Reviewing agents v1

Use the Agents page to see which AI agents are registered in an aidb database, what they're allowed to access, and how often governance denies their actions. Select Agents in the cluster sidebar to open it. The page is available only for aidb databases; HM and Loki sources don't record agent identities.

The page has two tabs: Roster and Behavior.

Browsing the roster

Use the Roster tab to see the agents registered in aidb, five per page, with their Agent name and Purpose. Use Search... to find an agent, or Filter agents to pick agents by name.

Selecting a row opens Agent Details on the right, with the agent's name and declared purpose, its Permissions, and its Recent Activity. The permissions come from the Postgres grants on the agent's role, for example SELECT (email, name) on public.customers or EXECUTE on 3 functions in billing. Recent Activity lists the agent's latest sessions with their start time; select an identifier to open one. View Agent Activity opens Activity filtered to the agent.

The viewer connects read-only. Change an agent's permissions in the database.

If the viewer's role can't read the aidb agent catalog, the tab shows Agent registry unavailable.

Reviewing agent behavior

Use the Behavior tab to see, for each agent, its governed actions and denied decisions over the last 7 days. It's a first look at which agents keep being denied, not a verdict. The period shows as a chip above the table. To look at another period, choose a date range of up to 31 days in Filter agents.

The cards at the top count Agents Observed, Governed Actions, agents that Needs Attention, and Denied Actions. The table lists each agent's Actions, Denied Actions, Denial Rate, Denials Per Day, Last Denied date, and a Signal:

SignalMeaning, with the default thresholds
No decisionsNo allowed or denied decision was recorded for the agent.
Not enough dataFewer than 10 governed actions, too few to judge.
OKLess than 5% of actions denied.
WatchFrom 5% to less than 20% denied.
Repeated20% or more denied.
Escalation blockedaidb refused at least one attempt to switch role, for example SET ROLE or set_config('role', ...). Shown ahead of the rate-based signal.

The table is sorted by signal, so the agents denied most often come first. The Needs Attention card counts agents with Repeated or Escalation blocked. A signal says what happened, not why: a high denial rate can mean an agent asks for more than its purpose allows, or that the grants for its purpose are too narrow for legitimate work. Check the denied steps before acting.

Filter agents also narrows the table by agent, by a range of denial rates, and by signal.

Selecting a row opens Agent Behavior on the right, with the agent's purpose, its Decisions (total, approved, and denied actions, and the denial rate), its Denial Reasons, and Objects in Denied Queries. View Agent Activity opens Activity filtered to the agent and the same period.

Objects in Denied Queries lists the tables that the agent's denied queries touched, with a count for each. aidb 7.7 doesn't record which object a denial was about, so the list is read from the query text and includes only queries that reference a single table. Queries that reference several tables, or none, aren't counted. If no object can be identified, the section isn't shown.

If the chart value bff.governanceDecisionsEnabled is false, the table shows only Agent, Groups, and Spans, without decision columns or signals.