Roadmap triển khai Agent Harness Layer
Tài liệu này trả lời câu hỏi: sau khi đã định vị LumiBase là “structured operating layer where humans, agents, data, workflows, and applications co-evolve”, những việc cần làm cụ thể là gì?
Mục tiêu không phải “thêm chat AI” nữa. Mục tiêu là biến mọi hành động của agent thành một vòng đời có cấu trúc: Goal → Run → Plan → Tool calls → Evaluation → Approval → Artifact commit → Audit/Memory.
0. Nguyên tắc ưu tiên
- Không cho agent ghi thẳng vào schema/content khi chưa có harness state. Mọi hành động có rủi ro phải gắn với
goalId,runId, policy snapshot và approval/evaluation. - Tách tool registry khỏi prompt. Tool nào được gọi, input schema, capability, risk policy và rate limit phải đến từ database/config, không đến từ lời agent tự khai.
- Artifact là output chính, chat chỉ là interface. Kết quả quan trọng phải được lưu thành artifact versioned: page, component, dataset, config, prompt, migration, API spec, workflow.
- Evaluation trước approval, approval trước commit. Admin không nên duyệt “text”; admin duyệt diff/artifact kèm test/eval result.
- Audit/replay là first-class. Một run thất bại phải xem lại được plan, tool calls, input/output đã mask secret, lỗi, cost và retry policy.
1. Phase A — Chuẩn hoá nền tảng DB và lifecycle
Mục tiêu: biến AI Copilot hiện tại từ chat/HITL rời rạc thành lifecycle có goal/run rõ ràng.
-
[DB]Thêmagent_goalsvớisiteId,title,description,source(user/flow/api/schedule),createdBy,assigneeAgent,priority,deadline,status,successCriteria jsonb,createdAt,updatedAt. -
[DB]Thêmagent_runsvớigoalId,siteId,agentName,provider,model,status,budget jsonb,policySnapshotHash,risk,startedAt,finishedAt,error. -
[DB]Thêmagent_plansvớirunId,steps jsonb,status,risk,approvalPolicy,createdAt,approvedAt,approvedBy. -
[DB]Thêmagent_tool_callsvớirunId,toolName,input jsonb,output jsonb,error,status,latencyMs,cost jsonb,createdAt; input/output phải hỗ trợ secret masking. -
[DB]Thêm indexes(siteId, status),(goalId, createdAt),(runId, createdAt)và cascade theositeId/goalIdhợp lý. -
[BE]TạoAgentRunServiceđể mở run, append plan/tool call, close run, fail run, retry run. -
[BE]RefactorAISecureHarness.execute()để nếu request chưa cógoalId/runIdthì tự tạo transient goal/run thay vì chỉ tạo approval rời rạc. -
[TEST]Property tests đảm bảo mọi tool call luôn thuộc đúngsiteId/runId, run failed vẫn giữ audit trail, cross-site không đọc được run/goal.
2. Phase B — Tool Registry và capability policy
Mục tiêu: nâng CORE_SKILLS từ hằng số trong package thành registry vận hành được.
-
[DB]Thêmagent_toolsvớiname,description,inputSchema,outputSchema,requiredCapabilities,riskPolicy,rateLimit,enabled,owner,extensionId?. -
[DB]Thêmagent_permissionsđể gắn agent/user/API key với policy/capabilities theovalidFrom,validUntil,environment. -
[BE]ImplementToolRegistryService: load tools từ core skills + extension tools + DB overrides; cache theositeIdvà invalidate khi tool/extension đổi. -
[BE]Chuẩn hoá risk policy:safe,review_required,dangerous,blocked; support rule theo capability, collection, action, environment. -
[BE]Enforce rate limit theo tool/agent/site để tránh runaway loops. -
[SDK]Thêm types choAgentTool,AgentCapability,AgentRiskPolicy. -
[FE]Studio page “Agent Tools” để admin bật/tắt tool, xem schema, capability, risk policy và lịch sử gọi. -
[TEST]Agent không thể gọi tool disabled, thiếu capability, vượt rate limit, hoặc risk bị policyblocked.
3. Phase C — Approval mở rộng: plan/tool/artifact
Mục tiêu: approval không chỉ dành cho ai_approvals kiểu skill nguy hiểm, mà thành cổng duyệt tổng quát.
-
[DB]Thêmagent_approvalsvớirunId,subjectType(plan/tool_call/artifact/schema_diff),subjectId,status,requestedByAgent,decidedBy,decisionReason,expiresAt,createdAt,decidedAt. -
[BE]Migration bridge: giữai_approvalsbackward-compatible nhưng ghi song song sangagent_approvalscho action mới. -
[BE]Approval policy engine:before_execute,before_commit,two_person_rule,owner_only,security_admin_only. -
[FE]Nâng Approvals Dashboard từ card skill đơn giản thành queue theo subject type, diff preview, eval summary, approve/reject/request changes. -
[BE]Audit mọi decision với actor, reason, before/after hash, request id. -
[TEST]Dangerous plan không execute trước approval; rejected artifact không commit; expired approval không còn hiệu lực.
4. Phase D — Artifact Store và versioning
Mục tiêu: output của agent trở thành tài sản có thể review, publish, rollback.
