Run and observe an Agent

An Agent Run is one precise execution of an activity from an Agent revision. It is the observability unit for understanding what was requested, which capabilities were used, and what result was produced.

What is executed

A launch selects an immutable revision and activity. The revision supplies the general objective and model-provider selection; the activity supplies instructions, typed contract, tools, and execution limits.

Agent revision provider + model
Activity contract + guardrails
Agent Run
Tool calls
Outputs / routes

The Run executes a precise contract: revision, activity, inputs, and capabilities are known before launch.

Model provider and model

The Agent revision carries the model provider and, optionally, an explicitly selected model. This provider is distinct from business providers used through extensions: it provides the AI capability executing the activity.

L’option Default uses the provider's default model. If an explicitly selected model is no longer available, Ormuz attempts the default model from the same provider and adds a warning to the Run when that fallback succeeds. If the default model is also unavailable, execution fails.

Model choice belongs to the revision

Changing model provider or model changes the executable contract and therefore goes through a new revision. Guardrails remain attached to activities because they describe the budget of each task.

Observe a Run

From the Console, a Run lets you inspect its status, executed revision and activity, visible inputs and outputs, tool calls, and associated diagnostics. When launched from a process, the Run remains linked to the Agent task node that triggered it and, when role-based continuity is used, to the corresponding memory role.

When Agent Memory is active, inspection also shows which memory was used and which new contribution was published. Memory remains working context distinct from the Run's business result.

This separation is useful: the process instance shows where the Agent sits in orchestration; the Agent Run shows what happened inside that execution.

A completed Run shows its activity, parent instance, and trace of model calls and validations.
A completed Run shows its activity, parent instance, and trace of model calls and validations. Enlarge

Understand what the Agent could receive

Agent Run detail exposes input_agent_visibility to make observable the processing applied to inputs at the Agent boundary. Annotations are path-based and use the following treatments when restriction or explicit disclosure must be indicated.

TraitementMeaning in this Run
rawThe raw value was allowed for the Agent on this path.
pseudonymizedThe Agent received a pseudonymized projection rather than the source value.
forbiddenThe value was not sent to the Agent.

The Console summarizes these annotations into restricted, raw access, or mixte view when several treatments coexist. A field without special observable treatment is not presented as restricted merely because it belongs to the Run input.

Agent access and operator visibility are independent

raw means the Agent was authorized to receive the raw value; it does not mean the operator can read it in clear text in history. A sensitive or secret value may remain masked for the operator and be inspectable only through targeted reveal, independently of the treatment applied to the Agent.

These annotations describe the disclosure treatment of this execution. They allow auditing whether data was raw, pseudonymized, or forbidden to the Agent; they do not reconstruct the exact model prompt or payload byte-for-byte.

Observed tools are those of the activity

The Run accesses only tools configured on the activity of the executed revision. Every call remains attached to its contract, effective parameters, and risk level low, medium, or high. This level describes the tool's maximum consequence; it replaces neither permissions nor data-protection rules.

The Tool catalog is independent from the process-node catalog. See Tool catalog and risk.

Warnings and errors

A Run can produce warnings without failing. A warning signals a condition worth attention — for example fallback to the default model or a diagnostic raised by a tool — while still allowing successful completion when the contract is satisfied.

Warning ≠ failure

An error prevents execution from satisfying its contract. A warning remains a durable diagnostic associated with the Run and may be summarized on the parent process without automatically turning the outcome into failure.

The global view is detailed in Observability.

Protected values

Inputs, tool results, Agent Memory, and outputs remain subject to data classifications. History surfaces mask protected values by default. When an investigation requires a precise persisted value, targeted reveal may be used when the user has the appropriate right.

See Controlled reveal.