ForgeLayer

AgentOS v0 foundation · deterministic control plane

AgentOS

Route, compare, govern, and record AI software work across specialized agents.

Create a controlled operating plan before an AI agent receives repository work.

Foundation only: no live agent execution, no external agent APIs, no autonomous workflows, no persistence, no analytics, and no billing.

Risk level does not mean the agent is bad. It means how much control and human approval the agent needs before its work is trusted, merged, or used.

Recommended for this task. No adapter authority or dispatch issued.

Deterministic router

No autonomous execution

AgentOS v0 returns routing hints and human checks only. ForgeLayer does not call Codex, Claude Code, Cursor, Copilot, Devin, or any external agent service from this page.

Registry onlyNo live agentsHuman approval
Workspace boundary

Workspace mode: private_beta. Role: anonymous. Auth required: no. Persistence allowed: limited/demo only. GitHub posting: disabled by default. Agent execution: disabled. Billing: not live.

Provider-aware routing v1

Loading deterministic routing analysis

No provider operation is performed while this read-only projection loads.

Connection and authority lifecycle

Recommendation → capability preview → connection prerequisite → authority gate → dispatch blocked

Current tasks stop before connection, authorization, and dispatch readiness. No recommendation, local workflow, or approval preview can fabricate dispatched, executing, output-received, or verified state.

Inspect Dispatch boundaries

Provider connection foundation

AgentOS compares products while connection authority stays separate.

Codex, Claude Code, and Cursor are first-class modeled products. Connection records do not select, assign, contact, or execute a provider.
Recorded previewcodex

Codex

Workspace membership recorded. Provider ownership and authentication remain unverified.

Modeled capabilities
14
Authentication / ownership
unavailable / unverified
Routing analysis
deterministic capability-based
Dispatch / execution
false / false
Recorded previewclaude_code

Claude Code

Workspace membership recorded. Provider ownership and authentication remain unverified.

Modeled capabilities
15
Authentication / ownership
unavailable / unverified
Routing analysis
deterministic capability-based
Dispatch / execution
false / false
Recorded previewcursor

Cursor

Workspace membership recorded. Provider ownership and authentication remain unverified.

Modeled capabilities
11
Authentication / ownership
unavailable / unverified
Routing analysis
deterministic capability-based
Dispatch / execution
false / false

These canonical connection records feed the provider-aware routing analysis above. Compatibility remains separate from authentication, authority, dispatch, and execution.

Repository prerequisite

Repository state informs deterministic recommendation analysis.

The workspace owns three deterministic GitHub repository previews. Installation, ownership, permission, metadata, contents, verification, and transport remain unavailable, so provider-aware routing stays preview-only.

Workspace repository inventory

1 repository host recognized

3 scenario-isolated GitHub repository previews. Installation, ownership, permissions, metadata, and contents remain unverified or unavailable.

Inspect Repository Connections
3Recorded previews
0Verified installations
0Verified repositories
0Metadata read enabled
0Contents read enabled
0Write enabled
0Webhooks configured
0Repository executions
Deterministic previewGitHub requests: 0GitHub writes: 0Provider inventory remains separate
Provider products recognized3
Repository host recognized1
Repository previews recorded3
Verified installations0
GitHub requests0
Dispatch availablefalse

Repository state informs deterministic recommendation analysis but does not select a provider and does not assign, contact, authorize, dispatch, or execute Codex, Claude Code, Cursor, or any other provider product.

Agent Governance Center

Route by fit. Govern by permission, policy, verification, and approval.

Inspect what each seeded agent may be considered for, which task categories remain restricted or blocked, and which human checks are required. Governance is deterministic and preview-only; it does not connect or execute agents.

Open Agent Governance

Approval Authority

Recommendation never creates authority.

Agent fit, Capability Package, Dispatch authorization, required approval, revocation, kill-switch state, and disabled transport remain separate. No recommendation grants repository access or executes a provider operation.

Inspect authority controls

AI software team controls

One operating model for specialized agents

AgentOS separates agent fit from agent authority, then carries required oversight into workflow, record, and Ledger foundations.
Available now

Agent registry

Normalizes specialized coding, review, security, prompt, and planning profiles.

