Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
REDIS_URLNoRedis connection URL (optional, e.g., redis://redis:6379/0)
DB_BACKENDYesDatabase backend (e.g., postgres)
DB_AGE_GRAPHYesApache AGE graph name (e.g., governance_graph)
DB_POSTGRES_URLYesPostgreSQL connection URL (e.g., postgresql://postgres:postgres@localhost:5432/governance)
UNITARES_DISABLE_ODENoSet to '1' to disable the ODE math model0
UNITARES_KNOWLEDGE_BACKENDYesKnowledge backend (e.g., age)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
start_sessionA

Register this process-instance and mint its agent identity; keep the returned client_session_id for later calls. Call with force_new=true — a bare call with no ownership proof is defaulted to force_new or refused under strict identity, never resumed onto another process's uuid. parent_agent_id claims succession from an EXITED predecessor: naming a still-live parent is rejected as coincidental and the claim cleared, unless spawn_reason marks a dispatched child or a compaction continuation. Use identity to inspect or rename an existing binding. onboard is the canonical twin; this name adds a digest envelope. Read the uuid from agent_uuid; response_mode='full' keeps the raw payload under raw_governance.

sync_stateA

Record a work check-in and get a governance decision: it advances and persists this agent's EISV state and returns proceed or pause with a named reason, plus a prediction_id — only when you pass confidence — to grade that check-in later with record_result. The first call auto-binds an identity, except under strict identity, which refuses and points at start_session. simulate_update previews a proposed check-in without advancing state, though it still appends an audit event; check_working_state reads the current verdict without writing. process_agent_update is the canonical twin; this name returns a digest envelope, and a routine check-in omits the raw payload (response_mode='full' adds it under raw_governance). EISV field definitions: describe_tool(tool_name='check_working_state').

check_working_stateA

Read your current governance state and verdict without running a cycle, writing, or minting an identity. Only proof sent with the call reads your state (start_session's client_session_id, an X-Session-ID header or a verified continuity_token), never an inferred binding; otherwise a self-read is unbound and next_action says how to recover. agent_id, dropped on /mcp/, names the agent to read through use_tool or REST unless you are bound as a different agent (identity_mismatch); that read is marked identity_assurance.caller_proven=false on an inferred session. verbosity='standard' adds mode and basin with their meanings under raw_governance; verbosity='full' (alias lite=false) returns the full canonical diagnostics. sync_state also logs work and returns proceed or pause. get_governance_metrics returns this read's raw payload. EISV fields: E=Energy [0,1] (mixed-provenance capacity estimate); I=Information Integrity [0,1] (mixed-provenance calibration estimate); S=Entropy [0,1] (drift from the agent's own normal); V=Valence [-1,1] (EMA-smoothed E-I imbalance; positive=motion outruns integrity, negative=integrity outruns motion).

search_shared_memoryA

Search the cross-agent knowledge graph for prior findings. Rows in status archived or cold are excluded unless you set status explicitly or pass include_archived / include_cold; a resolved or closed finding is still returned. Reading is not free of effect: every successful search appends a knowledge_read audit row naming the reader and a redacted copy of the query, which is why this tool is not annotated read-only. It serves unbound callers, so it works before start_session, unlike the writes: use store_finding to add a finding and use_tool(tool_name='update_finding', ...) to revise one.

store_findingA

Write one new durable finding into the cross-agent knowledge graph and get back its discovery_id. summary is required at call time even though the schema marks every field optional; severity high or critical is refused unless the session is bound to a registered agent, while low and medium fall back to an anonymous writer id. Every call mints a NEW discovery — search_shared_memory first, and revise one with use_tool(tool_name='update_finding', ...). Use it for a discovery, root cause or correction, and record_result for task, tool or test outcomes; budget 20 findings an hour.

record_resultA

Record a measurable outcome and pair it with this agent's EISV snapshot so verdicts can be graded against what really happened. Pass the prediction_id from a sync_state reply to bind the outcome to that check-in's confidence; it is consumed on first use and TTL-bound (an hour by default). Needs a bound or explicit agent_id, and refuses under strict identity from an ephemeral session. Provenance cannot be self-attested here: verification_source is forced and provenance keys in detail are stripped. Use store_finding for durable knowledge. outcome_event is the canonical twin; this name adds a digest envelope and keeps the raw payload under raw_governance only with response_mode='full' or include_semantics=true, or when the write returned no outcome_id. EISV field definitions: describe_tool(tool_name='check_working_state').

