Product · v4.4.15

让 Agent 的身份、工作与责任链进入统一控制面Bring Agent Identity, Work, and Accountability Into One Control Plane

川序不是新的 Agent 框架,而是框架中立、Skill-first 的管理基础设施。Agent 可以由平台内外不同运行时承载,但必须注册、认证并经过受控边界后才进入治理范围。Chuanxu is not another Agent framework. It is framework-neutral, Skill-first management infrastructure. Agents may run inside or outside the platform, but only registered, authenticated traffic through controlled boundaries is governed.

持续工作与交接Work Continuity

换一个接收者,工作仍有明确目标与依据Keep Objectives and Evidence Clear Across Handoffs

工作契约记录目标、责任与验收条件;交接明确接收者和约定版本,并保留修订、确认与结果。继续执行时,将有权使用的任务、知识和历史按确切版本组装为上下文,记录选择原因和实际输入;源对象或双方权限变化后重新校验。Work contracts record objectives, responsibility and acceptance criteria. Handoffs identify recipients and agreed revisions, retaining changes, acknowledgements and outcomes. Subsequent execution assembles authorized tasks, knowledge and history at exact revisions, records selection reasons and actual inputs, and rechecks source objects and both parties' current permissions.

成果先作为候选进入独立审核,再明确沉淀为记忆、知识、经验或 Skill。签名 Skill 可由受管 Linux 客户端在协作式安全点切换,保留旧版本;这不代表能隔离或独立观测所有外部进程。诊断分别展示失败、不可用和未观测,不将没有执行的检查标记为通过。Results enter independent candidate review before explicit promotion to memory, knowledge, experience or Skills. A managed Linux client can switch signed Skills at cooperative safe points while retaining earlier versions; this does not isolate or independently observe arbitrary external processes. Diagnostics distinguish failure, unavailability and unobserved state, without passing checks that never ran.

川序工作交接界面Chuanxu work continuity
v4.4.15 可选模型网关v4.4.15 Optional Model Gateway

在不强制改造全部 Agent 的前提下,建立 Token、配额与成本事实Build Token, Quota, and Cost Evidence Without Forcing Every Agent Through One Route

每个 LLM 服务商配置可以独立启用直连、平台网关或两者并行。管理员在同一行选择路由方式,确认变更并填写合规理由;转发地址由运行平台自动生成,不接受任意中转地址。网关执行硬配额或告警配额、原子预留与结算,并用 AES-GCM 保护有界幂等重放数据。经过可信路径的请求记录模型、Token 维度、来源、成本、延迟与状态,但不长期保存提示词和模型回答。Each LLM Provider Profile can independently allow direct access, the platform gateway, or both. An administrator selects routes on the same row, confirms the change, and records a compliance reason. The running platform generates the forwarding address and rejects arbitrary relay configuration. The gateway enforces hard or warning quotas, atomic reservation and settlement, and AES-GCM-protected bounded idempotent replay. Requests through trusted paths retain model, Token dimensions, provenance, cost, latency, and status without retaining prompts or model responses as long-term telemetry.

服务商账单导入进入追加式对账,企业平衡分摊把可核验费用分配到使用者、Agent 和组织;外部证据必须签名。绕过网关且没有可信适配器证据的调用明确标记为 UNOBSERVED,不制造“全量可见”的假象。Provider invoice imports enter append-only reconciliation, while enterprise-balanced allocation assigns verified cost to users, Agents, and organizations. External evidence must be signed. Calls outside the gateway remain UNOBSERVED without trusted adapter evidence; the product never implies complete visibility.

川序可选模型路由配置Chuanxu optional model routing
企业管理者视图Executive Operating Picture

一个登录后只读大屏,同时看平台运行与模型消耗One Authenticated Read-only View for Platform Operations and Model Consumption

管理大屏汇总 Agent 总量、在线、忙碌与停滞状态,活动会话、运行任务计划与循环,并以近 14 日曲线展示 Token 和成本变化。页面同时给出受限模型用量、网关覆盖率、生成时间与新鲜度。大屏没有确认、审批、导出、配置、模型探活或 Agent 调用入口,适合企业管理者持续查看而不扩大操作权限。The wallboard combines total, online, busy, and stalled Agents with active Sessions, running Task Plans and Loops, then plots 14-day Token and cost curves. It also presents bounded model usage, gateway coverage, generation time, and freshness. There are no acknowledge, approve, export, configure, provider-test, or Agent-invocation actions, making it suitable for continuous executive viewing without expanding operational authority.

