kural
kural is the company's only mouth — the one system that engages the outside world. A multi-agent force you buy on Marketplace, or hire over A2A so a buyer's own CRM and calendar agents can dispatch it. It discovers the right companies, researches each one in parallel, writes outreach worth reading, an LLM-as-judge fact-checks every claim, then sends the email as the buyer and books the meeting — and its Publisher wields the channel keys (X · Instagram · LinkedIn) — custodied by manas, never held in the mouth — to put kalai's media and kural's own copy live and answer every comment. A real, OAuth-authenticated, safe-by-construction irreversible action — not a draft sitting in your outbox.
One prospect enters the SequentialAgent spine. The Coordinator qualifies it, the Researcher fans out across the company in parallel, a brief and a draft are written, then the Fact-Checker runs as an after_agent judge — and only when it clears the gate does the safe-by-construction Sender fire the OAuth send + book. (When the dispatch is creative rather than email, the Publisher pairs kalai's cleared media with kural's own authored copy and takes it to the channels behind the founder's publish sign-off — the day's second tap.) Flip to single agent to see why one generalist loses.
Static view · the SequentialAgent spine in run order: Prospect → Coordinator (Claude·Vertex, qualify head) → Researcher (Gemini, ParallelAgent fans out 3 research tasks) → Market Intel → Writer → Fact-Checker (Claude·Vertex, after_agent LLM-as-judge gate @0.8) → on a clear, the safe-by-construction Sender (Gemini) sends as the buyer & books the meeting → meeting booked. For creative dispatch, the same mouth's Publisher (wields the X / IG / LinkedIn keys, custodied by manas) puts kalai's cleared media — paired with kural's own authored copy — live behind the founder's publish sign-off — the day's second tap. Enable JavaScript to run it live and compare against a single agent.
Take Northbeam, a seed-stage B2B SaaS with eight people and a fresh round: it needs qualified pipeline now, but a single ramped SDR costs more than its monthly burn allows. So the founder does outbound herself, badly: a generic template blasted to a scraped list, no research, no fact-checking, sent at the wrong time to the wrong person. It burns the list and the brand at once. Outbound is slow, generic, and dangerously easy to get wrong — and getting it wrong is irreversible too.
Seed → Series B startups
Founders and tiny GTM teams who need outbound now and can't hire a full sales org. Northbeam buys kural instead of a headcount.
Lean revenue teams
One RevOps lead who wants research-grade outbound at SDR-team volume, without the SDR team to manage.
Agencies & studios
Run client outbound at scale with a per-client safety gate and an audit trail of every message sent.
kural runs a deterministic spine — an ADK SequentialAgent (qualify → research → market intel → write → fact-check → send) — with a parallel research burst in the middle. Each stage hands its work to the next via output_key → {placeholder} with a Pydantic output_schema and locked sub-agent boundaries; nothing is sent until the after_agent LLM-as-judge gate clears it.
Discover & qualify prospects
The Coordinator builds the target set from your ideal-customer profile and decides what is actually worth pursuing — not everyone makes the cut. Weak fits are dropped before a cent of research is spent.
Research every prospect in parallel
The Researcher is a real ParallelAgent fan-out — one research task per company, all at once — grounded on live Google Search and Vertex AI Search. Funding, hiring, product launches, the named buyer, recent posts. Real facts, with sources. The fan-out is modeled on the enterprise parallel_task_decomposition_execution sample.
Read the signals, find the angle
Market & Growth Intelligence reads the research for the one reason this company should care right now — the trigger event, the pain, the timing — and hands a sharp brief to the writer.
Draft the tailored message
The Personalisation Writer drafts outreach built on the angle and the facts — specific, short, and addressed to a real person, not a merge field. One message per prospect, never a template blast.
The after_agent judge — fact-check, score, gate
The Fact-Checker runs as an after_agent LLM-as-judge: it verifies every claim against the cited research and scores the message on a rubric (tone, anti-spam, brand policy, claim support). Below the 0.8 bar — the same rubric-judge pattern as the small-business-loan sample — the message is sent back to the Writer, never sent out.
