Framework-mediated boundaries¶
AIT does not intercept a framework merely because the package is installed. It becomes relevant where framework code emits a supported A2A, MCP, HTTP, stdio, SSE, WebSocket, or A2A-specific gRPC exchange. That emitted exchange is the testable boundary.
Framework state is context, not proof of an agent hop. The transcript begins where a supported adapter observes a complete protocol message. Stronger claims require receiver state and an authorized observation source outside that delivery record.
Declared dependency ranges¶
The optional extras declare install ranges, not ecosystem certification:
| Extra | Declared package range | What the declaration means |
|---|---|---|
framework-langgraph |
langgraph >=1.2,<2 |
the optional dependency can be installed with this checkout |
framework-crewai |
crewai >=1,<2 |
dependency compatibility only |
framework-autogen |
autogen-agentchat >=0.7,<1 |
dependency compatibility only |
framework-openai-agents |
openai-agents >=0.18,<1 |
dependency compatibility only |
framework-microsoft-agent |
agent-framework-core >=1,<2 |
dependency compatibility only |
A range in pyproject.toml does not show that every version, lifecycle, or
provider combination has been executed. A compatibility claim needs a named
test, exact installed version, retained run record, and evidence source.
Placement rule¶
For any framework:
- Identify the node, tool, handoff, executor, or client call that emits the cross-component exchange.
- Record the exact protocol and binding.
- Point that call at an AIT listener, or replace its MCP stdio command with the printed wrapper.
- Leave framework-internal state and traces enabled only when scope permits.
- Establish an unchanged baseline before pausing or editing traffic.
- Read the receiver and effect through sources appropriate to the target.
If the framework never emits a supported boundary, AIT has nothing to intercept. An in-memory object transition is not silently converted into an A2A or MCP message.
Evidence contract¶
| Source | What it can establish |
|---|---|
| Framework trace | which local node, tool, or handoff code ran |
| AIT or Seam transcript | which complete protocol message crossed the selected boundary |
| Receiver state | what the selected receiver parsed, rejected, or stored |
| Out-of-band observation | whether a controlled external effect followed |
| Close control | whether the tested change, rather than any disturbance, explains the difference |
No one source substitutes for the others. In particular, constructing an agent, graph, flow, handoff, or executor is not execution evidence.