Skip to content

Launch Script: The Governed Agent That Remembers

Superseded 2026-08-03: the Founder Decisions doctrine in Engineering-Standard/glossary/platform-glossary.md is the current execution directive (product: "Bluefly Drupal Launch Factory"). This script's Kagent/ LiteLLM framing (line 53, 268) is not the canonical Drupal runtime -- see Vision.md's 2026-08-03 correction. Historical reference only.

Version: v1.1 | Date: 2026-05-21 | Duration: 15 minutes Audience: Platform architects, VPs of Engineering, CTOs evaluating agent governance Tone: Confident, evidence-driven, not hand-wavy Operator runbook: See amcs-phase1-demo-runbook.md for exact commands and environment setup


Narrative

"Every AI agent platform promises smart agents. We promise accountable ones. This launch shows an agent that remembers what it learned, proves what it did, and respects boundaries it cannot override."


Actors

Actor Role Tool
Operator Human presenter Browser + terminal
Accessibility Reviewer OSSA-governed AI agent drupal/ai_agents + drupal/tool
ContractPlane Evidence ledger contractplane_evidence table
Cedar Policy engine cedar_policy module
MemoryPlane Governed memory store Qdrant + OSSA MemoryContract

Prerequisites

See amcs-phase1-demo-runbook.md Steps 1–4 for exact setup commands.

Summary: - Drupal 11.x / Drupal CMS 2.0 with AMCS Starter Recipe applied - Contrib modules enabled: ai, ai_agents, ai_agents_ossa, tool, cedar_policy, contractplane_client, mcp_server, mcp_tools, ai_context - MemoryPlane module configured with Qdrant backend - MemoryPlane extends Drupal's ai_context and ContextControl patterns with governed memory contracts, evidence, and tiered promotion - LiteLLM proxy running with at least one model (Ollama acceptable for local acceptance) - Terminal access for evidence SQL queries - Sample webpage fixture with 4–5 accessibility violations


Launch Flow

Act 1: Meet the Agent (2 minutes)

What to show: The agent is not a black box. It has a portable identity.

  1. Show the OSSA manifest in the browser at /admin/config/ai/agents/accessibility-reviewer
  2. Point out: identity, capabilities, memory contract, governance constraints
  3. Say: "This manifest is portable. This same YAML deploys to Drupal today, Kubernetes via Kagent tomorrow, or any OSSA-compatible runtime. It is not locked to this CMS."

  4. Show the memory contract section

  5. Three collections: scan-results, remediation-history, false-positives
  6. Agent tier only — the agent cannot write to domain or global memory
  7. TTL: 48 hours for agent tier, 30 days for domain tier
  8. Say: "The agent has a memory contract. It defines what the agent can remember, where it stores it, and how long it lives. This is not a vague context window. It is a governed, auditable memory system."

Act 2: The Agent Scans (4 minutes)

What to show: The agent does real work and every action has a receipt.

  1. Trigger an accessibility scan against the sample page
  2. Technical steps: See amcs-phase1-demo-runbook.md Step 5
  3. Agent calls WCAG scanning tools via drupal/tool (Tool API plugins)
  4. Agent writes scan results to its scan-results memory collection via MemoryPlane
  5. Say: "The agent uses the Drupal Tool API — the same API that a large contrib library of MCP-compatible Drupal tools uses. It does not have a custom scanner. It uses the platform."

  6. 📍 Evidence Moment 1: memory.write.completed

  7. Open terminal, query contractplane_evidence:
    SELECT event_id, FROM_UNIXTIME(occurred_at), event_type, subject_id
    FROM contractplane_evidence
    WHERE event_type = 'memory.write.completed'
    ORDER BY occurred_at DESC LIMIT 5;
    
  8. Say: "Every memory write has a receipt. The agent cannot write silently. This row was created the instant the agent stored its scan results."

  9. Show the memory entry in MemoryPlane

  10. The agent's scan results are stored with content hash, source agent, session ID
  11. Say: "This memory is content-addressable. If anyone — human or agent — tampers with it, the integrity check will catch it."