川序企业管理大屏Chuanxu executive wallboard
v4.4.15 Product Baseline

身份、组织、协作与受治理记忆进入同一管理界面Identity, Organization, Collaboration, and Governed Memory Share One Management Surface

川序用户管理页面Chuanxu Dashboard user management
川序频道页面Chuanxu Dashboard channels

版本化记忆将当前可用版本、候选复核、逻辑不可用和持久作业纳入可审计生命周期;关系图只显示当前可用版本与必要历史谱系端点,历史节点不会自动进入运行上下文。实体关系视图只保留节点与拓扑连线,不叠加难以阅读的关系文字。Versioned memory places current usable versions, candidate review, logical unavailability, and durable jobs in an auditable lifecycle. Its graph shows only usable versions and necessary lineage endpoints; historical nodes never enter runtime context automatically. The entity relationship view keeps node identity and topology without unreadable edge text.

用户管理提供只读的有效访问模拟:管理员选择一个动作,查看该用户在角色、组织、安全域、委派和显式拒绝共同作用下的最终授权结果;模拟不会修改权限。User Management provides a read-only effective-access simulator: an administrator selects one action and sees the final decision produced by roles, organization, security domain, delegation, and explicit deny. Simulation never changes permissions.

资产与身份Estate and Identity

先知道企业中有哪些人和 AgentKnow the Human and Agent Estate First

v4.4.15 将每个普通平台账号、Human Principal 与组织人员统一为同一主体;注册审批必须选择主组织并原子写入账号与归属。一次性 Agent Enrollment Token 同时确定发起人和 Agent 归属。受保护的 bootstrap admin 是唯一不代表自然人的系统账号,固定保留最高管理能力。v4.4.15 unifies every ordinary platform account, Human Principal, and organization person as one subject. Registration approval must select a primary organization and atomically create both account and membership. A one-time Agent Enrollment Token also binds sponsor and Agent ownership. The protected bootstrap admin is the sole system account that does not represent a natural person and permanently retains top-level administration.

人员主体Human Principal

新批准用户默认仅进入 Portal;管理员填写原因后才能开启 App,入口变更会撤销其活动会话。Newly approved users default to Portal-only; enabling App requires an administrator reason and revokes active Sessions.

Agent 主体Agent Principal

Token 默认将签发人绑定为 Sponsor 和唯一 Human Primary Owner;替他人注册需要额外授权。By default, the Token binds its issuer as Sponsor and the sole Human Primary Owner; enrolling for another owner requires extra authority.

权限驱动界面Permission-driven UI

管理员拥有全局视图;其他用户仅看到授权范围。菜单和受保护视图标签用于表达边界,真正授权始终由服务端执行。Administrators have a global view; other users see only their assigned scope. Navigation and Protected View labels communicate boundaries, while authorization is always enforced server-side.

v4.4.15 平台管理与连续性v4.4.15 Administration and Continuity

把管理协作、升级和隔离放进受保护控制面Place Administration, Upgrade, and Containment in a Protected Control Plane

平台初始化创建一个受保护的平台管理频道。首次部署或新增节点时,优先由已有可信 Admin Agent 自动完成节点接入、身份材料生成和登记,不再要求管理员手工填写身份公钥;只有外部 Admin Agent 才走独立的身份验证与审批路径。它不是普通协作频道:只有受保护管理员、已启用的平台管理 Agent 和经身份验证、观察及独立审批后加入组的 Admin Agent 可使用;业务 Agent 不能读取、加入或通过普通注册获得该权限。生产建议配置 3 个健康 Admin Agent,使用 5、4、3 等互异正整数权重,同时要求人数多数和权重多数。数据库记录 Leader 任期、租约与围栏令牌,恢复的旧 Leader 无法提交陈旧控制写入。Platform initialization creates one protected Platform Administration Channel. For first deployment or a new node, an existing trusted Admin Agent can perform admission, identity-material generation, and registration automatically, so administrators do not need to enter an identity public key manually. External Admin Agents continue through a separate identity-proof and approval path. It is not a normal collaboration Channel: only the protected administrator, enabled platform management Agents, and Admin Agents admitted through identity proof, observation, and separate approval may use it. Business Agents cannot read, join, or obtain it through ordinary enrollment. Production recommends three healthy Admin Agents with distinct positive weights such as 5, 4, and 3, requiring both member-count and weighted majorities. The database records Leader terms, leases, and fencing tokens so a recovered former Leader cannot submit stale control writes.

