Skip to content

Framework-mediated boundaries

AIT does not intercept a framework merely because the package is installed. It becomes relevant where framework code emits a supported A2A, MCP, HTTP, stdio, SSE, WebSocket, or A2A-specific gRPC exchange. That emitted exchange is the testable boundary.

Framework code reaches AIT only through explicit A2A, MCP, streaming, or stdio adapters that share one decode, hold, decide, release, and evidence lifecycle. Framework code reaches AIT only through explicit A2A, MCP, streaming, or stdio adapters that share one decode, hold, decide, release, and evidence lifecycle. A mobile adapter view showing framework code entering an explicit protocol boundary before AIT can decode, hold, release, and record it. A mobile adapter view showing framework code entering an explicit protocol boundary before AIT can decode, hold, release, and record it.

Framework state is context, not proof of an agent hop. The transcript begins where a supported adapter observes a complete protocol message. Stronger claims require receiver state and an authorized observation source outside that delivery record.

Declared dependency ranges

The optional extras declare install ranges, not ecosystem certification:

Extra Declared package range What the declaration means
framework-langgraph langgraph >=1.2,<2 the optional dependency can be installed with this checkout
framework-crewai crewai >=1,<2 dependency compatibility only
framework-autogen autogen-agentchat >=0.7,<1 dependency compatibility only
framework-openai-agents openai-agents >=0.18,<1 dependency compatibility only
framework-microsoft-agent agent-framework-core >=1,<2 dependency compatibility only

A range in pyproject.toml does not show that every version, lifecycle, or provider combination has been executed. A compatibility claim needs a named test, exact installed version, retained run record, and evidence source.

Placement rule

For any framework:

  1. Identify the node, tool, handoff, executor, or client call that emits the cross-component exchange.
  2. Record the exact protocol and binding.
  3. Point that call at an AIT listener, or replace its MCP stdio command with the printed wrapper.
  4. Leave framework-internal state and traces enabled only when scope permits.
  5. Establish an unchanged baseline before pausing or editing traffic.
  6. Read the receiver and effect through sources appropriate to the target.

If the framework never emits a supported boundary, AIT has nothing to intercept. An in-memory object transition is not silently converted into an A2A or MCP message.

Evidence contract

Source What it can establish
Framework trace which local node, tool, or handoff code ran
AIT or Seam transcript which complete protocol message crossed the selected boundary
Receiver state what the selected receiver parsed, rejected, or stored
Out-of-band observation whether a controlled external effect followed
Close control whether the tested change, rather than any disturbance, explains the difference

No one source substitutes for the others. In particular, constructing an agent, graph, flow, handoff, or executor is not execution evidence.

Framework notes