Operator Onboarding
This guide is for a new operator who needs to understand what AGENT-33 does, how to get value quickly, and what surfaces matter first.
1. Understand the core surfaces
AGENT-33 has four primary operator surfaces:
- Control plane UI at
http://localhost:3000 - Runtime API at
http://localhost:8000 - Workflow and agent execution through
/v1/agents/*and/v1/workflows/* - Operational controls for reviews, evaluations, releases, autonomy, and memory
2. Know the first endpoints to verify
Start with these:
GET /healthGET /v1/agents/POST /v1/agents/{name}/invokeGET /v1/workflows/POST /v1/workflows/{name}/execute
See API Surface for the complete auth and scope map.
3. Know the main scope families
The most visible scopes are:
adminagents:readagents:writeagents:invokeworkflows:readworkflows:writeworkflows:executetools:executeoperator:readoperator:write
If you receive 403 Missing required scope, check API Surface before debugging anything else.
4. First operator workflow
Recommended first-run sequence:
- Start the stack with Docker Compose
- Verify
/health - Sign in to the UI
- Mint or obtain a JWT
- List registered agents
- Invoke the orchestrator
- Register and execute a minimal workflow
- Inspect dashboard and trace surfaces
Detailed commands are in:
5. Product areas to explore after first run
Agents
Use when you want direct, bounded execution against a named capability.
- discovery:
GET /v1/agents/ - invoke:
POST /v1/agents/{name}/invoke
Workflows
Use when you want repeatable multi-step execution.
- register:
POST /v1/workflows/ - execute:
POST /v1/workflows/{name}/execute
Reviews and releases
Use when you need explicit signoff and gatekeeping.
Evaluations and regression handling
Use when you need measured quality gates and baseline comparisons.
Memory and recall
Use when you need long-horizon context and retrieval-backed sessions.
6. What is local-only vs production-ready
Local-only defaults
- bootstrap login with
admin/admin - default secrets from
.env.example - convenience JWT minting from the API container
Production expectations
- disable bootstrap auth
- rotate secrets
- define your real identity and token issuing path
- use the production deployment and verification runbooks
- complete the Release Checklist
7. Operational guardrails to remember
- Most
/v1/*routes require authentication - Several services are still in-memory and reset on process restart
- Webhook endpoints remain unavailable until adapters are registered in-process
- Training surfaces exist, but some runtime wiring is partial by default