Kindgi The AI-native runtime for agents as infrastructure. Get started →

Reference

How it works.

Flow, provenance, HITL, guardrails, capabilities, memory, and supervisor.

§ 01 · Flow

Durable executor for agent workflows.

Every state transition is journaled to durable storage before it happens. When a wait fires, compute is released — not blocked. Retry, timeout, concurrency key, and priority are first-class per-edge properties.

  • Journaled · deterministic replay
  • Per-edge retry · timeout · concurrency · priority
  • Waits release compute · not process suspend
  • Running instances pin to graph version — survive deploys
agent.turn · v1.0.0 journaled · replay-safe
retry 3x parallel join: all join: all risk > 0.7 else classify agent retrieve tool extract agent reason agent must_cite check senior_review review draft_response agent
// task graph — declarative, versioned, journaled
{
  "id": "claims-triage.turn",
  "version": "1.4.0",
  "nodes": [
    { "id": "classify",  "kind": "agent",  "ref": "intent-classifier" },
    { "id": "retrieve",  "kind": "tool",   "ref": "precedents.search" },
    { "id": "extract",   "kind": "agent",  "ref": "fact-extractor" },
    { "id": "reason",    "kind": "agent",  "ref": "risk-analyzer" },
    { "id": "cite",      "kind": "check",  "ref": "must-cite" },
    { "id": "review",    "kind": "review", "ref": "senior-adjuster" },
    { "id": "respond",   "kind": "agent",  "ref": "draft-generator" }
  ],
  "edges": [
    { "from": "classify", "to": "retrieve",
      "policy": { retry: "3x-backoff", timeout: "30s" } },
    { "from": "classify", "to": "extract",
      "policy": { parallel: true } },
    { "from": "retrieve", "to": "reason",
      "policy": { join: "all" } },
    { "from": "extract",  "to": "reason",
      "policy": { join: "all" } },
    { "from": "reason",   "to": "cite" },
    { "from": "cite",     "to": "review",
      "policy": { on: "risk>0.7" } },
    { "from": "cite",     "to": "respond",
      "policy": { else: true } }
  ]
}
§ 02 · Provenance

Signed audit trail of every decision.

Every output traces back to every input that influenced it — cryptographically.

Prompts, retrieved chunks, tool results, model version, reviewer decisions, tenant policy in effect — all edges in a directed acyclic graph. Cryptographically signed and independently verifiable with any standard crypto library. The signed DAG is the audit artifact.

  • Signed · rotatable keys · revocation supported
  • Portable format — independently verifiable
  • Selective replay from any node backward
  • Feeds attestation, compliance exports, differential debugging
run 8f3a2c…9d · provenance Ed25519 · signed
inputs3 docs · 1 form
modelclaude-sonnet-4-6
policytenant-a · v14
reviewerJohn Doe
guardrails4 / 4 pass
cost$0.031
key idfirm-a · 2026-06
signature3f9a…c02e ✓
§ 03 · HITL

Human review with queues and escalation.

An operational surface with reviewer classes, queues, and escalation paths.

Approval queues, batched review, junior/senior reviewer routing, escalation paths, signed audit-bundle exports. Reviews are first-class kernel state — resumable across deploys, auditable end-to-end, exportable for regulator inspection.

  • Approval queues by reviewer class
  • Batched review — reduce reviewer fatigue
  • Escalation paths on time-out or dissent
  • Signed audit-bundle exports on approval
approval queue · senior adjusters 3 pending · 14 today
01CLAIMPerry-8f3a2c · fraud flagJohn Doe · 14s
02CLAIMMeridian-a91b · cost > $0.10queued 2m
03POLICYtenant-b · exception requestescalated
04MEMORossi-c2d4 · outbound draftapproved
05CLAIMBeacon-e5f6 · missing citationapproved
§ 04 · Guardrails

Typed, consistent assertions in CI and production.

Declare what the agent must never do, and what it must always do.

Guardrails evaluate at every turn — before tool calls, before responses, before human handoff. On failure, the runtime captures the input, the offending output, the specific check that fired, and the enforcement action taken; all signed into the audit trail.

