Agents, workflows and approvals

Agents
An agent runs a bounded model-and-tool loop, capped at 20 steps, over a closed registry of typed tools.
- There's no shell and no unrestricted HTTP tool.
- Read tools run directly.
- Memory writes and external actions are staged for approval.
Workflows
A workflow is a validated DAG of steps: retrieve, generate, template, condition, extract, action, approval, and handoff.
- A
handoffsends a proposal to Zyntra and waits aswaiting_externaluntil Zyntra's approvers decide. See integrations. - Each completed step writes a durable checkpoint.
- A run is pinned to the workflow revision it started with.
Connectors & actions
An administrator registers typed enterprise APIs.
GETcalls run as reads. Don't register aGETendpoint that changes state.POSTcalls are always staged as an exact-action approval.- Model providers and actions share the same host allow-list and credential-reference rules.
Approvals
When a step needs a human, Nuvora records:
- the exact action and its arguments
- a sha256 fingerprint of the action
- the proposer and an expiry
Only a different authenticated person with the approver or admin role can decide. The console disables self-approval, and the API refuses it with 403 A different person must approve.
The decision checks the fingerprint and the job checkpoint atomically. The worker then resumes the job on its pinned revision. Automatic POST retries are intentionally absent.
