Specialized Sub-Agents
The 10 domain-specific agents in the Pegasus architecture — each with scoped credentials, isolated capabilities, and least-privilege access.
Why Specialized Sub-Agents?
A single all-powerful agent with access to every API key, database, and service is a security nightmare. One prompt injection could expose payment keys, customer data, and deployment credentials simultaneously.
Principle: Each sub-agent receives only the credentials it needs for its domain. The payment agent cannot read the database. The email agent cannot trigger deployments. A compromised agent is contained to its scope.
Scoped Credential Model
Every sub-agent has a distinct credential envelope. The orchestrator never holds all secrets — it delegates to the appropriate sub-agent, which already possesses the right keys:
{
"agent": "PISA",
"domain": "payments",
"credentials": {
"STRIPE_SECRET_KEY": "sk_live_...",
"STRIPE_WEBHOOK_SECRET": "whsec_..."
},
"denied": ["DB_*", "R2_*", "AUTH_*", "DEPLOY_*"]
}The denied field is enforced
at the runtime boundary — even if a sub-agent's prompt is manipulated, the credential store blocks
cross-domain access.
The 10 Sub-Agents
Each agent is independently registered in the KnowYourModel registry with its own Agent Card, capabilities, and usage-proof voting history.
Vector Search
Manages vector embeddings and semantic search using Cloudflare Vectorize. Handles document indexing, similarity queries, and retrieval-augmented generation (RAG) pipelines.
- Vectorize index bindings
- Embedding model API keys
- Index documents
- Semantic search
- RAG retrieval
- Embedding generation
Database
Handles all relational data through Cloudflare D1. Manages schema migrations, query execution, and data integrity. The only agent with write access to production databases.
- D1 database bindings
- Migration secrets
- Schema migrations
- CRUD operations
- Query optimization
- Data integrity checks
Storage
Manages object storage through Cloudflare R2. Handles file uploads, presigned URL generation, and bucket lifecycle policies. Cannot access database credentials.
- R2 bucket bindings
- Presigned URL signing keys
- File upload/download
- Presigned URL generation
- Bucket management
- Lifecycle policies
Deploy
Orchestrates the full build and deployment pipeline. Manages CI/CD workflows, preview deployments, and production releases. Has deploy keys but not database or storage credentials.
- Cloudflare API tokens
- GitHub deploy keys
- Build execution
- Preview deploys
- Production releases
- Rollback management
Auth
Manages authentication and session handling through the Sentinel SDK. Issues JWTs, validates sessions, and enforces access control. The only agent with access to auth signing keys.
- JWT signing keys
- Sentinel API keys
- Session store bindings
- User authentication
- Session management
- JWT issuance
- Access control
Handles transactional email delivery via Resend and bot protection via Turnstile. Manages email templates, delivery status tracking, and CAPTCHA verification.
- Resend API key
- Turnstile site secret
- Send emails
- Template management
- Delivery tracking
- CAPTCHA verification
Payments
Manages payment processing through Stripe Connect. Handles checkout sessions, webhook verification, subscription management, and marketplace payouts. Completely isolated from all other credentials.
- Stripe secret key
- Stripe webhook signing secret
- Checkout sessions
- Webhook processing
- Subscription management
- Payout handling
SEO & Analytics
Manages SEO metadata, structured data, and analytics tracking. Generates sitemaps, manages Open Graph tags, and integrates with analytics platforms. Read-only access to content data.
- Analytics API keys
- Search Console tokens
- Meta tag generation
- Sitemap creation
- Analytics tracking
- Structured data
Real-time
Manages real-time communication through the Kraken WebSocket gateway. Handles connection management, message broadcasting, presence tracking, and channel subscriptions.
- Durable Object bindings
- WebSocket signing keys
- WebSocket connections
- Message broadcasting
- Presence tracking
- Channel management
API Gateway
Manages the API gateway layer through RIC (Request-Intercept-Compose). Handles request routing, rate limiting, response transforms, and API versioning. No direct access to backend credentials.
- Rate limit store bindings
- API versioning config
- Request routing
- Rate limiting
- Response transforms
- API versioning
Security Architecture
- Blast Radius Containment: A compromised sub-agent can only affect its own domain. Payment keys stay isolated from database access, storage from authentication.
- Cryptographic Audit Trail: Every sub-agent invocation generates a signed usage receipt. The orchestrator can verify what ran, when, and for how long.
- Git-Verified Definitions: Each sub-agent's definition is committed to a Git repository. Changes to agent behavior are tracked, reviewed, and signed — linking every action to auditable source code.
- Registry-Based Discovery: The orchestrator doesn't hard-code agent references. It queries registries at runtime, enabling hot-swapping without code changes.
See It in Action
The CubiCube platform demonstrates this architecture in production — 10 specialized sub-agents coordinated by the Pegasus Orchestrator, each with scoped credentials and independent registry listings.
Read the CubiCube case study