# Reference

> Field-level reference for Agent Stream surfaces, routing policies, provider configuration, guardrails, settings, and operations.

This section is dashboard-configuration guidance: for each dashboard page or panel, what you’ll find there, what each control does, and how to decide what to set it to.

For step-by-step configuration tasks, see [Get started](/products/affinidi-trust-fabric/agent-stream/get-started.md) and [Guides](/products/affinidi-trust-fabric/agent-stream/how-to-guides.md). For conceptual explanations, see [Concepts](/products/affinidi-trust-fabric/agent-stream/concepts.md).

## Surfaces

| Reference | What it covers |
| [Core configuration](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/surface-reference.md) | The fields shared by every surface: identity, listener/route settings, ingress formats, and identity pass-through. |
| [Providers](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/providers.md) | Every supported provider and its connection fields, how parameter overrides are applied, and how token pricing is worked out from the model catalog. |
| [Guardrails](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/guardrails.md) | Prompt Guard regex and model-backed PII rules, Expert Witness connectors, and Judge/Jury configuration fields. |
| [Routing and variants](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/routing-and-variants.md) | The Decider (content-based routing and Mirror mode), attribute-based routing rules, canary splits, and the variant/alias catalogue. |
| [Resilience and caching](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/resilience-and-caching.md) | Failover, weighted load balancing, streaming passthrough, and the response cache. |
| [Cost and usage limits](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/cost-and-usage-limits.md) | Rate limiting, cost tracking, per-stage usage limits, and breach/anomaly usage alerts. |
| [Server tools and modalities](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/server-tools-and-modalities.md) | Governed Web Search and Web Fetch tools, context-window compression, document ingestion, and the audio/image/realtime-voice input gates. |
| [IDE Surfaces](/products/affinidi-trust-fabric/agent-stream/reference/surfaces/ide-surfaces.md) | The IDE-catalogue surface type: catalog members, central client sign-in, per-member upstream authentication, and the published model list. |
## Security & access

| Reference | What it covers |
| [Secrets](/products/affinidi-trust-fabric/agent-stream/reference/security/secrets.md) | Secret record fields, value-disclosure rules, storage backends, and lifecycle operations. |
| [API keys](/products/affinidi-trust-fabric/agent-stream/reference/security/api-keys.md) | Managed API key fields, status, expiry, and rotation that preserves a key’s remaining lifetime. |
| [Source authentication](/products/affinidi-trust-fabric/agent-stream/reference/security/source-authentication.md) | The caller-authentication methods you can attach to a surface: JWT bearer, API key, API Key Provider, and mTLS client certificates. |
| [RBAC](/products/affinidi-trust-fabric/agent-stream/reference/security/rbac.md) | The administrator/poweruser/user role ladder and the full default permission map. |
## Policies

| Reference | What it covers |
| [OPA policies](/products/affinidi-trust-fabric/agent-stream/reference/policies/opa-policies.md) | The four Rego evaluation layers, how a policy is stored and versioned, the policy input document, the surface-level policy block, and VP evidence. |
## Teams & attribution

| Reference | What it covers |
| [Members](/products/affinidi-trust-fabric/agent-stream/reference/teams/members.md) | The Member record, identifier matching, per-member limits, auto-provisioning, and the built-in anonymous and sandbox members. |
| [Teams](/products/affinidi-trust-fabric/agent-stream/reference/teams/teams.md) | The Team record, surface-level attribution, and the team gate. |
## Governance

| Reference | What it covers |
| [Governance records](/products/affinidi-trust-fabric/agent-stream/reference/governance/governance-records.md) | The per-surface recording toggle, the signed record shape, its VC signature and hash chain, export sinks, and encryption and retention. |
## Observability

| Reference | What it covers |
| [Telemetry and exports](/products/affinidi-trust-fabric/agent-stream/reference/observability/telemetry-and-exports.md) | Sending telemetry to OTLP, Prometheus, Langfuse, and webhook destinations, and how to read the usage and rejection data behind the dashboard’s charts. |
| [Response headers](/products/affinidi-trust-fabric/agent-stream/reference/observability/response-headers.md) | Every x-agent-stream-* header a surface can return, and whether it appears on a buffered or a streamed response. |
| [Notifications and alerts](/products/affinidi-trust-fabric/agent-stream/reference/observability/notifications-and-alerts.md) | Setting up an alert integration, its per-type delivery configuration, and the event-type taxonomy that routes surface, drift, and usage alerts. |
| [LLM drift](/products/affinidi-trust-fabric/agent-stream/reference/observability/llm-drift.md) | Turning on drift monitoring for a surface, the nine drift dimensions, choosing baseline and threshold values, replay evaluation, and retention defaults. |
## Trust Fabric

| Reference | What it covers |
| [Gateways and connection points](/products/affinidi-trust-fabric/agent-stream/reference/trust-fabric/gateways.md) | Gateway records, connection points, and the out-of-band (OOB) approval workflow behind gateway-to-gateway (G2G) DIDComm messaging. |
| [Payments and marketplace](/products/affinidi-trust-fabric/agent-stream/reference/trust-fabric/payments-and-marketplace.md) | The model marketplace: the catalog card, purchasing a model, and the resulting API key. |
## Configuration & operations

| Reference | What it covers |
| [Settings](/products/affinidi-trust-fabric/agent-stream/reference/configuration/settings.md) | The dashboard’s Settings page: System, User, Users, Admin, Networking, Security, and Limits tabs, and when to move a setting off its default. |
| [Backup and encryption](/products/affinidi-trust-fabric/agent-stream/reference/configuration/backup-and-encryption.md) | The Settings page’s Backup, Restore, and Export Storage actions, and what each includes. |

## Pages in this section
- [Surfaces](/products/affinidi-trust-fabric/agent-stream/reference/surfaces.md)
- [Security & Access](/products/affinidi-trust-fabric/agent-stream/reference/security.md)
- [Policies](/products/affinidi-trust-fabric/agent-stream/reference/policies.md)
- [Teams & Attribution](/products/affinidi-trust-fabric/agent-stream/reference/teams.md)
- [Governance](/products/affinidi-trust-fabric/agent-stream/reference/governance.md)
- [Observability](/products/affinidi-trust-fabric/agent-stream/reference/observability.md)
- [Trust Fabric](/products/affinidi-trust-fabric/agent-stream/reference/trust-fabric.md)
- [Configuration & Operations](/products/affinidi-trust-fabric/agent-stream/reference/configuration.md)

