Basil Harness
Basil Harness turns an agent request into a Run: an immutable manifest, a disposable sandbox, leased tool execution and an ordered event stream. It is what makes agents safe enough to run for everyone.
What you get
Everything an agent run needs to be trusted.
Each capability below is a property of every Run, not an add-on.
Traceable execution
Task state, tool operations and model usage are recorded in order, so you can follow progress, locate problems and account for AI use.
Cloud execution
Tasks run on servers, not laptops. Long and scheduled work has a home that is always on.
Unified knowledge and methods
Authorised documents, history and Skills are loaded into the run so the agent works the way the company has decided.
Controlled environment
Files and programs run in an isolated sandbox, bounded by authorisation scope and directory permissions. Employee machines and critical data stay out of reach.
One runtime, many apps
HR, sales and operations agents share the same file handling, tool calling and run records. Build once, maintain once.
Idle sandboxes pause
Without work, sandboxes are paused automatically and resumed when a task arrives.
Leases and fencing
Execution rights are leased and fenced across instances. A stale instance can no longer commit state or results.
Model flexibility
Connect different model services and choose per task. No single-vendor dependency.
Limits on waste
Caps on duration, tool calls and identical repeated operations keep agents from looping.
Progress despite failures
When one tool fails, the agent tries another authorised method or finishes the unaffected parts, and reports exactly what was left.
Cancel at any time
Change of plan? Cancel the run. Running processes are stopped too.
Reusable workspaces
Files and the environment carry over to the next task, so continuous work does not restart from zero.
Read here, write there
Reference material can be mounted read-only while working directories stay writable.
Run lifecycle
Every run has a shape you can reason about.
Queued, started, attempted, paused, recovered, cancelled or completed: the state machine is explicit and every transition is an event.
- run.queued
- run.started
- attempt.startedlease 30s · fencing token
- tool.startedtool.completedcheckpointinteraction.requestedrun.pausedrun.recoveringuser input · resume
- run.completed
Leased
Execution rights are held on a short lease, so a worker that disappears can never block the run.
Fenced
Each attempt carries a fencing token; a stale instance can no longer commit state or results.
Replayable
Every transition is an ordered event, so any run can be inspected or replayed after the fact.
Sandbox & resources
Mount exactly what a task may touch.
The user's workspace, Skills, Works, Connectors, Apps and attachments are projected into the sandbox under /workspace/resources with per-path read-only and writable overrides.
disposable · created per session · destroyed after
Sandbox tools
- exec
- process
- read
- write
- edit
- delete
- view_image
Always available
- session_status
- request_user_input
Read-only reference material
Skills and company material mount read-only. The agent can read and cite them, never change them.
Writable working directory
Only the task directory and attached files accept writes, and only for this run.
Secrets written straight into the sandbox
Credentials land in the sandbox environment and never pass through the model.
Model flexibility
Bring the model the task needs.
The manifest names the provider, API family and base URL for each run. Switch models per team or per task without changing the runtime.
API families
- OpenAI Completionsopenai-completions
- OpenAI Responsesopenai-responses
- Anthropic Messagesanthropic-messages
- Google Generative AIgoogle-generative-ai
- Azure OpenAIazure-openai-responses
Thinking level
thinkingLevel · off disables thinking, every other level requests it
Observability
Every event, in order, replayable.
Runs emit a strictly increasing event sequence: state changes, tool starts and results, context checkpoints and usage. Live deltas stream over Redis; durable events land in PostgreSQL.
Events per run
Tool executions
Input tokens
Output tokens
run 359415397587451 · qwen/deepseek-v4-pro
Live
Redis stream · message deltas the moment they are produced
Durable
PostgreSQL run_events · the single source of truth, strictly ordered
- 1run.queued
Basil Harness ships inside AOS.work and is available for platform teams building their own agent applications.