Skip to content
An open contract for reliable agent harnesses

Better models.Reliable agent work.

ContextOS helps teams define what successful agent work means, bound what an agent can do, and retain evidence of what happened. Apply its schemas and deterministic compiler reference to your existing runtime, starting with one workflow.

Open specification, reference code, and implementation guides for platform and product teams. Production controls run in your infrastructure.

See ContextOS in action
Illustrative DecisionRecord
verified
{
"record_id": "dr_run_7f3a",
"decision_key": "support.refund.execute",
"status": "DECIDED",
"actor.delegated_user_id": "usr_771",
"lineage.pack_version": "ctxpack.support@5.2.0",
"policy_decisions[0].verdict": "allow",
"outputs.transaction_id": "txn_q9",
"tool_lineage[0].reversal_token": "rv_refund_txn_q9",
"replay.replay_packet_id": "rp_run_7f3a",
"audit.record_hash": "sha256:9ea1…"
}
identity boundpolicy enforcedrecovery ready
Decision Studio

Explore evidence-backed decisions.

See a decision contract in use.

Import account data, prioritize renewal reviews, and inspect the evidence behind each recommendation in this browser-based example.

Open Decision Studio
Reference trace

What a reliable harness must be able to show.

Follow one illustrative refund run through context, authorization, execution, and acceptance. The artifacts describe an implementing runtime; the site does not execute payments. Recovery depends on the tool and the external system.

CompiledContext

Context

Only current, verified, in-scope evidence enters the run.

context-manifest.jsoncompiled
pack_versionctxpack.support@5.2.0
evidence_refs3 admitted / 0 unresolved
budget1,864 / 2,400 tokens
compiled_context_hashsha256:9f0b…c41a
Recorded verdict

Policy

Policy remains outside the prompt and evaluates the live action envelope.

policy-verdict.jsonallow
bundlePOLICY_RETURNS_V4@4.0.0
identityverified · tenant matched
rulesR_REFUND_REQUIRES_IDV + R_HIGH_VALUE_REQUIRES_APPROVAL
approval_gateGATE_FINANCE_APPROVAL · satisfied
Identity-bound call

Tool

The model proposes. The Tool Gateway validates identity, scope, arguments, and effect risk.

tool-call-envelope.jsonauthorized
tool_call_idtc_121
workload_identityspiffe://contextos/agents/support
capabilitypayments.issue_refund
action_riskexternal_state · user_delegated · compensatable
approval_mode_effectivedestructive
idempotency_keyik_2x9k…0p3z
Evaluator verdict

Critic

The path is scored against evidence and gates, not against the agent’s confidence.

run scorecardaccept
1.00
policy
0.94
utility
0.86
latency
1.00
safety
0.91
cost
Normalized result

Effect

The gateway verifies external state and preserves a concrete recovery handle.

tool-result-envelope.jsonpostcondition met
effectrefund(txn_q9, 4200 INR)
mutation_refpayments:txn_q9
postconditionrefund.status = settled
reversal_tokenrv_refund_txn_q9 · provider-specific
DecisionRecord

Receipt

The run closes only when the six operational questions have typed answers.

sealed receipt
dr_run_7f3a
replay ready
What did it see?ctxpack.support@5.2.0 · 3 verified refs
Whose authority?agt_support on behalf of usr_771
Why was it allowed?POLICY_RETURNS_V4 · approval satisfied
What did it change?refund txn_q9 · postcondition confirmed
Why did it pass?policy 1.00 · utility 0.94 · safety 1.00
Can we recover?rp_run_7f3a · reversal token pinned
trace 4bf92f…4736record hash sha256:9ea1…
Five-plane architecture

Five responsibilities for one agent run.

Use the planes to assign ownership of evidence, model input, decisions, effects, and controls. They are logical boundaries: one application can implement several planes, and a managed provider can own part of the execution.

pinned RunContext · principal_chain usr_771 → agt_support · tenant acme_prod · budget 4,720 tokens · policy pins v4 · trace 4bf92f…4736
same run id · same authority ceilingevery boundary emits evidence
Why now

The model is one part.The whole system must earn trust.

Harnesses now provide long-running execution, tools, skills, and session state. Your application still owns accepted outcomes and authorized effects. ContextOS makes those obligations explicit across implementations.

Define done before the run

Specify the accepted outcome, required evidence, and prohibited effects. Check the observed result and the path that produced it.

Evaluate the whole release

Compare model, harness, skills, tools, and environment together. Keep version evidence, held-out cases, cost, and a rollback target.

Keep control at the boundary

A managed session or connected tool does not establish permission. Bind each effect to the caller, task, policy, and current approval.

Remove machinery that stopped helping

Re-test planners, resets, skills, and reviewers when models change. Simplify where evidence supports it while preserving authorization and outcome checks.

Read the current direction and evidence
Start with one workflow

Define done. Bound actions. Verify the result.