Surfaces
How work reaches an agent
Four ways in. One contract underneath.
A Surface is the boundary a person or a system engages an agent through. Cantora registers it per Environment, so Test and Live never share one.
All surfacesLast 24 hours12 runs
Customer operations Agent
run_0219 · Slack thread- Agent Release
- Version 18
- Identity
- tenant_42
- Evidence
- Retained
Request acceptedIdentity, scope, and Agent Release resolved
That is why a second surface is a registration rather than a second product. The agent's behavior is an Agent Version, and the Surface is where its answer is delivered.
Delivery is its own durable act
| Property | What it means |
|---|---|
| Registered per Environment | Test and Live use different Surface registrations, never a shared one |
| Identity is bound, not inferred | An inbound external identity maps to a Tenant and a User before any work starts |
| Delivery is separate from the answer | The Turn becomes durable first, then delivery runs with its own identity and idempotency, so a delivery failure never silently loses the work |
| Surfaces receive Cantora events | Never raw provider events, and never hidden reasoning content |
| Pinned behavior | A Run resolves its Agent Release once, so a release during a busy hour cannot change an answer already in flight |
See the systems an agent reads from, or how it computes an answer.
Get started
Scope your first agent
Bring one bounded workflow and its systems. Check readiness, or describe it now.