Skip to content

Guides

Traces and reviews

Follow one piece of work end to end through every record it touched, have people look at what agents did after they did it, and take back access nobody vouches for.

#Traces

Every request runs inside a W3C trace. A caller’s valid traceparent is continued; otherwise one is minted. Every response returns a traceparent header, and every ledger record written while handling the request carries it, along with the subject that acted.

So a single unit of work, say an agent’s model call, its tool call through the proxy, the approval a person gave and the card authorisation that followed, can be read back in order:

curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/traces/4bf92f3577b34da6a3ce929d0e0e4736" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"

Send your own traceparent from your agent framework and Immiscible’s records join your trace; export them to your tracing backend as OpenTelemetry.

#Reviews

A share of agent actions in each risk band, and every action that tripped a signal, goes to a person to review after the fact. The reviewer is never the agent’s sponsor or the person it acts for.

Shell
curl "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/reviews?status=pending&mine=1" -H "cookie: __Host-sid=$IMMISCIBLE_SESSION"

curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/reviews/rev_8b1f" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" \
  -d '{ "verdict": "concern", "note": "Paid the right supplier but the invoice was a duplicate." }'
VerdictMeans
oklooked, nothing wrong
concernsomething to fix, recorded against the agent
incidentfreezes the agent under an incident hold

Each verdict is signed by the deployment’s key as an attestation of who reviewed what and what they said (the note is kept as a digest in the chain), so “who looked at this, when, and what did they say” has an answer an auditor can check. Give people the reviewer governance role to receive reviews.

#Recertification

Access granted once and never looked at again is how standing privilege accumulates. A recertification campaign asks, for every active agent, whoever answers for it to look at its access profile as it stands and decide:

Shell
# start a campaign, due in 14 days
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/certifications" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" -d '{ "dueDays": 14 }'

# certify (or revoke) one agent in it
curl -X POST "https://immiscible.fly.dev/api/w/$IMMISCIBLE_WORKSPACE/certifications/crt_44f0/agents/agt_4f2c91a7" \
  -H "cookie: __Host-sid=$IMMISCIBLE_SESSION" -H "x-immiscible-csrf: 1" \
  -H "content-type: application/json" -d '{ "decision": "certify", "note": "Still pays supplier invoices; scope unchanged." }'

A certification records the hash of the profile that was looked at, signed. Access nobody recertified by the due date is taken back: the agent is demoted to intern and frozen under a security hold, by the same background sweep that runs approval deadlines.

#Approver health

A control that depends on attention has to measure attention. GET /api/w/:wid/governance/approvers shows, for each approver, how many requests they decided, how often they said yes, how fast, and how many they decided in less time than it takes to read the request.