Available now

Task routing

Classifies software work and returns deterministic routing hints.

Available now

Capability matching

Matches detected work types to agent strengths and supported work.

Available now

Control-risk comparison

Compares fit, safety, autonomy, and oversight requirements without judging agent quality.

Available now

Supporting-agent recommendations

Separates the primary route from supporting review or specialist roles.

Available now

Workflow planning

Creates draft approval checklists, blocked actions, risks, and next steps.

Available now

Agent Work Records

Documents proposed work, evidence, risks, approvals, and merge readiness.

Available now

Ledger connection

Derives an AI Work Ledger preview from a draft Work Record.

Available now

Human approval gates

Keeps repository work, commands, posting, and merge decisions under human control.

Not live

Controlled execution

Future permission, identity, audit, and kill-switch controls before any agent execution.

Guided routing scenarios

Start with a realistic software task

Each preset loads the real deterministic router and draft workflow planner. No agent or external service is contacted.

Control lifecycle

Task to auditable software work

Output intake and verification are future controlled stages. Everything available today remains planning, comparison, and draft record generation only.
  1. 01
    Task

    Define the software task, scope, changed paths, and risk tolerance.

    Available
  2. 02
    Capability analysis

    Detect work types and required specialist capabilities.

    Available
  3. 03
    Agent recommendation

    Rank primary and supporting profiles with reasons and cautions.

    Available
  4. 04
    Workflow plan

    Create a draft route with checks, blocked actions, and next steps.

    Available
  5. 05
    Agent output intake

    Future controlled intake for external agent artifacts; no agent is connected today.

    Future / controlled
  6. 06
    Verification

    Future evidence verification for tests, policy, and produced changes.

    Future / controlled
  7. 07
    Human approval

    A human confirms evidence, scope, permissions, and merge readiness.

    Available
  8. 08
    Work Record

    Document the task, proposed agent, risks, evidence, and approvals.

    Available
  9. 09
    Ledger

    Create a derived, non-persistent ledger preview for audit context.

    Available

Legacy deterministic profile demo

Explore historical agent profiles

This earlier profile router remains for historical demo continuity. It is not the canonical workspace provider recommendation; use Provider-Aware Routing above for Codex, Claude Code, and Cursor.

Routing result is current. Deterministic analysis runs locally with no network wait.

Routing decision

Generic Security Agent is the primary routing fit

Recommendation only

security review, code review detected. 2 supporting profiles can add specialist review or implementation context.

Control notes

  • Routing hint only; no agent is executed or given repository access.
  • Review output, evidence, and merge readiness before trusted use.
  • Human security approval is required.

Routing summary

Detected security review, code review. Returned 3 deterministic AgentOS routing recommendations with no live execution.

security reviewcode review

85% confidence

Generic Security Agent

Primary route

ForgeLayer is not executing this agent or giving it repo access.

Why this agent

  • Matches detected work: security review, code review.
  • Generic Security Agent is strongest for security review and auth changes.

Cautions

  • AgentOS v0 returns routing hints only; no agent is executed.
  • Do not route secrets or private credentials to this agent.

Human checks

  • Confirm scope, repo policy, tests, and merge readiness before acting.
  • Generic Platform Guidance: Human approval required before using this agent for repository changes.
  • Security-sensitive work requires human security review.

60% confidence

Generic Review Agent

Supporting route

ForgeLayer is not executing this agent or giving it repo access.

Why this agent

  • Matches detected work: code review.
  • Generic Review Agent is strongest for code review and merge risk review.

Cautions

  • AgentOS v0 returns routing hints only; no agent is executed.
  • Do not route secrets or private credentials to this agent.

Human checks

  • Confirm scope, repo policy, tests, and merge readiness before acting.
  • Security-sensitive work requires human security review.

45% confidence

GitHub Copilot

Supporting route

ForgeLayer is not executing this agent or giving it repo access.

Why this agent

  • Matches detected work: code review.
  • GitHub Copilot is strongest for small code edits and test generation.

Cautions

  • AgentOS v0 returns routing hints only; no agent is executed.
  • Human review is required before code changes are merged.
  • Do not route secrets or private credentials to this agent.