The judge clears the gate — then the safe-by-construction send
Once the after_agent judge clears it, the Sender is safe by construction: a before_tool callback re-checks eligibility and value caps, a confirm-before-send step gates the irreversible call, and a Firestore pause / repair / resume ledger means a crash can never double-send. Only then does the Sender send the email as the buyer (OAuth) and book the meeting on their calendar — OTel-traced, logged to BigQuery.
A single chatbot writing a cold email is a toy. kural wins because work moves down a SequentialAgent spine of specialists who each do one thing well, and the two highest-stakes judgments — who is worth pursuing, and whether a message clears the send gate — run on Claude via Vertex AI, while Gemini powers the high-volume routine agents. Both models, one Google Cloud runtime. kural is the company's only mouth: the Coordinator decides, the spine works, and only the Sender (outreach email + booking) and the Publisher (wielding the social channel keys manas custodies) ever touch the outside world — each behind a gate.
Coordinator
qualify head of the spineThe entry of the SequentialAgent spine. It qualifies prospects and decides what's worth pursuing — the highest-stakes who-do-we-pursue judgment — then emits a Pydantic output_schema object under an output_key that the next agent reads. Sub-agent boundaries are locked, so it cannot reach past its one job. Qualification can burn a list, so it runs on the strongest judgment model.
Researcher
ParallelAgent fan-outA real ParallelAgent — spins up one research task per prospect and runs them all at once, grounded on live web sources so the facts are real and cited. The fan-out is modeled on the enterprise parallel_task_decomposition_execution sample (the GTM-cluster samples have none).
Market / Growth Intelligence
finds the angleReads the research for the trigger event and the reason-to-care-now, then writes a tight brief for the writer.
Personalisation Writer
drafts outreachTurns the angle plus the verified facts into one short, specific message per prospect — addressed to a person, never a template.
Fact-Checker
the after_agent judge · owns the gateRuns as an after_agent LLM-as-judge: scores every claim against the cited research on a rubric (claim support, tone, anti-spam, brand policy). Below the 0.8 bar the message goes back to the Writer, never out. This is the send gate — the second highest-stakes judgment, so it too runs on the strongest model.
Sender
safe by constructionOnly fires once the judge clears the gate. A before_tool callback re-checks eligibility + value caps, a confirm-before-send step gates the call, and a Firestore pause / repair / resume ledger means a crash never double-sends. It sends as the buyer (OAuth) — never a shared key — and books the meeting.
Publisher
wields the channel keys · the only mouthThe only agent that wields the channel keys — X · Instagram · LinkedIn — though even it never holds the raw tokens: manas custodies them; the mouth gets a scoped, tokenless grant. It takes kalai's compliance-cleared media over A2A, pairs it with kural's own authored copy, formats it per channel, and publishes only after the founder's publish sign-off (the day's second tap). It also posts the cleared comment-replies through this same spine. It never edits kalai's creative — a tweak goes back to kalai.
Nothing else in the company touches the outside. The Coordinator decides who is worth pursuing, the spine researches and writes, but only kural engages — and within kural only the Sender (outreach email + booking) and the Publisher (the social channels) ever cross the line into the world. Both fire behind a gate, and the human gate that puts creative live is the founder's second tap, held right here at the mouth.
Publisher — wields X · Instagram · LinkedIn
No other agent in the company — not the Coordinator, not the Sender, not kalai — wields a social channel key; only the Publisher does, and even it never holds the raw token — manas custodies the keys and lends the mouth a scoped, tokenless grant. The Publisher takes kalai's compliance-cleared media over A2A, pairs it with kural's own authored post copy, formats per channel (caption length, aspect, tags, the platform's own affordances), and publishes only after the founder's publish sign-off. It never edits kalai's creative; if a live piece needs a tweak, the Publisher returns it to kalai and waits — the Publisher carries; kural's Writer authors the words upstream.
kalai's Compliance check is an internal, fail-closed gate before the handoff; the human sign-off is the founder's second tap at the Publisher, at the mouth, just before the world. arivu commands, kalai makes the media, kural writes and speaks. kural never edits kalai's creative — a tweak returns to kalai.
