certslothcertsloth
← PAA overview

Professional Agentic Architect / STUDY TOOLS

Professional Agentic Architect — Quick review

As checked 10 October 2026, beta registration is closed and Google announces general-availability registration for 2 November. This is an advance refresher based on the published beta guide; recheck the final scope before booking.

Reviewed 10 October 2026. Use the linked official exam guide for your exam version. These are condensed revision notes; the topic pages provide worked distinctions and more recall practice. Google’s 2026 guides use newer Gemini Enterprise Agent Platform names while some APIs and documentation still use Vertex AI.

Memory hook: Ground knowledge, bound tools, evaluate trajectories, govern identities.

Availability caveat: this is the published beta-scope revision guide. On 10 October 2026, Google states beta registration is closed and general-availability registration opens 2 November. Recheck the official guide when booking; future scope may change. Agent Runtime was formerly Agent Engine; Agent Search was formerly Vertex AI Search.

1. Build low-code agents — 1.1–1.2

Use explicit pages/states, transitions and event handlers for mandatory ordered processes; generation can interpret requests without owning the entire control flow. Gemini Enterprise Agent Designer and Customer Experience Agent Studio serve supported low-code workflows. Instructions define task, limits, data/tool usage, format and escalation. Examples demonstrate behavior; a system prompt alone cannot enforce permissions.

Enterprise connections need source identity, document ACLs, tenant boundaries, ingestion refresh and deletion propagation. Process text/image/audio/video with appropriate extraction and preserve source metadata. Transcription/captioning may lose context; test representative material. Agent Search supplies retrieval capabilities but does not authorize every connected record for every user.

2. Use coding agents safely — 2.1–2.2

Antigravity and supported coding agents combine repository context, skills, MCP tools, hooks/rules, plugins and subagents. Capability is not authorization. Use isolated workspaces with narrow credentials, filesystem/network scope and explicit task boundaries. Cloud Workstations/GKE can supply controlled environments; broad mounted credentials defeat nominal isolation.

Workflow: define observable behavior → scoped investigation → reviewable patch → independent tests/security checks → inspect diff → approved delivery. For performance fixes measure before/after; for vulnerability work verify the exploit path is removed. Generated tests may reproduce the same mistaken assumption. Agents CLI/registries help supported enterprise workflows; distinguish human administrative mode from delegated agent operations and audit both.

3. Build custom systems — 3.1–3.3

Choose model size, managed/self-hosted deployment and open/proprietary licensing by task evidence, latency, cost, privacy and operations. ADK supplies agent/tool composition. Session state is current interaction context; durable memory retains selected cross-session information. Managed sessions/Memory Bank require per-user/tenant access, consent/provenance and expiration/deletion design. A context window is not durable storage.

RAG sequence: select authorized sources → extract/chunk with metadata → embed with a versioned model → index → retrieve under identity filters → rerank → pass bounded evidence → verify answer/citations. Vector Search/Agent Retrieval or database-backed retrieval fit different access/scale requirements. Similarity is not identity or truth; mixing embedding models without reindexing can degrade results.

Pattern Use and control
Sequential agents Ordered dependencies; validate each handoff
Parallel agents Independent tasks; cap concurrency and reconcile outputs
Graph workflow Branches/joins and explicit state transitions
MCP Tool/context interfaces; authenticate each server/call
A2A Interaction among agent systems; constrain peer trust and shared context

Agent Identity/Registry/Gateway/runtime capabilities support discovery and governance; discovery does not grant access. Tool schemas need input/output validation, deadlines, idempotency and bounded retries. Handoffs carry task ID, permitted scope, state references and completion criteria. Limit recursion, calls, tokens, elapsed time and repeated delegation; propagate cancellation. A coordinator must handle partial failures and conflicting state.

4. Evaluate and deploy — 4.1–4.2

Create representative golden cases plus ambiguity, adversarial content, unavailable tools and authorization failures. Evaluate retrieval, answer quality, groundedness, selected tool, arguments, execution sequence, outcome, safety, latency and cost. A correct answer reached through an unauthorized action is a failure. ADK evalsets, managed generative evaluation and custom raters serve different checks; calibrate judges with human evidence.

