Architecture / Separate authority paths
Evidence informs.
Policy governs.
The agent coordinates two independent MCP servers. Knowledge supplies documentary evidence with provenance; Gateway supplies bounded live observation and governed actions. Neither server calls the other.
Agent flow
One agent, two separate sessions, explicit checkpoints.
- 01
Helix MCP Knowledge
Retrieve documentary evidence
Search selected official documentation and an explicitly authorised project space. Return source identity, scope, version context and retrievable sections.
Boundary: no connection to live Helix and no operational action.
- 02
MCP-capable agent
Contrast evidence and infer
Keep observed facts, documentary claims and inference distinct. Identify missing evidence, contradictions and the next permissible step.
Boundary: reasoning does not create authority.
- 03
Helix MCP Gateway
Observe live state or propose action
Use an explicit environment and policy-bounded operation. Reads establish current state; sensitive actions use a separate plan, review and apply path.
Boundary: policy can narrow the account's access, never expand it.
- 04
Policy + human review
Control the consequential step
Stop when a material fact is unresolved. If a sensitive action is later justified, present the exact proposal to a human before the authorised apply step.
Boundary: a useful preflight can end before any plan exists.
Separation is deliberate. Knowledge and Gateway do not communicate with each other. The authorised client opens separate sessions and carries only the evidence needed for its own reasoning and the next permitted call.
Responsibility map
Each claim has an owner.
- What the documentation says
- Knowledge evidence, with source and scope
- What the live target reports now
- Gateway observation, within explicit read policy
- What those facts may imply
- Agent inference, labelled and reviewable
- What is allowed
- Gateway policy and the authorised Helix account
- Whether a sensitive proposal proceeds
- Human review of the exact pending plan
