Skip to content
Private preview The Kodeus SDK and demo app are not public yet. Get early access
Kodeus
Glossary

Glossary

Standalone definitions for the terms the rest of the site uses in passing. Each one is the meaning we use when we write about the runtime.

Per-tenant runtime

A per-tenant runtime is an isolated execution environment for one organization, so its workloads, database, secrets and memory stay separate from every other tenant.

Kodeus creates, runs and retires workloads inside that boundary. On Kodeus Cloud the database is ours, per tenant. In your VPC or an airgapped deployment the database is yours. Either way, one tenant’s run does not read another’s secrets. Isolation is part of the runtime, not a later hardening pass.

AI agent infrastructure and enterprise describe where that boundary lives.

Agent identity

Agent identity is the authenticated identity on a request, so an action is recorded as taken for a specific person rather than a shared service account.

The runtime derives it from a verified credential. Session and per-user memory follow that identity. A second user cannot reach the first user’s connected accounts, and Kodeus tests that separation with a six-part adversarial isolation suite. If the trace cannot name who the turn was for, the identity model has failed.

See AI agent governance for how identity feeds approval and audit.

Guardrail policy

A guardrail policy is a rule, declared in the spec, that the runtime evaluates at a checkpoint and can use to monitor, redact, block, escalate, abort or hold an action before the tool runs.

Kodeus ships 45 rules across six policy families, checked at five checkpoints. Fail closed means no verdict, no action: the turn goes to a person. A blocked call never reaches the tool, and the refusal is an event in the same trace as a successful call. Policy is not a sentence in the prompt. The model can still try the call. The runtime is what refuses it.

The full account is AI agent governance. The record of the refusal is AI agent observability.

MCP server

An MCP server is a server that exposes tools through the Model Context Protocol. The agent calls an action, the server performs it, and the result comes back in a shape the runtime can record.

Kodeus attaches an MCP server in one command and still applies policy before the call. An agent can itself be exposed as an MCP server. A wide server with a shared key looks convenient and fails the moment a second user arrives, because the credential and the identity have to stay per user. The checklist for choosing one is on the best MCP servers page. That page is criteria, not a ranked directory of vendors.

Read best MCP servers.

Operating layer

The operating layer is the runtime a product’s agent runs on: identity, credentials, memory, guardrails and a record of what it did, for every user.

Kodeus drafts the application and runs it. You describe the agent in kodeus.yaml, the Console or the SDK. The model should be replaceable. The operating layer should not be. The same policy engine runs locally, in your VPC, on Kodeus Cloud and airgapped.

Start at the platform.

Credential vault

A credential vault is encrypted storage for the accounts a user has connected, so the agent can act for that user without a shared secret in the environment.

Kodeus keeps three credential stores and encrypts them per user with AES-256-GCM, with rotation and revocation. Key lifecycle events appear in the trace. A shared environment variable is how a prototype becomes an incident: the second user inherits the first user’s access.

The control is listed on enterprise.

Dry run

A dry run is a turn where the agent plans the tool calls and executes nothing, so you can inspect what it intended before anything touches a real system.

It is the cheapest rehearsal. The plan shows up in the same kind of record as a live turn, including the calls a guardrail would have refused. Use it before you connect a tool that moves money, files a claim, or sends a message a customer will see.

How to read that record is on AI agent observability.

OpenTelemetry trace

An OpenTelemetry trace is the structured record of a turn: the tools called, the arguments, the results, the guardrail verdicts, the latency and the cost.

It is exported as OpenTelemetry, so it can land in the collector you already run. Approval records include the approver and the time. The point of the trace is that you do not reconstruct the day from application logs after something goes wrong. On Warren, the published example redacts the figures and still shows a daily loss limit holding an order.

The walkthrough is AI agent observability. Warren’s trace is on the Warren case study.

Frequently asked questions

What is a per-tenant runtime?

An isolated execution environment for one organization. Its workloads, database, secrets and memory do not cross into another tenant.

What is agent identity?

The authenticated identity on a request, so an action is recorded for a specific person rather than a shared service account.

What is a guardrail policy?

A rule in the spec that the runtime evaluates at a checkpoint. It can monitor, redact, block, escalate, abort or hold an action before the tool runs. No verdict means no action.

What is an MCP server?

A server that exposes tools through the Model Context Protocol. Kodeus attaches one in a single command and still applies policy before the call. An agent can also be exposed as an MCP server.

Is Kodeus an operating system?

No. Kodeus is the operating layer. It drafts the application and runs it, with identity, credentials, memory, guardrails and a record.

Can I bring an agent I already built in LangGraph or CrewAI?

No. Kodeus is not a host for an agent from another framework. The comparisons explain the difference. They are not a migration guide.

What does fail closed mean?

If policy does not return a verdict, the action does not run. The turn goes to a person.

What is a dry run?

The agent plans the turn and executes nothing, so you can inspect the intended tool calls before a real system is touched.

See a term in a real turn

Book a demo and we will trace one action, including a call a guardrail policy held.