Skip to main content

Core Data Structures

AgentDNA revolves around the following core data structures.

Actor​

Every participant in a workflow is an Actor, identified by a globally unique Actor ID. AgentDNA currently supports three Actor types:

  • user
  • agent
  • tool

Envelopes reference Actors by their ID.

Envelope​

An Envelope captures a single interaction between two Actors.

Every Envelope is digitally signed by the sender and references its parent Envelopes, allowing workflows to be represented as a cryptographically verifiable chain.

{
"from": "coordinator_actor_id",
"to": "worker_actor_id",
"payload": "{\"action\":\"produce_task_spec\"}",
"epoch": 1782668362,
"status_code": 1000,
"hash": "<Hash of the Envelope's content>",
"signature": "3046022100...",
"parent_envelope": [ ... ]
}
FieldDescription
fromID of the Actor building the Envelope
to(Optional) ID of the Actor receiving the Envelope
payloadAction or message exchanged between Actors
epochUnix timestamp of Envelope formation
status_codeStatus code for errors that occurred while the Envelope was formed
hashHash of the Envelope's content, which is signed and verified
signatureHex-encoded signature by the Actor building the Envelope
parent_envelopeList of Envelopes upon which the current Envelope is built

Status codes​

The following status codes are set on an Envelope:

CodeDescription
1000No issues found
1001Agent not whitelisted
1002Error while performing Agent whitelist verification
2001Envelope verification failed under light mode
2002Envelope verification failed under heavy mode
2003Envelope verification failed under boundary mode
2999CoCA verification failure for an unknown reason
4001MCP Tool execution error. A special case where the workflow isn't interrupted
4002Generic Middleware execution error

IntentWorkflow​

An IntentWorkflow represents the complete lifecycle of an intent.

Rather than storing a sequence of events, AgentDNA stores the latest Envelope. Every Envelope recursively references its parents, allowing the entire chain of custody to be reconstructed from a single object.

IntentWorkflow is a DTO (Data Transfer Object) that is passed between the Actors of an agentic workflow.

For example:

{
"type": "intent_workflow",
"version": "1.0",
"remarks": "",
"info": {},
"envelope": {
"from": "worker_actor_id",
"to": "coordinator_actor_id",
"payload": "{\"status\":\"completed\"}",
"epoch": 1782668370,
"status_code": 1000,
"hash": "<Hash of the Envelope's content>",
"signature": "...",
"parent_envelope": [
{
"from": "coordinator_actor_id",
"to": "worker_actor_id",
"payload": "{\"action\":\"produce_task_spec\"}",
"epoch": 1782668362,
"status_code": 1000,
"hash": "<Hash of the Envelope's content>",
"signature": "...",
"parent_envelope": []
}
]
}
}

Each parent_envelope links to the previous interactions, forming a nested chain that captures the complete journey of an intent from its origin to its final outcome.

Cards​

Cards are immutable records stored on the Provenance Layer. They represent persistent identities and completed workflows that can be independently retrieved and verified. They can be thought of as immutable append-log files, where the only way to edit information is to append new information. This allows us to version check the changes made on a Card. One such instance is the Agent Card, where every entry reflects a policy change of the Agent.

UserCard​

A UserCard represents a Human identity.

@dataclass
class UserCard:
type: str
id: str
metadata: dict[str, Any] = field(default_factory=dict)
FieldDescription
typeCard type. Supported values: user, agent and tool
idUnique identifier of the User Card.
metadataOptional metadata associated with the user identity.

AgentCard​

An AgentCard represents a deployed AI Agent.

@dataclass
class AgentCard:
type: str
id: str
metadata: dict[str, Any] = field(default_factory=dict)
policy: str = ""
FieldDescription
typeCard type. For example, agent.
idUnique identifier of the Agent Card.
metadataOptional metadata describing the deployed Agent.
policyThe Agent's policy document captured at deployment time.

Workflow Provenance Card​

A Workflow Provenance Card represents a completed IntentWorkflow.

Unlike User and Agent Cards, which represent identities, a Workflow Provenance Card captures a complete execution of an intent.

It stores the final IntentWorkflow, including the nested Envelope chain and all associated signatures. Since each Envelope references its parents, the stored workflow preserves the complete chain of custody from the initiating Human through every participating Agent and tool to the final response.

This immutable record allows the entire workflow to be independently verified and audited at any point in the future.