Kona Agentic OS · The platform

The AI operating layer, end to end.

One governed agentic core plus the three capabilities every system shares — the Workflow Engine, the Integration Hub, and Security · Governance · HITL — deployed as a dedicated, isolated instance per customer.

The core · Agentic OS

Four systems. One closed loop.

Record and Engagement feed Intelligence; Intelligence feeds Action; Action writes back. Every deployment answers one daily question: "What needs attention today, why, what should we say or do, and what action should be recorded next?"

Instance-based, ServiceNow-styleone dedicated, isolated instance per customer on the same versioned core.
Core / config splitproducts are thin configurations — ontology, scoring, prompts, playbooks, connectors — never forks.
Layered rolloutRecord → Engagement → Intelligence → first governed Action agent. No agent runs before the record layer is clean.
System 1
System of Record
The clean, governed data foundation — party kernel, ontology, append-only event log.
System 2
System of Engagement
Omnichannel communication and the operator console with ranked work lists.
System 3
System of Intelligence
Scoring, ageing detection, memory, retrieval, model routing, eval harness.
System 4
System of Action
Governed agents that do the work — and queue anything sensitive for approval.
The canonical daily loop

What every instance does before you log in.

1 Scheduled trigger loads active records by owner
2 Detects overdue and missing-action items
3 Scores and ranks by urgency and ageing
4 Generates grounded talking points
5 Drafts the follow-ups
6 Publishes a ranked work list
7 Notifies the owner
8 Operator reviews, approves, or updates
9 Outcome written to the event log
The Workflow Engine

Deterministic orchestration for agentic work.

Triggers, schedules, and approval flows as versioned, declarative config. Agents are workflows with LLM steps — not free-roaming chatbots — with a human in the loop wherever it matters.

Triggers & schedules
Record events, timers, and inbound signals start workflows deterministically — the daily loop is just a scheduled workflow.
Approval flows
Sensitive steps pause into the approval inbox; timeouts mean not sent, never silently sent.
Idempotent & checkpointed
At-least-once execution with idempotency keys — a retry never double-sends or double-writes.
Compensation & recovery
Failed steps roll back or compensate; partial work never leaves records inconsistent.
Versioned declarative config
Workflows are config, not code forks — diffable, reviewable, and instance-owned.
Execution traces & replay
Every run is traced end to end and replayable for debugging and audit.
The Integration Hub

Governed connectors for every system and agent.

Five connector classes, one governed lifecycle — credentials live in a token vault, and every connector is mapped to the ontology before an agent can touch it.

Channel connectors
Slack, WhatsApp, email, SMS — outbound sends and inbound reply capture.
Source-system connectors
CRMs, SIS/LMS, stores, and databases synced into the record layer.
Webhook ingestion
Signed inbound events from forms, payments, and partner systems.
MCP tool connectors
Agent-callable tools exposed through the MCP-style gateway — schema-validated and permissioned.
Outbound APIs
Governed writes to external systems, on-behalf-of authorized and fully audited.
Connector lifecycle Registered Authenticated Mapped Tested Enabled Monitored
Security · Governance · HITL

Governance built into the core — not bolted on.

Every agent action is authenticated, scoped, human-gated where sensitive, and auditable — the most common reason agentic pilots die is missing governance, so Kona treats it as a core layer.

The autonomy ladder — authority is earned
Scoring, ageing detection, talking points
Auto · explainable & audited
Draft message — never auto-sent unless allow-listed
Auto · draft only
Safe record updates (next action, notes)
Auto · on-behalf-of authorized
Allow-listed template send
Auto · every send audited
Personalized outbound message (timeout = not sent)
Human approval
High-impact transitions — conversions, closures
Human approval
Duplicate merge
Human approval
Credential, financial & entitlement actions
Never delegated · human admin only
Zero-tolerance release gates Eval pass rate required 0 authorization violations 0 grounding violations 100% trace coverage 100% event-log coverage
Identity & authorization
Every actor — human or agent — has an identity; every action is on-behalf-of authorized with least privilege.
Autonomy ladder & HITL
Each action class carries an explicit authority level; approvals are recorded, expirable, and auditable.
Secrets & data protection
Token vault, encryption in transit and at rest, sensitive-field redaction before any model call.
Observability & audit
Agent traces linked to the append-only event log — every decision reconstructable.
Instance isolation
A dedicated instance per customer: own database, credentials, config, and upgrade window.
AI threat controls
Untrusted-input rules, grounding judges, output screening, and hard-zero eval failures.
Standards & ecosystem alignment
MCP — Model Context Protocol
The tool gateway and connectors are MCP-based; every server registered, permissioned, and audited.
A2A — Agent-to-Agent
Reserved for the multi-agent phase; external agents are treated as untrusted counterparties.
OpenTelemetry GenAI
Agent traces follow the GenAI semantic conventions — backend-agnostic observability, linked to the event log.
OWASP Top 10 for Agentic Applications (2026)
Threat controls mapped and re-verified every release.
OWASP Top 10 for LLM Applications
Untrusted-input rule, grounding judges, output screening, and hard-zero eval failures.
EU AI Act & emerging regulation
Autonomy ladder, HITL approval records, event log, and exportable audit trails.

Agents act. You stay in control.

Book a demo — we'll walk one of your workflows through the daily loop and the autonomy ladder, live.

Book a demo
At a glance

Platform — Kona Agentic OS

Kona Agentic OS is the shared operating layer behind every KDigital product and service.

It keeps agent instructions, tools, state, permissions, approvals, evaluation and observability inside one governed operating model — so autonomy is a setting you choose per workflow, not a property of the whole system.