OpenKedge / programmable agent control
KedgeFlow.OpenFlow for the
agentic world.
Keep the intelligence in your agents. Put execution authority in a programmable control plane.
Connect the tools you already use through explicit contracts for evidence, permission, enforcement, and outcomes.
Your agent stack
Reason, plan, propose
KedgeFlow
Evidence → admission → authority
Protected systems
Cloud · databases · enterprise APIs
The idea
Intelligence proposes.
Authority permits.
KedgeFlow is OpenKedge’s programmable control-plane architecture and protocol for consequential AI-agent actions. It separates agent reasoning from execution authority: check policy and evidence, issue permission for one exact action, enforce it at the protected resource, and track the outcome.
OpenFlow separated network control from packet forwarding. KedgeFlow applies that design idea to agents, then adds action-specific grants, evidence freshness, and outcome reconciliation. The analogy is architectural; KedgeFlow is a proposed protocol and reference implementation.
OpenFlow / SDN backgroundEvidence before authority
Policy, semantic judgments, and human review support admission for the exact proposed action.
Permission for one action
An action-bound, single-use grant is claimed before dispatch. The protected resource checks its guard.
Outcomes stay accountable
A confirmed receipt closes the loop. An unconfirmed effect stays unknown until reconciliation.
One framework. Your tools.
Give every tool a clear role.
Agent frameworks propose. Evidence providers inform. Policy evaluates. Authority is issued and claimed. Gateways mediate. Outcomes close the loop.
KedgeFlow / ecosystem & contract map
Select a tool to inspect its roleAgent plane
Keep your agent stack
Models, planners, graphs, and crews propose actions through an Agent Adapter.
Evidence providers
Support the proposed action
Semantic judgments, telemetry, and human review become scoped, time-bound witnesses.
View Jev · TypeSafe contractControl plane
Admit. Then issue authority.
Separate admission and grant services connect policy decisions to exact, single-use permission.
Evidence
Bound witnesses → admission
Authority
Exact grants → gateway
Outcomes
Attempt receipts → reconciliation
Contract & information bus · shared action identity links the records; it does not make them interchangeable.
Evidence providers
Jev · TypeSafe
A System One model that answers typed Choice, Score, and Noul questions about supplied state.
The integration contract
Treat semantic answers as evidence inputs. Bind the evaluated state, question, model context, uncertainty, and validity to the proposal; independent admission decides whether that evidence is sufficient.
Architecture mapping adapted from whitepaper §5.2, with Jev added as a semantic Evidence Provider input. This map describes integration responsibilities; it is not a list of shipped adapters or vendor conformance approvals. The bus is a view of typed contracts, not a deployed shared message broker.
Read all tool roles and integration contracts
Agent plane
- OpenAI Agents SDK
- Agent runtime with function-tool guardrails and tracing.
Freeze the proposed action before admission and enumerate the invocation paths covered by the adapter. Route protected effects through the gateway.
Exact proposal → admission request
- Claude Agent SDK
- Agent runtime with permission rules and tool-approval hooks.
Preserve the exact action and caller binding across approval. Isolate any shell, SDK, or filesystem route that could bypass the protected execution path.
Tool proposal → admission request
- Google ADK
- Agent runtime with callbacks around tool invocation.
Use a callback or wrapper as the adapter surface; capture the exact proposal and document which tool paths it mediates.
Frozen tool call → admission request
- LangGraph
- Stateful orchestration with persistence and human interrupts.
Bind resumed execution to the approved proposal and stable operation identity. A checkpoint is separate from proof that the protected resource committed.
Approved proposal identity → resumed workflow
- Microsoft Agent Framework
- Agent and multi-agent orchestration; function middleware provides an adapter attachment surface.
Document middleware coverage and identify the independently administered services that own grant verification, credentials, and effect mediation.
Agent proposal → independently enforced action
- CrewAI
- Agent crews and persistent Flows with human-feedback workflows.
Bind review to the exact consequential action, then connect continuation to admission, grant redemption, and outcome retrieval.
Reviewed proposal → bounded continuation
Evidence providers
- Jev · TypeSafe
- A System One model that answers typed Choice, Score, and Noul questions about supplied state.
Treat semantic answers as evidence inputs. Bind the evaluated state, question, model context, uncertainty, and validity to the proposal; independent admission decides whether that evidence is sufficient.
Typed semantic judgment → scoped witness → admission
- OpenTelemetry
- Collection and export of traces, metrics, and logs.
Wrap observations with producer identity, observation time, proposal/resource binding, validity, and coverage. A log entry alone supplies neither trust nor authority.
Observed state → provenance-bound witness
- Human review / WebAuthn
- Human decisions supported by public-key authentication assertions.
Bind the review challenge to the exact proposal and policy epoch; verify origin, challenge, reviewer authority, and enrollment assumptions.
Proposal-bound review → signed witness
Control plane
- OPA
- Policy evaluation separated from enforcement, with support for policy bundles.
Record the policy version and input provenance, define evidence obligations, and connect the decision to independently enforced issuance and redemption.
Policy + verified inputs → admission decision
- Cedar
- Principal/action/resource/context authorization and schema-based policy validation.
Bind verified witness facts to policy inputs. Inspect evaluation diagnostics and fail closed on errors; an allow verdict does not establish evidence sufficiency by itself.
