Agent definition

In most frameworks "an agent" is a process: a prompt, a list of tools, an API key, and a while loop. OAP splits that into two things you can actually govern — a reviewable template you version and approve (the AgentClass), and a disposable running instance that is scoped and budgeted (the AgentSession).

One reviewable class, two independent sessions — each with its own scope, budget, and audit trail.

Why the split matters

Conflating the definition of an agent with a running instance of it is where the operational failures come from: there's no artifact to review before it acts, no boundary on its blast radius, and no backstop when a run goes sideways. Pulling the two apart fixes all three.

An AgentClass is the durable, reviewable definition: which model, which tools, which identity, what it's authorized to do, where it can be reached, and its budgets. It's a Kubernetes resource — you diff it, review it, and pin it. An AgentSession is one disposable run of that class: a fresh, scoped instance with its own budget and its own audit trail, torn down when it's done. The class is the thing you trust; the session is the thing that acts.

Go deeper

  • AgentClass & AgentSession — the template/instance split, field by field.
  • The agent loop — how a turn runs, and where the safety hooks sit.
  • Skills — reusable capabilities an agent can be granted.
  • Packaging — the .oap bundle: shipping an agent and its dependency graph as one signed artifact.