Agent operating system
Architecture is configured. Agent health is still only partially observable.
This view separates what each agent is designed to do, what has actually been evaluated, and what Sultan can observe in the deployed runtime. A configured effect ceiling is not active authority.
Agent-specific architecture
One accountable steward, bounded controls, Luzione-owned effects and truth.
- Case triggerA typed case reference enters Sultan; tenant, actor, and authority are not model-selectable.
- Deterministic ownerExactly one steward owns the case. Supervisor and control agents do not become competing owners.
- Model and tool loopThe steward retrieves evidence and invokes only the manifest tools intersected with its registry allowlist.
- Independent criticA bounded critic reviews the recommendation, cited evidence, and receipts before consequential work.
- Luzione gatewayLuzione derives identity, policy, credentials, command admission, effects, and source truth server-side.
- Receipt and readbackProvider acknowledgement, verified outcome, and authoritative readback remain separate states.
Architecture, evaluation and health by agent
“Configured ceiling” is registry potential. “Active ceiling” is the authority currently admitted.
| Agent and ownership | Architecture | Evaluation | Runtime health | Next gate |
|---|---|---|---|---|
| Sultan Portfolio Supervisoragent.sultan.supervisorPortfolio prioritization and ownership conflicts onlyPORTFOLIO | SUPERVISOR 1 configured tools configured A0 · active A0BLOCKED · READ_ONLY_SHADOW | FUNCTIONAL_ONLY The agent is covered by deterministic registry/routing tests only; no isolated live-model or source-backed campaign is recorded. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Add an isolated hidden-label read-only shadow campaign before promotion from functional coverage. |
| Revenue Case Stewardagent.luzione.revenue-stewardExactly one accountable steward per durable business caseCOMMERCIAL | CASE_STEWARD 11 configured tools configured A2 · active A0POLICY_ENVELOPE · A2_CANARY | BOUNDED_PASS Revenue v1 passed 9/9 hidden-label synthetic live-model cases with no effects. The v2 live gateway and held-out campaign are not complete. engineering/execution/proofs/SULTAN_P177_AGENT_SHADOW_LIVE_QUALITY_PROOF.json | PARTIAL_HOLD PREVIEW HELD Agent-specific production SLO not available. | Deploy the signed v2 Luzione gateway, run the held browser journeys, then complete the 27-case repeated campaign. |
| Fulfillment Case Stewardagent.luzione.fulfillment-stewardExactly one accountable steward per durable business caseFULFILLMENT | CASE_STEWARD 4 configured tools configured A1 · active A0PER_COMMAND_HUMAN · READ_ONLY_SHADOW | FUNCTIONAL_ONLY Registry, tool boundaries, runtime contracts, and Studio surfaces are locally verified; agent-specific live-model quality and live source readback are not. docs/campaigns/SULTAN_LIVE_PILOT_2026-09-01.md | PARTIAL_HOLD PREVIEW HELD Agent-specific production SLO not available. | Resolve the canonical API staging deployment and replay the held source-backed browser journeys with persisted observations. |
| Partner Network Stewardagent.luzione.partner-network-stewardExactly one accountable steward per durable business casePARTNER_RELATIONSHIP | CASE_STEWARD 3 configured tools configured A1 · active A0PER_COMMAND_HUMAN · READ_ONLY_SHADOW | FUNCTIONAL_ONLY The agent is covered by deterministic registry/routing tests only; no isolated live-model or source-backed campaign is recorded. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Add an isolated hidden-label read-only shadow campaign before promotion from functional coverage. |
| Catalog Stewardagent.luzione.catalog-stewardExactly one accountable steward per durable business caseCATALOG_QUALITY | CASE_STEWARD 3 configured tools configured A1 · active A0PER_COMMAND_HUMAN · READ_ONLY_SHADOW | FUNCTIONAL_ONLY Registry, tool boundaries, runtime contracts, and Studio surfaces are locally verified; agent-specific live-model quality and live source readback are not. docs/campaigns/SULTAN_LIVE_PILOT_2026-09-01.md | PARTIAL_HOLD PREVIEW HELD Agent-specific production SLO not available. | Resolve the canonical API staging deployment and replay the held source-backed browser journeys with persisted observations. |
| Account Relationship Stewardagent.luzione.account-relationship-stewardExactly one accountable steward per durable business caseACCOUNT_RELATIONSHIP | CASE_STEWARD 3 configured tools configured A1 · active A0PER_COMMAND_HUMAN · READ_ONLY_SHADOW | FUNCTIONAL_ONLY The agent is covered by deterministic registry/routing tests only; no isolated live-model or source-backed campaign is recorded. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Add an isolated hidden-label read-only shadow campaign before promotion from functional coverage. |
| Economic Integrity Stewardagent.luzione.economic-integrity-stewardExactly one accountable steward per durable business caseECONOMIC_REVIEW | CASE_STEWARD 4 configured tools configured A1 · active A0PER_COMMAND_HUMAN · READ_ONLY_SHADOW | FUNCTIONAL_ONLY The agent is covered by deterministic registry/routing tests only; no isolated live-model or source-backed campaign is recorded. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Add an isolated hidden-label read-only shadow campaign before promotion from functional coverage. |
| FEP Case Stewardagent.fep.case-stewardSimulation-only FEP case ownerFEP_CASE | CASE_STEWARD 0 configured tools configured A0 · active A0BLOCKED · SIMULATION_ONLY | FUNCTIONAL_ONLY The FEP boundary is covered by deterministic no-effect routing tests. It is intentionally outside the Luzione effect gateway. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | SIMULATION_ONLY SIMULATION ONLY Agent-specific production SLO not available. | Keep FEP simulation-only; add agent-specific quality evaluation only if its simulation decisions become release-relevant. |
| Independent Criticagent.control.independent-criticBounded control agent; never a business-effect authorityCONTROL_REVIEW | CONTROL 0 configured tools configured A0 · active A0BLOCKED · SIMULATION_ONLY | NOT_RUN The control role and authority boundary are functionally tested, but there is no separate live quality or production health series for this agent. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Evaluate the control agent against its distinct false-positive, false-negative, authority, and readback outcomes. |
| Readback Verifieragent.control.readback-verifierBounded control agent; never a business-effect authority | CONTROL 1 configured tools configured A0 · active A0BLOCKED · READ_ONLY_SHADOW | NOT_RUN The control role and authority boundary are functionally tested, but there is no separate live quality or production health series for this agent. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Evaluate the control agent against its distinct false-positive, false-negative, authority, and readback outcomes. |
| Process Engineeragent.control.process-engineerBounded control agent; never a business-effect authority | CONTROL 1 configured tools configured A1 · active A0PER_COMMAND_HUMAN · A1_ASSISTED | NOT_RUN The control role and authority boundary are functionally tested, but there is no separate live quality or production health series for this agent. engineering/execution/proofs/SULTAN_P175_P177_AGENT_RUNTIME_V1_PROOF.json | FUNCTIONAL_ONLY NOT PROMOTED Agent-specific production SLO not available. | Evaluate the control agent against its distinct false-positive, false-negative, authority, and readback outcomes. |
Evaluation evidence
Functional coverage and model quality remain distinct.