Reference

Field-level reference for Agent Stream surfaces, routing policies, provider configuration, guardrails, settings, and operations.

This section is dashboard-configuration guidance: for each dashboard page or panel, what you’ll find there, what each control does, and how to decide what to set it to.

For step-by-step configuration tasks, see Get started and Guides. For conceptual explanations, see Concepts.

Surfaces

ReferenceWhat it covers
Core configurationThe fields shared by every surface: identity, listener/route settings, ingress formats, and identity pass-through.
ProvidersEvery supported provider and its connection fields, how parameter overrides are applied, and how token pricing is worked out from the model catalog.
GuardrailsPrompt Guard regex and model-backed PII rules, Expert Witness connectors, and Judge/Jury configuration fields.
Routing and variantsThe Decider (content-based routing and Mirror mode), attribute-based routing rules, canary splits, and the variant/alias catalogue.
Resilience and cachingFailover, weighted load balancing, streaming passthrough, and the response cache.
Cost and usage limitsRate limiting, cost tracking, per-stage usage limits, and breach/anomaly usage alerts.
Server tools and modalitiesGoverned Web Search and Web Fetch tools, context-window compression, document ingestion, and the audio/image/realtime-voice input gates.
IDE SurfacesThe IDE-catalogue surface type: catalog members, central client sign-in, per-member upstream authentication, and the published model list.

Security & access

ReferenceWhat it covers
SecretsSecret record fields, value-disclosure rules, storage backends, and lifecycle operations.
API keysManaged API key fields, status, expiry, and rotation that preserves a key’s remaining lifetime.
Source authenticationThe caller-authentication methods you can attach to a surface: JWT bearer, API key, API Key Provider, and mTLS client certificates.
RBACThe administrator/poweruser/user role ladder and the full default permission map.

Policies

ReferenceWhat it covers
OPA policiesThe four Rego evaluation layers, how a policy is stored and versioned, the policy input document, the surface-level policy block, and VP evidence.

Teams & attribution

ReferenceWhat it covers
MembersThe Member record, identifier matching, per-member limits, auto-provisioning, and the built-in anonymous and sandbox members.
TeamsThe Team record, surface-level attribution, and the team gate.

Governance

ReferenceWhat it covers
Governance recordsThe per-surface recording toggle, the signed record shape, its VC signature and hash chain, export sinks, and encryption and retention.

Observability

ReferenceWhat it covers
Telemetry and exportsSending telemetry to OTLP, Prometheus, Langfuse, and webhook destinations, and how to read the usage and rejection data behind the dashboard’s charts.
Response headersEvery x-agent-stream-* header a surface can return, and whether it appears on a buffered or a streamed response.
Notifications and alertsSetting up an alert integration, its per-type delivery configuration, and the event-type taxonomy that routes surface, drift, and usage alerts.
LLM driftTurning on drift monitoring for a surface, the nine drift dimensions, choosing baseline and threshold values, replay evaluation, and retention defaults.

Trust Fabric

ReferenceWhat it covers
Gateways and connection pointsGateway records, connection points, and the out-of-band (OOB) approval workflow behind gateway-to-gateway (G2G) DIDComm messaging.
Payments and marketplaceThe model marketplace: the catalog card, purchasing a model, and the resulting API key.

Configuration & operations

ReferenceWhat it covers
SettingsThe dashboard’s Settings page: System, User, Users, Admin, Networking, Security, and Limits tabs, and when to move a setting off its default.
Backup and encryptionThe Settings page’s Backup, Restore, and Export Storage actions, and what each includes.