Master Equation|Identity + Context + Agents + Verification + Audit

The Execution Layer for Enterprise AI Agents.

WorkAgent OS is not a chatbot. It is a specified multi-tenant execution architecture where human knowledge workers and AI agents collaborate through live company context, policy-controlled tools, verifiable execution, and human-in-the-loop approvals.

The architecture is designed to give AI agents identity, context, scoped tools, policy controls, approvals, verification, and auditability — so they can safely act inside real business workflows.

PREVIEW: AI Chief of StaffEnterprise Fleet (SPEC)

Public specification v1.1 — production implementation and verification evidence have not been published with this website.

* The model is not the product. Models are interchangeable reasoning modules inside the Agent Runtime.

runtime@workagent-os ~ kernel-v1.1 (SPEC • Tenant-Isolated by Design)
8-Layer Execution Model — Specification
01Identity & ContextTenant → User → Scope
02Agent RuntimeInterchangeable LLMs
03Planning DAGParallel sub-tasks
04Tool SelectionStrict JSON Schemas
05Risk & PolicyABAC + RBAC gates
06ExecutionMCP-Native Gateway
07VerificationRead-back state check
08Audit LedgerTamper-evident logs
Strict Isolation
Tenant-Isolated by Design (RLS Spec)
8 Layers
Agent Execution Architecture
Action Integrity
Canonical SHA-256 Payload Hashing
MCP-Native
Bi-directional Tool & Connector Gateway
8-Layer Agent Execution Model

How WorkAgent OS Executes Work

From authenticated user identity to verified external action, every operation follows a specified 8-layer enterprise lifecycle:

"AI agents that can act — with context, permissions, verification and accountability."
Layer 01

Identity & Context

Establishes identity chain (Tenant → User → Agent) and curates minimal necessary context.

Layer 1 of 8
Layer 02

Agent Runtime

Interchangeable reasoning engine orchestrating intent, memory, and DAG steps.

Layer 2 of 8
Layer 03

Planning DAG

Compiles dependency graph; runs independent retrieval sub-tasks in parallel.

Layer 3 of 8
Layer 04

Tool Selection

Selects tools matching strictly defined JSON Schemas via the MCP-native gateway.

Layer 4 of 8
Layer 05

Risk & Policy

Dynamic Risk Formula (Impact × Irreversibility × Externality × Sensitivity × Uncertainty × 100).

Layer 5 of 8
Layer 06

Action Execution

Canonical payload hashing with unique idempotency keys to eliminate side-effects.

Layer 6 of 8
Layer 07

Verification

Active external state read-back comparing actual tool outcome against expected schema.

Layer 7 of 8
Layer 08

Audit Ledger

Emits tamper-evident audit event linking actor, canonical action hash, and result.

Layer 8 of 8
Identity Chain:Tenant → User Identity → Agent Identity → Policy Scope → Scoped Tool → Action
Agents never run as unconstrained tenant-wide service accounts.

Built for Every Enterprise Stakeholder

WorkAgent OS aligns the productivity needs of employees with the rigorous governance mandates of IT and Security teams.

Target Persona: Employee

Personal AI Chief of Staff & Productivity

Daily morning priorities and open blocker digest synthesized across tools
Automated prep for upcoming meetings with attendees, CRM deals, and past threads
Instant extraction of action items into Jira/Linear with human confirmation
Automated overdue deliverable detection across email and chat channels
Enterprise Case Review
"My AI Chief of Staff acts like a senior executive assistant—reading my schedule, finding the right Drive slides, and preparing draft tasks before I even ask."
Illustrative persona outcome — not a customer testimonial.
WorkAgent OS Target DesignTenant-Isolated by Design
Section 17 Specification • Buyer Value Realization

From Manual Knowledge Work to Verified Execution

How enterprise workflows are designed to transform when autonomous agents operate within policy boundaries, verifiable tool access, and action integrity hashing. Platform capabilities below are designed targets, not measured benchmarks. Read the specification.

