ForthAI

Simple interface with enterprise-grade agentic kernels

A governed capability runtime across your systems of record — one governed exit for every action, not a chatbot bolted on top.

Architecture overview

Reliable agents at scale. Knowledge that compounds.

The architecture is built for two outcomes: agents your enterprise can trust with real work — every action governed, approved, and on the record — and a memory layer that turns every reviewed run into enterprise-wide knowledge, an intellectual asset that compounds over time.

Governance & trustgoal in ↓ · result out ↑
Interfaces
Where requests arrive and human decisions happen — in the surfaces your team already uses.
Web
Raise requests, track progress, and sign off in the browser.
API
Programmatic access through the same governed path.
Email
Forward or CC a request; the agent picks it up.
Chat
Set goals and confirm decisions in conversation.
Embedded UI
Surfaces embedded inside the systems you already run.
Agent layer
Optional AI reasoning over one governed runtime — the harness proposes, the runtime executes.
Agent harnessoptional
Context, planning, synthesis — drafts a typed, bounded plan. Proposes; never executes.
contextplanningsynthesis
proposes
Governed runtimealways on
Every agent-originated action enters here — and the capability kernel is its one governed exit.
statehitlcapability kernelevidence
Memory layerbeside the path
Grounds every plan and learns from reviewed outcomes — context, never authority.
DIKW retrievalplan time
Hands the harness the relevant slice of every tier — each item with provenance.
datainformationknowledgewisdom
review promotes
Governed learningreview gated
Reviewed outcomes become reusable context, guidance, and playbook candidates — never enforced rules.
contextguidanceplaybook candidates
Capability kernel
The one governed exit: policy, permission scope, and approval enforcement on every action.
Validation & replay
Typed plans validated before they run; idempotency keys, replay protection, and reconciliation prevent duplicate effects.
Human in the loop
Inspect at any time; pause, approve, cancel, or take ownership at safe persisted checkpoints.
Evidence capture
Decisions, approvals, and effects recorded authoritatively.
Context graph
A semantic axis across the stack — business objects, their context, and the capabilities associated with each object type. The kernel, not the graph, decides what's permitted.
DIKW retrieval
Data, information, knowledge, wisdom — layered, and returned with provenance.
Governed learning
Reviewed outcomes become reusable context, guidance, and playbook candidates — enforced rules ship only through a versioned policy change.
Not the ledger, not the rulebook
Operational truth stays in your systems of record; policy stays in the kernel's versioned store.
Tool layer
Typed capabilities and governed connectors — transport into the systems where work lands.
Typed capabilities
Every action has a strict, declared input and output.
ERP connectors & APIs
Governed reads and writes into SAP, Yonyou, Kingdee, and your own services.
MCP adapters
External tools normalized through capability schemas, tenant credentials, allowlists, audit, and egress controls — then the same guardrails.
Systems of record & action
Where work lands and the record lives — reached through governed interfaces, never bypassed.
WorkERP
The ForthAI-native suite — governed by the kernel directly.
ERP
Orders, invoices, inventory.
CRM
Accounts, pipeline, service.
SCM
Suppliers, purchasing, logistics.
OA
Docs, approvals, comms.
Data services
Reports, warehouses, data interfaces.
Observability & analytics

Traces, health, cost, and performance for every run; telemetry never replaces audit evidence.

Traces
Run and step telemetry correlated end to end, wherever integrations expose it.
Health
Reliability, latency, and error rates.
Cost
Spend per run, per agent, per org.
Performance
Throughput, cycle time, outcomes.
Governance

Wraps every layer — nothing runs outside it.

Policy & permissions
Every action checked against versioned policy and permission scope before it runs.
Approvals
Human sign-off enforced at the thresholds you set.
Audit evidence
Decisions, approvals, and effects recorded authoritatively.
Capacity controls
Budgets, rate limits, and kill-switches on every agent.
hover a layer to see what's inside — memory grounds and learns beside the execution path, never on it
Inside the memory layer

Runs leave data. Review builds knowledge. Plans borrow wisdom.

