Basil Harness

Basil Harness turns an agent request into a Run: an immutable manifest, a disposable sandbox, leased tool execution and an ordered event stream. It is what makes agents safe enough to run for everyone.

run 359415397587451 · qwen/deepseek-v4-proqueued
seqeventdetail
waiting for run
Basil Harnessreplay · 28 events

What you get

Everything an agent run needs to be trusted.

Each capability below is a property of every Run, not an add-on.

Traceable execution

Task state, tool operations and model usage are recorded in order, so you can follow progress, locate problems and account for AI use.

Cloud execution

Tasks run on servers, not laptops. Long and scheduled work has a home that is always on.

Unified knowledge and methods

Authorised documents, history and Skills are loaded into the run so the agent works the way the company has decided.

Controlled environment

Files and programs run in an isolated sandbox, bounded by authorisation scope and directory permissions. Employee machines and critical data stay out of reach.

One runtime, many apps

HR, sales and operations agents share the same file handling, tool calling and run records. Build once, maintain once.

Idle sandboxes pause

Without work, sandboxes are paused automatically and resumed when a task arrives.

Leases and fencing

Execution rights are leased and fenced across instances. A stale instance can no longer commit state or results.

Model flexibility

Connect different model services and choose per task. No single-vendor dependency.

Limits on waste

Caps on duration, tool calls and identical repeated operations keep agents from looping.

Progress despite failures

When one tool fails, the agent tries another authorised method or finishes the unaffected parts, and reports exactly what was left.

Cancel at any time

Change of plan? Cancel the run. Running processes are stopped too.

Reusable workspaces

Files and the environment carry over to the next task, so continuous work does not restart from zero.

Read here, write there

Reference material can be mounted read-only while working directories stay writable.

Run lifecycle

Every run has a shape you can reason about.

Queued, started, attempted, paused, recovered, cancelled or completed: the state machine is explicit and every transition is an event.

run 359415397587451 · state run.queuedqueued
  1. run.queued
  2. run.started
  3. attempt.startedlease 30s · fencing token
  4. tool.startedtool.completedcheckpoint
    interaction.requestedrun.pausedrun.recovering
    user input · resume
  5. run.completed

Leased

Execution rights are held on a short lease, so a worker that disappears can never block the run.

Fenced

Each attempt carries a fencing token; a stale instance can no longer commit state or results.

Replayable

Every transition is an ordered event, so any run can be inspected or replayed after the fact.

Sandbox & resources

Mount exactly what a task may touch.

The user's workspace, Skills, Works, Connectors, Apps and attachments are projected into the sandbox under /workspace/resources with per-path read-only and writable overrides.

sandboxrun 359415397587451
containercreating

    disposable · created per session · destroyed after

    Sandbox tools

    • exec
    • process
    • read
    • write
    • edit
    • delete
    • view_image

    Always available

    • session_status
    • request_user_input
    • Read-only reference material

      Skills and company material mount read-only. The agent can read and cite them, never change them.

    • Writable working directory

      Only the task directory and attached files accept writes, and only for this run.

    • Secrets written straight into the sandbox

      Credentials land in the sandbox environment and never pass through the model.

    Model flexibility

    Bring the model the task needs.

    The manifest names the provider, API family and base URL for each run. Switch models per team or per task without changing the runtime.

    run.manifest.jsonimmutable
    1. {
    2. "version": 1,
    3. "runId": "359415397587451",
    4. "model": {
    5. "api": "openai-responses",
    6. "provider": "openai",
    7. "modelId": "gpt-5",
    8. "baseUrl": "https://api.openai.com/v1",
    9. "contextWindow": 400000,
    10. "thinkingLevel": "high"
    11. }
    12. }

    API families

    • OpenAI Completions
    • OpenAI Responses
    • Anthropic Messages
    • Google Generative AI
    • Azure OpenAI

    Thinking level

    offminimallowmediumhighxhighmax

    thinkingLevel · off disables thinking, every other level requests it

    Observability

    Every event, in order, replayable.

    Runs emit a strictly increasing event sequence: state changes, tool starts and results, context checkpoints and usage. Live deltas stream over Redis; durable events land in PostgreSQL.

    0

    Events per run

    0

    Tool executions

    0

    Input tokens

    0

    Output tokens

    run 359415397587451 · qwen/deepseek-v4-pro

    Live

    Redis stream · message deltas the moment they are produced

    redis · live · 359415397587451streaming

      Durable

      PostgreSQL run_events · the single source of truth, strictly ordered

      postgresql · run_eventseventSeq 1
      1. 1run.queued
      Basil Harness

      Basil Harness ships inside AOS.work and is available for platform teams building their own agent applications.