Operational DimensionTraditional Enterprise WorkflowWorkAgent OS Execution Platform
01.Context Assembly
Analysts manually cross-reference Gmail threads, Drive files, Slack conversations, and Jira tickets — a slow, repetitive process prone to stale data.Designed: automated 9-stage context resolution plus a separate retrieval/ranking pipeline (structured fetch, semantic search, relevance, source authority, recency, dedup, token budget, citations).
02.Tool Writes & Mutations
Copy-paste between tools, forgotten CRM stages, mistyped ticket updates, and orphaned follow-ups prone to human fatigue.Designed: idempotent execution DAG, pre-validated against tool JSON schemas via an MCP Gateway so credentials stay out of model context.
03.Risk Scoring & Approvals
Informal Slack DMs or unreviewed auto-execution scripts; zero quantitative risk assessment before high-impact changes.Designed: normalized Risk Formula (0–100). Actions scoring > 50 are intended to require hash-bound human approval before execution can proceed.
04.Failure Recovery
Silent failures on 429/500 API responses; half-executed workflows left in corrupted states requiring manual engineering triage.Designed: active state verification loop — re-reads external system state and triggers retry, compensating action, reconciliation, or escalation depending on connector capability.
05.Forensic Audit Ledger
Fragmented logs siloed across 5 separate vendor portals; zero tamper-evident link connecting original user intent to side-effects.Designed: tamper-evident audit ledger, sequentially chained with SHA-256 hashes binding tenant, actor, policy version, and canonical action payload.

“Execution isn’t success until external state is verified.”

The verification principle behind the proposed read-back and recovery model.

“External content can provide information. It cannot grant authority.”

The trust principle behind the proposed authority hierarchy and untrusted-content firewall.

PREVIEWProposed Product Wedge

AI Chief of Staff — Preview Overview

Acts as a personal autonomous chief of staff for employees and executives. Reads calendar schedules, searches email threads, synthesizes Drive proposals, catches delayed deliverables, and drafts action plans.

Production implementation and verification evidence have not been published with this website. The Chief of Staff preview is an early demonstration of intended behavior — it is not a live production deployment.

Planned Responsibilities
  • Daily executive priority briefing and blocker detection
  • Meeting prep with automatic CRM, Gmail, and Drive synthesis
  • Action item extraction and Jira/Linear task generation
  • Overdue deliverable tracking across team tools
Inspect the agent specification
Platform Infrastructure

The 6-Layer Platform Architecture

WorkAgent OS decouples interchangeable reasoning models from business rules, persistence, and tool integrations. The 6-Layer Platform Architecture provides the multi-tenant infrastructure host, while the 8-Layer Execution Model governs each agent action lifecycle.

Platform Hierarchy (System Infrastructure)
Layer 1

Presentation & Workspace Layer

Modern Next.js 16 web application, role-based Employee Workspace, Admin Console, and Human-in-the-Loop review portals.

Layer 2

API Gateway & Security Boundary

Enterprise gateway (SPEC) designed for authentication, request-signature validation where applicable, tenant isolation, and rate limiting. Request-signature checks (e.g. JWT or webhook verification) are distinct from action payload hashes.

Layer 3

Agent Runtime & Execution Engine

The core reasoning engine. Features modular LLM adapters (Claude, GPT, DeepSeek), 9-step Context Engine, Dynamic Risk Engine, and State Verification.

Layer 4

MCP-Compatible Tool Gateway

Bi-directional connector gateway providing tenant-scoped, permission-controlled tool access to enterprise SaaS and internal databases.

Layer 5

Enterprise Multi-Tenant Storage Layer

Strictly segregated multi-tenant persistence layer combining relational data, vector embeddings, and tamper-evident audit logging.

Layer 6

Observability, Cost & Evaluation Layer

Full OpenTelemetry-compliant execution tracing, real-time cost accounting, and automated regression evaluation suites.

Recommended Enterprise Production Stack:
Next.js 16 (TypeScript)FastAPI / Python RuntimePostgreSQL + pgvectorRedis Pub/Sub & CacheS3-Compatible Object StoreDocker / Containerized WorkersOpenTelemetry Tracing
Layer Inspector: Layer 3

Agent Runtime & Execution Engine

Isolation Scope: Strict Tenant RLS

The core reasoning engine. Features modular LLM adapters (Claude, GPT, DeepSeek), 9-step Context Engine, Dynamic Risk Engine, and State Verification.

Core Modules & Protocols:

9-Stage Context Resolution

Context resolution stages: Identity, Tenant, User, Task, Conversation, Org, Memory, Tool, Policy. Retrieval and ranking (structured fetch, semantic search, relevance, source authority, recency, dedup, budget, citations) run as a separate pipeline.

Planning & Tool Router

Decomposes requests into step-by-step DAGs, selects verified tools, validates JSON schemas.

Policy & Risk Engine

Normalized formula: Impact × Irreversibility × Externality × Sensitivity × Uncertainty × 100. 0-100 tiered action gates.

State Verification & Recovery

Re-reads external state post-execution, verifies outcome schema against expected entity, and triggers compensation, retry, reconciliation, or escalation depending on connector capability.

