Agent-to-Agent (A2A)

Google built the protocol. We built the governance.

The A2A protocol — created by Google, now hosted by the Linux Foundation and backed by 150+ organizations — defines how agents communicate. GaaS is the governance layer that lets you say “yes” to workflows you’d otherwise handle manually. When actions go through a GaaS pipeline, you can let your agents do more.

GaaS is an A2A v1.0 agent, built on the official A2A SDK and tested on every change with the official A2A conformance suite (TCK): every MUST-level requirement it can test passes.

delegation chain · a2a
Simulated
Hop 1 · depth 0
from → to
orchestrator → procurement-agent
action
delegate · source three supplier quotes
verdict
approve · 22 ms
Hop 2 · depth 1
from → to
procurement-agent → payments-agent
action
delegate · pay the chosen supplier
verdict
approve · 27 ms
Hop 3 · depth 2
from → to
payments-agent → bank gateway
action
transact · $48,000, new payee
verdict
escalate · 31 ms · held for a person
Audit chain
aud_1f…→aud_7c…→aud_e4…
Each hop recorded with its parentChain hash-verified

MCP gives agents tools. A2A gives agents colleagues. GaaS lets them do more.

The Membrane

Govern every action — or just the ones that matter.

GaaS is a policy enforcement point — a governance membrane. Intents flow in. The membrane evaluates each one against your policies. Approved actions flow out.

Every intent evaluated
7/7 pass through the membrane
Full membrane
Plan
Query
Analyze
Delegate
Execute
Validate
Report
GaaS
✓ pass
✓ pass
✓ pass
✓ pass
✓ pass
✓ pass
✓ pass
One checkpoint
1/7 evaluated — the rest fly blind
Selective
Plan
Query
Analyze
Delegate
Execute
Validate
Report
GaaS
no eval
no eval
no eval
✓ pass
no eval
no eval
no eval

Both are valid. GaaS is a membrane — semi-permeable, selective, always present. You decide what passes through.

The Governance Gap

A2A defines communication.
It doesn’t define trust.

What A2A provides
Agent Cards for capability discovery
Structured task lifecycle management
JSON-RPC 2.0 transport layer
Push notifications and streaming (GaaS’s endpoint streams; push notifications are not available yet)
Skill-based agent discovery
What GaaS adds
Policy evaluation on every interaction
Real-time risk scoring and thresholds
Tamper-evident audit trails
Human-in-the-loop escalation
Regulatory compliance (EU AI Act, PCI DSS, PSD2)

A2A is the language. GaaS is what lets operators say “yes” — because when actions go through a governance pipeline, you unlock workflows you’d never automate otherwise.

A2A + GaaS

The governance layer for the agent economy.

Enterprise
Compliance Audit Trails Trust Tiers HITL Escalation
GaaS
Policy Risk Scoring Verdicts Delegation Chains
A2A Protocol
Agent Cards Tasks JSON-RPC SSE
Agent Runtime
LLMs Tools Memory State
Governance Proxy
A2A messages sent to GaaS’s A2A v1.0 endpoint go through the five-stage governance pipeline — intent, context, policy, deliberation, decision — and the verdict becomes the task’s state: approve → completed, block → rejected, escalate → input-required, where a person decides. Forwarding messages on to the target agent (the /a2a/proxy/* extension) is built, not yet switched on.
Agent Trust Registry
A2A’s Agent Cards describe capabilities. GaaS adds dynamic trust scores based on interaction history, compliance posture, and governance track record.
Payment Governance
Agents executing financial transactions via A2A get spend-limit enforcement, PCI DSS and PSD2 compliance, and mandate validation before funds move.
Delegation Chains
A2A enables multi-agent delegation. GaaS audits every link — when Agent A delegates to B who delegates to C, each governed hop is recorded with its parent, and every record in the chain is hash-verified (SHA-256).
Cross-Org Federation
Built, not yet enabled: when A2A connects agents across organizations, GaaS negotiates governance requirements and verifies mutual compliance before the first message is exchanged.
Shadow Mode
Deploy governance on your A2A interactions without enforcement. See what would have been blocked, modified, or escalated — zero risk, full visibility.
governance-check
risk-assessment
audit-trail
escalation
deliberation
agent-trust
payment-governance
A2A Protocol, created by Google  ·  Linux Foundation  ·  150+ Organizations

Connect

Connect over A2A v1.0.

Everything an A2A client needs, as production runs it.

Endpoint
JSON-RPC at POST https://api.gaas.is/a2a/v1. Every call needs the A2A-Version: 1.0 header; without it the reply is error -32009, as the spec requires.
Agent Card
https://api.gaas.is/.well-known/agent-card.json. The old /.well-known/agent.json redirects there.
Methods
SendMessage, SendStreamingMessage, GetTask, ListTasks, CancelTask and SubscribeToTask. Push notifications are not available yet (error -32003).
Sign-in
An API key in the X-API-Key header, the same key as the rest of the API, is the only sign-in.
Isolation
A task belongs to the organization whose key created it; any other organization gets “task not found”.
Verdicts as states
approve → completed, block → rejected, escalate → input-required: a person decides, and a follow-up message on the task reports the decision.
Proxy
/a2a/proxy/* is a GaaS extension: it governs messages but does not forward them to the target agent yet.

Why Now

Regulation is arriving faster than governance.

The EU AI Act (Article 14) mandates human oversight for high-risk AI systems. As A2A adoption accelerates multi-agent deployments, enterprises need a governance layer between protocol and production. GaaS provides the policy evaluation, audit trails, and human-in-the-loop escalation that regulators require — without slowing down the agents that A2A connects.

FAQ

Frequently Asked Questions

Does adding GaaS governance to A2A agent calls add significant latency?

Routine A2A-mediated governance decisions clear the GaaS pipeline in under 100ms. For agent-to-agent workflows — which involve network round-trips, model inference, and tool execution that dwarf that figure — governance latency is imperceptible. Only high-stakes actions that trigger deliberation take longer (about 40–60 seconds end to end). You configure per-action risk thresholds to control which path each action takes.

How does GaaS handle trust between agents in a multi-agent chain?

Each agent has a trust tier on its profile (Registered, Verified or Certified; today every customer agent is Registered) and a trust score computed from its interaction history. When Agent A delegates to Agent B via A2A, each governed hop is recorded with its source agent, target agent and parent record, so the whole delegation chain can be walked and hash-verified (GET /v1/audit/{audit_id}/delegation-chain), and a Tier 1 policy limits delegation depth. Trust is not inherited: each hop is evaluated on its own.

Do all agents in a multi-agent system need to be individually registered?

Each autonomous agent that can change state in the world (send a message, execute a transaction, modify a record) should be individually registered. Sub-agents or tools that only fetch and return information do not. Rule of thumb: if it can act, it governs; if it only reads or transforms, it does not.

Can GaaS govern A2A actions without modifying the protocol?

Yes. GaaS integrates at the agent layer, not the protocol layer. Your agent declares intent to GaaS before executing the A2A-mediated action. The A2A message exchange is unchanged — no modifications to the protocol, agent card format, or inter-agent communication flow are required.

A2A connects your agents.
GaaS lets you automate more.

When governance is in place, you can say “yes” to workflows you’d otherwise handle yourself. Start with Shadow Mode — see exactly what GaaS would govern, zero enforcement, full visibility.