Documentation
Grouped in the order most people need them. If you are evaluating rather than building, start with Trust — what is provable, and what each proof deliberately does not cover — then Operate, which says plainly what is pre-alpha, what is deliberately absent, and how to check either answer yourself.
Start here
Enough to run something and understand what you just ran.
Getting started
Fifteen minutes from nothing to a run that survives a crash, replays exactly, and refuses to rewrite its own history.
Your first agent
Build one support-triage agent from an empty file to a durable, tool-using, pinnable declaration — every step a command, every mistake a refusal.
Concepts
Runs and cases, effects and dispositions, labels and typed release — the vocabulary everything else is built from.
Build
Writing an agent: what you declare, what the runtime enforces, and how to test it without a provider.
Cookbook
Task-shaped recipes: build an agent, keep large bytes out of the chain, require a human, undo work when a later step fails.
Manifest reference
Every field an agent declaration may carry, what enforces it, and what an absent value means.
Publishing and pinning agents
A content-addressed agent manifest, signed and published, and a registry that refuses to rewrite a version once it exists.
Testing agents
A fake provider, deterministic fault injection, a store conformance battery, and the assertion that proves replay actually replayed.
How it works
The mechanisms, and why each is shaped the way it is. Read these when you need to predict behaviour rather than look it up.
Architecture
The determinism boundary, module layout, replay modes and canonical bytes — how the pieces of the agent runtime fit together.
The effect protocol
At-most-once outward calls: intent before action, unknown outcomes that stay unknown, sagas, transactional effect groups, and what stopping a run does.
The journal
An append-only, hash-chained journal with per-record signatures and a per-plane Merkle log — what it proves, and the claims it refuses to make.
Plans, cases and time
Frozen authorization graphs, month-long cases, durable waits and timers, budgets that bind, human tasks and batch runs.
Models, agents and peers
Calling models, other agents and A2A peers: governed egress, MCP tools, media fetching, and exactly what crosses the wire.
Trust
What can be proven, by whom, and what each proof deliberately does not cover.
How this is proven
Model-checked TLA+ specifications, every crash point without a fault injector, and a mutation sweep that breaks each guarantee on purpose.
Record format
The normative wire specification for agentplane's journal records, hash chain, Merkle log and export file — enough to verify a history without this crate.
Security model
The trust boundary, information-flow labels, delegation and egress — with an explicit account of what is not covered.
Erasure and keys
Cryptographic erasure that reaches backups, envelope encryption, key rotation and revocation, and the tenancy boundary.
Regulation
EU AI Act obligation by obligation, mapped to mechanisms that exist — and an explicit list of the ones that do not.
Operate
Running it: what will change under you, what to pin, and what to do when something is stuck.
Operations
Deploying, high availability, retention, observability, and a runbook for every state a run can get stuck in.
Status
What is pre-alpha in agentplane, which surfaces to pin, what is deliberately not built, the format-freeze conditions, and how to check any of it yourself.
Upgrading
What a hard cut means before the format freeze, and the procedure for moving a plane from one agentplane build to the next.