§04 — ARTIFACTS · PW-01 · ● IN BUILD
The agent crashed after calling Stripe. Did the customer get refunded zero times, once, or twice?
KEEL records every model call and tool call to a durable log before it is used. Kill the worker mid-refund and a fresh one resumes from the log, with no repeated model calls and no second refund. Then fork the same run onto another model and compare.
01 · Record
Don’t make the model deterministic.
Make the run deterministic by recording. LLM output, tool results, the clock and randomness all pass through ctx and land in an append-only, hash-chained log.
02 · Recover
Intent before effect.
The refund’s intent is durable before Stripe is called, and its idempotency key comes from the step, not the attempt. Every retry, by any worker, carries the same key.
03 · Fork
Real runs, new model.
Fork at any step onto another model. History is shared, not copied; irreversible tools are simulated; the diff shows trajectory, outcome, tokens and cost.
Run it yourself
# one process, no Postgres
git clone https://github.com/Agensphere/keel
cd keel && cargo run -p agensphere-keel-cli -- dev
