Two agents, one limit, one refused.
All guides
Architecture
Updated
5 min read
by Anlyon Team

What is an execution layer for AI agents?

How an agent execution layer differs from authentication, authorization, orchestration and an LLM gateway, with Anlyon's supported paths, receipt grades and shared limits.

executionauthorizationarchitecture

An AI agent execution layer receives a requested operation, enforces the controls on that path, makes the external call and records its outcome. An authorization layer answers whether the operation is allowed. Execution also handles what happens after permission: credentials, dispatch, duplicate requests and uncertain results.

In Anlyon's hosted path, the agent names an action and supplies input. Anlyon holds the provider credential and makes the call. The agent holds an Anlyon credential with narrow permissions. Your reasoning loop stays in your own runtime.

Which layer does which job?

LayerQuestion it answersExample responsibility
AuthenticationWho is asking?Identify a user, agent or API key
AuthorizationMay this caller do this?Check action, environment and input against policy
OrchestrationWhat happens next?Persist a graph, pause a run, select the next tool
LLM gatewayHow does this model request run?Route model calls and account for model usage
Action executionWhat request actually reaches the provider?Resolve a credential, dispatch a fixed operation, retain its result
Outcome verificationDid the intended change happen?Read the result back from the provider

These responsibilities can coexist in one product. Compare the actual execution path, not just the category name.

Four Anlyon paths, four different promises

PathWho makes the external call?What the result establishes
Local approvals.gate()Your function, with your credentialsAn approval decision and its record
Hosted action with no declarationAnlyon, using a configured HTTP templateThe destination's HTTP response, or an unknown outcome
Declared actionAnlyon, using your template plus impact, verify or governedA graded receipt. confirmed means your own verify rule matched
Adapter-backed actionAnlyon, using an operation-specific adapterA graded receipt. confirmed means the adapter read the provider's own record

The last two rows are governed actions. They draw from shared limits across every agent, session and key in an environment, bind each approval to the exact request, and return a graded receipt.

There are three adapters:

  • stripe.refund for Stripe refunds.
  • github.file_update for one existing text file on a configured branch that is not the default branch.
  • resend.email_send for one email from a designated sending domain, counted in emails.

A declared action covers any HTTPS API you can describe as an action. impact says how much one call changes, in money or a unit you declare. verify is a GET on the action's own host that reads the result back. governed: true opts in without either. For an API you declare, you write what the action counts, and Anlyon enforces it before dispatch.

See the adapter contract and the limits guide for a code sample.

What does “the agent never holds the key” mean?

It means the provider secret stored in Anlyon's vault is absent from the agent runtime. The agent holds an Anlyon key scoped to the actions it may invoke. Remove direct provider credentials and alternate write paths from that runtime, so every write goes through the hosted controls.

Limit what the agent's Anlyon key can invoke, keep administrative permissions separate, and use policies, approvals and impact limits on the actions that matter. Credential custody keeps the provider secret out of reach of a prompt-injected agent.

What a receipt tells you

A 2xx response can mean a provider accepted work, not that it completed the business operation. Every governed action returns a receipt with a grade that says how the outcome was established.

GradeWhat it means
confirmedA read-back matched, or an adapter read the provider's own record of the operation
acknowledgedThe provider accepted the request with a 2xx and nothing read it back. An operator's manual resolution to succeeded also grades here
unknownNo usable response. Anlyon does not send the request again
failedThe provider rejected the request, or the request never left Anlyon
refusedAnlyon stopped the call at dispatch, for example on a changed request or an exhausted limit
deniedThe approval was denied

Read each grade for exactly what it says:

  • confirmed is a matched read-back. A Resend receipt is confirmed when Resend's own record returns the email on read-back. For a declared action it means your own verify rule matched.
  • unknown is not failed. A lost response is recorded as unknown and is not sent again. It stays unknown until a read-back finds the operation, a replay inside the provider's idempotency window returns the original response, or an operator settles it.
  • refused covers a changed request. A changed request sent with a reviewed preview is refused. A change at the provider after review is a different case. On GitHub the write is conditional on the reviewed blob SHA, and a stale write grades failed.

A receipt is a database record with provider evidence. A manually resolved outcome is labelled manual. An action with no declaration retains the HTTP result. After a lost response, inspect the record and reconcile it before any new write. Read outcomes and receipts and idempotency.

When Anlyon fits

Evaluate Anlyon when you can route a bounded set of consequential calls through hosted actions and want a shared limit, a bound approval and a graded receipt on those calls. The tool-selection guide compares it with integration platforms, AWS Bedrock AgentCore Policy and framework interrupts.

Early Beta Access is free, with no credit card. See current terms and pricing.

Start with a test action · Execution documentation

Frequently asked questions

What does production execution for AI agents mean?

It means turning an agent's requested operation into a call against a real system, with controls and an outcome record. Anlyon uses the phrase for hosted action execution. The agent names an action, and Anlyon makes the call.

What does an execution receipt tell you about a refund?

A receipt carries a grade that says how the outcome was established. Confirmed means a read-back matched. Acknowledged means the provider accepted the request and nothing read it back. A receipt is a database record with provider evidence, and a manual resolution is labelled separately from provider verification.

Free tier, no credit card. One command if you use Claude or Cursor.

$ claude mcp add anlyon -- npx -y @anlyonhq/mcp-server