What is an execution layer for AI agents?
How an agent execution layer differs from authentication, authorization, orchestration and an LLM gateway, with Anlyon's supported paths, receipt grades and shared limits.
An AI agent execution layer receives a requested operation, enforces the controls on that path, makes the external call and records its outcome. An authorization layer answers whether the operation is allowed. Execution also handles what happens after permission: credentials, dispatch, duplicate requests and uncertain results.
In Anlyon's hosted path, the agent names an action and supplies input. Anlyon holds the provider credential and makes the call. The agent holds an Anlyon credential with narrow permissions. Your reasoning loop stays in your own runtime.
Which layer does which job?
| Layer | Question it answers | Example responsibility |
|---|---|---|
| Authentication | Who is asking? | Identify a user, agent or API key |
| Authorization | May this caller do this? | Check action, environment and input against policy |
| Orchestration | What happens next? | Persist a graph, pause a run, select the next tool |
| LLM gateway | How does this model request run? | Route model calls and account for model usage |
| Action execution | What request actually reaches the provider? | Resolve a credential, dispatch a fixed operation, retain its result |
| Outcome verification | Did the intended change happen? | Read the result back from the provider |
These responsibilities can coexist in one product. Compare the actual execution path, not just the category name.
Four Anlyon paths, four different promises
| Path | Who makes the external call? | What the result establishes |
|---|---|---|
Local approvals.gate() | Your function, with your credentials | An approval decision and its record |
| Hosted action with no declaration | Anlyon, using a configured HTTP template | The destination's HTTP response, or an unknown outcome |
| Declared action | Anlyon, using your template plus impact, verify or governed | A graded receipt. confirmed means your own verify rule matched |
| Adapter-backed action | Anlyon, using an operation-specific adapter | A graded receipt. confirmed means the adapter read the provider's own record |
The last two rows are governed actions. They draw from shared limits across every agent, session and key in an environment, bind each approval to the exact request, and return a graded receipt.
There are three adapters:
stripe.refundfor Stripe refunds.github.file_updatefor one existing text file on a configured branch that is not the default branch.resend.email_sendfor one email from a designated sending domain, counted inemails.
A declared action covers any HTTPS API you can describe as an action. impact says how much one call changes, in money or a unit you declare. verify is a GET on the action's own host that reads the result back. governed: true opts in without either. For an API you declare, you write what the action counts, and Anlyon enforces it before dispatch.
See the adapter contract and the limits guide for a code sample.
What does “the agent never holds the key” mean?
It means the provider secret stored in Anlyon's vault is absent from the agent runtime. The agent holds an Anlyon key scoped to the actions it may invoke. Remove direct provider credentials and alternate write paths from that runtime, so every write goes through the hosted controls.
Limit what the agent's Anlyon key can invoke, keep administrative permissions separate, and use policies, approvals and impact limits on the actions that matter. Credential custody keeps the provider secret out of reach of a prompt-injected agent.
What a receipt tells you
A 2xx response can mean a provider accepted work, not that it completed the business operation. Every governed action returns a receipt with a grade that says how the outcome was established.
| Grade | What it means |
|---|---|
confirmed | A read-back matched, or an adapter read the provider's own record of the operation |
acknowledged | The provider accepted the request with a 2xx and nothing read it back. An operator's manual resolution to succeeded also grades here |
unknown | No usable response. Anlyon does not send the request again |
failed | The provider rejected the request, or the request never left Anlyon |
refused | Anlyon stopped the call at dispatch, for example on a changed request or an exhausted limit |
denied | The approval was denied |
Read each grade for exactly what it says:
confirmedis a matched read-back. A Resend receipt is confirmed when Resend's own record returns the email on read-back. For a declared action it means your own verify rule matched.unknownis notfailed. A lost response is recorded as unknown and is not sent again. It stays unknown until a read-back finds the operation, a replay inside the provider's idempotency window returns the original response, or an operator settles it.refusedcovers a changed request. A changed request sent with a reviewed preview is refused. A change at the provider after review is a different case. On GitHub the write is conditional on the reviewed blob SHA, and a stale write gradesfailed.
A receipt is a database record with provider evidence. A manually resolved outcome is labelled manual. An action with no declaration retains the HTTP result. After a lost response, inspect the record and reconcile it before any new write. Read outcomes and receipts and idempotency.
When Anlyon fits
Evaluate Anlyon when you can route a bounded set of consequential calls through hosted actions and want a shared limit, a bound approval and a graded receipt on those calls. The tool-selection guide compares it with integration platforms, AWS Bedrock AgentCore Policy and framework interrupts.
Early Beta Access is free, with no credit card. See current terms and pricing.
Frequently asked questions
What does production execution for AI agents mean?
It means turning an agent's requested operation into a call against a real system, with controls and an outcome record. Anlyon uses the phrase for hosted action execution. The agent names an action, and Anlyon makes the call.
What does an execution receipt tell you about a refund?
A receipt carries a grade that says how the outcome was established. Confirmed means a read-back matched. Acknowledged means the provider accepted the request and nothing read it back. A receipt is a database record with provider evidence, and a manual resolution is labelled separately from provider verification.
