Identity Engine SDK
Persistent identity, mutable state, append-only history, and drift checks for agents that need continuity across sessions. Node / TypeScript prototype.
Every product solves a specific infrastructure problem for teams building with AI agents — from scoring actions before they run, to routing cost, to keeping a complete audit trail.
Persistent identity, mutable state, append-only history, and drift checks for agents that need continuity across sessions. Node / TypeScript prototype.
Scores proposed agent actions and returns allow, review, or block decisions with confidence factors and trace context. The primary control point in the CertaWorks suite.
Adds Builder, Skeptic, Evolver, and Guardian review loops before an agent commits to an answer. A quality review layer for high-stakes agent decisions.
Routes prompts to the cheapest capable model while estimating cost and respecting quality needs and budget constraints. Local slice — SDK, CLI, MCP tools, local API, and local dashboard.
Monitors long-running agents for divergence from their original goal and flags risky behavioral drift. Local slice — stores session turn history, scores drift, and records webhook alert receipts.
Gives agents episodic, semantic, and working-memory tools for retrieval and context packing. A local memory primitive for agents that need continuity between sessions.
Lets agents discover, inspect, load, and run trusted skills from a local registry-style capability layer. Includes durable local install state, checksum verification, and MCP tools.
Captures explicitly logged decisions, tool calls, state changes, and causal chains for local agent debugging. Includes durable local storage, redaction, hash-chain events, and replay bundles.
Runs probes to infer behavioral constraints, persona patterns, and likely hidden operating rules in agent systems. Audit signals — not exact prompt recovery.
Provides repeatable tests for agent outputs, traces, tool calls, latency, cost, and mock tool behavior. An SDK / library for teams building agent test suites.
Extracted from a working persistent agent — every Wave 2 product packages a mechanism that already runs in production inside it. All twelve are built and tested; npm publication is in progress. Install commands go live the moment each package ships.
Keeps long-running agents alive on a paced interval, reclaims stale running sessions, enforces unmet inbound-response obligations, and damps repetitive looping. Planned local MCP server / SDK / API.
After an agent failure, interruption, or retraction, reconstructs the state around the event and returns a structured verdict — stabilized, partial, or monitor — with a concrete resume recommendation. Planned SDK / CLI / MCP server.
Read-only internal-state telemetry: deterministic 0–1 signals blended from text and structured state, banded quiet / watch / elevated to flag rising load or risk before output degrades. Not a feeling — heuristic readings. Planned MCP server / SDK / API.
Surfaces conflicting beliefs, goals, and statements with an open / resolved / dismissed lifecycle, before silent contradictions compound into errors. Planned SDK / CLI / MCP server.
An independent, real-time observer that audits an agent's claims — preflight, advisory, report — and writes findings as receipts. Complements the Audit & Replay Logger; it does not replace it. Planned MCP server / SDK / API.
Discovers, correlates, and retrieves proof-of-action receipts across subsystems and sessions, making the whole suite's proof-trail queryable. Planned MCP server / SDK / API.
Advisory, read-only governance at the episode and pattern level, with efficacy feedback. It recommends; it does not enforce, and never auto-certifies recovery. Sits above per-action gating. Planned MCP server / SDK / API.
Controlled autonomy with the brakes built in first: activation gate, enforcement matrix, and lifecycle stop controls. Read-only by default, human-stoppable — autonomous pursuit is gated and not live. Planned MCP server / SDK.
An evidentiary three-role decision audit — Witness, Adversary, Architect — that audits the receipts behind a committed claim. Composes with Multi-Voice Deliberation. Planned MCP server / SDK.
Governed loading of third-party plugins and MCP servers — registration, capability authorization, handshake gatekeeper, lifecycle, and a forensic sink. Read-only by default; it governs plugins but does not guarantee their safety. Planned MCP / plugin / SDK / API.
Dormant by default, fail-closed: no external call fires unless explicitly activated and approved, and queuing never sends. Prevents accidental external side effects from agents. Planned MCP server / SDK / API.
Structured self-maintenance with a read-only review phase, a typed human approval gate, then scoped execution that writes a change-log receipt. No mutation runs without explicit approval. Planned SDK / CLI / MCP server.
In validation — Agent Communication Firewall. A shadow-only boundary firewall for agent communication: where Confidence Gate judges proposed actions, ACF judges traffic crossing trust boundaries between agents. Implemented inside a working persistent agent; currently in validation. No install documentation until validation completes.
Every product in the suite is a decision-support layer. These tools help teams evaluate, route, log, and observe agent actions — they do not replace human judgment, legal review, or production controls.
CertaWorks is a live product suite, not a finished platform. Each product has a clear scope, an honest status label, and known limits documented on its product page.
Every tool in the suite ships as a local install. No data leaves your machine by default. Hosted cloud features are roadmap items — not current reality.
Ten products are published on npm under the @certaworks scope, each with a verified install guide. Twelve more are built and tested, with npm publication in progress — their install commands activate as each package ships.