Version model, prompt, retrieval, tool schema and policy together. Compare changes to a fixed baseline and continuously sample production within privacy rules. Agent Runtime provides managed agent hosting; Cloud Run and GKE supply different container/control tradeoffs. State persistence, duration, networking, scaling and cost—not popularity—choose the runtime.

Trace model/retrieval/tool spans and correlate across handoffs. Diagnose slow external tools, poor retrieval, unauthorized calls, reasoning loops, quota and runtime failures separately. Release gradually with quality/safety/latency gates and a known-good rollback. Token usage and per-task cost matter alongside request count.

5. Secure and govern — 5.1–5.2

Use dedicated identities, narrow IAM, supported PAB resource boundaries, OAuth-based tool authorization and user-context propagation. A universal administrator credential erases user boundaries. Agent Gateway/Registry and policy controls support permitted traffic/capabilities; Model Armor/Sensitive Data Protection supplement filtering and data protection.

Treat retrieved documents, web content and tool results as untrusted input. Authorize proposed actions outside the model against the original user scope. Require exact target/change and an appropriate human or pre-authorized gate for consequential operations. Keep credentials, egress, logs, retention and incident ownership controlled; test injection, cross-tenant memory, malicious arguments and guardrail bypasses.

Traps to catch

  • Tool discovery is not permission; a safety filter is not authorization.
  • More agents can multiply cost, races and failure paths. Shared memory needs ownership.
  • A subagent saying “done” or a healthy container does not prove the external task succeeded.

Last-pass self-check

1. Which facts should a handoff preserve?

Task identity, allowed scope, minimal required context/state references, expected output and completion criteria.

2. When choose RAG instead of relying on model memory?

When answers need current or private knowledge with source access control, provenance and refresh requirements.

3. An agent gets the right answer but reads another tenant’s data. Pass?

No. Authorization and data isolation are part of task success, regardless of answer quality.

4. Why evaluate tool arguments and execution trajectory?

A fluent final answer can conceal unauthorized, redundant, unsafe or incorrect external actions.

5. What does a principal access boundary fail to provide by itself?

It constrains eligible resource access where supported; it does not grant the needed IAM permissions or replace tool authorization.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Low-code agents and connected knowledge

Memory hook: Flow for certainty; generation for flexibility.

Must remember

  • Gemini Enterprise Agent Designer and Customer Experience Agent Studio provide low-code ways to configure agent behavior. Use explicit states/pages, transitions and event handling when the process requires predictable order.
  • Instructions define role, scope, output and escalation. Few-shot examples demonstrate behavior; prompt templates should distinguish trusted instructions from user or retrieved content.
  • Enterprise connectors and Agent Search retrieve organizational knowledge. Preserve document permissions, tenant boundaries, refresh schedules and source attribution throughout ingestion and retrieval.
  • Multimodal sources need appropriate extraction, metadata, chunking and evaluation. A transcript or image caption can lose important context; verify against representative source material.
  • A conversational workflow should collect missing information, validate it, invoke permitted tools and confirm outcomes. Escalate when evidence, authorization or task confidence is insufficient.
  • Test normal, ambiguous, adversarial and unavailable-data paths. A low-code designer reduces implementation work but does not remove security, reliability or evaluation responsibilities.

Choose under exam pressure

Requirement Choice and reason
A regulated process has mandatory ordered steps Explicit workflow states with controlled generative assistance.
An employee asks about private policies Authorized enterprise retrieval with evidence and access checks.

Traps

  • A connector does not make every indexed document public to every agent user.
  • A fluent conversation can still skip a required business step.

Practise this topic

02 · Coding agents and controlled development

Memory hook: Tools grant capability; policy sets limits.