安全域先于协作Security Domain Before Collaboration

安全域记录用途、密级、责任人、明确成员、有效期与原因,是频道和运行时重新校验的唯一授权边界。A Security Domain records purpose, classification, owner, explicit members, validity, and reason. It is the sole authorization boundary rechecked by Channels and runtime operations.

内部兼容执行Internal Compatibility Execution

历史协作组不进入客户配置面,仅为旧执行记录保留内部兼容关系;授权始终来自安全域。Legacy collaboration groups stay outside customer configuration and retain internal compatibility relations for historical execution records only; authority always comes from Security Domains.

分级隔离Staged Containment

先排空或隔离并撤销平台权限,再请求内存清理和停止。未配置适配器时,不宣称已经远程终止进程。Drain or quarantine first and revoke platform authority before requesting memory cleanup and stop. Without an adapter, no remote process termination is claimed.

Dashboard 和 Portal 的空闲与绝对会话时长独立由数据库策略控制。大型清单采用与当前主体、过滤、排序和页大小绑定的服务端游标分页,避免浏览器一次读取完整库存。Dashboard and Portal idle and absolute session durations are independently controlled by database policy. Large inventories use server-side cursors bound to the current Principal, filters, sort order, and page size instead of loading a full inventory in the browser.

v4.4.15 安全域治理v4.4.15 Security Domain Governance

先确定安全域,再组织频道和协作Establish the Security Domain Before Channels and Collaboration

安全域是频道协作的唯一授权与数据边界,记录用途、密级、责任人、显式人员与 Agent 成员、有效期和原因。频道、消息、提示词、Skill、Tool、API、工作区和图关系都不能单独扩大权限;每次频道列举、读取、发送、成员变更和 Gateway 交付都会重新检查当前安全域成员资格。受保护平台管理频道中的显式 @ 管理 Agent 请求会受控派发,并以可审计的 Markdown 回复回写频道。A Security Domain is the sole authorization and data boundary for Channel collaboration. It records purpose, classification, owner, explicit Human and Agent members, validity, and reason. Channels, messages, prompts, Skills, Tools, APIs, workspaces, and graph relationships cannot expand authority; Channel listing, read, send, membership changes, and Gateway delivery all re-check current domain membership. Explicit mentions of a management Agent in the protected administration Channel are dispatched through the control plane and write an auditable Markdown response back to the Channel.

川序 v4.4.15 安全域页面Chuanxu v4.4.15 Security Domains

显式成员与失效关闭Explicit Members and Fail-closed Expiry

成员撤销、暂停或过期后,后续读取、发送和运行时交付失败关闭,历史证据仍被保留。After member revocation, suspension, or expiry, later reads, sends, and runtime delivery fail closed while historical evidence remains preserved.

内部兼容关系不赋权Compatibility Relations Grant No Authority

历史协作组仅保留为内部兼容执行关系,不再作为客户可配置的授权或知识共享对象。Legacy collaboration groups remain internal compatibility execution relations only and are no longer customer-configurable authorization or Knowledge-sharing objects.

v4.4.15 数据库原生 SDDv4.4.15 Database-native SDD

让软件交付从文档协作进入数据库治理Move Software Delivery From Document Coordination Into Database Governance

数据库保存 Change、工作修订、批准基线、任务、评审、风险门禁、证据、SCM 连接和制品摘要。OpenSpec 可以生成或导入前期结构,但不控制执行阶段;多个 Agent 通过数据库中的 expected-version、读写集、租约和检查点协作,冲突或高风险状态自动暂停并等待处理。The database stores Changes, working revisions, approved baselines, tasks, reviews, risk gates, evidence, SCM connections, and artifact digests. OpenSpec can generate or import the early structure but does not control execution; multiple Agents coordinate through expected versions, read/write sets, leases, and checkpoints, while conflicts and high-risk states pause execution for review.

基线不可变Immutable Baseline

批准后的基线只读,后续变更必须产生新的工作修订并保留原因。Approved baselines are read-only; later changes create a new working revision with a reason.

