Skip to main content

Key concepts

AlphaAgent is an operating system for agents that mirrors how a high-performing team works: a specialist grounded on your doctrines and policies that run at scale privately in your AWS account. Each section links to the page that documents the screen in full.

The whole system in one picture​

Your Organisation account deploys a Studio into each account you register, one fresh account per deployment. Each deployment heartbeats and meters to the AlphaAgent Console (drawn for one deployment only). An application reaches a governed deployment through its REST API. Libraries carry resources between deployments. Your Entra ID tenant signs people in to both consoles.

Organisation​

Your Organisation is your AlphaAgent Organisations install: one per company, in its own AWS account, at a hostname you choose. It holds the fleet, registered accounts, the identity provider, users and roles, Libraries, API keys, Fleet Configuration Templates, Update Manager rules and the audit log. See The console: layout and roles.

Deployment: standard or governed​

A deployment is one Studio in one registered AWS account, created from the deployment wizard, where you choose once and for life between Standard (personal resources; sharing goes through Libraries) and Governed (everyone assigned works on the same resources and files; only governed deployments offer programmatic access). See Deploy your first Studio and Working in a governed deployment.

Release, Fleet Configuration Template and Update Manager​

A release is a Studio version mirrored into your Organisation. A Fleet Configuration Template is a versioned set of deployment settings you deploy from or point an Update Manager rule at; the rule keeps its listed deployments on the template's release, on a schedule inside a maintenance window. See Fleet configurations and Update Manager.

Licence, heartbeat and metering​

A licence key authorises one Studio deployment: created in the AlphaAgent Console, shown once, pasted into the wizard. Studio then heartbeats every 5 minutes. Metering receipts carry token counts and who caused them, never content, and are billed through AWS Marketplace. A hold shows a "Billing alert:" banner; a block shows "Service halted" until the next good heartbeat. See Console: licences, usage and billing and Banners you may see.

Identity and roles​

Your Entra ID tenant is used twice: a SAML enterprise application you create during the install signs administrators into the Organisations console; an application the Organisation creates per Studio signs its users in, once your tenant is connected. Roles live in the Organisations console (Owner, Operator and Viewer tiers plus built-in roles per deployment or Library); Library membership (Contributor or Reader) is a separate grant; Studio has no roles. See Users, groups and roles and Identity and access.

Agent and agent version​

An agent is a specialist: named instructions grounded on your documents, data and systems. The prompt is saved as written or optimised, and every change creates a new version. Configure opens the Agent Map to pin connectors, one knowledge graph version and one environment; Save & Activate applies it. A fresh Studio has no agents: create one before Chat. See Agents.

Knowledge graph (AMPG) and versions​

A knowledge graph, called an AMPG (Augmented Multi Resolution Property Graph) in Studio, is built from your documents. Every build is a version: Ready, Building, Failed or Cancelled. An agent pins one Ready version until you move it, and a graph cannot be deleted while an agent is pinned to it. See Knowledge graphs.

Connector​

A connector gives agents a tool for one external system: a SQL Database (PostgreSQL or MySQL), Snowflake, a REST API described by an OpenAPI document, an MCP Server, or an AWS account reached by assuming a role. Test Connection checks the target before you save, and every save is an immutable version that agents pin. SQL connectors are read-only at run time. See Data connectors.

Environment​

An environment is a sandboxed Linux container where an agent runs Python and shell tools. Create it from the prebuilt image ("AlphaAgent Python") or a custom image, set memory, timeout and workspace storage, and provision it. An agent pins at most one. See Execution environments.

Workflow, run, schedule and approval​

A workflow is a board of steps built from five node types: Task, Handoff, Conditional, AMPG update and Redact PII. Saving creates a version; activate one, then Run Now or Run on Schedule. A step that requires approval parks the run as Needs you until someone approves it or sends it back. To turn a chat into a workflow, ask the agent; there is no button. See Workflows.

Library, share, pull and Update my copy​

A Library is typed: it holds one kind of resource, with Contributors (share and pull) and Readers (pull only). Share publishes a version; Download vN fetches a first copy and Update my copy to vN adds the pulled version to the copy you hold. A workflow travels with its dependencies and arrives as Draft · ready to activate with those dependencies active. See Libraries and sharing.

Inbox​

The Inbox is the Studio dock tile whose badge counts what is running and what needs you, filtered as All, Needs you, Running or Done. It lists runs, approvals and publish cards for new knowledge-graph versions. See Inbox.

Workspace files​

Every user has a workspace: files uploaded in chat, files an agent writes, and a run's inputs and outputs. The Files tab scopes them as "This conversation", "All my files" and, in a governed deployment, "Everyone's files". See Files, previews and approvals.

Governor​

The Governor is a separate model call that oversees each step of a run. Between tool calls it judges whether the agent is still on the step's objective and, if not, notes or steers. It never interrupts a tool call or ends a step; after three steers on one step it only comments. See The Governor.

PII redaction​

PII redaction has a deployment-wide default: Off on a standard deployment, Mask on a governed one, changeable through a Fleet Configuration Template. A workflow can tighten it but never loosen it (Off, Mask, Hash or Drop rows), and the API serves a run's outputs only once redaction is complete. See PII redaction.

API key​

An API key lets one of your systems run workflows on one governed deployment. An Organisations administrator mints it on the Programmatic Access page, bound to that deployment and the workflows it may use. Two credentials are shown once: the key (Authorization: Bearer <key>) and the key external id (the X-AlphaAgent-Key-External-Id header), the second factor. See API keys.