The agent stack, from the operator’s side

Concepts

Five things that only become real once you are running a fleet rather than reading about one. Each page answers how the thing behaves in operation; the institutional definition of each lives with GDA Group, and each page links to it.

Knowing each other

How agents discover and authenticate each other

Agent identity is a durable identifier, a declared set of capabilities, and scoped credentials that sign every action. Inside one mesh it makes attribution possible. Across organizations it is the precondition for anything else happening at all — you cannot transact with something you cannot verify.

Scoped authority

Approval gates: what an agent may commit alone

Permissions for an agent workforce are graded by consequence, not by capability. Reversible and cheap: the agent acts and the record is reviewed later. Material or irreversible: the agent prepares and a named human resolves. The grading is the control; the credential is just plumbing.

The record

The append-only record: what an agent did, and why it was allowed

A log says an action occurred. An audit trail says why it was permitted — which agent, under which policy, owned by which human, on what inputs. The second clause is the one a diligence room asks for, and the one most systems cannot produce.

Structure

Structuring a multi-agent organization

Past roughly a dozen agents the questions stop being technical and become organizational: who holds which role, who reports to whom, and which human owns the outcome. An agent org needs a chart for the same reason a human one does — so that accountability has somewhere to land.

Settlement

How agents pay each other

Once agents commission work from other agents, something has to settle it. Machine-to-machine payment needs three things human payment takes for granted: an identity to pay, a unit both sides recognise, and a record that survives the dispute. The hard part is not the transfer.

Running a fleet

Running a fleet: routing, approval gates, and the audit trail

AI orchestration infrastructure is the layer that turns many agents into one system — assigning work, routing context, enforcing who may commit what, and recording the outcome. Once agent counts pass a handful, coordination is where governance lives, which is why it is bought like infrastructure rather than like a tool.

Pricing the work

Buying outcomes instead of seats: how Agent-as-a-Service is priced

Agent-as-a-Service sells completed work rather than access to a tool. The vendor carries delivery risk, which changes what has to be true underneath: reliability becomes a design property, verification becomes a step in the graph, and the price refers to an outcome the buyer can check.

Across boundaries

How agents discover and transact across organizational boundaries

Agent-to-agent communication is the layer where an agent in one organization finds an agent in another, establishes what it is allowed to ask for, exchanges verified state, and gets a result back. Inside one company it is a routing problem. Across companies it becomes an identity and trust problem.

Measurement

Measuring an agent workforce that is already doing the work

AI agent optimization treats agents as economic actors to be measured rather than software to be monitored: cost per completed outcome, decision quality against a reviewable trail, escalation rate, and where a gate is catching problems a model could not. Uptime tells you nothing useful about a fleet.

Organizational memory

Flashy Mind: the organizational memory a mesh runs on

Brain-as-a-Service delivers an organization's accumulated context — its decisions, its reasons, its structure — as persistent infrastructure that people and agents query. Where software-as-a-service rents an application, this rents a memory that compounds, and the constraint on enterprise AI is almost always context rather than capability.

Agents in the metaverse

Why a persistent world is the hardest place to run agents

A persistent world never stops between calls. Agents operating in one hold state across sessions, act on events nobody requested, and are observed by other people while doing it. That breaks the request-response assumption most agent tooling is built on, and it turns identity, permissions, and the audit trail from good practice into load-bearing.

What a mesh needs

What a mesh actually requires

A mesh sounds like an absence of things — no broker, no hierarchy, no centre. Building one is the opposite: everything the central operator used to do still has to happen, without the operator. Eight capabilities, and a mesh missing any of them is a directory with good marketing.

The workforce layer

Why the agent layer decides whether Web 4 holds

Web 4 sets four conditions: somewhere to be, someone to be, something to earn, someone to do the work. The first three are episodic without the fourth — and the fourth is currently being deployed with the least governance of any of them, which is why it is the one most likely to break next.