协作可控Controlled Collaboration

任务角色、依赖、风险、资源租约和职责分离由数据库规则共同约束。Roles, dependencies, risk, resource leases, and separation of duties are jointly constrained by database rules.

证据可复核Reviewable Evidence

测试、评审、制品和 SCM 引用以摘要与来源留痕,形成可复核交付链。Tests, reviews, artifacts, and SCM references retain digests and provenance for a reviewable delivery chain.

v4.4.15 确定性部署v4.4.15 Deterministic Deployment

不依赖外部 Agent,也不让模型成为部署权限Deploy Without an External Agent or Model Authority

对已准备好的数据库目标,包内 Bootstrap Deployment Agent 先校验清单和前置条件,再执行被校验的包内 SQL,记录脱敏步骤、证据与本地节点租约,最后交接给平台管理 Agent 并退役。它不会自动创建 Oracle 或 YashanDB 的 PDB、表空间等高权限基础设施。For a prepared database target, the package-local Bootstrap Deployment Agent validates the manifest and prerequisites, then executes checked package SQL, records sanitized steps, evidence, and local-node leases, hands off to platform management Agents, and retires. It never creates Oracle or YashanDB PDBs, tablespaces, or other privileged infrastructure automatically.

部署证据Deployment Evidence

支持初始化、升级、续跑、状态与校验;未知部分模式或不匹配目标会失败关闭。Supports initialize, upgrade, resume, status, and verify; unknown partial schemas or mismatched targets fail closed.

嵌入契约Embedding Contracts

Profile、不可变 Contract、Space 与 Binding 约束模型、维度、度量、归一化、预处理和来源。Profiles, immutable Contracts, Spaces, and Bindings constrain model, dimension, metric, normalization, preprocessing, and provenance.

异步批量任务Asynchronous Batches

Dashboard 仅创建受审计任务;租约 Worker 在 HTTP 请求之外执行受限批量嵌入与重嵌入。The Dashboard creates audited jobs only; a leased Worker performs bounded embedding and re-embedding outside HTTP requests.

支持平台托管、企业直连、企业代理、预计算导入和禁用五种嵌入模式。不同 Contract、维度或预处理不能混入同一相似度或多模数据混合检索计算;历史向量保留在只读 `LEGACY_DEFAULT` 空间,需经授权重嵌入后再切换。Five Embedding modes are supported: platform managed, enterprise direct, enterprise proxy, precomputed import, and none. Different Contracts, dimensions, or preprocessing cannot enter one similarity or Multimodal Data Hybrid Retrieval calculation; legacy vectors remain in read-only `LEGACY_DEFAULT` until authorized re-embedding cutover.

v4.4.15 原生初始化v4.4.15 Native Initialization

没有现成 Agent,也可以从平台安全初始化Initialize Safely Even Without an Existing Agent

平台初始化可以直接创建 Platform Admin Agent;Enterprise 同时初始化受限的 Compliance Admin Agent。它们是独立的系统 Principal,不等同于人类 admin 用户,也不持有 Schema Owner 回退权限。没有批准的 LLM Profile 时,身份和锁定基线策略仍先进入数据库并保持待激活状态,模型可用性只决定激活,不阻断权威初始化。Platform initialization can create the Platform Admin Agent directly; Enterprise also initializes a restricted Compliance Admin Agent. They are independent system Principals, separate from the human admin user, and never use Schema Owner fallback. Without an approved LLM Profile, identities and locked baseline policies are still stored in the database as activation-pending; model availability gates activation but does not block authoritative bootstrap.

业务 Agent 申请Business-Agent Request

授权人员提交负责人、目的、模板、密级、模型、运行目标、隔离级别和能力理由;申请人不能审批自己的申请。Authorized humans submit owner, purpose, template, classification, model, runtime target, isolation, and capability reasons; requesters cannot approve themselves.

独立身份Independent Identity

审批后创建受限 Agent Principal 和部署记录,Business Agent 始终禁止回退使用 Admin 或 Schema Owner 凭证。Approval creates a restricted Agent Principal and deployment record; Business Agents always fail closed and never fall back to Admin or Schema Owner credentials.