Act 3: The Agent Remembers (3 minutes)

What to show: Memory makes agents smarter over time — and the reads are audited too.

  1. Trigger a second scan of a related page
  2. Agent reads its previous scan results from memory via MemoryPlane
  3. Agent uses prior context to identify patterns across pages
  4. Say: "The agent is not starting from scratch. It remembers what it learned on the first scan. It uses that context to find patterns."

  5. 📍 Evidence Moment 2: memory.read.completed

  6. Query contractplane_evidence for the read event:
    SELECT event_id, FROM_UNIXTIME(occurred_at), event_type, subject_id
    FROM contractplane_evidence
    WHERE event_type = 'memory.read.completed'
    ORDER BY occurred_at DESC LIMIT 5;
    
  7. Say: "We can prove the agent accessed its memory. We know what it read, when, and which session triggered it."

  8. 📍 Evidence Moment 3: memory.search.completed (if agent performed semantic search)

  9. Show the search event with query hash and result count
  10. Say: "Even semantic search is audited. We log the query hash and result count. No silent background retrieval."

Act 4: The Agent Tries to Promote — And Fails (3 minutes)

What to show: This is the money moment. Policy enforcement is real and provable.

  1. The agent requests memory promotion
  2. After finding a common pattern (e.g., "all pages missing alt text on hero images"), the agent requests to promote this finding from agent tier to domain tier
  3. Say: "The agent thinks this insight is valuable enough to share across the domain. It requests a promotion."

  4. 📍 Evidence Moment 4: memory.promote.requested

    • Show the promotion request in contractplane_evidence:
      SELECT event_id, FROM_UNIXTIME(occurred_at), event_type, subject_id
      FROM contractplane_evidence
      WHERE event_type = 'memory.promote.requested'
      ORDER BY occurred_at DESC LIMIT 5;
      
    • Source tier: agent. Target tier: domain. Justification included.
    • Say: "The request is on the record. Source tier, target tier, justification — all logged."
  5. 🚫 DENIAL MOMENT: Cedar blocks the promotion

    • Cedar policy evaluates: the agent does not have promote permission on the domain tier without operator approval
    • The promotion is denied automatically
    • Technical reference: See amcs-phase1-demo-runbook.md Steps 6–7
  6. 📍 Evidence Moment 5: memory.promote.denied

    • Show the denial event with policy_ref pointing to the Cedar policy:
      SELECT event_id, FROM_UNIXTIME(occurred_at), event_type, subject_id
      FROM contractplane_evidence
      WHERE event_type = 'memory.promote.denied'
      ORDER BY occurred_at DESC LIMIT 5;
      
    • Say: [Pause. Let it land.] "The agent cannot escalate its own memory. That requires a human. And the denial — including which Cedar policy blocked it — is on the permanent record."
    • This is the money moment. Pause for 3 seconds after saying this. Let the audience absorb it.

Act 5: The Operator Approves (2 minutes)

What to show: Human-in-the-loop is real, not a checkbox.

  1. Operator approves the promotion via the Drupal admin UI

    • Navigate to the memory promotion approval UI
    • Note: Target product route — requires implementation bead for Phase 1 release candidate
    • Review the justification, click approve
    • Say: "Now a human reviews the justification and approves. This is not a rubber stamp. The operator sees exactly what the agent wants to promote and why."
  2. 📍 Evidence Moment 6: memory.promote.approved

    • Show the approval event with approved_by field:
      SELECT event_id, FROM_UNIXTIME(occurred_at), event_type, subject_id
      FROM contractplane_evidence
      WHERE event_type = 'memory.promote.approved'
      ORDER BY occurred_at DESC LIMIT 5;
      
    • Say: "Now there is an unbroken chain: the agent requested, policy denied self-promotion, a human approved, and the memory was promoted. Every step has a receipt."
  3. Show the promoted memory now visible in the domain tier

    • Other agents in the domain can now access this insight
    • Say: "This is governed knowledge transfer. Not clipboard. Not Slack. Not a shared Google Doc. Auditable. Portable. Standard."