Deterministic Zero-Trust Protocol
spec_ref: Section 6 System Architecture
Autonomous Enterprise Workforce

The WorkAgent OS Agent Fleet

Led by the AI Chief of Staff as the proposed product wedge (PREVIEW), backed by specialized workforce agents defined in the specification with strict tool contracts and scoped permissions.

AI Chief of Staff

PREVIEWProposed Wedge

Executive Co-pilot & Orchestrator

Risk Tier: Medium

Proactive daily prioritization, cross-tool context synthesis, and executive meeting prep.

Proposed MCP Connectors:Google CalendarPREVIEWGmailPREVIEWGoogle DrivePREVIEWSlackPREVIEWJiraPREVIEWLinearPREVIEWSalesforcePREVIEW
Sample Request:

"Prepare me for today's 2 PM Acme executive briefing and flag any open Jira blockers."

Key Responsibilities:

  • Daily executive priority briefing and blocker detection
  • Meeting prep with automatic CRM, Gmail, and Drive synthesis
  • Action item extraction and Jira/Linear task generation
  • Overdue deliverable tracking across team tools
  • Weekly automated executive progress digests

Execution Reasoning Trace (DAG Steps):

[Step 01]Query Google Calendar for attendee list and meeting agenda
[Step 02]Retrieve recent customer history from Salesforce and Gmail threads
[Step 03]Extract proposal metrics from Google Drive presentation
[Step 04]Synthesize meeting briefing with talking points and open risks
[Step 05]Prompt user with interactive approval to file follow-up Jira tickets

Enterprise Sales Agent

SPEC

Pipeline Acceleration & Deal Intelligence

Risk Tier: Medium

Autonomous account research, CRM hygiene, and meeting brief generation.

Proposed MCP Connectors:SalesforcePREVIEWHubSpotPREVIEWGmailPREVIEWLinkedIn Sales NavPREVIEWSlackPREVIEW
Sample Request:

"Summarize Acme Corp's deal trajectory, recent objection trends, and recommend next pricing tier."

Customer Success Agent

SPEC

Retention & Proactive Health Monitoring

Risk Tier: Low

Monitors client health scores, surfaces churn risks, and orchestrates quarterly business reviews.

Proposed MCP Connectors:ZendeskPREVIEWMixpanelPREVIEWSlackPREVIEWGoogle SlidesPREVIEWIntercomPREVIEW
Sample Request:

"Run a sentiment and health analysis for our top 10 enterprise accounts renewing this quarter."

Project & Sprint Agent

SPEC

Delivery Orchestration & Blocker Resolution

Risk Tier: Low

Cross-functional sprint coordination, dependency graph analysis, and velocity optimization.

Proposed MCP Connectors:LinearPREVIEWJiraPREVIEWGitHubPREVIEWSlackPREVIEWNotionPREVIEW
Sample Request:

"Identify which PRs are blocking the upcoming v2.4 release and ping relevant reviewers."

Autonomous Meeting Agent

PREVIEW

Live Transcription & Consensus Capturing

Risk Tier: Low

Real-time meeting synthesis, commitment tracking, and instant bi-directional tool sync.

Proposed MCP Connectors:Google MeetPREVIEWZoomPREVIEWSlackPREVIEWGoogle DocsPREVIEWGoogle CalendarPREVIEW
Sample Request:

"Extract decisions from today's Product Architecture Sync and create tickets for owners."

Deep Research Agent

SPEC

Market Intelligence & Multi-Source Synthesis

Risk Tier: Low

Exhaustive multi-source investigation with tamper-evident source citations and fact-checking.

Proposed MCP Connectors:Brave SearchPREVIEWInternal Vector DBPREVIEWNotionPREVIEWGoogle DrivePREVIEWConfluencePREVIEW
Sample Request:

"Conduct a comparative teardown of modern Enterprise MCP gateway architectures."

Developer & Codebase Agent

SPEC

Code Intelligence & CI/CD Debugging

Risk Tier: High

Autonomous codebase navigation, PR triage, test reproduction, and safe refactoring.

Proposed MCP Connectors:GitHubPREVIEWGitLabPREVIEWSentryPREVIEWDockerPREVIEWLinearPREVIEW
Sample Request:

"Diagnose intermittent timeout in AgentRun webhook test and generate fix PR."

Finance & Operations Agent

SPEC

Compliance & Budget Governance

Risk Tier: Critical

Expense reconciliation, budget tracking, vendor invoice verification, and risk auditing.

