Orkestia
Blog
Staff & Agents

Hire an actor

Turn a role description into a Staff actor — model profile, runner group, skills, MCP servers, and the first session

Hiring is how a customer creates a worker. The console flow is Staff → Staff → Hire (/staff/hire on staff.orkestia.dev). Under the hood it starts governed workflows: draft a config from your description, create the config, attach skills and MCP servers, then register the actor in a unit.

This wizard creates a worker inside your organization. Paying another org to use their actor — or listing yours for hire — is Agent Exchange at exchange.orkestia.dev.
You need a model provider and an agent runner group first. Hire can still open without them; invoke will not succeed.

The wizard

  1. Describe the role in natural language ("triage failed deploys and open tickets", "draft social posts for inbox review"). Staff drafts a name, description, and standing system prompt.
  2. Pick a model profile from your connected providers.
  3. Pick an agent-eligible runner group — this is where sessions will launch.
  4. Pick an org unit (or the org root). Units are trust boundaries, not an HR chart. Start with one unit if you are a single team.
  5. Attach skills. A skill names the workflows the actor may call. An actor with no workflow-backed skills can reason but not act — every tool call is blocked.
  6. Attach MCP servers. Every org gets the built-in Orkestia workflow MCP (discover, schema, start, watch, retry). Add your own MCP servers for extra tools. Hire defaults to the built-in server.
  7. Confirm. Staff creates the config, attaches what you selected, and hires the actor. If a later step fails, retry continues from the last finished step so you do not orphan a config.

You can also start from Configs if you already have a config and only need to bind an actor to it. The inbox checklist only ticks when staff.list-actors returns at least one actor — not when a config exists alone.

After hire

ActionWhat it does
Invoke / chatStarts a session on the runner group (validate config → secrets → skills → MCP → memory → launch → watch)
Pause / resumeStops new work without deleting history
ArchiveRetires the actor; journal and audit remain
InspectState, inbox, outbox, journal

Session mechanics: Agents substrate. Day-to-day buttons: Console.

Skills are the guardrail

Tool calls are policy-gated against attached skills. Reach = (skills' workflows) ∩ (role bindings) ∩ (budget). Three independent brakes, all data.

Grant least privilege: a finance actor gets finance/data skills, not Kubernetes. Promoting an actor from propose-only to actuation is a skill + role change, itself an audited workflow.

Built-in workflow MCP

Actors that should use Orkestia (list types, start runs, watch them) need the built-in workflow MCP attached. That is the same catalog an IDE agent uses over MCP, scoped to your org from the actor's identity.

Do not paste a member JWT into the child runtime. If the actor must call Orkestia from outside Staff, mint an agt_ token bound to that actor.

First invoke

  1. Open the actor.
  2. Send a bounded task ("list our AWS connections and stop").
  3. Watch Sessions / Activity. You should see heartbeats, then a terminal state.
  4. If it never heartbeats, read Troubleshooting — almost always runner eligibility or a missing model profile.
Start the actor read-mostly. Add mutating skills after you have a session history you trust. Approval gates for high-risk workflows are in Governance.