Identity + action + context → policy verdict
- etcd
- An atomic transactional substrate for an authority ledger and registry observations.
Compare root generation, claim state, and required reservations in one authority transaction. Consuming a grant does not itself commit the business-resource change.
Grant root + claim → conserved authority state
Enforcement plane
- Envoy
- Request mediation with an external-authorization filter.
Add exact grant verification, shared redemption state, credential custody, outcome handling, and tested fail-closed coverage to implement the Execution Gateway contract.
Action-bound grant → guarded dispatch
- Kubernetes
- Conditional object updates using resourceVersion to reject stale writes.
Advertise the target’s actual guard strength and correlate its result. A per-object condition does not establish every cross-resource invariant.
Protected guard + action → target result
Outcome service
- Temporal
- Durable workflows and Activities for orchestration and reconciliation.
Use stable operation identities and reconcile unknown effects before re-execution. Compensation is a separately admitted action, with resource-specific limits.
Attempt identity + receipt → outcome reconciliation
Identity & containment
- SPIFFE / SPIRE
- Verifiable workload identity and workload attestation building blocks.
Authenticate both the subject and the workload under the deployment’s trust policy. Workload identity is an input to authorization, not the action grant itself.
Subject + workload identity → authenticated bindings
- OAuth / OIDC
- Subject authentication, proof-of-possession tokens, and credential-exchange primitives.
Preserve user delegation and exact grant scope during exchange. Keep target credentials in the enforcement plane and obtain them only after the authority claim.
Bound identity + claimed grant → scoped target credential
- gVisor
- Application isolation through a userspace kernel.
Declare and constrain filesystem, network, and credential access. Pair containment with admission and enforcement for protected enterprise effects.
Isolation policy → constrained agent environment
Transport interfaces
- MCP
- Tool discovery and invocation transport.
Negotiate the KedgeFlow profile, bind consequential tools/call requests to a frozen proposal and registered descriptor, and atomically claim the grant before dispatch.
Tool call + exact grant → execution gateway
- A2A
- Agent discovery, collaboration, task status, and capability extensions.
Carry typed execution-root references and bind delegation to the authority service’s root generation. A completed agent task does not itself establish resource commit.
Delegated root reference → authenticated retrieval
Jev × KedgeFlow
A semantic signal.
A governed decision.
Jev answers typed questions about supplied state. In this architecture, those answers become proposal-bound evidence for admission. A separate authority service issues the execution grant.
01
Ask a typed question
Choice · Score · Noul
02
Bind the witness
State · proposal · validity
03
Check admission
Policy · evidence sufficiency
04
Issue an exact grant
Independent execution authority
Build from an inspectable reference
Architecture. Protocol. Code.
The v0.9 reference pairs the Rust kedgeflow crate and kf-proxy gateway with KF-JSON-0.2 schemas and signed fixtures.
Local verification · October 5, 2026
- Rust tests
- 52
- Python compatibility tests
- 24
- real etcd members
- 3
The record also covers official MCP client checks and a mock fenced resource. These runs verify local mechanics; production adapters, complete containment, and the full admission stack remain separate deployment work.
Inspect the verification recordWhat is KedgeFlow?
KedgeFlow is OpenKedge’s programmable control-plane architecture and protocol for consequential AI-agent actions. It separates agent reasoning from execution authority: check policy and evidence, issue permission for one exact action, enforce it at the protected resource, and track the outcome.
Why call KedgeFlow OpenFlow for the agentic world?
OpenFlow separates network control from packet forwarding through an explicit interface. KedgeFlow applies that architectural idea to AI agents: separate reasoning, execution authority, and protected effects. The analogy describes the design; KedgeFlow is a proposed protocol and reference implementation, not an adopted networking or industry standard.
Does KedgeFlow replace LangGraph, CrewAI, or agent SDKs?
No. Those runtimes keep their planning, memory, and orchestration responsibilities. An Agent Adapter captures exact proposals; independently administered services admit them, issue bounded grants, and enforce protected effects. The ecosystem map describes integration responsibilities, not ready-made or certified integrations.
Where does Jev fit in KedgeFlow?
Jev supplies typed semantic judgments as an Evidence Provider input. A proposed adapter would bind those judgments, their evaluated state, and uncertainty to an exact action. Independent admission checks policy and evidence before a separate Grant Authority issues execution permission. A Jev answer is evidence, not execution authority.
How does KedgeFlow relate to MCP and A2A?
MCP carries tool discovery and invocation; A2A carries agent collaboration and task messages. KedgeFlow proposes additional contracts for evidence, action-bound grants, conserved delegation, and outcome linkage. These are negotiated extensions, not guarantees supplied by the base protocols.
What has been implemented and verified?
The v0.9 reference includes the Rust kedgeflow crate and kf-proxy gateway, KF-JSON-0.2 schemas, and signed fixtures. The October 5, 2026 verification record reports 52 Rust tests and 24 Python compatibility tests passing, including real three-member etcd and official MCP client checks. The runs validate local mechanics; production target coverage, complete containment, and a full admission-to-execution deployment remain separate gates.
What happens if an action times out?
An unconfirmed effect remains unknown. Consumed authority is retained, and query-only reconciliation looks for a result tied to the existing attempt. A timeout neither proves that nothing happened nor grants permission to retry the mutation.