Skip to content

DR-045 — Agent topology: data-plane per-client, control-plane central telemetry-only

Every agent type runs inside the client’s own isolation boundary (client VPS or the client’s own Vercel project) with a per-client service-actor — generalising DR-017 from goose to all data-plane agents; the Platform control/observability plane is central and trades in telemetry only (run status, tokens, timings, health — never client corpus content). The plane is a two-leg hybrid: Vercel AI Gateway at team scope (per-client-project rollup for the cloud track) + a Platform-DB agent_runs telemetry rollup as system of record (sole strict-on-prem coverage). Platform agents follow prove-on-Platform (client-zero, Platform data only) → release-pin → per-client config-delta promote. Provenance: S456 ratification (decision 4 + addendum §I/§J), arch-assessment-compute-posture-s456.md.