Concepts
Understanding AgentVisor™'s core concepts helps you build secure, reliable agents.
Overview
AgentVisor combines several technologies to provide secure agent execution:
- Sandbox Isolation: gVisor or container-based isolation
- Policy Enforcement: Fine-grained access control via Manetu PolicyEngine
- Durable Execution: Temporal workflows for reliability
- Transparent Proxying: HTTP requests intercepted and policy-checked
Key Concepts
Architecture
How the host and guest runtimes communicate, and the security boundaries between them.
Sandbox Modes
The three isolation levels: none, docker, and gvisor.
Transports
How external clients access AgentVisor agents through protocol-specific API endpoints (OpenAPI, MCP, A2A).
Gateways
How agents access external services (MCP servers, other agents) through policy-enforced, credential-protected connections.
Credential Brokering
How API keys are protected using symbolic tokens, ephemeral TLS termination, and host-side credential substitution.
HTTP Proxy
How HTTP requests are transparently proxied through the host runtime.
Egress Controls
How the policy gate and the always-on SSRF guard independently control which outbound destinations an agent can reach.
Temporal Integration
How Temporal provides durable execution and state management.
Policy Enforcement
How Manetu PolicyEngine controls access to resources.
Authorization Enrichment
How per-server Rego policies translate low-level gateway signals into semantic operation and resource identifiers before the policy engine evaluates them.
Checkpointing
How agent state is persisted and recovered.
Observability
OpenTelemetry tracing, Prometheus metrics, and trace context propagation.
Runtime Tracing
Syscall-level visibility into agent behavior via gVisor seccheck for security monitoring and debugging.
Payload Encryption
AES-256-GCM encryption for Temporal workflow data at rest.
See also the Reference section for config-key-level detail behind several of these concepts, including TLS Trust Configuration.
Design Principles
AgentVisor follows these design principles:
-
Security by Default
- Agents have no direct network access
- All external access requires policy approval
- Sandbox escape is prevented by container boundaries (and syscall interception in gVisor mode)
- Real credentials never enter the sandbox (credential brokering)
-
Transparent Compatibility
- Standard HTTP libraries work unmodified
- LangChain/LangGraph patterns work as-is
- No special client code required
-
Policy-Based Control
- Declarative policy definitions
- Fine-grained resource-level control
- Audit logging for compliance
-
Durability First
- Automatic checkpointing
- Recovery from failures
- Human-in-the-loop support