Human checks

  • Confirm scope, repo policy, tests, and merge readiness before acting.
  • Generic Platform Guidance: Human approval required before using this agent for repository changes.
  • Security-sensitive work requires human security review.

Task-to-Agent Workflow

Draft routing plan

ForgeLayer is only creating a workflow plan. No agent is executed, no repo access is granted, and nothing is persisted. Draft workflow only.

draft workflow only

Primary route

Generic Security Agent

Approval checklist

  • Confirm task scope, repo policy, and acceptance criteria before routing.
  • Review PromptForge and RepoBrain signals before trusting agent output.
  • Security-sensitive work requires explicit human security review.

Routing risks

  • This is a draft routing plan only; no agent has executed work.
  • Security or permission changes can create merge risk if reviewed only by an agent.

Blocked actions

  • Execute an agent automatically.
  • Grant repository access automatically.
  • Open or merge a PR automatically.
  • Run shell commands automatically.
  • Change GitHub posting settings.

Next steps

  • Assign security review as a required human checkpoint.
  • Review Generic Security Agent as the proposed primary agent profile.
  • Confirm the approval checklist with a human reviewer.
  • Use MergeGuard after code exists to verify risk, policy checks, and merge readiness.

Agent Work Records

Draft AI work record

Agent Work Records document what an AI agent was asked to do, what evidence exists, what risks were found, and whether human approval is still required. v0 does not execute or persist agent work. Draft work record only.

persisted: false

Use this form to document what an AI agent was asked to do, what files it may affect, what evidence exists, what risks remain, and whether human approval is still missing.

One path per line.

One evidence item per line.

One risk per line.

One approval per line. Leave empty to show not_ready.

Draft generation only. No agent runs and no record is persisted.

Record summary

Review an auth middleware change before merge

Merge readiness: not_ready

Evidence

  • Tests not run yet
  • Manual security review required

Risks

  • Auth/session behavior may affect protected routes

Approvals

  • No approvals recorded yet.

Blocked actions

  • Execute an agent automatically.
  • Auto-merge or approve code automatically.
  • Post to GitHub automatically.
  • Run commands automatically.
  • Grant repository access automatically.
  • Share secrets or credentials.

Generic Security Agent work record is proposed. Detected work: security_review, code_review. Evidence: 2. Risks: 1. Approvals: 0. Human review required: yes. Merge readiness: not_ready.

Ledger preview

Review an auth middleware change before merge

persisted: false

Derived AI Work Ledger entry only. No persistence, no live agent execution, and no autonomous workflow.

Agent Comparison · legacy deterministic profiles

Compare historical profile controls

Compare agents by fit, control risk, autonomy, and required human checks. ForgeLayer does not execute agents. Comparison only.

Control risk is about oversight, not agent quality.

persisted: false
Agents optional

Leave all unchecked to compare all seeded agents.

Comparison only. Scores are deterministic control hints, not performance guarantees.

Comparison summary

Generic Security Agent

Routing hint only

Routing hint only. ForgeLayer is not executing this agent or giving it repo access.

Generic Security Agent is the strongest fit for security review work. Generic Review Agent is the safer control choice. Compare control risk before routing any real work.

Tradeoffs

  • Higher autonomy can speed up planning or implementation, but it increases approval and audit needs.
  • Lower control risk usually means safer review-only use, but less implementation capability.
  • Generic Security Agent fits the task better, while Generic Review Agent has stronger safety posture.
  • Devin has the highest control risk and needs the strictest gates.

Required human checks

  • Confirm task scope and repo policy before routing.
  • Review agent output before use, merge, deploy, or posting.
  • Security review requires human security signoff.
  • High control-risk agents require limited permissions and audit notes.
  • Code changes, commands, and PR creation require explicit approval.
  • Never provide secrets, tokens, private keys, or credentials.

ForgeLayer

Generic Review Agent

low control risk

Fit reasons

  • Task language matches this agent's best-fit use cases.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Do not provide secrets or credentials.

ForgeLayer

Generic Security Agent

medium control risk

Fit reasons

  • Supports security review work.
  • Task language matches this agent's best-fit use cases.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Do not provide secrets or credentials.

