by workload
What teams put on it first.
Each of these is a job the runtime does today. The mechanisms under each one ship; none of them is a roadmap.
CI/CD & release management
A pipeline change is a code change. A code change an agent makes has to arrive the way any other one does: as a commit somebody reviews.
- Mission-scoped git workspaces. Changes arrive as reviewable commits
- A language server validates edits before the agent applies them
- The runtime rolls an edit back when validation fails
- Granted the pipeline, never the deploy
Vulnerability & CVE response
An advisory lands. The question is whether it is reachable in your estate, not whether it is severe in general.
- Findings land in the shared graph, so the next run starts from them
- Missions run on your trigger: CI, a webhook, or a scheduler you own
- Scanner output is evidence in the timeline, not an inbox
- Every conclusion replays to the step that produced it
Coding agents, under control
The problem with a coding agent is not what it writes. It is what it can reach while it writes.
- Grants at the repository, tool and data level
- An agent can never exceed the engineer who granted it
- Model-generated code that declares untrusted input runs in a microVM
- The timeline attributes every prompt and edit, and replay rebuilds them
Security testing
Offense and defense on one runtime, and both write into one picture of the environment.
- Hosts, paths and findings accumulate in the tenant graph
- Untrusted payloads detonate in a microVM
- Declared egress, enforced at that boundary
- A mission replays move by move for the report
Incident response
During an incident nobody has time to rebuild what the automation did. Afterwards, everybody needs to.
- The timeline captures every act as the work happens
- Replay returns the same sequence every time
- Agents act on short-lived credentials that expire in 55 seconds
- You can revoke a grant mid-incident without a redeploy
Compliance evidence
Evidence collection is the work nobody wants and everybody has to do twice a year.
- Every action traces to a named human's grant
- Timeline exports for a reviewer
- A mission has a type, so the same check runs the same way
- Controls stated with their boundaries, not as a certification claim