Basil Harness

Basil Harness 把一次 Agent 请求变成一次 Run:不可变的清单、一次性沙箱、租约式工具执行和有序的事件流。正是它让 Agent 足够安全,可以交给每个人使用。

run 359415397587451 · qwen/deepseek-v4-proqueued
seqeventdetail
waiting for run
Basil Harnessreplay · 28 events

你将获得

让一次 Agent 运行值得信任的一切。

以下每一项能力都是每次 Run 的固有属性,而非附加选项。

可追溯的执行

任务状态、工具操作与模型用量按顺序记录,便于跟踪进度、定位问题、核算 AI 使用。

云端执行

任务在服务器上运行,而非笔记本。长时任务与定时任务有一个永远在线的家。

统一的知识与方法

授权文档、历史记录与 Skills 一并加载到运行中,Agent 按公司既定的方式工作。

受控的环境

文件与程序在隔离沙箱中运行,受授权范围与目录权限约束。员工电脑与关键数据始终隔离在外。

一个运行时,多种应用

人力、销售与运营的 Agent 共用同一套文件处理、工具调用与运行记录。构建一次,维护一次。

空闲沙箱自动暂停

没有任务时,沙箱自动暂停;任务到来时,自动恢复。

租约与围栏

执行权在实例间以租约方式分配并加以围栏。过期的实例无法再提交状态或结果。

灵活的模型选择

接入不同的模型服务,按任务选择。不依赖单一供应商。

杜绝浪费

对时长、工具调用次数与相同重复操作设置上限,防止 Agent 陷入循环。

失败也能推进

某个工具失败时,Agent 会尝试其他授权方法,或完成不受影响的部分,并如实报告未完成的内容。

随时取消

计划有变?取消运行即可,正在执行的进程也会一并停止。

可复用的工作区

文件与环境延续到下一项任务,连续工作不必从零开始。

此处只读,彼处可写

参考资料可以只读挂载,工作目录保持可写。

运行生命周期

每一次运行,都有可推演的形态。

排队、启动、尝试、暂停、恢复、取消或完成:状态机明确定义,每一次状态迁移都是一个事件。

run 359415397587451 · state run.queuedqueued
  1. run.queued
  2. run.started
  3. attempt.startedlease 30s · fencing token
  4. tool.startedtool.completedcheckpoint
    interaction.requestedrun.pausedrun.recovering
    user input · resume
  5. run.completed

Leased

Execution rights are held on a short lease, so a worker that disappears can never block the run.

Fenced

Each attempt carries a fencing token; a stale instance can no longer commit state or results.

Replayable

Every transition is an ordered event, so any run can be inspected or replayed after the fact.

沙箱与资源

任务能触碰什么,就只挂载什么。

用户的工作区、Skills、Works、Connectors、Apps 与附件被投射到沙箱的 /workspace/resources 之下,并可按路径分别设定只读或可写。

sandboxrun 359415397587451
containercreating

    disposable · created per session · destroyed after

    Sandbox tools

    • exec
    • process
    • read
    • write
    • edit
    • delete
    • view_image

    Always available

    • session_status
    • request_user_input
    • Read-only reference material

      Skills and company material mount read-only. The agent can read and cite them, never change them.

    • Writable working directory

      Only the task directory and attached files accept writes, and only for this run.

    • Secrets written straight into the sandbox

      Credentials land in the sandbox environment and never pass through the model.

    灵活的模型选择

    任务需要什么模型,就用什么模型。

    清单为每次运行指明提供商、API 类型与基础 URL。按团队或按任务切换模型,无需改动运行时。

    run.manifest.jsonimmutable
    1. {
    2. "version": 1,
    3. "runId": "359415397587451",
    4. "model": {
    5. "api": "openai-responses",
    6. "provider": "openai",
    7. "modelId": "gpt-5",
    8. "baseUrl": "https://api.openai.com/v1",
    9. "contextWindow": 400000,
    10. "thinkingLevel": "high"
    11. }
    12. }

    API families

    • OpenAI Completions
    • OpenAI Responses
    • Anthropic Messages
    • Google Generative AI
    • Azure OpenAI

    Thinking level

    offminimallowmediumhighxhighmax

    thinkingLevel · off disables thinking, every other level requests it

    可观测性

    每一个事件,有序、可回放。

    运行产生严格递增的事件序列:状态变更、工具启动与结果、上下文检查点与用量。实时增量经 Redis 流式传输,持久事件落入 PostgreSQL。

    0

    每次运行的事件数

    0

    工具执行次数

    0

    输入 token

    0

    输出 token

    run 359415397587451 · qwen/deepseek-v4-pro

    Live

    Redis stream · message deltas the moment they are produced

    redis · live · 359415397587451streaming

      Durable

      PostgreSQL run_events · the single source of truth, strictly ordered

      postgresql · run_eventseventSeq 1
      1. 1run.queued
      Basil Harness

      Basil Harness 内置于 AOS.work,也面向自建 Agent 应用的平台团队提供。