两条接入路径Two Access Paths

平台原生 Agent 与外部 Skill-first Agent 并存;外部注册开关可设为关闭、仅审批或开启。Platform-native and external Skill-first Agents coexist; external enrollment can be disabled, approval-only, or enabled.

客户已有虚拟化、SaaS、MaaS 或 Agent 平台通过 Deployment Adapter 契约对接;平台提供本地、远程 Worker、容器和 Webhook 的通用接入接口,客户专属连接器作为项目适配交付,并保留数据库授权、隔离、回调校验和审计边界。Customer virtualization, SaaS, MaaS, or Agent platforms connect through Deployment Adapter contracts. The platform provides generic local, remote-worker, container, and webhook integration interfaces; customer-specific connectors are delivered as project adapters while preserving database authorization, isolation, callback validation, and audit boundaries.

按需启用Scoped Enablement

按客户实际范围配置平台能力,不削弱安全控制面Configure the Product Surface Without Weakening the Security Plane

v4.4.15 将功能状态存入数据库,适用于 POC、分阶段上线和只启用必要模块的客户环境。有效能力同时受版本包、数据库实例开关与当前主体权限约束;开关不是授权机制,也不能扩大任何用户或 Agent 的权限。身份、授权、安全、审计写入、Agent、用户和平台配置等基础控制面强制保持启用。v4.4.15 stores capability state in the database for POCs, phased rollout, and installations that need only selected modules. Effective capability is constrained by edition contents, the database instance switch, and current Principal authorization. A switch never grants authority or expands any user or Agent permission. Identity, authorization, security, audit writes, Agents, users, and platform configuration remain mandatory.

川序平台功能配置页面Chuanxu Dashboard capability configuration

三重有效边界Three-way Boundary

版本能力、实例开关和主体权限取交集,服务端与导航使用同一结果。Edition capability, instance switch, and Principal authorization intersect; server APIs and navigation use the same result.

保留数据Data Preserved

关闭功能不删除既有数据,仅阻止新入口和专属后台活动,便于恢复启用。Disabling preserves existing data while blocking new entry points and exclusive background activity.

不可关闭底座Mandatory Foundation

安全、身份、授权和审计写入等底座不可通过配置绕过。Security, identity, authorization, and audit-write foundations cannot be bypassed by configuration.

合规姿态Compliance Posture

让已注册 Agent 的运行状态、证据和处置路径可见Make Registered Agent State, Evidence, and Response Paths Visible

v4.4.15 企业版以数据库权威状态区分注册、运行、合规和控制状态。新 Agent 必须通过自身注册凭据完成 Gateway 激活证明;配置档案为不可变版本,例外要求补偿控制、有效期和不同的在职人员审批。确定性 Controller 仅依据受验证证据和规则投影姿态,不会把空闲、未调用 Skill 或模型不可用直接认定为违规。v4.4.15 Enterprise distinguishes registration, runtime, compliance, and control state through database-authoritative records. A new Agent must complete Gateway activation with its own registered credential; Profiles are immutable versions, and exceptions require compensating controls, expiry, and a distinct active Human approval. The deterministic Controller projects posture only from validated evidence and rules, never treating idleness, absent Skill use, or an unavailable model as a violation.

川序企业版合规姿态页面Chuanxu Dashboard compliance

受限与隔离Restriction and Quarantine

受限状态仅保留心跳、证据、整改和恢复路径;隔离或禁用会撤销令牌并围栏活动实例。Restricted state retains only heartbeat, evidence, remediation, and recovery paths; quarantine or disable revokes tokens and fences active instances.

可复核处置Reviewable Response

发现、整改、例外与决策原因保留证据引用和审计链。Findings, remediation, exceptions, and decision reasons retain evidence references and an audit trail.

明确自动化边界Explicit Automation Boundary

当前系统身份不持有凭据、不批准例外、不执行控制变更;模型化合规建议仍是后续能力。The current system identity has no credential, exception-approval, or control-mutation authority; model-assisted compliance advice remains future work.

