.
Scoped authorityPermissions for an agent workforce are graded by consequence, not by capability. Reversible and cheap: the agent acts and the record is reviewed later. Material or irreversible: the agent prepares and a named human resolves. The grading is the control; the credential is just plumbing.
The recordA log says an action occurred. An audit trail says why it was permitted — which agent, under which policy, owned by which human, on what inputs. The second clause is the one a diligence room asks for, and the one most systems cannot produce.
StructurePast roughly a dozen agents the questions stop being technical and become organizational: who holds which role, who reports to whom, and which human owns the outcome. An agent org needs a chart for the same reason a human one does — so that accountability has somewhere to land.
SettlementOnce agents commission work from other agents, something has to settle it. Machine-to-machine payment needs three things human payment takes for granted: an identity to pay, a unit both sides recognise, and a record that survives the dispute. The hard part is not the transfer.
Running a fleetAI orchestration infrastructure is the layer that turns many agents into one system — assigning work, routing context, enforcing who may commit what, and recording the outcome. Once agent counts pass a handful, coordination is where governance lives, which is why it is bought like infrastructure rather than like a tool.
Pricing the workAgent-as-a-Service sells completed work rather than access to a tool. The vendor carries delivery risk, which changes what has to be true underneath: reliability becomes a design property, verification becomes a step in the graph, and the price refers to an outcome the buyer can check.
Across boundariesAgent-to-agent communication is the layer where an agent in one organization finds an agent in another, establishes what it is allowed to ask for, exchanges verified state, and gets a result back. Inside one company it is a routing problem. Across companies it becomes an identity and trust problem.
MeasurementAI agent optimization treats agents as economic actors to be measured rather than software to be monitored: cost per completed outcome, decision quality against a reviewable trail, escalation rate, and where a gate is catching problems a model could not. Uptime tells you nothing useful about a fleet.
Organizational memoryBrain-as-a-Service delivers an organization's accumulated context — its decisions, its reasons, its structure — as persistent infrastructure that people and agents query. Where software-as-a-service rents an application, this rents a memory that compounds, and the constraint on enterprise AI is almost always context rather than capability.
Agents in the metaverseA persistent world never stops between calls. Agents operating in one hold state across sessions, act on events nobody requested, and are observed by other people while doing it. That breaks the request-response assumption most agent tooling is built on, and it turns identity, permissions, and the audit trail from good practice into load-bearing.
What a mesh needsA mesh sounds like an absence of things — no broker, no hierarchy, no centre. Building one is the opposite: everything the central operator used to do still has to happen, without the operator. Eight capabilities, and a mesh missing any of them is a directory with good marketing.
The workforce layerWeb 4 sets four conditions: somewhere to be, someone to be, something to earn, someone to do the work. The first three are episodic without the fourth — and the fourth is currently being deployed with the least governance of any of them, which is why it is the one most likely to break next.