Collect the request, current state, authorised context and environmental signals.
Production agent systems index
Build the loop.
Govern the outcome.
A researched directory of dependable frameworks, protocols, runtimes, observability systems, memory layers and browser infrastructure for production AI agents.
Agent architecture
A model proposes.
A system acts.
Production agents need more than tool calling. State, permissions, durable execution, evidence, recovery and human escalation determine whether an agent remains useful when the happy path ends.
SYSTEM MAP / 06 CONNECTED LAYERS
Separate the roles.
Control the boundary.
- 06Experience and intentUser request, application state, events and interaction contract
- 05Reasoning and orchestrationPlanning, routing, handoffs, graph state and stopping rules
- 04Memory and contextWorking state, session history, retrieval and system-of-record data
- 03Tools and executionAPIs, code, browser actions, sandboxes and external systems
- 02Policy and approvalIdentity, permissions, side-effect controls and human checkpoints
- 01Evidence and recoveryTraces, evaluations, replay, retries, rollback and incident response
Production loop
Autonomy needs
control points.
A dependable loop makes uncertainty visible, constrains actions and preserves enough evidence to understand, interrupt and recover every consequential run.
Choose a bounded plan, route work and define the condition that ends the loop.
Invoke tools with typed inputs, least privilege and explicit side-effect boundaries.
Inspect outputs, tool results and policy checks before accepting the next state.
Store only the state, evidence and memory the next step or future run truly needs.
Pause for approval, hand off to a person or recover safely when confidence falls.
Agent systems directory
Choose for the failures
you can operate.
Systems are grouped by the layer they primarily own. Order within each layer balances maturity, ecosystem reach, operational depth and source clarity. A framework, protocol and runtime are not interchangeable units.
Try another layer, maturity, deployment path, access model or search term.
Same-layer comparison
Compare like with
like.
Choose up to three systems from one layer for a direct comparison. Before selection, the guide below separates five common production architectures.
0 of 3 selected
Protocol boundaries
Connect the layers.
Keep the authority.
Interoperability reduces bespoke wiring, but it does not replace trust decisions. Identity, credential custody, approval and data policy still belong outside the model's control.
- 01 / TOOLS
- MCP standardises how applications discover and invoke external tools, data and workflows.
- 02 / AGENTS
- A2A standardises discovery, tasks and communication between independent agent systems.
- 03 / USERS
- AG-UI standardises the event stream between an agent backend and an interactive application.
- 04 / EVIDENCE
- OpenTelemetry conventions help correlate model, tool, agent and infrastructure activity.
Research method
Useful comparisons need
honest boundaries.
Each profile names the layer it primarily owns, its access model, maturity, deployment path and official source. Capability labels distinguish native features from integrations and external systems.
Define the layer
A framework, protocol, durable runtime and tracing platform solve different parts of the system.
Verify the direction
Migration paths and successor projects matter as much as a familiar project name.
Separate access
Open source, open standards, open core and managed services carry different operating choices.
Inspect state
Persistence, retries, replay and recovery need explicit ownership outside model output.
Test side effects
Tool quality includes identity, permission, approval and rollback, not only successful invocation.
Date every claim
Fast-moving projects are checked against current official documentation and repositories.
Open ecosystem reference: Agentic AI Foundation ↗
Before production
Six questions before
the first real action.
What may the agent change?
List every side effect and assign identity, scope, approval and rollback requirements.
What survives a restart?
Define durable state, idempotency, retry limits and recovery after partial execution.
Which memory is authoritative?
Separate convenience memory from business records and make deletion and retention explicit.
How is quality measured?
Use representative tasks, deterministic checks, human review and trace-based regression sets.
When does a person intervene?
Set approval gates, confidence thresholds, escalation paths and useful interruption states.
Can the run be explained?
Capture inputs, tool results, decisions, costs, failures and final state without exposing secrets.
Engineering the control plane
From agent concept
to working system.
ADOR.IS designs governed agent workflows, software platforms, model-serving systems, data integrations, browser operations and observability around real permissions and measurable outcomes.
[email protected] ↗