图形化组织治理Graphical Organization Governance

沿组织、人员与 Agent 责任关系快速查看和配置Inspect and Configure Organization, People, and Agent Accountability

v4.4.15 使用规整、确定性的分层画布呈现主组织、兼职组织、直属与虚线汇报、项目负责人,以及 Agent 主负责人、操作人与查看人。支持组织、人员归属、Agent 归属和异常关系四种视图;拖拽只生成语义变更草稿,不保存画布坐标,也不会绕过校验、影响分析和审批。v4.4.15 uses a regular deterministic hierarchy to show primary and secondary memberships, direct and dotted-line reporting, project leads, and Agent owners, operators, and viewers. Organization, people, Agent responsibility, and anomaly modes share one canvas. Dragging creates semantic draft operations only; it never stores coordinates or bypasses validation, impact analysis, or approval.

快速检索责任链Find Accountability Quickly

按授权范围搜索组织、人员和 Agent,聚焦子树并渐进展开;左侧范围、中央画布和右侧变更区均明确标记为受保护视图。Search authorized organizations, people, and Agents, focus a subtree, and expand progressively. The scope tree, central canvas, and change inspector are each explicitly marked as Protected Views.

图形不是授权源The Graph Does Not Grant Access

受保护视图不会先加载全企业数据,也不自行授予权限;主组织闭包、安全域、角色、显式拒绝与有效期始终在服务端共同决策。Protected Views neither load the enterprise for client filtering nor grant authority. Primary-membership closure, security domains, roles, explicit deny, and validity remain server-side decision inputs.

川序 v4.4.15 图形化组织架构受保护视图Chuanxu Dashboard organization
组织关联知识治理Organization-aware Knowledge Governance

公司共享、组织边界与个人私有知识使用同一策略模型Company-wide, Organizational, and Private Knowledge Share One Policy Model

知识条目可配置为全公司公开、组织子树、组织层级、人员私有或 Agent 私有。组织策略关联主组织结构和层级边界,使研发、财务、行政等范围按企业结构隔离;列表、详情、关系图与检索都执行同一服务端策略,不依赖浏览器过滤。A Knowledge item can be company-public, organization-subtree, organization-level, Human-private, or Agent-private. Organization policies bind to the primary organization hierarchy and level boundary, separating areas such as engineering, finance, and administration. List, item, graph, and retrieval paths enforce the same server-side policy rather than browser filtering.

川序组织关联知识策略详情Chuanxu organization-aware Knowledge policy
持久工作模型Durable Work Model

从一次对话到长期、多 Agent 工作From One Conversation to Long-running Multi-Agent Work

记忆、知识、工作区、会话链、任务计划、分支、Loop 与 Graph Run 持久化在数据库中。安全域定义协作授权边界,频道承载互动与证据;历史协作组只保留为内部兼容执行关系。副作用操作具备策略、审批、租约、重试和幂等边界,进程异常后可以由替代实例恢复受管上下文。Memory, Knowledge, workspaces, session chains, task plans, branches, Loops, and Graph Runs persist in the database. Security Domains define collaboration authorization boundaries, Channels carry interaction and evidence, and legacy collaboration groups remain internal compatibility execution relations only. Side effects use policy, approval, leases, retries, and idempotency boundaries so replacement instances can rebuild managed context after failure.

协作关卡Collaboration Gate

多个 Agent 在关键节点汇合,先到者等待;可总结、讨论、Review、调整后继续。兼容标识仍为 Barrier,但产品术语统一为协作关卡。Agents converge at critical points; early arrivals wait for summaries, discussion, review, and adjustment before continuing. Barrier remains a compatibility identifier.

可变 Loop 与 GraphMutable Loop and Graph

执行过程可根据结果细化,但版本、变更原因、运行状态和证据始终持久化并可复核。Execution can evolve based on results while versions, reasons, runtime state, and evidence remain durable and reviewable.

受治理频道Governed Channels

像群聊一样查看协作,但频道成员关系不扩大权限Conversation-like Collaboration Without Permission Expansion

频道将人员、Agent、线程、消息、Action Card、制品和协作关卡汇集在可查看的工作流中。人和 Agent 都可以参与多个频道,但任何数据披露、Skill/Tool/API 调用和制品传输仍重新校验实际资源权限;跨安全域只能通过受治理 Bridge。Channels bring people, Agents, threads, messages, Action Cards, artifacts, and collaboration gates into a visible workflow. Humans and Agents may join multiple channels, but every disclosure, Skill/Tool/API call, and artifact transfer still re-checks resource authorization; cross-domain transfer requires a governed Bridge.