Inbound engagement · comment & mention replies — the same safe spine
Conversations create replies. When a mention or comment comes in, it is not answered on some separate, weaker path — it flows through the exact same writer → fact-check → send spine as outreach. kural listens through manas, drafts in the founder's voice, clears every claim, and only then posts. Sensitive replies are held for the founder.
manas surfaces the inbound
manas's Social Sentiment Imbiber pulls the mentions, comments and replies that kural's conversations generate and hands them over A2A as cited candidate signals. manas knows; it never posts or decides.
Personalisation Writer drafts the reply
The same Writer drafts the response in the founder's voice, grounded in manas — never out-of-corpus, never invented. One reply, specific to what was actually said.
Fact-Checker clears it — same gate
The reply clears the same after_agent LLM-as-judge gate @0.8 as outreach — claim support, tone, anti-spam, brand policy. Below the bar it goes back to the Writer, never out. No second, weaker path.
Shipped through the Sender / Publisher spine — sensitive replies HELD
Cleared replies post through the same Sender / Publisher spine — the Sender for direct/email channels, the Publisher for the social channels whose keys it wields (manas custodies them). A sensitive reply is held at a founder gate before it goes out. Same safety, no shortcut.
kural authors the post copy, then carries kalai's cleared media and formats it per channel. It never alters the creative itself — a media tweak returns to kalai, who makes.
Every outbound message and every reply clears the after_agent LLM-as-judge gate @0.8, grounded in manas's cited corpus — refuses out-of-corpus.
One researched message per prospect, one grounded reply per comment — never a template blast. The list and the brand survive.
Creative reaches the world only through the Publisher, behind the founder's publish sign-off — the day's second tap. The mouth waits for the human.
kural is scaffolded with the agent-starter-pack and built on Google's Agent Development Kit, running entirely on Google Cloud. Gemini powers the many routine agents; Claude (Sonnet / Opus) runs through Vertex AI Model Garden for the two highest-stakes decision agents. It ships with a checked-in eval set, OTel + BigQuery observability, and a safe-by-construction action gate — the Google-grade bar, not a demo.
Track 3 fit — the four mandates, checked
A product other companies buy on Google Cloud Marketplace and provision into their own org — Northbeam (our named seed-stage B2B SaaS buyer) installs it into its own project, not a consumer app.
Deployed to Vertex AI Agent Engine via deployment/deploy.py (Cloud Run + IAP secondary), autoscaling and per-tenant isolated in the buyer's own project; always-on cadence via Cloud Scheduler + OIDC.
Gemini plus Claude through Vertex AI Model Garden — every model call runs through Vertex on Google Cloud, grounded by Vertex AI Search.
Exposed over A2A via to_a2a() with a published Agent Card and a StreamableHTTP MCP server, so a buyer's CRM and calendar agents can discover kural and hire it — authenticated per request as the buyer.
kural replaces the part of an SDR team Northbeam can't justify hiring: the research and the writing at volume, done well, behind an LLM-as-judge gate and a safe-by-construction send the founder controls. The buyer keeps the judgment that matters — who to target, what the offer is — and hands kural the grind. And because kural speaks A2A, Northbeam's own CRM agent can hire it directly.
Time
The ~3.5 hours of research-and-write per genuinely personalised sequence collapses into a parallel run measured in minutes.
The list
The send-safety gate + fact-check stop the one-shot mistake that quietly torches a target account forever.
Headcount
Outbound coverage at team scale before the company can justify — or manage — a sales org. Buy it, plug it in, grow.
The agent doesn't just suggest the email. It researches the company, an LLM-as-judge checks every claim, it clears the send gate, and then it actually sends it as the buyer and books the meeting. That last step — live, not a mock — is the product.