Main Agent
The Main Agent is the orchestrator at the center of the system. When a user asks a question, the Main Agent handles the full request lifecycle:- Classifies the intent: determines whether the request is a lookup, comparison, trend analysis, root cause investigation, forecast, or action
- Determines data sources: identifies which connected data sources are needed to answer the question
- Checks permissions: validates the user’s access against the required data
- Routes to agents: dispatches the request to the appropriate data-source agent(s)
- Synthesizes results: combines responses from multiple agents for cross-source queries
- Selects visualization: picks the optimal chart or table component
- Streams the response: delivers results progressively back to the user
The Main Agent never directly accesses customer databases. It does not hold database credentials. All data access is delegated to data-source agents over internal WebSocket connections.
Data-Source Agents
Each connected data source has a dedicated agent. An agent is a containerized service responsible for a single data source.Agent Characteristics
Agent Isolation
Each agent runs in its own Docker container. There is no shared filesystem or memory between agents. Credentials are stored only within each agent’s container. All inter-agent communication goes through the WebSocket server.Cross-Source Queries
When a user’s question requires data from multiple sources, the Main Agent coordinates across agents:- The Main Agent identifies all required data sources
- It dispatches parallel requests to each relevant data-source agent
- Each agent executes against its own data source independently
- The Main Agent synthesizes the results into a unified response
Action Agents
Action Agents are architecturally separate from Data-Source Agents. While data-source agents handle read operations, Action Agents handle write-back operations such as creating records, updating statuses, or triggering external systems.The separation between read and write agents is an architectural decision, not just a security policy. Data-source agents cannot write, and action agents use entirely different credential sets and approval workflows.
Why This Architecture
The multi-agent model is not arbitrary — it delivers concrete architectural benefits:Independent Scaling
Each data-source agent can be scaled independently based on query load. A heavily-queried PostgreSQL source can have more agent instances without affecting the BigQuery agent.
Fault Isolation
If one agent fails or becomes overloaded, all other data sources remain accessible. A problem with the SAP agent does not take down PostgreSQL queries.
Technology Flexibility
Different agents can use different connection strategies — SQL for relational databases, REST for APIs like Salesforce, file parsing for Excel. The Main Agent does not need to know the details.
Credential Minimization
The Main Agent, which handles LLM communication and orchestration, never sees database credentials. Each agent holds only the credentials it needs for its specific data source.
Resource Profile
Each component has a defined resource footprint for deployment planning:Report Engine
The Report Engine is a dedicated component that runs independently from the interactive query path. It handles background and scheduled workloads:- Scheduled report generation and delivery: recurring reports run on defined schedules
- Anomaly detection baseline models: continuous learning from historical data patterns
- Continuous metric monitoring: tracks key metrics and detects deviations
- Triggered alert investigation: automatically investigates when alerts fire
The Report Engine is architecturally separate from the interactive query pipeline. Scheduled processing does not compete with interactive queries for resources, ensuring consistent response times for live users.
Communication Flow
All communication between the Main Agent and data-source agents uses internal WebSocket connections. This provides real-time, bidirectional messaging with streaming support.Further Reading
Security Perspective
How the agent model enforces security boundaries and credential isolation
Data Flow
Detailed request and response flow through the system
AI Engine
How the intelligence layer processes queries
Infrastructure
Deployment model and scaling strategies