Must remember

  • Coding agents such as Antigravity and supported third-party agents can inspect repositories, propose patches and run tools. Give them a scoped workspace and explicit task boundaries.
  • MCP exposes tool/resource interfaces; skills, rules, plugins, hooks and subagents customize workflows. Review each integration’s permissions and data access rather than trusting its name.
  • Use isolated development environments such as Cloud Workstations or appropriately configured GKE sandboxes. Limit network egress, secrets, filesystem access and privileged execution.
  • Ask agents to produce reviewable changes with meaningful tests, dependency checks and static analysis. Generated tests can mirror a bug, so inspect the intended behavior independently.
  • Agent-assisted refactoring, performance tuning and vulnerability remediation need measured before/after evidence. Do not let a tool claim replace build or runtime validation.
  • Agents CLI and registries can help manage supported enterprise agent workflows. Distinguish human-operated administrative actions from delegated agent operations and audit both.

Choose under exam pressure

Requirement Choice and reason
An agent needs to inspect a private repository Scoped repository access in an isolated environment.
A plugin requests deployment credentials for linting Reduce or reject the unnecessary capability.

Traps

  • A sandbox with broad mounted credentials is not effectively isolated.
  • More parallel agents do not guarantee correct integration or lower total cost.

Practise this topic

03 · Custom agents, memory and retrieval

Memory hook: Session is now; memory is selected history.

Must remember

  • ADK supports custom agent composition and tools. Choose large/small, managed/self-hosted and open/proprietary models according to task quality, security, latency, cost and operational control.
  • Session state holds current interaction context; durable memory retains selected information across sessions. Managed sessions and Memory Bank help with lifecycle, but applications still need user/tenant isolation and deletion rules.
  • RAG pipelines ingest, chunk, embed, retrieve, filter and rerank. Evaluate recall and relevance separately from generated-answer quality; use metadata and identity filters before exposing evidence.
  • Agent Retrieval/Vector Search and database-backed retrieval serve different scale and access patterns. Keep embedding versions, index freshness and source identifiers aligned.
  • Tools expose explicit schemas and bounded capabilities. Validate arguments and results, use timeouts and safe retries, and distinguish read-only retrieval from irreversible business actions.
  • Agent Identity/Registry and supported MCP servers help discover and authorize capabilities. Discovery is not an access grant; authenticate each call and propagate the user context when needed.

Choose under exam pressure

Requirement Choice and reason
Remember a preference across sessions A scoped durable memory record with consent, provenance and expiry where appropriate.
Retrieve current internal facts Permission-aware RAG rather than relying on model weights.

Traps

  • A long context window is not a durable database.
  • Similarity search alone cannot guarantee exact entity identity or authorized access.

Practise this topic

04 · Protocols and multi-agent coordination

Memory hook: Explicit handoffs, bounded loops, shared contracts.

Must remember

  • Sequential agents handle ordered dependencies; parallel agents handle independent work; graph workflows express branching and joins. Use the simplest orchestration that meets the task.
  • A coordinator delegates bounded responsibilities and combines results. Peer-to-peer designs need explicit ownership, termination and conflict handling so agents do not endlessly hand work back and forth.
  • MCP commonly connects agents to tools/context; A2A supports interaction between agent systems. Protocol compatibility does not replace authentication, authorization or input validation.
  • Use typed handoff payloads with task identity, allowed scope, state references and completion criteria. Avoid copying entire private conversations to every worker.
  • Cap recursion, tool calls, concurrent work, token budgets and elapsed time. Retry transient failures with limits; propagate cancellations and avoid repeating non-idempotent operations.
  • Agent Runtime, identity, registry and policy capabilities provide managed building blocks. Preserve correlation identifiers across agents and tools so partial failure can be reconstructed.

Review details

Design the handoff as a contract: task ID, scoped authorization, minimal necessary context, state references, output schema and completion criteria. Parallel workers need a merge/conflict policy; sequential workflows need explicit dependency failure and cancellation. A repeated tool call after a timeout may already have changed external state, so retries need idempotency or reconciliation.

