Urizen · Anansi Agent Harness

Anansi

The code validation and governed execution environment for agent workflows. A developer environment that makes context, delegation, intent, permissions, verification, and traceability visible and testable.

Play one governed action Read a verified code review

One governed action, seven stations, every station a receipt. Rendered from real Anansi console projections: the session is a declared specimen; the review case is one retained change. Nothing here is a mock-up.

Try it · you are the model

Propose anything. The harness decides.

The model can ask for anything — the words carry no authority on their own. Send a proposal through the seven stations and watch where the harness accepts it or stops it, and why. Every outcome is a receipt.

guided simulation of the decision path · no live session or effect runs here · the retained session and receipts are below
You · the modelproposes

Pick something to ask for. Try the rogue ones.

The harnessdecides
  • Proposal
  • Identity
  • Plan
  • Execution
  • Effect
  • Receipt
  • Completion
the model proposesPick a proposal to begin.
No proposal yet. The harness is idle.
Receiptsevery outcome

One line per attempt. Refusals are receipts too.

  • Nothing proposed yet.
The model never holds executive authority. Baobab owns the decision; Anansi owns witness, sandbox, custody, and receipt.

Below is the real thing: one retained governed session, its control plane, a verified code review, and the exact capacity ledger.

01 · One governed action

The model proposes. The harness decides.

Seven stations. The mark is the progress figure: each circle lights as its station passes, and the hub goes gold at completion. Every value below is read from the retained records, not typed in.

Press play, or use ← →.
Four GG0 roots at session start

02 · The operator's view

What the operator can see, and what the operator cannot do.

The six capabilities the harness names — context, delegation, visible intent, permission boundary, verification, traceability — projected from the same records. A digest with a held record links to it. A digest without one is marked not in store, and the console never treats a digest as policy content. The operator view adds no semantic authority.

Traceability

Only explicit digest-field edges are drawn. Solid nodes are held records; hollow nodes are digests without a held record. No inferred dependency edges.

03 · Verifiable code review

One retained change, reviewed under BRK-0, executed under AVS-0.

The decision comes first. Then the obligations, the findings, the inspection targets, and the effect boundary. The joined receipt is verified by the existing verifier, not by this page.

04 · Capacity, with exact statuses

What is built, at the scope it was verified.

Each card carries the status label its implementation record carries. Implemented + Verified finite means the controls passed at one recorded fixture scope, not in production. Records dated 2026-08-02 to 2026-08-12.

Contract kernel V1

Twelve canonical objects, seventeen session states, three effect outcomes: not_invoked, committed, effect_uncertain. Strict canonical JSON codecs; a receipt joins four authorities without merging them.

Implemented + Verified finite

Operator console UI-0 · UI-2 · UI-4

Read-only projections from retained envelopes: the session view, the six-capability control plane with 41 explicit trace edges, and the review case view. TUI and static GUI from one immutable view.

Implemented + Verified finite

Verifiable code review · AVR-0 + BRK-0

One retained bounded change: PASS, three obligations resolved, joined receipt verified. Generated FAIL and Unresolved cases exercise the refusal paths. Baobab owns the decision; Anansi owns witness, sandbox, custody, receipt.

Implemented + Verified finite

Verifiable sandbox · AVS-0, AVS-1D

Five cumulative proof levels up to result_validated; S1 and S2 verified, S3–S5 open. AVS-1D: one macOS Seatbelt policy blocked write, read, connect, and fork; os_policy_verified. Launcher signing trust Unresolved.

Implemented + Verified finite S3–S5 Open

Source witness · ASR-1

Exact-equality support for a declared output occurrence reaches support_validated only after the pinned validator accepts. Installed read-only command verifies the frozen 0.12.0rc1 kit against an exact manifest SHA-256.

Implemented + Verified finite

Subagent runtime V0

Serial in-memory lifecycle kernel: one root, one task tree, spawn and capacity limits, one result per turn token, strict child records. One child artifact bound to GG0 evidence_digest; joined receipt verified. 38 focused tests, 192-test inventory.

Implemented + Verified finite

Subagent executor V1 · ASX-1

One bounded child process under a nested Seatbelt profile, one deterministic digest workload, exact limits (5 s, 16 KB in, 16 KB out, one process). Effect committed, custody retained. 42 focused tests, 262-test SDK.

Implemented + Verified finite closure Unresolved

Dependency discovery · ADD-0

Exact static Python import edges from a verified Git witness, an uncertainty frontier for dynamic or ambiguous imports, SCCs, an acyclic condensation, deterministic layers, and a GEW-0 projection that rejects cycles and incomplete scope.

Implemented + Verified finite semantics Open

Full agent harness · AFH-1

The target: two joined planes, a conventional agent execution plane and the Anansi authority and evidence plane, against a pinned behavioural reference. Thirteen cumulative release gates, R0–R12.

Specified · gates Open

Sources: the implementation results and specifications in Anansi/docs/business_strategy/, dated as named. Product repositories remain authoritative for every status word above.

05 · What this demo proves

Exact claims, and their edges.

Established at the recorded scope

  • The console projects six capabilities and an explicit trace graph from retained anansi-object-envelope-v1 records. Implemented + Verified finite
  • One retained bounded change was reviewed under BRK-0 and executed under AVS-0 with a joined receipt that verifies. Implemented + Verified finite
  • The joined action receipt binds identity, plan, execution, and effect receipts without merging their authority. Verified finite

Not established here

  • The session is a declared specimen. No live session produced it, and no provider effect happened. Open
  • Independent reproduction, stable release, and production release of Anansi. AFH-1 conformance: gates R0–R12. Open
  • Model quality, general agent correctness, or production hostile-host protection. Non-object