-
[DB]Thêmagent_artifactsvớirunId,siteId,type,target,title,contentRefhoặccontent jsonb,hash,version,status(draft/reviewing/approved/published/rejected/rolled_back),createdAt. -
[BE]Artifact writers cho các type đầu tiên:schema_diff,page_spec,component_spec,seed_data,api_spec,prompt,migration. -
[BE]Commit adapters: artifactschema_diff→ collections/fields/relations;seed_data→ items;page_spec→ pages; tất cả đi qua permission + approval. -
[FE]Artifact review UI: diff view, JSON/raw mode, linked collections/items, approve/publish/rollback. -
[SDK]Client methods: list artifacts by goal/run, get artifact, approve/publish/rollback. -
[TEST]Artifact hash ổn định; publish idempotent; rollback khôi phục version trước; artifact cross-site bị deny.
5. Phase E — Evaluation Gate
Mục tiêu: admin duyệt dựa trên bằng chứng, không dựa trên niềm tin vào LLM.
-
[DB]Thêmagent_evaluationsvớirunId,artifactId,kind,status,score,summary,details jsonb,createdAt. -
[BE]Eval runner đầu tiên: JSON schema validation, permission diff lint, schema migration dry-run, generated API spec validation, prompt safety check. -
[BE]Policy: artifact loạischema_diff/migrationkhông được request approval nếu chưa có eval pass hoặc explicit override. -
[OPS]Sandbox smoke test cho generated app/page spec ở Docker runtime trước khi publish. -
[FE]Hiển thị eval summary trong approval/artifact UI với trạng thái pass/warn/fail. -
[TEST]Artifact fail eval không publish được; warning cần reason khi override; eval result gắn đúng artifact hash.
6. Phase F — Memory và knowledge base có kiểm soát
Mục tiêu: memory hữu ích nhưng có scope, expiry, provenance và quyền truy cập.
-
[DB]Thêmagent_memoryvớisiteId,scope(site/collection/item/user/goal),sourceType,sourceId,content,embedding,confidence,expiresAt,createdAt. -
[BE]Memory write policy: chỉ ghi memory từ artifact/evaluation/approved output hoặc nguồn content rõ provenance. -
[BE]RAG context builder gom schema, permissions, recent runs, approved artifacts, memory phù hợp scope và field mask. -
[BE]PII/secrets redaction trước khi memory được embed hoặc đưa vào context. -
[TEST]User/agent chỉ retrieve memory trong policy scope; expired memory không vào context; field bị mask không xuất hiện trong RAG.
7. Phase G — App Generation MVP
Mục tiêu: chứng minh LumiBase không chỉ quản lý content mà giúp tạo business software.
-
[AI]SkillgenerateAppSpecđọc collections/fields/relations/policies và sinhpage_spec+component_specartifacts. -
[AI]SkillgenerateApiDocssinhapi_specartifact từ schema và permission public/role. -
[AI]SkillgenerateSeedDatasinhseed_dataartifact với eval schema validation trước khi insert. -
[BE]App generation run template cho use case e-commerce: products/orders/customers/storefront. -
[FE]Wizard “Generate app from schema”: chọn collections, target app, constraints, budget, approval policy. -
[TEST]End-to-end: tạo goal generate storefront → plan → artifacts → eval → approval → publish page/spec.
8. Phase H — Observability, cost và operations
Mục tiêu: agent vận hành được trong production, không chỉ demo.
-
[BE]Metrics: run count, success/fail rate, approval latency, tool latency, eval fail rate, token/cost estimate. -
[OPS]Grafana dashboard “Agent Harness”: runs by status, cost by agent/tool/site, approval backlog, failed evals. -
[BE]Budget enforcement: max tool calls, max runtime, max estimated cost, max artifact size. -
[BE]Dead-letter queue cho run/tool call fail nhiều lần. -
[FE]Run detail timeline: plan, tool calls, logs, evals, approvals, artifacts. -
[TEST]Run vượt budget bị stop an toàn và ghi reason; retry không duplicate committed artifacts.
9. Thứ tự triển khai khuyến nghị
- A1 lifecycle DB + service:
agent_goals,agent_runs,agent_tool_calls,AgentRunService. - B1 tool registry: đưa
CORE_SKILLSvào registry có risk/capability/rate limit. - C1 approval tổng quát:
agent_approvals+ Approvals Dashboard mới. - D1 artifact store: bắt đầu với
schema_diff,seed_data,api_spec. - E1 evaluation gate: schema validation + permission diff + dry-run.
- G1 app generation e-commerce demo: tạo luồng đầu tiên có thể demo end-to-end.
10. Definition of Done cho mỗi phase
- Có migration/schema Drizzle và docs cập nhật trong
docs/vi/data-model.md. - Có route/API contract trong
apps/cms/openapi.yamlvà SDK type tương ứng. - Có property tests cho multi-tenant isolation, permission/capability, idempotency hoặc approval invariant.
- Có Studio UI tối thiểu để admin quan sát/duyệt/debug, không chỉ endpoint backend.
- Có audit log và metrics tối thiểu.
- Chạy được cả Cloudflare Workers và Docker runtime; nếu chưa hỗ trợ một runtime phải có feature flag và docs giới hạn.