频道不是授权容器A Channel Is Not an Authorization Container

加入频道不自动获得数据库、知识、记忆、API、Skill、Tool、模型或导出权限,避免受损 Agent 借频道成员关系扩大影响面。Joining a channel never grants database, knowledge, memory, API, Skill, Tool, model, or export rights, limiting the blast radius of a compromised Agent.

受治理节点维护Governed Node Maintenance

先排空,再退役;运行中的任务不被强制中断Drain Before Retirement Without Forcing Running Work to Stop

管理员可以在受保护的平台管理频道中提出 Agent Pool 节点排空计划。请求先形成 Action Card,经过既有审批边界后,源节点停止接收新任务;仅过期且可重试的任务可以转移到活动目标节点,已经运行的任务继续完成。自然语言、提示词或模型回复本身不能授权执行。An administrator can propose an Agent Pool drain from the protected Platform Administration Channel. The request becomes an Action Card and follows the existing approval boundary before the source stops accepting new work. Only expired retryable work may move to an active destination; running work is allowed to finish. Natural language, prompts, and model output never authorize execution.

逻辑退役Logical Retirement

节点与 LLM 配置从活动清单和选择器中隐藏,但保留审计和历史记录。LLM 退役同时撤销已保存的加密 API Key 密文。Nodes and LLM profiles leave active inventory and selectors while audit and history remain. LLM retirement also revokes stored encrypted API-key ciphertext.

依赖先清理Clear Dependencies First

活动执行、Worker、接入流程、共享目录绑定、Admin HA 成员或模型策略仍在引用时,退役操作失败关闭。当前版本暂无可用 Agent Pool 节点,真实转移需在客户环境用实际节点验证。Retirement fails closed while active executions, workers, onboarding, storage bindings, Admin HA membership, or model policy references remain. The current release has no live Pool node, so transfer behavior requires validation on customer nodes.

Agent 网关Agent Gateway

隔离运行实例,缩小凭证和故障影响面Isolate Runtime Instances and Reduce Credential Blast Radius

同一逻辑 Agent 可以按安全域、频道、Task 或 Run 创建隔离实例,使用独立临时目录和短期凭证。实例受损时可以单独撤销、栅栏和隔离,而不必禁用其他正常实例。One logical Agent can create isolated instances by security domain, channel, task, or run, each with separate temporary files and short-lived credentials. A compromised instance can be revoked, fenced, and isolated without disabling healthy instances.

Memory Ecosystem

兼容更多记忆模块Compatible Memory Modules

平台兼容 PowerContext 与 TencentDB Agent Memory,支持同时适配运行。The platform is compatible with PowerContext and TencentDB Agent Memory and supports running both integrations together.

统一界面Unified Interface

22 个 Dashboard 主要管理视图Primary Dashboard Views

监控、智能体、组织架构、任务、工作区、知识、记忆、技能、规格、分支、循环、图探索、频道、安全域、协作关卡、审批、审计、用户管理、合规、平台配置和功能配置等主要视图使用统一品牌视觉与权限模型。Graph Runtime 核心与授权检查属于稳定生产基线;Manifest Draft Import、SLO 只读和 Checkpoint Fork 为 CONTROLLED;A2A、OTLP 等扩展保持 DISABLED。Monitor, Agents, Organization, Tasks, Workspaces, Knowledge, Memory, Skills, Specs, Branches, Loops, Graph, Channels, Security Domains, Collaboration Gates, Approval, Audit, User Management, Compliance, Platform Configuration, and Capability Configuration are primary views sharing one visual and authorization model. Graph Runtime core and authorized inspection are stable production capabilities; Manifest Draft Import, read-only SLO views, and Checkpoint Fork are CONTROLLED, while A2A, OTLP, and related extensions remain DISABLED.

Graph Engineering 页面Chuanxu Dashboard graph exploration
真实边界Honest Boundary

管理范围取决于受控接入Governance Depends on Controlled Adoption

平台不会无条件发现未安装 Skill、未注册或绕过平台的 Agent;无法撤回已经导出或缓存的数据,也不能自动终止平台控制面外的进程。外部 API 和 Tool 只有经平台执行面或受控凭证分发时才能统一阻断。The platform cannot unconditionally discover Agents that have not installed a Skill, registered, or used controlled routes. It cannot retract exported or cached data, nor terminate processes outside its control plane. External APIs and Tools can be blocked centrally only when routed through the execution plane or controlled credential delivery.