All four write to
governance_signals — the operator-actionable observation surface — surfaced via the dashboard, webhook, REST, and CLI. Sideband findings are never injected into an agent’s prompt. That boundary is structural, not a convention: the database rejects any write to the agent-facing advisory table with a sideband source. See governance signals for the full operator workflow.
Why sideband
Some signals only emerge across time, across sessions, or across the team — not on any single request. A single trace might pass every gate. The pattern of dozens of traces, across half the fleet, can still be telling you the agents are drifting apart ontransparency or that one agent has quietly stopped escalating high-stakes decisions.
The runtime gateway can’t see those patterns — it sees one request, one agent, one moment. The observer has the wider lens: it reads the team’s alignment cards on a configurable cadence, runs the detectors, and writes findings to governance_signals.
Sideband never intervenes on the request that triggered it and never touches an agent’s context. It observes on its own schedule and produces a record for an operator to see and act on — a dashboard entry, a webhook delivery, a row in
GET /v1/teams/:id/governance/signals. There is no mechanism, at any layer, that carries a sideband finding into an agent’s prompt.How the detectors are wired
The observer’s cron tick follows a five-step loop per active team:- Enumerate active teams via an internal RPC. Filters: not archived, ≥2 non-deleted member agents.
- Fetch the team’s effective Trust Posture via
GET /v1/teams/:id/effective-posture. The composer folds Platform → Org → Team with strictest-wins semantics per axis. - Fetch member agents and their alignment cards via the canonical card store.
- Run the three pure-synchronous detectors (
computeTeamCoherence,analyzeFaultLines,checkFleetCoherence) against the posture body’s per-axis thresholds. Each axis runs only if it’senabledand the team’s per-axis cadence has elapsed. - Fan out signals per the posture’s
fan_out.rule. The default — and only v1 value — isper_named_affected_agent: one row per agent named in the finding.
sideband_sweep_log (upserted by team_id × axis × day) — proof-of-coverage evidence for SOC 2 / EU AI Act control mappings, even when no findings are produced. Read it via GET /v1/teams/:id/sideband-coverage.
The Posture is the policy surface
Detectors don’t carry their own thresholds. Every per-source firing rule lives in the team’s effective Trust Posture and composes with strictest-wins per layer:
If you want a detector tuned tighter for a banking team, you tighten the posture — never the detector code. See the how-to: Tuning sideband detection via Trust Posture.
Per-pattern emission for the fleet axis
The fleet axis can fire on three independent patterns:outliers, min_pair_score, and cluster_partition. When more than one fires on the same sweep, the observer emits one row per pattern with a distinct source_ref.pattern_type — one detection event per (rule, target, time-window), not aggregated.
scope, scope_id, source, pattern_type) also means a repeated firing of the same condition refreshes the existing open row rather than stacking duplicates. See Governance signals.
Multi-team agents
An agent that is a member of N teams is swept under N independent effective postures — each team’s posture composition is its own fold, and strictest-wins does not cross team boundaries. A finding that names the same agent under two different teams produces two independentgovernance_signals rows, scoped to their respective teams.
Webhook events
Each sideband firing emits a<source>.fired webhook event so external subscribers (SIEM, ticketing, alerting) can react:
sideband.coherence.firedsideband.fault_line.firedsideband.fleet.firedsideband.drift.fired— emitted when a stored integrity checkpoint crosses the per-agent drift threshold, not by the per-team sweep; see Drift Detection
Compliance evidence — proof-of-coverage
Operations security buyers expect two artifacts:- Findings — what fired, when, on which agent. Read via
GET /v1/teams/:id/governance/signalsorGET /v1/agents/:id/governance/signals, filtered tosideband.*sources. - Coverage proof — even when nothing fired, evidence that the detector ran during the reporting window.
GET /v1/teams/:id/sideband-coveragereturns a per-axis 30-day rollup fromsideband_sweep_log.
Sideband and AEGIS
Sideband findings are a signal to operators, never a runtime instruction to the agent. AEGIS does not inject sideband observations into agent prompts.See also
- Governance signals — the operator surface every sideband finding lands on, and the full ack/resolve/dismiss lifecycle
- Trust Posture — the policy artifact that drives every per-team sideband threshold
- Drift Detection — the per-agent timescale, complementary to per-team sideband
- Fleet Coherence — dimensional team coherence scoring
- Tuning sideband detection via Trust Posture — the customer-facing how-to
- Webhook contract — delivery guarantees for
sideband.*.firedevents