Skip to main content

Runtime Surface Map

AxonFlow exposes seven named runtime paths, plus framework adapters and control-plane APIs. Confusion starts when those three categories are mixed together.

  • A runtime path determines who executes an action and where policy is enforced.
  • A framework adapter helps a specific tool call one or more runtime paths.
  • A control-plane API manages policies, providers, connectors, audit records, or evidence. It is not another execution mode.

For endpoint-level detail, use Runtime Request Paths. For a recommendation, use Choosing an Integration Mode.

The Complete Runtime Model​

FamilyPathExecution ownerPrimary purpose
Caller-owned executionDecision ModeInfrastructure gatewayCentral policy decisions across traffic behind a shared gateway
Caller-owned executionGateway ModeApplicationPre-check and explicit audit around an existing provider call
Caller-owned executionMCP governanceMCP host or connectorInput, output, and connector-scoped policy around tool calls
Caller-owned executionWCPExternal orchestratorStep gates and lifecycle records around an externally executed workflow
AxonFlow-managed executionProxy ModeAxonFlowGoverned model request, provider routing, usage, and audit in one flow
AxonFlow-managed executionMAPAxonFlowGenerated plan, governed execution, versions, and plan lifecycle
Advanced service accessDirect OrchestratorDepends on selected APILow-level access for a trusted internal platform service

This grouping explains useful similarities without collapsing distinct contracts. Gateway Mode and WCP both keep execution with the caller, but one surrounds a model call and the other surrounds workflow steps. Proxy Mode and MAP both keep execution inside AxonFlow, but one processes a model request and the other owns a generated plan.

Ownership Map​

Runtime Path Boundaries​

Decision Mode​

Use an infrastructure gateway as the enforcement point. It calls POST /api/v1/decide, applies the verdict, and fulfills supported obligations before forwarding.

Start with Decision Mode.

Gateway Mode​

Keep the direct provider call in application code. The application calls /api/policy/pre-check before the provider and /api/audit/llm-call afterward.

Start with Gateway Mode.

Proxy Mode​

Send the model request through Agent POST /api/request. AxonFlow owns the governed provider lifecycle and routes ordinary processing to Orchestrator /api/v1/process.

Start with Proxy Mode.

MCP Governance​

Govern tool input and output at MCP boundaries. This is the path that carries connector identity for connector-scoped policy.

Start with MCP Overview and MCP Policy Enforcement.

Multi-Agent Planning​

Use /api/v1/plan and /api/v1/plan/execute when AxonFlow should generate, store, and execute a plan.

Start with Multi-Agent Planning Overview.

Workflow Control Plane​

Use WCP when LangGraph, n8n, Temporal, Airflow, or another engine should keep workflow execution. The external engine calls AxonFlow before and after each governed step.

Start with Workflow Control Plane.

Direct Orchestrator​

Use Orchestrator :8081 directly only from a trusted internal service. The chosen endpoint still determines whether the operation is governed processing, MAP, WCP, predefined workflow execution, or a control-plane action.

Start with Orchestrator API Endpoints and the Authentication and Header Matrix.

Predefined Workflow Execution​

POST /api/v1/workflows/execute lets a caller submit a workflow definition for AxonFlow-managed execution. It is not WCP because the external caller does not execute each step, and it is not MAP because AxonFlow does not generate the plan from an objective.

Treat it as a workflow variant within the AxonFlow-managed family. See the Workflow and MAP API.

Framework Adapters​

Framework integrations choose or combine the runtime paths above. They do not create new governance semantics by themselves.

Framework or toolCommon path choices
LangChainGateway or Proxy for model calls; MCP for tools; WCP for explicit workflow state
LangGraphGateway for wrapped calls; WCP for node gates; MCP for tools
Google ADKPlugin callbacks around model and tool boundaries; MCP for connector-scoped controls
CrewAIGateway around wrapped model or crew calls; MCP for governed tools
n8nWCP-style gates or explicit HTTP calls at selected workflow positions
Claude Code, Cursor, CodexHook-based tool governance where the IDE exposes a blocking hook
LiteLLM or infrastructure gatewaysDecision Mode for shared enforcement; Proxy where AxonFlow owns provider routing

Start with the SDK and Integration Overview and then verify the interception point documented on the framework page. A hook or wrapper only governs calls that actually pass through it.

Control-Plane APIs​

The following surfaces configure or inspect the runtime. They are not additional modes:

  • policy CRUD and policy hierarchy
  • provider and routing configuration
  • connector administration
  • audit, usage, decision, and workflow search
  • evidence and compliance exports
  • organization, identity, and deployment administration where enabled

Reach these APIs through the Agent proxy where supported, or through a trusted Orchestrator connection. Keep their operational permissions separate from application runtime credentials.

Common Combinations​

ArchitectureCommon combination
New model-backed applicationProxy Mode plus MCP governance for connector work
Existing application or frameworkGateway Mode plus MCP governance for tools
Existing external workflowWCP plus MCP governance at tool steps
AxonFlow-generated agent planMAP plus MCP governance for connector steps
Shared enterprise gateway estateDecision Mode, adding MCP governance where connector-specific controls matter
Internal platform control surfaceAgent for application traffic, Direct Orchestrator for trusted automation only

Common Misconceptions​

  • WCP and MAP are not synonyms. WCP governs an externally executed workflow; MAP generates and executes a plan inside AxonFlow.
  • Gateway Mode and Decision Mode are not synonyms. Gateway Mode is an application pre-check and audit pair; Decision Mode is a gateway-facing decision contract with obligations.
  • Proxy Mode and Direct Orchestrator are not synonyms. Proxy Mode normally starts at Agent /api/request; Direct Orchestrator is a service-access choice that can reach several endpoint families.
  • MCP governance is composable. It adds connector identity and tool input/output checks to other paths.
  • Framework integrations are adapters. Their coverage is limited to the model, node, hook, or tool boundaries they actually intercept.