OpenKedge / programmable agent control

KedgeFlow.OpenFlow for the agentic world.

Keep the intelligence in your agents. Put execution authority in a programmable control plane.

Connect the tools you already use through explicit contracts for evidence, permission, enforcement, and outcomes.

Reference codeArchitecture & protocol · v0.9

The idea

Intelligence proposes.
Authority permits.

KedgeFlow is OpenKedge’s programmable control-plane architecture and protocol for consequential AI-agent actions. It separates agent reasoning from execution authority: check policy and evidence, issue permission for one exact action, enforce it at the protected resource, and track the outcome.

OpenFlow separated network control from packet forwarding. KedgeFlow applies that design idea to agents, then adds action-specific grants, evidence freshness, and outcome reconciliation. The analogy is architectural; KedgeFlow is a proposed protocol and reference implementation.

OpenFlow / SDN background

Evidence before authority

Policy, semantic judgments, and human review support admission for the exact proposed action.

Permission for one action

An action-bound, single-use grant is claimed before dispatch. The protected resource checks its guard.

Outcomes stay accountable

A confirmed receipt closes the loop. An unconfirmed effect stays unknown until reconciliation.

One framework. Your tools.

Give every tool a clear role.

Agent frameworks propose. Evidence providers inform. Policy evaluates. Authority is issued and claimed. Gateways mediate. Outcomes close the loop.

Whitepaper §5.2

KedgeFlow / ecosystem & contract map

Select a tool to inspect its role

Agent plane

Keep your agent stack

Models, planners, graphs, and crews propose actions through an Agent Adapter.

Proposal & reference bus

Evidence providers

Support the proposed action

Semantic judgments, telemetry, and human review become scoped, time-bound witnesses.

View Jev · TypeSafe contract

Control plane

Admit. Then issue authority.

Separate admission and grant services connect policy decisions to exact, single-use permission.

Enforcement plane

Mediate the protected effect

The gateway claims authority; a resource adapter checks the actual target guard.

Evidence

Bound witnesses → admission

Authority

Exact grants → gateway

Outcomes

Attempt receipts → reconciliation

Contract & information bus · shared action identity links the records; it does not make them interchangeable.

Outcome service

Know what happened

Correlate receipts, retain unknown outcomes, and reconcile before considering another effect.

Identity & containment

Keep the boundary intact

Authenticate users and workloads. Keep standing credentials and alternate mutation paths outside the agent’s reach.

Evidence providers

Jev · TypeSafe

A System One model that answers typed Choice, Score, and Noul questions about supplied state.

The integration contract

Treat semantic answers as evidence inputs. Bind the evaluated state, question, model context, uncertainty, and validity to the proposal; independent admission decides whether that evidence is sufficient.

What crosses the bus

Typed semantic judgment → scoped witness → admission

Official documentation

Architecture mapping adapted from whitepaper §5.2, with Jev added as a semantic Evidence Provider input. This map describes integration responsibilities; it is not a list of shipped adapters or vendor conformance approvals. The bus is a view of typed contracts, not a deployed shared message broker.

Read all tool roles and integration contracts

Agent plane

OpenAI Agents SDK
Agent runtime with function-tool guardrails and tracing.

Freeze the proposed action before admission and enumerate the invocation paths covered by the adapter. Route protected effects through the gateway.

Exact proposal → admission request

Claude Agent SDK
Agent runtime with permission rules and tool-approval hooks.

Preserve the exact action and caller binding across approval. Isolate any shell, SDK, or filesystem route that could bypass the protected execution path.

Tool proposal → admission request

Google ADK
Agent runtime with callbacks around tool invocation.

Use a callback or wrapper as the adapter surface; capture the exact proposal and document which tool paths it mediates.

Frozen tool call → admission request

LangGraph
Stateful orchestration with persistence and human interrupts.

Bind resumed execution to the approved proposal and stable operation identity. A checkpoint is separate from proof that the protected resource committed.

Approved proposal identity → resumed workflow

Microsoft Agent Framework
Agent and multi-agent orchestration; function middleware provides an adapter attachment surface.

Document middleware coverage and identify the independently administered services that own grant verification, credentials, and effect mediation.

Agent proposal → independently enforced action

CrewAI
Agent crews and persistent Flows with human-feedback workflows.

Bind review to the exact consequential action, then connect continuation to admission, grant redemption, and outcome retrieval.

Reviewed proposal → bounded continuation

Evidence providers

Jev · TypeSafe
A System One model that answers typed Choice, Score, and Noul questions about supplied state.

Treat semantic answers as evidence inputs. Bind the evaluated state, question, model context, uncertainty, and validity to the proposal; independent admission decides whether that evidence is sufficient.

Typed semantic judgment → scoped witness → admission

OpenTelemetry
Collection and export of traces, metrics, and logs.

Wrap observations with producer identity, observation time, proposal/resource binding, validity, and coverage. A log entry alone supplies neither trust nor authority.

Observed state → provenance-bound witness

Human review / WebAuthn
Human decisions supported by public-key authentication assertions.

Bind the review challenge to the exact proposal and policy epoch; verify origin, challenge, reviewer authority, and enrollment assumptions.

Proposal-bound review → signed witness

Control plane

OPA
Policy evaluation separated from enforcement, with support for policy bundles.

Record the policy version and input provenance, define evidence obligations, and connect the decision to independently enforced issuance and redemption.

Policy + verified inputs → admission decision

Cedar
Principal/action/resource/context authorization and schema-based policy validation.

