Basil Harness

Basil Harness 把一次 Agent 請求變成一次 Run:不可變的清單、一次性沙箱、租約式工具執行和有序的事件流。正是它讓 Agent 足夠安全,可以交給每個人使用。

run 359415397587451 · qwen/deepseek-v4-proqueued
seqeventdetail
waiting for run
Basil Harnessreplay · 28 events

你將獲得

讓一次 Agent 執行值得信任的一切。

以下每一項能力都是每次 Run 的固有屬性,而非附加選項。

可追溯的執行

任務狀態、工具操作與模型用量按順序記錄,便於跟蹤進度、定位問題、核算 AI 使用。

雲端執行

任務在伺服器上執行,而非筆記本。長時任務與定時任務有一個永遠線上的家。

統一的知識與方法

授權文件、歷史記錄與 Skills 一併載入到執行中,Agent 按公司既定的方式工作。

受控的環境

檔案與程式在隔離沙箱中執行,受授權範圍與目錄許可權約束。員工電腦與關鍵資料始終隔離在外。

一個執行時,多種應用

人力、銷售與運營的 Agent 共用同一套檔案處理、工具呼叫與執行記錄。構建一次,維護一次。

空閒沙箱自動暫停

沒有任務時,沙箱自動暫停;任務到來時,自動恢復。

租約與圍欄

執行權在例項間以租約方式分配並加以圍欄。過期的例項無法再提交狀態或結果。

靈活的模型選擇

接入不同的模型服務,按任務選擇。不依賴單一供應商。

杜絕浪費

對時長、工具呼叫次數與相同重複操作設定上限,防止 Agent 陷入迴圈。

失敗也能推進

某個工具失敗時,Agent 會嘗試其他授權方法,或完成不受影響的部分,並如實報告未完成的內容。

隨時取消

計劃有變?取消執行即可,正在執行的程序也會一併停止。

可複用的工作區

檔案與環境延續到下一項任務,連續工作不必從零開始。

此處只讀,彼處可寫

參考資料可以只讀掛載,工作目錄保持可寫。

執行生命週期

每一次執行,都有可推演的形態。

排隊、啟動、嘗試、暫停、恢復、取消或完成:狀態機明確定義,每一次狀態遷移都是一個事件。

run 359415397587451 · state run.queuedqueued
  1. run.queued
  2. run.started
  3. attempt.startedlease 30s · fencing token
  4. tool.startedtool.completedcheckpoint
    interaction.requestedrun.pausedrun.recovering
    user input · resume
  5. run.completed

Leased

Execution rights are held on a short lease, so a worker that disappears can never block the run.

Fenced

Each attempt carries a fencing token; a stale instance can no longer commit state or results.

Replayable

Every transition is an ordered event, so any run can be inspected or replayed after the fact.

沙箱與資源

任務能觸碰什麼,就只掛載什麼。

使用者的工作區、Skills、Works、Connectors、Apps 與附件被投射到沙箱的 /workspace/resources 之下,並可按路徑分別設定只讀或可寫。

sandboxrun 359415397587451
containercreating

    disposable · created per session · destroyed after

    Sandbox tools

    • exec
    • process
    • read
    • write
    • edit
    • delete
    • view_image

    Always available

    • session_status
    • request_user_input
    • Read-only reference material

      Skills and company material mount read-only. The agent can read and cite them, never change them.

    • Writable working directory

      Only the task directory and attached files accept writes, and only for this run.

    • Secrets written straight into the sandbox

      Credentials land in the sandbox environment and never pass through the model.

    靈活的模型選擇

    任務需要什麼模型,就用什麼模型。

    清單為每次執行指明提供商、API 型別與基礎 URL。按團隊或按任務切換模型,無需改動執行時。

    run.manifest.jsonimmutable
    1. {
    2. "version": 1,
    3. "runId": "359415397587451",
    4. "model": {
    5. "api": "openai-responses",
    6. "provider": "openai",
    7. "modelId": "gpt-5",
    8. "baseUrl": "https://api.openai.com/v1",
    9. "contextWindow": 400000,
    10. "thinkingLevel": "high"
    11. }
    12. }

    API families

    • OpenAI Completions
    • OpenAI Responses
    • Anthropic Messages
    • Google Generative AI
    • Azure OpenAI

    Thinking level

    offminimallowmediumhighxhighmax

    thinkingLevel · off disables thinking, every other level requests it

    可觀測性

    每一個事件,有序、可回放。

    執行產生嚴格遞增的事件序列:狀態變更、工具啟動與結果、上下文檢查點與用量。實時增量經 Redis 流式傳輸,持久事件落入 PostgreSQL。

    0

    每次執行的事件數

    0

    工具執行次數

    0

    輸入 token

    0

    輸出 token

    run 359415397587451 · qwen/deepseek-v4-pro

    Live

    Redis stream · message deltas the moment they are produced

    redis · live · 359415397587451streaming

      Durable

      PostgreSQL run_events · the single source of truth, strictly ordered

      postgresql · run_eventseventSeq 1
      1. 1run.queued
      Basil Harness

      Basil Harness 內建於 AOS.work,也面向自建 Agent 應用的平臺團隊提供。