Agents on Kodeus run as long lived, isolated processes. Work resumes after a restart. Failures recover. Turns are scheduled per user, so one busy user cannot stall everyone else. Background routines, retries and scheduled runs are part of the runtime, not something you bolt on.
Long running work picks up where it stopped. State needed to continue is persisted, not held in a process.
Each user gets a bounded share. A runaway session is contained to the person who started it.
Scheduled and event triggered runs, with the same policy and traces as an interactive turn.
Identity on Kodeus is derived from a verified credential, never from the request body. Each user’s connected accounts live in their own encrypted store, and one user’s session cannot reach another’s. This is the part that breaks first when a product goes from one user to two, and it is the part we test hardest.
Orgs, users, databases and secrets are separated at the runtime, not in application code.
Encrypted per user with AES-256-GCM. Key issuance, rotation and revocation are runtime operations.
A six part adversarial isolation suite runs against every release. Ask for the report.
Short term and long term memory per user, with context compaction and eviction, so an agent that has been running for six months does not carry six months of context into every turn. Knowledge is stored durably and scoped to the user or the organisation that owns it.
Compaction and eviction keep the per-turn context flat, so cost per turn in month six looks like month one.
45 guardrails across six policy families, applied at five checkpoints in every turn. Before the turn, after planning, before any tool call, after the tool call, and before the reply. A rule can monitor, redact, block, escalate or hold the action for a named person. If a rule cannot be evaluated the action does not happen. Spend limits and loop detection are enforced here too, because a prompt cannot enforce a budget.
No verdict means no action. The turn goes to a person.
Name the actions that wait. The record shows who approved, when, and what they changed.
Caps per agent and per user. An agent retrying a failing tool overnight is stopped, not billed.
Every turn produces an OpenTelemetry trace with the rule verdicts, latency and cost of each call. Approval records carry the approver and the time. Execution history is retrievable later, which is the difference between “the agent said it did this” and “here is what it did”.
OpenTelemetry, with rule verdicts per step, per-call latency, token and cache usage.
Approver, time, original draft and edited version.
A correct run is saved and replayed after a prompt or model change, so drift shows up before users see it.
Models are chosen per agent and changed in a line of config. OpenAI, DeepSeek and Claude run today. Bring your own keys and pay the provider directly, or let Kodeus route. Any MCP server can be attached, and an agent can be exposed as an MCP server itself or talk to other agents over agent to agent transports.
The model should be replaceable. The operating layer should not be.
Runs on your laptop against the same runtime and the same policies, with no account needed.
Inside your VPC on AWS, GCP or Azure, against your own database. The only outbound traffic is to the model provider you choose.
We run it for you. Per-tenant isolation, metering and the Console out of the box.
No outbound network at all. Models hosted inside the perimeter. For sites where the cable is pulled.
Same runtime in all four. Nothing calls Kodeus at serve time.
{{ f.a }}