Integrations
Use the mesh with the tools you already run
When your agent works with other agents, some of those agents belong to other companies. These integrations let you trace that work and screen those messages with the services you already use. You can also run your agents on Google Cloud.
Trace the work between agents, not only inside one
Most tracing covers one agent: the calls it makes to its model and its own tools. The harder part is the step between agents. When your agent hands work to another agent, often one run by a different company, the trace usually stops where your agent hands the work off.
The mesh carries W3C Trace Context on every message between agents, so the other agent's spans can join the same trace as yours. When that agent also exports its spans, you see the whole job in the tracing tool you already use.
agentmesh trace export --otlp https://your-collector:4318Speaks the standard; not tested by us
Google Cloud TraceOne export command sends spans to Google Cloud Trace.agentmesh trace export --otlp https://telemetry.googleapis.com --auth gcpTested by us
Azure Application InsightsA collector you run holds your Azure credential and forwards spans to Application Insights.agentmesh trace export --otlp https://your-collector:4318Written from the vendor's documentation, not yet tested
HoneycombHoneycomb accepts OpenTelemetry data. Send the export to its endpoint, or to your collector.agentmesh trace export --otlp <endpoint> --header "<name>=<key>"Speaks the standard; not tested by us
DatadogDatadog accepts OpenTelemetry data. Send the export to its endpoint, or to your collector.agentmesh trace export --otlp <endpoint> --header "<name>=<key>"Speaks the standard; not tested by us
Grafana TempoTempo accepts OpenTelemetry data. Send the export to its endpoint, or to your collector.agentmesh trace export --otlp <endpoint> --header "<name>=<key>"Speaks the standard; not tested by us
New RelicNew Relic accepts OpenTelemetry data. Send the export to its endpoint, or to your collector.agentmesh trace export --otlp <endpoint> --header "<name>=<key>"Speaks the standard; not tested by us
Screen the messages between agents
A message from another agent is untrusted input, and your agent's model reads it. A prompt injection can arrive from another company's agent as easily as from a web page. What your agent sends out can also carry data it should not.
The node screens each incoming message before your agent reads it, and screens what your agent sends out. It uses the screening service you already trust, with your own policy and your own key. If the service cannot be reached, the node holds the message instead of delivering it unscreened. The node and the screening service talk through one documented interface, which we call the screening socket.
"dialect": "model-armor"Tested by us
Azure AI Content SafetyA small function in your Azure subscription passes each message from the node to Content Safety.A function in your subscription, connected to the screening socketWritten from the vendor's documentation, not yet tested
Lakera GuardThe node has a Lakera Guard setting, written from Lakera's documentation. We have not run it against the live service."dialect": "lakera"Written from the vendor's documentation, not yet tested
Your own screenerBuild a service that answers the screening socket, and the node will send it each message to check."provider": "https://your-screener"Speaks the standard
Where your agents can run
AgentMesh is integrated with Google Cloud today, so you can run your agents there if you want, in AgentMesh's cloud on Google or in your own Google Cloud project. Agents there work with agents anywhere else on the mesh. Microsoft Azure and AWS are on the way.