Solutions

Production architecture for autonomous work

ForgeCrux turns agent experiments into operable systems: identity, budgets, tool rights, memory isolation, human-in-the-loop, traces, and evaluation—while every model call and MCP invocation still passes the AI and MCP gateways.

N-hop

bounded A2A

Hard limits on delegation depth to stop runaway swarms.

step

trace granularity

Every thought, model call, and tool result is replayable.

HITL

on high-risk verbs

Payments, deletes, and external send require approval.

CI

eval before prod

Golden tasks block uncertified agent versions.

Enterprise architecture

Production agentic topology

Business events become governed work: supervisor and specialists call models and tools only through ForgeCrux gateways.

Production agentic topology

ForgeCruxProbing Deeper, Stacking Precision

Demand

ITSM / CRM cases

ServiceNow, Salesforce

Chat & APIs

Employee and customer

Schedulers

Batch and cron agents

Agent Gateway fabric

Supervisor

Plan, hop limits, budget

Specialists

Domain skills, A2A

HITL & kill switch

High-risk verbs

Capability + SoR

AI Gateway

Models + guardrails

MCP + API Gateways

Tools and systems

Systems of record

SAP, data, comms

ForgeCrux · confidential architecture

Agentic AI reference architecture

End-to-end workflow from product intent to production systems — roles, fabric, gateways, MCP, and backends.

ForgeCruxProbing Deeper, Stacking Precision

Roles & interfaces

Business intent, architecture, and delivery surfaces.

Product owner

Business logic & outcomes

Architect

Blueprint & controls

Developer

Code, commit, certify

Cursor

IDE / Codex

CLI

Web apps

Agent fabric

Intelligence, traffic, identity, and specialized workers.

ForgeCrux AI Gateway

Routing · RBAC · guardrails · spend · traces

Orchestration engine

Multi-step tasks & decomposition

Agent catalog

Governed inventory of specialists

Agent builder

Low-code + GitOps definitions

Doc agent

Test agent

Code agent

Infra agent

LLM pool

GCP · AWS · Azure · self-hosted

Agent & MCP plane

Secure interoperability from agents to the real world.

ForgeCrux Agent Gateway

Identity · A2A · HITL · Kubernetes runtime

Contextual
interoperability

ForgeCrux MCP Gateway

Discovery · vault · tool RBAC · audit

Secure
integration

API layer

Salesforce · SAP · ServiceNow · custom APIs

Backends & infrastructure

Systems of record, delivery, and clouds.

Databases

Vector · SQL · NoSQL

Legacy systems

SOAP · mainframe · ESB

CI / CD

GitOps · tests · evals

Clouds

AWS · Azure · GCP · private

Control path: Policy · Identity · Observability across every hop

Data path: Channel → Agent Gateway → AI Gateway → MCP → API → SoR

Autonomy with a contract

Agents act only inside identity, budget, and tool scopes you define.

Composable enterprise skills

APIs, models, and MCP tools are capabilities—never raw credentials inside the agent.

Operable like microservices

Versions, traces, SLOs, and incident response apply to agents the same way they apply to APIs.

Key Capabilities

Business-process agents with named owners and SLAs
Supervisor, specialist, and swarm topologies
Authenticated agent-to-agent messaging
Least-privilege tool packs via MCP Gateway
Model access only via AI Gateway policies
Long-running workflows with resume and compensation
HITL for irreversible or high-value actions
Memory isolation, TTL, and redaction
Step-level traces and DAG replay
Simulation, red-team, and quality gates
Token, dollar, and tool-call budgets per run
Kill switch, pause, and drain

Complete Agentic AI capabilities

Everything required to publish, secure, mediate, observe, and operate agentic ai workloads on ForgeCrux.

Enterprise uses

Where autonomous work becomes an operable production system.

  • Operations and ITSM: case-driven agents with named owners and SLAs
  • Customer support: bounded tools, HITL on refunds and account changes
  • Finance and procurement: hop limits, budgets, and compensation on failure
  • Engineering: code/test/infra specialists behind Agent Gateway identity
  • Platform teams: same GitOps, traces, and on-call as microservices
  • Risk: kill switch, pause, drain, and eval gates before promotion

Installation & deployment

Runtime beside the gateways agents are allowed to call.

  • Agent Gateway on Kubernetes with identity, A2A, and HITL queues
  • AI and MCP gateways required in-path—no direct provider or tool keys
  • SaaS, hybrid, or self-hosted control plane for catalog and policy
  • Memory plane isolation per agent version and environment
  • Multi-region runtimes with fair-share scheduling
  • Helm / Terraform promotion of agent definitions

Setup & onboarding

Pilot one process, then clone the topology.

  • Pick a bounded workflow with a clear system of record
  • Register the agent: owner, risk tier, credentials, budget
  • Publish tool packs only through MCP Gateway virtual catalogs
  • Route models only through AI Gateway policies
  • Turn on step-level traces and HITL for side effects
  • CI evals on golden tasks before production versions

Security & control

Autonomy only inside identity, budget, and tool scope.

  • Unique agent identity; no anonymous bots
  • N-hop and recursion limits to stop runaway swarms
  • HITL on payments, deletes, and external send
  • Memory TTL, isolation, and redaction
  • Token, dollar, and tool-call budgets per run
  • Immutable DAG replay for incident response

Orchestration patterns

Enterprise shapes for multi-agent work.

  • Supervisor–specialist, sequential, and graph workflows
  • Compensation and saga-style undo on failure
  • Idempotent writes to systems of record
  • Deadline, hop, and recursion limits
  • Fair-share scheduling across business units
  • Multi-region active-active runtimes

Risk and operations

Keep agents inside SLO, budget, and policy.

  • Per-run token, dollar, and tool budgets
  • Loop detection and automatic pause
  • Canary versions and shadow tasks
  • On-call dashboards and kill switches
  • Quality evals tied to business KPIs
  • Cost showback to the owning domain

Data flows

How requests, policies, and telemetry move through ForgeCrux in this solution.

Happy-path task flow

A support or ops task completing under policy.

1

Intake

Ticket payload

2

Supervisor

Plan steps

3

Model

AI Gateway

4

Tool

MCP / API

5

Write-back

SoR + trace

High-risk action flow

When policy requires a human before side effects.

1

Agent intent

Proposed action

2

Risk engine

Tier + budget

3

HITL queue

Owner approve

4

Execute

Scoped tool call

5

Evidence

Who / why / what

How teams run Agentic AI on ForgeCrux

Pilot one process

Pick a bounded workflow with a clear system of record and owner.

Identity first

No production agent without registry entry, risk tier, and credentials.

Tools through gateways

Ban direct SaaS keys inside agent code.

Trace from day one

If you cannot replay a run, it is not ready.

HITL the side effects

Start with suggest-then-apply; automate after evals pass.

Scale the pattern

Clone the supervisor topology to the next domain, not a new stack.

Ready to get started with Agentic AI?

Talk to our team about deploying Agentic AI in your enterprise environment.