Agent definition
In most frameworks "an agent" is a process: a prompt, a list of tools, an API key, and a while
loop. OAP splits that into two things you can actually govern — a reviewable template you
version and approve (the AgentClass), and a disposable running instance that is
scoped and budgeted (the AgentSession).
Why the split matters
Conflating the definition of an agent with a running instance of it is where the operational failures come from: there's no artifact to review before it acts, no boundary on its blast radius, and no backstop when a run goes sideways. Pulling the two apart fixes all three.
An AgentClass is the durable, reviewable definition: which model, which tools, which identity, what it's authorized to do, where it can be reached, and its budgets. It's a Kubernetes resource — you diff it, review it, and pin it. An AgentSession is one disposable run of that class: a fresh, scoped instance with its own budget and its own audit trail, torn down when it's done. The class is the thing you trust; the session is the thing that acts.
Go deeper
- AgentClass & AgentSession — the template/instance split, field by field.
- The agent loop — how a turn runs, and where the safety hooks sit.
- Skills — reusable capabilities an agent can be granted.
- Packaging — the
.oapbundle: shipping an agent and its dependency graph as one signed artifact.