Skip to content

How the ecosystem fits

The five repositories form one runtime. Each owns one kind of authority, and Agent WebUI presents those capabilities without duplicating them.

Knuckles-Team runtime architecture showing Agent WebUI, GraphOS, agent-utilities, epistemic-graph, and agent-connector-sdk in their owned positions.

Component ownership

Agent WebUI

The operator experience: browser presentation, local interaction state, accessible navigation, and a same-origin server boundary.

Documentation →

GraphOS

The public runtime gateway: MCP, REST, A2A, identity, policy, fleet supervision, and WebUI composition.

Documentation →

agent-utilities

The agent control plane: agent decisions, orchestration, workflows, evaluation, and skills.

Documentation →

epistemic-graph

The durable multimodal engine: graph, SQL, RDF, vector, time, blobs, reasoning, provenance, and transactions.

Documentation →

agent-connector-sdk

The governed source boundary: typed discovery, reads, ingestion records, server registration, and write-back contracts.

Documentation →

One request, one owner at every step

  1. Present

    Agent WebUI collects the operator's intent and renders typed events and results.

  2. Admit

    GraphOS verifies identity, applies runtime policy, and selects the owned service boundary.

  3. Act

    agent-utilities runs agent behavior; connector services perform authorized external effects.

  4. Commit

    epistemic-graph validates and records durable state, evidence, provenance, and receipts.

What the WebUI consumes

Surface Authority WebUI responsibility
Chat, sessions, goals, workflows, prompts, skills agent-utilities through GraphOS Render state, collect input, and surface approvals
Graph, RDF, schema, objects, tables, code, documents, memories epistemic-graph through GraphOS Provide guided and expert exploration without storing a second truth
MCP Apps, connector catalogs, source operations GraphOS and connector services Discover typed capabilities and render governed invocation results
Identity, roles, request policy, fleet health GraphOS Apply the server decision to navigation and interaction controls

The browser never receives a GraphOS service credential. The WebUI FastAPI host performs same-origin delegation using the verified request context injected by GraphOS, and every downstream component remains authoritative only for its own contract.

Shared language

Use the ecosystem glossary for the canonical meaning of GraphOS, the agent control plane, the knowledge engine, connector boundary, MCP, A2A, OWL, RDF, SHACL, and UQL.