  • Zero-LLM checks by default · fast · deterministic · cheap
  • LLM-judge scorers opt-in with explicit cost accounting
  • Same source of truth for CI + runtime
  • Enforcement per guardrail: halt / retry / escalate / log
claims-triage-agent · guardrails 4 declared · 4 passing
defineAgent({
  id: "claims-triage",
  guardrails: [
    mustCite({ min: 1 }),
    neverCallTool("delete_claim"),
    outputMatches(ClaimSchema),
    maxToolCalls({ n: 50 }),
    cost({ max: "$0.05", on: "escalate" }),
  ],
  // same object · prod runtime + CI
});
§ 05 · Capabilities

Model routing by declared requirement.

Agents declare what they need, not which model they use.

The router matches capability declarations to models that satisfy them, under per-tenant policy and per-run budget. Per-tenant provider allow/deny lists are enforced at the kernel on every call. Bring-your-own-model providers plug in through the same routing interface.

  • Declare needs · router picks the model
  • Per-tenant provider policy · kernel-enforced
  • Per-run cost cap · aggregated per tenant
  • Typed adapter interface · BYO providers
capabilities · request → route tenant-a · US-only
needs: [
  "structured_output",
  "context >= 200k",
  "thinking",
  "cost <= $0.05/call",
]
// tenant policy: no OpenAI · US regions only
// budget remaining: $0.043 / $0.100

→ route: claude-sonnet-4-6 (us-east-1)
  reason: satisfies all · under budget · policy-clean
§ 06 · Memory

Append-only log plus typed facts.

Two primitives. Semantic recall, cross-conversation history, and working-memory context are views derived from both.

An append-only log of turns, tool calls, tool results, agent messages. Typed, versioned facts with declared retrieval hints — semantic, recency, exact, or graph. Every fact write is causally linked to the log entry that produced it, which feeds provenance.

  • Log: append-only · timestamped · causal
  • Facts: typed · versioned · retrieval-hinted
  • Scopes: thread · matter · doc · org · session
  • Retention + deletion follow tenant policy automatically
memory · scope: matter · Perry-8f3a2c 42 log · 8 facts
t0LOGturn.user · "review the counter draft"42 kb
t1LOGtool.call · corpus.search(q="indemnity")3 hits
t2FACTgoverning_law · "Delaware"retrieve: exact
t3FACTindemnity_cap · "$10M mutual"retrieve: exact
t4FACTcounterparty_style · vector[768]retrieve: semantic
§ 07 · Supervisor

Bounded remediation, immutable ground.

Bounded fixes proposed against an immutable ground layer.

The supervisor observes runs, detects guardrail violations, proposes fixes in bounded artifact tiers, dry-runs proposals against held-out evals, and routes surviving proposals to your reviewers. It cannot modify its own guardrails or evaluation criteria — that's the immutable ground layer, human-authored, versioned through normal engineering flow.

  • Bounded scope · prompts, retrieval, tool config first
  • Dry-run against held-out evals before proposal
  • Routes to reviewer with full audit context
  • Cannot modify its own guardrails — ever
supervisor · proposal 47b1 awaiting review
01TRIGGERguardrail "mustCite" failed 4x in 100 runspattern
02PROPOSEretrieval-k: 3 → 5tier 1
03DRYRUNagainst 500-run eval set+7% pass
04ROUTEsenior reviewer requiredS. Chen · 6h
05GROUNDguardrails unchanged · verifiedimmutable

Licensing.

Apache-2.0
  • Client SDK, CLI, and authoring SDK
  • Definition libraries: agents, tools, guardrails, flows, graph, schema, types, capabilities
  • Model provider adapters: Anthropic, OpenAI-compat, in-process
  • Interface packages: crypto, authz
  • Docs, templates, skills
BSL 1.1
  • Kernel and api-server
  • All Postgres-backed registries and stores
  • Sandbox adapters
  • Authz and HITL runtime
  • Provenance, crypto implementation, secrets stack, memory, blob, MCP, observability, audit-events

Additional Use Grant: internal enterprise use is granted without restriction. Change Date: Apache-2.0 four years after each release.

Ready to try it

Boot the runtime in one command.