A consolidated, one-page view of every layer in the reference architecture (Ch. 3) and representative technologies for each. Tools are illustrative of their category, not endorsements; this space moves quickly, so treat the column on the right as a starting set, not a shortlist frozen in time. Match each choice to the first principles of its chapter, not to fashion.
| Layer | Core job | Deciding principle | Representative technologies | Ch. |
|---|---|---|---|---|
| Durable execution | Run agent loops that survive failure; fan-out/in; HITL | Persist progress, not results | Temporal · Hatchet · Inngest · DBOS · Restate | 4–5 |
| Agent framework / state | Model the loop as a typed state machine | State is a value, not a process | LangGraph · custom FSM on durable engine | 5 |
| Model gateway | Single chokepoint for all inference | Decouple app from model | LiteLLM · TensorZero · Portkey · Bedrock/Vertex | 6 |
| Reasoning & prompt opt. | Choose deliberation depth; optimize prompts on data | Spend deliberation where it pays | ReAct · Reflexion · DSPy (MIPROv2 · GEPA) | 7 |
| Tools / protocol | Standardize how agents call capabilities | The tool interface is a prompt | MCP (servers/clients) · JSON-Schema tools | 8 |
| Code sandbox | Run untrusted model code safely | Treat all agent code as hostile | E2B · Modal · Daytona · Firecracker · gVisor | 9 |
| Memory | Persist & recall across sessions | Curation, not accumulation | Letta (MemGPT) · Mem0 · Zep · pgvector | 10 |
| Retrieval / knowledge | Ground reasoning in real data | Retrieval quality gates answers | pgvector · Qdrant · Weaviate · Milvus · Cognee (GraphRAG) | 11 |
| Multi-agent / interop | Coordinate agents; talk to peers | Coordination must buy capability | Orchestrator–worker · A2A protocol | 12 |
| Interaction layer | Stream agent state to a human surface; take direction back | Adopt the protocol; the UI is yours | AG-UI · CopilotKit · SSE / WebSocket | 13 |
| Threat model | Enumerate the agentic attack surface; trace every threat to a control | Model threats before controls; map to a shared taxonomy | OWASP LLM Top 10 · OWASP Agentic Top 10 (ASI) · MAESTRO · MITRE ATLAS | 14 |
| Identity & authz | Prove who acts; scope what they may do | Least privilege, on behalf of a principal | SPIFFE/SPIRE · OAuth2 · token exchange (RFC 8693) | 15 |
| Agent identity | Give the agent itself a first-class, governable identity | Identify the agent, not only the workload | Entra Agent ID · Bedrock AgentCore Identity · delegation chain | 15 |
| Payments | Let agents transact, bounded | Autonomy over money needs the tightest controls | x402 · scoped budgets + approval | 15 |
| Guardrails / safety | Filter I/O; defend against injection | Break the trifecta structurally | NeMo Guardrails · Guardrails AI · Llama Guard | 16 |
| Policy & governance | Enforce & audit what's allowed; comply | If it wasn't logged, it didn't happen | OPA/Rego · immutable audit log · DPDP/GDPR/EU AI Act · ISO 42001 · SOC 2 | 17 |
| Observability | Reconstruct what the agent did & why | Instrument for "what did it do, and why?" | OpenTelemetry (GenAI) · Langfuse · Arize Phoenix · LangSmith | 18 |
| Evaluation | Measure quality; gate changes | You can't improve what you don't measure | Offline + online · LLM-as-judge · Braintrust · Phoenix | 19 |
| Cost / FinOps | Meter, attribute, and cap spend | Cost is a runtime constraint | Lago · OpenMeter · per-run/tenant budgets | 20 |
| Scale & capacity | Guarantee throughput; orchestrate concurrency | Separate the three capacity layers | Provisioned throughput · vLLM · K8s/GPU · circuit breakers/bulkheads | 21 |
| Deployment / CI-CD | Ship changes without regressions | Gate on evals + policy | Tekton · OPA gate · canary/staged rollout | 21 |
| Infrastructure as code | Declare the platform & control plane as reviewed config | The platform itself is code, reconciled to desired state | OpenTofu · Crossplane · GitOps · policy-as-code | 21 |
| Foundation | Stores & compute everything rests on | Prefer one system you operate well | Postgres (+pgvector) · object store (S3/R2) · Kafka · Redis · Kubernetes | 3 |
| Model serving | Decide self-host vs. API vs. hybrid; serve open models | Reach inference through the gateway, never wire it in | vLLM · SGLang · TGI · provider APIs · hybrid | 3 |
| MCP control plane | Broker, discover & authorize tool access | The gateway is the MCP policy enforcement point | MCP gateway · registry · OAuth 2.1 (PRM/8707) · token exchange | 22 |
| Network substrate | Carry every request with identity & resilience | Push cross-cutting concerns into the substrate | Istio ambient · Cilium (eBPF) · SPIFFE/SPIRE · Envoy | 23 |
| Sandbox fleet | Isolate model code at scale, locally & in prod | Target an isolation interface, not a VMM | Firecracker · Cloud Hypervisor · libkrun · gVisor · snapshots | 24 |
| Metering & billing | Turn usage into revenue, correctly | Meter & enforce at the gateway, invoice downstream | Lago · OpenMeter · Metronome · Stripe Billing · idempotent events | 25 |
| Multi-tenancy | Serve many customers from one platform | Isolate by default, pool by exception | RLS / schema-per-tenant · BYOK · per-tenant quota · tenant tag | 26 |
| Data architecture | Govern the whole data estate | One lifecycle, lineage, one retention/residency policy | data classes · lineage / provenance · provable erasure | 27 |
| Model lifecycle | Choose, customize & version models | Customize at the cheapest effective layer | prompt → RAG → SFT/LoRA → DPO → distill · model registry | 28 |
| Secrets | Hold runtime credentials safely | A secret in the context window is a leaked secret | Vault / KMS · short-TTL · broker at the boundary | 15 |
| Reliability & DR | Promise & defend a service level | Commit to a measured floor; DR-test the system of record | SLO + error budget · capacity math · RPO/RTO · backups | 29 |
· · ·