Proposed MCP Connectors:QuickBooksPREVIEWNetSuitePREVIEWStripePREVIEWPostgreSQLPREVIEWSlackPREVIEW
Sample Request:

"Audit enterprise API spend for last month and flag any department exceeding allocated quota."

Simulation — Synthetic Enterprise Data
  • No production side-effects — nothing executes against real systems.
  • Identities, tool calls, hashes, costs, and timings are examples.
  • Clicking approve performs no real authentication or hash verification.

Target semantics are documented in the Trust Center approval lifecycle.

Interactive Runtime Simulation

End-to-End Execution & Approval Trace

Witness the exact execution sequence defined in Section 23 of the master spec: "Prepare me for today's Acme executive meeting" including context assembly, risk evaluation, and hash-bound human sign-off.

EnvironmentDemo Simulation
TenantAcme Corp (89f2a)
AgentChief of Staff (PREVIEW)
Policy GateABAC (Simulated)
Risk Score5 / 100
VerificationRead-Back (Simulated)
Simulating Agent

AI Chief of Staff (Tenant: enterprise_corp_89)

Step 01
Verify Tenant Scope & Delegated Identity
Risk: 5/100
Step 02
Resolve Context Scopes
Risk: 8/100
Step 03
Retrieve Scheduled Meeting
Risk: 10/100
Step 04
Fetch Account History & Deal Context
Risk: 15/100
Step 05
Semantic Document Search
Risk: 12/100
Step 06
Compile Execution Plan
Risk: 18/100
Step 07
Generate Meeting Dossier
Risk: 18/100
Step 08
Score Proposed Jira Write
Risk: 68/100
Step 09
Hash-Bound Approval Gate
Risk: 68/100
Step 10
Execute Jira Write (Simulated)
Risk: 30/100
Step 11
Verify External State (Simulated)
Risk: 15/100
Step 12
Commit Audit Record & Report
Risk: 5/100
Phase: Identity & Tenant Resolution
Tool: runtime_internal•Risk Score: 5/100
// Action Description:

Simulated authentication of session user ([email protected]) under Tenant ID tenant_89f2a. Example identity delegation chain: Tenant → User → Agent.

// Verified Output State:
{"tenant_id": "tenant_89f2a", "user_role": "VP_PRODUCT", "identity_chain": "tenant_89f2a:user_alex:agent_chief_of_staff", "status": "AUTHORIZED (simulated)"}
Real-Time Policy Governance

The Dynamic Risk Scoring Engine

The specification defines a normalized quantitative score that is evaluated before execution. This is an illustrative scoring model — policies, tenant configuration, and scope checks can still deny low-scoring actions:

RiskScore = Impact × Irreversibility × Externality × Sensitivity × Uncertainty × 100
Adjust Risk Factor Variables
1. Impact (Blast Radius):0.95 / 1.00
0.10 (Single record read)1.00 (Irrevocable financial/system change)
2. Irreversibility (Rollback Barrier):0.90 / 1.00
0.10 (Trivial compensation/undo)1.00 (Completely irreversible side-effect)
3. Externality (Scope Boundary):0.92 / 1.00
0.10 (Local session memory only)1.00 (External world / Partner / Customer)
4. Sensitivity (Data Classification):0.92 / 1.00
0.10 (Public documentation)1.00 (Restricted PII / Financial credentials)
5. Uncertainty (Variance / Execution Ambiguity):0.94 / 1.00
0.10 (Deterministic contract)1.00 (High ambiguity / Open-ended prompt)
Real-Time Formula Evaluation:
0.95 × 0.90 × 0.92 × 0.92 × 0.94 × 100 = 68 / 100
Evaluated Action Tier:
68 / 100
Human Approval Required
Governance Policy Outcome:

Execution paused. Canonical JSON SHA-256 action hash locked until authorized user sign-off.

Action Status: APPROVAL_GATE_PENDING
Audit Stamp: audit_hash_0x7b2f
0 - 20: Auto ExecutionRead / Safe
21 - 50: ABAC / Policy CheckStandard Writes
51 - 80: Human Approval GateHigh-Impact
81 - 100: Deny / Elevated ApprovalCritical Risk
Relational Schema & ER Engine

The WorkAgent OS Data Model

Formally defined in Section 20 & 21 of the specification. Built for PostgreSQL with Row-Level Security (RLS) to enforce multi-tenant boundaries at the database kernel level.

11 Core Platform Entities:
Table: public.agent_runs

AgentRun

RLS Filter: tenant_id = current_tenant()

Single end-to-end execution lifecycle instance capturing telemetry and token costs.

