{ "query": "refund policy" }Agents versioned like software.
Governed like infrastructure.
Agorch is the control plane for your agent ecosystem: compose multi‑Agent workflows, test them like software, publish immutable releases—and govern context, credentials and approvals from one place.
illustrative run
Multi-Agent graphs with approvals and loops
Save runs as tests, rerun before publishing
Gated, sealed and immutable
Resolved at dispatch, never in history
Multi-Agent workflows
on a canvas.
Deliver one focused Agent, then compose a graph when the job needs one—agents, actions, approvals, checks and loops as first-class nodes. After a run, replay lights up the exact path it took.
triageagentkb.searchactioncrm.readactionrefundsapprovalescalationagentresolveragentreplyend
illustrative canvas · replay lights the path r_8f42 took; the review branch stays dark
Agents you can test.
Like software.
A run you liked becomes a repeatable test: expected path, required tools, forbidden calls, output assertions. Releases are blocked until the evidence is green and current.
refund flow4 checkspassangry customer tone1 warningwarnno tools bound3 checkspassescalation handoffevidence stale · rerunstale
Run a behavior against the draft or the published version.
Review the executed path, tools and outputs.
Save only stable behavior as a test—status, path, tools and outputs become expectations.
Rerun before publishing. Evidence goes stale when the Agent changes, and the plane knows.
One release.
Every Agent current.
Releases are gated: sealed test evidence, policy evaluation, dependency lock. Publish an immutable version and every runtime that binds it moves to it—no drift, no copy-pasted prompts.
agents/support-triage v42published- prod · websupport-triagev42
- prod · slacksupport-triagev42
- prod · apisupport-triagev42
- stagingsupport-triagev42
- partner portalsupport-triagev42
- your clientsupport-triagev42
- +3 more runtimesv42
illustrative release · every runtime current on v42
Built like infrastructure.
Every layer stays explicit: what an Agent can call, who approves, where credentials resolve and what the trace keeps.
An explicit capability surface
An Agent sees only what you bound—tools from MCP servers and HTTP endpoints, with discovery built in. Nothing implicit reaches the engine.
crm.readmcp:hubspotboundkb.searchmcp:notionboundhttp.fetchendpoint:api.internalboundtickets.writemcp:zendesknot boundCentralized approvals
Sensitive actions pause for approval—decided per topic, enforced everywhere.
refundsauto · policypaymentsreviewpii-exportdeniedA signed catalog
Every package passed publisher review and signing—evidence before install.
signature verifiedpermissions 2 scopesauth oauth2risk tier mediumDispatch-time credentials
Configured providers resolve at the moment of dispatch. Secrets never enter the execution history.
hubspot-oauthresolved at dispatchtoken ••••••••never written to historyOrdered trace & replay
Every transition is persisted, so the graph can be replayed and audited.
01 kb.search212ms02 crm.read98msreplay r_8f42exact orderRuns in your client
Execution can return to your authenticated client—provider access stays yours.
handler localadapter mcpprovider access yoursRun your agent ecosystem
like a product.
One repository, one published version, every Agent current—approvals, context and credentials governed from a single plane.
See the product