For protocol questions, remember MCP connects tools/context, while A2A supports agent-system interaction. Neither is automatically a trust boundary. Authenticate endpoints, constrain forwarded credentials and avoid distributing an entire user's private session to every subordinate agent.

Choose under exam pressure

Requirement Choice and reason
Three independent research tasks Bounded parallel execution followed by evidence-aware consolidation.
An action must wait for approval An explicit workflow gate before the authorized tool call.

Traps

  • A successful subagent response is not proof that its external action succeeded.
  • Shared memory without ownership rules can create races and data leakage.

Practise this topic

05 · Evaluate, deploy and observe

Memory hook: Test the answer and the path taken.

Must remember

  • Build golden datasets with expected outcomes, authorized tools and edge cases. Evaluate retrieval, final response, tool selection/arguments, trajectory, safety and successful completion.
  • ADK evaluation sets, managed generative evaluation and custom raters address different checks. Calibrate automated judges with human review; avoid evaluating only easy happy paths.
  • Separate development evaluations from continuous production sampling. Redact sensitive data, preserve reproducible versions and compare model/prompt/tool changes against a fixed baseline.
  • Agent Runtime offers managed agent hosting; Cloud Run suits supported stateless/container workloads; GKE provides Kubernetes control. Compare execution duration, state, networking, scaling and cost.
  • Trace model calls, retrieval and tool spans with correlation IDs. Diagnose reasoning loops, slow tools, failed permissions, poor retrieval and unavailable dependencies as distinct problems.
  • Roll out gradually with quality, latency, cost and safety gates. Keep a known-good configuration and artifact for rollback; monitor token usage and concurrency as well as request count.

Review details

An evaluation matrix should include answer correctness, retrieved evidence, tool selection, argument validity, action order, authorization and actual completion. A test can fail even if its final text is correct—for example, if an agent read another tenant's document or executed a duplicate payment.

Use fixed regression cases plus fresh production/adversarial samples, keeping expected evidence separate from model training examples. Calibrate autoraters, inspect false passes/failures, and record model/prompt/retrieval/tool/policy versions. When latency rises, inspect spans and repeated loops before buying a larger model or adding more agents.

Choose under exam pressure

Requirement Choice and reason
An agent answers correctly but calls an unauthorized tool Fail the evaluation; outcome alone is insufficient.
Latency rises after adding a tool Inspect tool spans and retry behavior before changing the model.

Traps

  • A golden dataset that mirrors training examples overstates quality.
  • A healthy container does not prove an agent is completing tasks correctly.

Practise this topic

06 · Identity, guardrails and governance

Memory hook: Authorize actions outside the model.

Must remember

  • Give agents dedicated identities and least-privileged access. Principal access boundary policies constrain eligible resource access where supported; IAM permissions and explicit policy still govern actual actions.
  • OAuth-based tool access and identity propagation can preserve user authorization. Avoid a single administrator token that makes every user’s request equally powerful.
  • Agent Gateway/Registry provide supported control and visibility points; Model Armor and Sensitive Data Protection help screen harmful or sensitive content. Apply controls at input, retrieval, tool calls/results and output.
  • Prompt injection can arrive through documents, websites or tool responses. Treat those as untrusted data and validate proposed actions against the original user scope and external policy.
  • Use human approval for consequential actions, with an exact target and proposed change. Keep network boundaries, secret storage, audit, retention and incident response aligned with organizational policy.
  • Test guardrail bypasses, unauthorized data access, malicious tool arguments and cross-tenant leakage. Governance needs enforceable controls and accountable owners, not merely a system prompt.

Choose under exam pressure

Requirement Choice and reason
An agent proposes deleting a production dataset External authorization, explicit bounded approval and an appropriate recovery process.
A retrieved document requests secret exfiltration Treat it as malicious data and block the unauthorized tool action.

Traps

  • A safety filter cannot grant permission to a resource.
  • A principal access boundary is not a substitute for granting the required narrow role.

Practise this topic

Search across every published topic.