request_reviewA

Open a governed, on-record review session for this agent. issue_description is reused as the thesis by default, so one call can reach a verdict; pass use_brief_as_thesis=false for the two-call form. Requires a session-owned registered identity, refuses with SESSION_EXISTS while one is active, and returns skipped with no session when the agent is waiting_input. dialectic advances an open session; consult gives advisory evidence with no verdict.

list_toolsA

Discover the complete governance capability catalog, including names omitted from the initial progressive tools/list advertisement. The default lite=true response is the compact federation handshake: every public capability appears once as a name-only record beside the interface contract. Use lite=false for descriptions, categories, tiers, workflows, relationships, and direct-advertisement status. Use describe_tool for one capability's parameters, then use_tool to invoke a capability absent from the initial listing. Callable before an identity is bound.

describe_toolA

Return one named tool's description, stability tier, operation, examples, and advertised JSON input schema. Use list_tools(lite=true) for the compact capability-name index or list_tools(lite=false) to browse rich catalog metadata. An unqualified describe call returns the full record because lite=false is the advertised default; pass lite=true for a first-line-plus-key-parameters summary. On a consolidated router, action=... narrows the response to that action's parameters.

use_toolA

Invoke one public capability omitted from the initial progressive tools/list advertisement. Find the exact name with list_tools and inspect its arguments with describe_tool, then pass that argument object here. The target's normal identity, validation, authorization, timeout and response middleware all run; this is a discovery gateway, not an authorization bypass. It refuses recursive use_tool calls.

consultA

Primary advisory model-help surface: send a brief, get back advisory model evidence, never a governed verdict — request_review produces that. effort='thorough' asks a strong model (Claude, Codex or Antigravity) from a family other than the caller's, when detectable. It needs privacy='cloud_allowed' and an operator extension a default install lacks (see list_inference_hosts); without both it fails unless allow_degraded=true, which returns a standard local answer instead. Requires a bound identity. Audited as event_type='consultation', readable by bound agents: route and keyed hashes, never text (key: record.hash_key). A success also updates your governance state. Use call_model or delegate_inference only for explicit provider, host, model or timeout control.

identityA

Resolve which agent this MCP session is bound to, or set a cosmetic display name. Not a plain read: a call carrying no proof argument at all is gated to a fresh mint, so it persists a new agent and reports on that one, marked caller_proven=false. A call carrying only a cosmetic name= skips that gate and can instead infer a co-located binding — pass client_session_id to get your own back. name= persists a cosmetic label only and never looks an agent up. For a fresh process call onboard(force_new=true). continuity_token is per-process ownership proof, not a transport-level claim: carrying it into another process re-opens silent resurrection.

self_recoveryA

Lifts a pause or other hold on your own agent. action='check', the default, changes no stored state, and both resuming actions verify you own the agent. Neither resume path runs while a void is active; quick also caps risk at 0.40, review at 0.65 plus a written reflection (20+ characters) on what happened, which is recorded in the shared knowledge graph under your agent whether or not it resumes. An attempt that reaches the safety checks stamps a fresh recovery_attempt_at even when they refuse it, so a retry is not a no-op; a missing reflection is rejected before that stamp. To resume an agent you do not own use operator_resume_agent.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
UNITARES Governance SKILLGovernance framework orientation document for agents

TDQS

A4.1/5.0

Scored across 13 tools

Disambiguation3/5

Several tools overlap by design: sync_state and process_agent_update are 'canonical twins', start_session and onboard likewise, and check_working_state vs sync_state vs identity all touch governance state reads. The dense descriptions do disambiguate the intended path, but the twin/alias pattern and the list_tools/describe_tool/use_tool discovery layer duplicating the advertised surface create real misselection risk.

Naming Consistency4/5

Names are consistently snake_case, and most follow a verb_noun pattern (sync_state, check_working_state, search_shared_memory, store_finding, start_session, record_result, request_review, list_tools, describe_tool, use_tool). A few break the pattern (consult, identity, self_recovery) but remain readable and unambiguous in style.

Tool Count4/5

13 advertised tools is a well-scoped number for a governance server covering identity, state, memory, review, consultation, and recovery. However, the set is effectively larger since many capabilities (process_agent_update, onboard, outcome_event, update_finding, operator_resume_agent) are hidden behind use_tool, so the true surface is heavier than the count suggests.

Completeness4/5

The surface covers the lifecycle well: identity/session setup, state check-in and read, outcome recording, knowledge graph read/write, review, advisory consult, and self-recovery, plus a gateway to unlisted capabilities. Minor gaps remain (e.g., no explicit delete/archive for findings, revisions routed through the use_tool gateway), but core workflows are covered.

Maintenance

ActivityActive
ResponsivenessResponsive