---
name: argus-multi-agent-workflow
description: Coordinate machine-readable Argus fact retrieval with structured, neutral handoffs.
---

# Argus Data Layer Handoffs

## Customer-Side Installation

Set `ARGUS_BASE_URL`, run `argus auth login`, and use the live Agent Tool Registry as the runtime authority. Approved unattended clients may read `ARGUS_MACHINE_API_KEY`; do not pass credentials through a remote shell.

Authentication is independent for each participant; discover capabilities with `tool:agent_tool_registry`. Share only returned structured facts and metadata when permissions and license terms allow it.

Use explicit subjects, symbols, filters, and request `as_of`; validate returned `effective_as_of` as response metadata. Use `tool:evidence_bundle_export` for a reproducible structured handoff. Include audit identifiers and coded coverage gaps.

Discover with `argus tool-registry` and apply binding `parameter_aliases` and `parameter_encodings`. CLI/MCP list arguments are comma-separated strings; REST lists are JSON arrays. Read live OpenAPI or MCP `list_tools().inputSchema` for executable shapes. Business responses use `success`/`result`/`audit_id`; registry discovery is a raw snapshot. With OAuth omit caller/institution fields. Check MCP `isError` before decoding structured content and resolve real production subjects rather than copying example identifiers.

Argus does not orchestrate Agents, persist user lists, create narratives, recommend actions, execute strategies, or control accounts. Credentials are never shared between participants.

## OAuth tool grants

Discovery does not grant execution rights. Check `permission_requirements.default_oauth_access`; the signed public OAuth scope covers only the reviewed default whitelist. `metric_catalog` and the five `stream_*` tools need explicit signed tool grants plus required scopes, or an authorized machine credential. Permission, tenant, source-license, and output-policy checks always apply. Do not retry a permission denial unchanged.