Close (1 minute)

  1. Summary

    • "In 15 minutes you saw:
    • An agent with a portable OSSA identity — runs on Drupal, exports to Kubernetes
    • Governed memory with three isolation tiers — agent, domain, global
    • Six evidence events proving every action — write, read, search, request, deny, approve
    • A Cedar policy that prevented unauthorized escalation — agents cannot grade their own homework
    • A human-in-the-loop approval that completed the chain — governance, not theater
    • All of this installed with one Composer command and one Drush recipe"
  2. CTA

    • "Install it: composer require bluefly/amcs-starter && drush recipe:apply bluefly/amcs-starter"
    • "Book a governance audit: bluefly.io/governance-audit"
    • "Read the standard: openstandardagents.org"

Evidence Moments Summary

# Event Type What It Proves
1 memory.write.completed Agent memory writes are audited — no silent storage
2 memory.read.completed Agent memory reads are audited — no silent retrieval
3 memory.search.completed Semantic search is audited — query hash + result count logged
4 memory.promote.requested Agent escalation requests are logged with justification
5 memory.promote.denied Policy enforcement is provable — Cedar policy ID on record
6 memory.promote.approved Human approval is on the permanent record

Failure / Denial Moment

Location: Act 4, Steps 11–12

What happens: The accessibility reviewer agent identifies a cross-page pattern ("all pages missing alt text on hero images") and requests to promote this insight from its private agent memory to the shared domain memory tier. Cedar policy evaluates the request and denies it because the agent does not have promote permission without operator approval.

Why this matters: The agent cannot escalate its own authority. It cannot decide that its insight is important enough to share with other agents. A human must approve. And both the denial and the approval are recorded as evidence events with integrity hashes.

What to say: "Your agents cannot grade their own homework."


Relationship to Operator Runbook

This launch script is the operator-facing launch script. The technical implementation steps (module enable commands, Drush commands, SQL queries, environment setup) are documented in amcs-phase1-demo-runbook.md.

This Script Covers The Runbook Covers
Narrative and positioning DDEV setup and module enable
What to say at each step Exact Drush and SQL commands
Audience engagement timing Cedar policy import steps
Evidence moment framing ContractPlane evidence verification
CTA and close AMC bundle export and validation
Objection handling Clean checkout reproducibility

Rule: If a technical step changes, update the runbook. If the narrative changes, update this script. Do not duplicate technical commands between the two files.


Drupal Contrib Architecture Notes

All components use Drupal contrib — not custom code:

Component Drupal Contrib Module Rule
Agent execution drupal/ai_agents Rule B — agents own execution
LLM calls drupal/ai Rule A — AI Core owns providers
Tool calls (WCAG scan) drupal/tool + drupal/tool_belt Rule C — tools own execution contract
MCP protocol drupal/mcp_server Rule D — MCP owns protocol
Workflow (if shown) drupal/eca Rule E — ECA owns workflow
Agent templates drupal/ai_agents_ossa 29 pre-built templates
Context storage drupal/ai_context Structured AI context
Policy enforcement cedar_policy Cedar authorization
Evidence contractplane_client ContractPlane evidence

Project Binding

Build onto existing projects. Do NOT create parallel systems:

Concern Existing Project Action
OSSA memory contract openstandardagents Extend spec/schema
AMC bundle openstandardagents/catalog Add accessibility-reviewer bundle
ContractPlane evidence contractplane-sdk + contractplane_client Add memory event schemas
Cedar policies cedar-policies + cedar_policy Add memory promotion policies
Drupal agent import ai_agents_ossa Import OSSA manifest
Drupal execution drupal/ai_agents + drupal/tool + tool_belt Use contrib execution
Memory storage ai_context first, then thin MemoryPlane adapter Evaluate ai_context before custom
LLM calls drupal/ai through LiteLLM No direct SDK calls
Workflow ECA or FlowDrop only No custom workflow
Protocol mcp_server / mcp_client only No custom REST
Docs/runbooks BluTown/bus/ledgers/runbooks/lanes/amcs-factory No scattered docs
Engineering tracking BluTown / Gas Town beads No ad hoc task lists