Agent-to-Agent (A2A)
Google built the protocol. We built the governance.
The A2A protocol — created by Google, now hosted by the Linux Foundation and backed by 150+ organizations — defines how agents communicate. GaaS is the governance layer that lets you say “yes” to workflows you’d otherwise handle manually. When actions go through a GaaS pipeline, you can let your agents do more.
GaaS is an A2A v1.0 agent, built on the official A2A SDK and tested on every change with the official A2A conformance suite (TCK): every MUST-level requirement it can test passes.
- from → to
- orchestrator → procurement-agent
- action
- delegate · source three supplier quotes
- verdict
- approve · 22 ms
- from → to
- procurement-agent → payments-agent
- action
- delegate · pay the chosen supplier
- verdict
- approve · 27 ms
- from → to
- payments-agent → bank gateway
- action
- transact · $48,000, new payee
- verdict
- escalate · 31 ms · held for a person
MCP gives agents tools. A2A gives agents colleagues. GaaS lets them do more.
The Membrane
Govern every action — or just the ones that matter.
GaaS is a policy enforcement point — a governance membrane. Intents flow in. The membrane evaluates each one against your policies. Approved actions flow out.
Both are valid. GaaS is a membrane — semi-permeable, selective, always present. You decide what passes through.
The Governance Gap
A2A defines communication.
It doesn’t define trust.
A2A is the language. GaaS is what lets operators say “yes” — because when actions go through a governance pipeline, you unlock workflows you’d never automate otherwise.
A2A + GaaS
The governance layer for the agent economy.
/a2a/proxy/* extension) is built, not yet switched on.Connect
Connect over A2A v1.0.
Everything an A2A client needs, as production runs it.
- Endpoint
- JSON-RPC at
POST https://api.gaas.is/a2a/v1. Every call needs theA2A-Version: 1.0header; without it the reply is error-32009, as the spec requires. - Agent Card
https://api.gaas.is/.well-known/agent-card.json. The old/.well-known/agent.jsonredirects there.- Methods
- SendMessage, SendStreamingMessage, GetTask, ListTasks, CancelTask and SubscribeToTask. Push notifications are not available yet (error
-32003). - Sign-in
- An API key in the
X-API-Keyheader, the same key as the rest of the API, is the only sign-in. - Isolation
- A task belongs to the organization whose key created it; any other organization gets “task not found”.
- Verdicts as states
- approve →
completed, block →rejected, escalate →input-required: a person decides, and a follow-up message on the task reports the decision. - Proxy
/a2a/proxy/*is a GaaS extension: it governs messages but does not forward them to the target agent yet.
Why Now
Regulation is arriving faster than governance.
FAQ
Frequently Asked Questions
Does adding GaaS governance to A2A agent calls add significant latency?
Routine A2A-mediated governance decisions clear the GaaS pipeline in under 100ms. For agent-to-agent workflows — which involve network round-trips, model inference, and tool execution that dwarf that figure — governance latency is imperceptible. Only high-stakes actions that trigger deliberation take longer (about 40–60 seconds end to end). You configure per-action risk thresholds to control which path each action takes.
How does GaaS handle trust between agents in a multi-agent chain?
Each agent has a trust tier on its profile (Registered, Verified or Certified; today every customer agent is Registered) and a trust score computed from its interaction history. When Agent A delegates to Agent B via A2A, each governed hop is recorded with its source agent, target agent and parent record, so the whole delegation chain can be walked and hash-verified (GET /v1/audit/{audit_id}/delegation-chain), and a Tier 1 policy limits delegation depth. Trust is not inherited: each hop is evaluated on its own.
Do all agents in a multi-agent system need to be individually registered?
Each autonomous agent that can change state in the world (send a message, execute a transaction, modify a record) should be individually registered. Sub-agents or tools that only fetch and return information do not. Rule of thumb: if it can act, it governs; if it only reads or transforms, it does not.
Can GaaS govern A2A actions without modifying the protocol?
Yes. GaaS integrates at the agent layer, not the protocol layer. Your agent declares intent to GaaS before executing the A2A-mediated action. The A2A message exchange is unchanged — no modifications to the protocol, agent card format, or inter-agent communication flow are required.
A2A connects your agents.
GaaS lets you automate more.
When governance is in place, you can say “yes” to workflows you’d otherwise handle yourself. Start with Shadow Mode — see exactly what GaaS would govern, zero enforcement, full visibility.