Memory is organized as a DIKW ladder — data, information, knowledge, wisdom. Every governed run leaves evidence at the bottom, review promotes it upward tier by tier, and at plan time retrieval hands the harness the relevant slice of every tier, each item with provenance.

wisdom exits as guidance — never enforcement
governed learning
04Wisdom
review gate
03Knowledge
distilled
02Information
structured
01Data
dikw retrieval
memory grounds; it never authorizes
01 / 06
evidence in
in ← from the governed runtime

Every run's evidence lands as data. Only reviewed outcomes climb — memory never learns from an unreviewed run.

scroll to continue
Agent harness

One plan by default. A team only when it pays.

WorkOS is a governed capability runtime: the harness plans, the capability kernel executes. Planner–executor is the default for predictable, auditable runs; orchestrator–worker steps in only when decomposition genuinely adds value — so a simple request never turns into a multi-agent swarm burning tokens.

Most requestsplanner–executor

One bounded plan on one governed path — no coordination overhead.

User request
Planner
Bounded execution plan
Capability kernel
policypermissionapprovalidempotency
Systems of record
Evidence · state · observability
Complex workorchestrator–worker

The planner brings in an orchestrator only when the job truly decomposes — parallel domain workers, one governed exit.

Planner
Orchestrator
scoped, budgeted delegation
Finance domain binding
CRM domain binding
Knowledge & analysis worker
every worker's actions converge on
Capability kernel
same policy, approval, and evidence gates for every worker
No default swarms — decomposition has to earn its token cost, and every agent-originated workflow is enforced through the capability kernel and its state machine: checkpointed, resumable, audited.
Self-evolve through experience

Reviewed outcomes make future work better.

The governed runtime records what happened. Memory accepts reviewed facts, corrections, and learning candidates, then returns sharper context for future work.

Governed runtime

Produces structured evidence of what ran, what stalled, and where a human intervened.

run outcomes
reviewed context
Memory layer

Promotes reviewed outcomes into reusable context, guidance, and playbook candidates.

Evidence capture

Completed work leaves structured run evidence — never reconstructed from memory.

Reviewed learning

People accept, correct, or reject proposed improvements before they become reusable guidance — enforced rules ship only through a versioned policy change.

Human feedback

Approvals and corrections become signal — folded back into the playbook.

Human in the loop

AI runs the work. You make the calls.

One request, end to end: the harness plans, the kernel executes. Inspect at any time — pause, approve, cancel, or take ownership at safe persisted checkpoints.

01
you
One request
Chase every invoice more than 30 days overdue.

Instructions in Layman's terms.

02–07Human in the Loop
One governed runtime takes it from here
02
agents
The optional Agent Harness proposes a bounded plan; the governed runtime validates it and binds the Finance specialist configuration.
Clarification: “Include accounts already on payment plans?” — you answer in one line, the plan updates.? clarified
03
tools
A governed READ pulls the live overdue ledger from the ERP — operational truth from the system of record, never from Memory.
04
memory
Memory adds context: account history and last quarter's reviewed playbook. Context, not authority.
05
workflowagents
The kernel resolves your current credit policy from its versioned store and dry-runs one drafted action per account. Two large accounts trip the credit-hold workflow.
06
workflowhuman
Policy-selected approvals: the two holds route to your credit manager for sign-off — nothing lands back on your desk.
Credit manager reviews the two holds — approve, edit, or reject in one tap.✓ 2 approved
07
tools
Idempotent commit: schema-validated, replay-protected calls do the work — ERP notes, reminder emails, payment plans — then every effect is reconciled against the ERP.
Sign-off: the outgoing batch is summarized for you — nothing sends until you sign off.✓ signed off
inspect at any time — intervene at safe persisted checkpoints
08
you
Result comes back

40 invoices chased, 2 signed off by your credit manager — effects reconciled, every step on the record, and the run filed as a reviewed learning candidate.

who · what · when · why
Start here

Start with the smallest win.

Schedule a 30-minute free consultation with us.