Bind verified witness facts to policy inputs. Inspect evaluation diagnostics and fail closed on errors; an allow verdict does not establish evidence sufficiency by itself.

Identity + action + context → policy verdict

etcd
An atomic transactional substrate for an authority ledger and registry observations.

Compare root generation, claim state, and required reservations in one authority transaction. Consuming a grant does not itself commit the business-resource change.

Grant root + claim → conserved authority state

Enforcement plane

Envoy
Request mediation with an external-authorization filter.

Add exact grant verification, shared redemption state, credential custody, outcome handling, and tested fail-closed coverage to implement the Execution Gateway contract.

Action-bound grant → guarded dispatch

Kubernetes
Conditional object updates using resourceVersion to reject stale writes.

Advertise the target’s actual guard strength and correlate its result. A per-object condition does not establish every cross-resource invariant.

Protected guard + action → target result

Outcome service

Temporal
Durable workflows and Activities for orchestration and reconciliation.

Use stable operation identities and reconcile unknown effects before re-execution. Compensation is a separately admitted action, with resource-specific limits.

Attempt identity + receipt → outcome reconciliation

Identity & containment

SPIFFE / SPIRE
Verifiable workload identity and workload attestation building blocks.

Authenticate both the subject and the workload under the deployment’s trust policy. Workload identity is an input to authorization, not the action grant itself.

Subject + workload identity → authenticated bindings

OAuth / OIDC
Subject authentication, proof-of-possession tokens, and credential-exchange primitives.

Preserve user delegation and exact grant scope during exchange. Keep target credentials in the enforcement plane and obtain them only after the authority claim.

Bound identity + claimed grant → scoped target credential

gVisor
Application isolation through a userspace kernel.

Declare and constrain filesystem, network, and credential access. Pair containment with admission and enforcement for protected enterprise effects.

Isolation policy → constrained agent environment

Transport interfaces

MCP
Tool discovery and invocation transport.

Negotiate the KedgeFlow profile, bind consequential tools/call requests to a frozen proposal and registered descriptor, and atomically claim the grant before dispatch.

Tool call + exact grant → execution gateway

A2A
Agent discovery, collaboration, task status, and capability extensions.

Carry typed execution-root references and bind delegation to the authority service’s root generation. A completed agent task does not itself establish resource commit.

Delegated root reference → authenticated retrieval

Jev × KedgeFlow

A semantic signal.
A governed decision.

Jev answers typed questions about supplied state. In this architecture, those answers become proposal-bound evidence for admission. A separate authority service issues the execution grant.

  1. 01

    Ask a typed question

    Choice · Score · Noul

  2. 02

    Bind the witness

    State · proposal · validity

  3. 03

    Check admission

    Policy · evidence sufficiency

  4. 04

    Issue an exact grant

    Independent execution authority

Build from an inspectable reference

Architecture. Protocol. Code.

The v0.9 reference pairs the Rust kedgeflow crate and kf-proxy gateway with KF-JSON-0.2 schemas and signed fixtures.

Local verification · October 5, 2026

Rust tests
52
Python compatibility tests
24
real etcd members
3

The record also covers official MCP client checks and a mock fenced resource. These runs verify local mechanics; production adapters, complete containment, and the full admission stack remain separate deployment work.

Inspect the verification record

Clear answers

KedgeFlow, explained.

Download the whitepaper PDF
What is KedgeFlow?

KedgeFlow is OpenKedge’s programmable control-plane architecture and protocol for consequential AI-agent actions. It separates agent reasoning from execution authority: check policy and evidence, issue permission for one exact action, enforce it at the protected resource, and track the outcome.

Why call KedgeFlow OpenFlow for the agentic world?

OpenFlow separates network control from packet forwarding through an explicit interface. KedgeFlow applies that architectural idea to AI agents: separate reasoning, execution authority, and protected effects. The analogy describes the design; KedgeFlow is a proposed protocol and reference implementation, not an adopted networking or industry standard.

Does KedgeFlow replace LangGraph, CrewAI, or agent SDKs?

No. Those runtimes keep their planning, memory, and orchestration responsibilities. An Agent Adapter captures exact proposals; independently administered services admit them, issue bounded grants, and enforce protected effects. The ecosystem map describes integration responsibilities, not ready-made or certified integrations.

Where does Jev fit in KedgeFlow?

Jev supplies typed semantic judgments as an Evidence Provider input. A proposed adapter would bind those judgments, their evaluated state, and uncertainty to an exact action. Independent admission checks policy and evidence before a separate Grant Authority issues execution permission. A Jev answer is evidence, not execution authority.

How does KedgeFlow relate to MCP and A2A?

MCP carries tool discovery and invocation; A2A carries agent collaboration and task messages. KedgeFlow proposes additional contracts for evidence, action-bound grants, conserved delegation, and outcome linkage. These are negotiated extensions, not guarantees supplied by the base protocols.

What has been implemented and verified?

The v0.9 reference includes the Rust kedgeflow crate and kf-proxy gateway, KF-JSON-0.2 schemas, and signed fixtures. The October 5, 2026 verification record reports 52 Rust tests and 24 Python compatibility tests passing, including real three-member etcd and official MCP client checks. The runs validate local mechanics; production target coverage, complete containment, and a full admission-to-execution deployment remain separate gates.

What happens if an action times out?

An unconfirmed effect remains unknown. Consumed authority is retained, and query-only reconciliation looks for a result tied to the existing attempt. A timeout neither proves that nothing happened nor grants permission to retry the mutation.