ForgeLayer

Generic Prompt Engineer Agent

low control risk

Fit reasons

  • General comparison baseline.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Do not provide secrets or credentials.

GitHub

GitHub Copilot

low control risk

Fit reasons

  • General comparison baseline.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Code modification increases review and merge-control needs.

Anthropic

Claude Code

medium control risk

Fit reasons

  • Task language matches this agent's best-fit use cases.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Code modification increases review and merge-control needs.

OpenAI

Codex

medium control risk

Fit reasons

  • General comparison baseline.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Code modification increases review and merge-control needs.

Cursor

Cursor

medium control risk

Fit reasons

  • General comparison baseline.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Code modification increases review and merge-control needs.

Cognition

Devin

high control risk

Fit reasons

  • General comparison baseline.

Cautions

  • Task language overlaps with use cases this agent should avoid.
  • Requires human approval before trusted use.
  • Code modification increases review and merge-control needs.

Control principles

Authority stays with the software team

AgentOS can recommend and document. It cannot grant access, execute work, approve output, or make repository decisions.

Control 01

Recommendation only: no agent is executed or contacted.

Control 02

Draft workflow only: plans do not grant repository or tool access.

Control 03

Draft Work Record only: agent records and Ledger previews are not persisted.

Control 04

Comparison only: scores describe fit and required oversight, not guaranteed quality or speed.

Control 05

Human approval is required before code, commands, PR creation, posting, merge, or production use.

Control 06

Secrets, tokens, private keys, credentials, and environment values must not be shared with agents.

Legacy deterministic profile registry

Historical and future agent profiles

Not current workspace routing

Low Control Risk

Review-only or developer-in-the-loop suggestions. Still review before use.

Medium Control Risk

Can affect code, tests, repo structure, or PR decisions. Generic Platform Guidance: Human approval required before merge.

High Control Risk

More autonomous or broader control. Requires strict approval gates, limited permissions, and audit logs.

OpenAI

Codex

medium control risk

General coding agent suited for scoped implementation, refactors, tests, and repo analysis.

Risk = required oversight, not agent quality.

Best for

  • scoped bug fixes
  • feature build tasks
  • test generation

Avoid for

  • unbounded autonomous execution
  • secret handling

Anthropic

Claude Code

medium control risk

Coding assistant suited for careful reasoning, refactors, documentation, and review-oriented edits.

Risk = required oversight, not agent quality.

Best for

  • refactors
  • documentation
  • planning

Avoid for

  • unreviewed production migrations
  • secret-dependent work

Cursor

Cursor

medium control risk

IDE-native coding assistant for interactive implementation and local developer workflows.

Risk = required oversight, not agent quality.

Best for

  • small features
  • bug fixes
  • refactors

Avoid for

  • unreviewed security changes
  • long autonomous tasks

GitHub

GitHub Copilot

low control risk

Inline coding assistant for localized suggestions, tests, docs, and small implementation tasks.

Risk = required oversight, not agent quality.

Best for

  • small code edits
  • test generation
  • documentation

Avoid for

  • large migrations
  • security-sensitive rewrites

Cognition

Devin

high control risk

Autonomous-style software agent category for larger tasks that need strict human controls.

Risk = required oversight, not agent quality.

Best for

  • planned feature work
  • bug investigations
  • multi-step repo analysis

Avoid for

  • security-sensitive changes without approval
  • secret access

ForgeLayer

Generic Review Agent

low control risk

Read-only review persona for risk, merge readiness, and policy-aware code review.

Risk = required oversight, not agent quality.

Best for

  • code review
  • merge risk review
  • repo analysis

Avoid for

  • code modification
  • running commands

ForgeLayer

Generic Security Agent

medium control risk

Security review persona for auth, permissions, secrets, sensitive paths, and policy violations.

Risk = required oversight, not agent quality.

Best for

  • security review
  • auth changes
  • permissions changes

Avoid for

  • code execution
  • secret access

ForgeLayer

Generic Prompt Engineer Agent

low control risk

Prompt review persona for improving task prompts before coding agents generate changes.

Risk = required oversight, not agent quality.

Best for

  • prompt engineering
  • planning
  • documentation

Avoid for

  • code modification
  • command execution