Columns & Types:

ColumnTypeDescription
idUUIDPrimary key
conversation_idUUIDParent conversation
statusENUMPENDING, RUNNING, APPROVAL_WAIT, COMPLETED, FAILED
started_atTIMESTAMPTZExecution start
completed_atTIMESTAMPTZExecution completion
costNUMERIC(10,5)Total token cost in USD

Foreign Key Relationships (Section 21 ERD):

N─1 Conversation1─N ToolCall1─N Approval1─N AuditEvent
Developer API Reference

REST & MCP API Surface

Section 22 of the specification defines proposed endpoints for agent runs, hash-bound approvals, semantic memory queries, and audit logs. All endpoints below are SPEC — responses are SIMULATION examples, not live latency or availability guarantees. Copying a request payload does not imply an implemented API.

API Surface Endpoints:
All Requests Scope:

Authorization: Bearer <tenant_scoped_jwt>
X-Tenant-ID: tenant_89f2a

POST/v1/agents/{agent_id}/runsSPEC

Proposed endpoint: initialize an autonomous execution run for an agent with tenant context and prompt payload.

Request Payload:application/json
{
  "conversation_id": "conv_9921",
  "prompt": "Prepare me for today's Acme meeting and summarize blockers.",
  "context_overrides": {
    "time_window_hours": 48
  },
  "max_budget_usd": 0.50
}
Example Response (200 OK):SIMULATION • Not a live gateway response
{
  "run_id": "run_01j98ab7",
  "agent_id": "chief-of-staff",
  "status": "RUNNING",
  "estimated_cost_usd": 0.084,
  "steps_planned": 5,
  "created_at": "2026-10-08T18:30:00Z"
}
Production Readiness

Definition of Done — Readiness Targets

Section 30 of the master specification defines the readiness targets an agent must meet before any production release. These are engineering targets in the specification — no item below has been verified in a published production deployment. Production implementation and verification evidence have not been published with this website.

Target: multi-tenant Row-Level Security (RLS) isolation across storage layers
Target: model providers decoupled behind a standard reasoning adapter
Target: strict JSON Schema validation for every MCP tool call
Target: high-impact actions gated behind canonical SHA-256 action hash human approval
Target: OpenTelemetry traces capturing latency, tokens, and policy outcomes
Target: prompt injection and untrusted content quarantine test coverage
Target: idempotency keys and external state verification with recovery workflows
30-Day Engineering Rollout Plan
Section 29 Spec
Week 1Core Foundation & Anthropic Adapter

Monorepo setup, Auth, Tenant Resolver, PostgreSQL schema, AgentRun tables, Claude adapter, baseline UI.

Week 2MCP Integrations & Context Engine

Google Calendar, Gmail, Drive connectors, Tool registry, Context Builder ranking, Chief of Staff MVP.

Week 3Permissions, Slack & Jira Human Approval

Slack and Jira/Linear MCPs, ABAC permission engine, approval UI, idempotency keys, audit events.

Week 4Observability, Evaluation & Hardening

OpenTelemetry tracing, token cost accounting, golden evaluation suite, prompt injection tests, production demo.

Integration Catalog — PREVIEW

Proposed Connector Catalog

Every connector referenced by the agent fleet is listed here with its public status. These are proposed connectors — design examples only; no production connector registry has been published and none are silently active.

Google CalendarPREVIEWGmailPREVIEWGoogle DrivePREVIEWSlackPREVIEWJiraPREVIEWLinearPREVIEWSalesforcePREVIEWHubSpotPREVIEWLinkedIn Sales NavPREVIEWZendeskPREVIEWMixpanelPREVIEWGoogle SlidesPREVIEWIntercomPREVIEWGoogle MeetPREVIEWZoomPREVIEWGoogle DocsPREVIEWBrave SearchPREVIEWInternal Vector DBPREVIEWNotionPREVIEWConfluencePREVIEWGitHubPREVIEWGitLabPREVIEWSentryPREVIEWDockerPREVIEWQuickBooksPREVIEWNetSuitePREVIEWStripePREVIEWPostgreSQLPREVIEW
Trust Center

Honest Status, Data Handling & Security Posture

Status legend for every claim on this site, identity and approval lifecycles, residency and retention matrices, model provider handling, threat model, and responsible disclosure — all labeled LIVE, PREVIEW, SPEC, or ROADMAP.

Open Trust Center

Ready to Deploy Autonomous Agents with Enterprise Confidence?

The WorkAgent OS specification unites AI agents, enterprise SaaS tools, and human oversight into one policy-bounded, verifiable execution architecture.