Core Concepts
AI applications and agents that call LLM providers directly have no shared control point: every team wires up its own keys, retries, and safety checks, and nobody can answer who spent what, on which model. Agent Stream provides that shared control point: identity, guardrails, cost governance, and observability, configured once on a surface and applied to every call. Architecture →
Agent Stream is part of the Affinidi Trust Fabric, a suite of products for decentralised identity management, scope governance, and trust in agentic AI systems.
Concepts in order
The concepts follow the order in which most teams build their understanding of Agent Stream: architecture and actors first, then trust-fabric integration, surfaces, model configuration, governance controls, operations, and lifecycle.
| Concept | What it explains |
|---|---|
| Architecture | How Agent Stream sits between your applications and the providers they call, and how it is deployed as a single, hot-reloadable appliance. |
| Entities and Actors | Overview of the actors, entities, credentials, and organisational references managed across Agent Stream. |
| Trust Fabric integration | How gateway-to-gateway DIDComm, the model marketplace, and x402 payments put Agent Stream on the trust fabric. |
| Surfaces | How the LLM Surface fronts one provider adapter and the IDE Surface aggregates them into a governed model menu. |
| Providers and Models | How provider adapters, model capabilities, pricing, and request profiles resolve from the hot-reloadable catalogue. |
| Surface Variants | How named Surface variations inherit base configuration and support aliases, targeted rollout, and safe promotion. |
| Prompt Management | How versioned prompt templates, point-in-time snapshots, and the interactive playground support centrally managed prompts. |
| Pipeline and stages | The named stages every request passes through, and why unused stages add no latency. |
| Security and access control | How identity, RBAC, secrets management, and SSRF protection secure callers and the appliance control plane. |
| Policies | How gateway-level and surface-level Rego policies decide whether a request is allowed. |
| Guardrails | How Prompt Guard, Expert Witnesses, Judge, and Jury layer content safety around a call. |
| PII protection | How Prompt Guard detects sensitive data and pseudonymises it with NER IDs or static redaction. |
| Cost and usage governance | How Agent Stream meters cost and tokens per stage and enforces budgets before they are exceeded. |
| Cost and attribution | How members and teams attribute spend and usage and enforce quota controls. |
| Resilience and caching | How failover, load balancing, retry, and response caching protect model calls. |
| LLM drift detection | How a surface samples live traffic and replays captured sessions to track behaviour against a baseline. |
| Governance records | How signed, tamper-evident records and hash chains prove what entered a surface, how it was processed, and what left. |
| Observability | What telemetry Agent Stream produces, what the dashboard shows, and how to export it to your own stack. |
| Storage and Lifecycle | How Agent Stream manages persistence boundaries, hot-reloadable configuration, and warm-standby failover. |
Glad to hear it! Please tell us how we can improve more.
Sorry to hear that. Please tell us how we can improve.
Thank you for sharing your feedback so we can improve your experience.