Guides
Traces and reviews
Follow one piece of work end to end through every record it touched, have people look at what agents did after they did it, and take back access nobody vouches for.
#Traces
Every request runs inside a W3C trace. A caller’s valid traceparent is continued; otherwise one is minted. Every response returns a traceparent header, and every ledger record written while handling the request carries it, along with the subject that acted.
So a single unit of work, say an agent’s model call, its tool call through the proxy, the approval a person gave and the card authorisation that followed, can be read back in order:
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/traces/4bf92f3577b34da6a3ce929d0e0e4736" \
-H "cookie: __Host-sid=$IMMISCIBLE_SESSION"// Join your own trace to Immiscible's: send your traceparent, read ours back.
const res = await fetch('https://immiscible.fly.dev/v1/actions/authorize', {
method: 'POST',
headers: {
authorization: `Bearer ${process.env.IMMISCIBLE_AGENT_KEY}`,
'content-type': 'application/json',
traceparent: '00-4bf92f3577b34da6a3ce929d0e0e4736-00f067aa0ba902b7-01',
},
body: JSON.stringify(action),
});
console.log(res.headers.get('traceparent'));Send your own traceparent from your agent framework and Immiscible’s records join your trace; export them to your tracing backend as OpenTelemetry.
#Reviews
A share of agent actions in each risk band, and every action that tripped a signal, goes to a person to review after the fact. The reviewer is never the agent’s sponsor or the person it acts for.
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/reviews?status=pending&mine=1" -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/reviews/rev_8b1f" \
-H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
-H "content-type: application/json" \
-d '{ "verdict": "concern", "note": "Paid the right supplier but the invoice was a duplicate." }'| Verdict | Means |
|---|---|
ok | looked, nothing wrong |
concern | something to fix, recorded against the agent |
incident | freezes the agent under an incident hold |
Each verdict is signed by the deployment’s key as an attestation of who reviewed what and what they said (the note is kept as a digest in the chain), so “who looked at this, when, and what did they say” has an answer an auditor can check. Give people the reviewer governance role to receive reviews.
#Recertification
Access granted once and never looked at again is how standing privilege accumulates. A recertification campaign asks, for every active agent, whoever answers for it to look at its access profile as it stands and decide:
# start a campaign, due in 14 days
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/certifications" \
-H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
-H "content-type: application/json" -d '{ "dueDays": 14 }'
# certify (or revoke) one agent in it
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/certifications/crt_44f0/agents/agt_4f2c91a7" \
-H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
-H "content-type: application/json" -d '{ "decision": "certify", "note": "Still pays supplier invoices; scope unchanged." }'A certification records the hash of the profile that was looked at, signed. Access nobody recertified by the due date is taken back: the agent is demoted to intern and frozen under a security hold, by the same background sweep that runs approval deadlines.
#Approver health
A control that depends on attention has to measure attention. GET /api/w/:wid/governance/approvers shows, for each approver, how many requests they decided, how often they said yes, how fast, and how many they decided in less time than it takes to read the request.