Documentation · The Lagstyr handbook
Agents and their runs
An agent is a probabilistic worker that proposes and executes within granted skills, immutable risk routing and explicit authority limits. It cannot expand its own powers, and nothing about it changes silently. That last sentence is the one the Agents pages exist to prove.
The fleet
Agents lists every agent your installation runs, what each is allowed to reach, and what each may spend. Below the fleet is the work the fleet abandoned: tasks that failed past their retries and now need a person. Nothing on this page changes an agent. Every change is a governed proposal, and each agent’s page shows the ones that were made and who approved them.
One agent
An agent’s own page has four parts: the agent, what it may reach, its recent activity, and what has been changed about it. The last part is the governed change history, headed by the sentence No agent self-improves silently: every change below it was a proposal, and the decisions that authorised each follow.
A Contain it section lets you pause every active action class the agent holds. Pausing is the same governed break-glass call an operator would make one class at a time; nothing is bypassed, and restoration goes back through proposal and approval, never a direct switch.
An Agent evaluation page behind each agent shows the feedback labels, evaluation cases and scorecards behind the rates its main page reports. It is the evidence behind the numbers; the console does not run model traffic itself.
A run
A run is one execution of an agent. Its transcript page shows the run’s facts — the agent, the model, the provider, the prompt version — and then every turn the run recorded, in order, with its kind and content. You reach a run from the agent’s page, from a proposal it raised, or from a chat message. Cancellation is a run control, not a chat-only courtesy: once requested, the worker checks before and after model and tool boundaries and the kernel refuses further dispatch. A run triggered by a tainted causal parent inherits that provenance monotonically; starting another generation does not turn untrusted context into trusted authority.
The transcript shows what the agent was told and what it said. It does not show effects, receipts or verification state; those live on the External effects page, and the evidence attached to a proposal lives on the proposal. A run is the reasoning record. The other pages are the effect record.
Spot-checks
At T3 an action has already happened when you see it. Agent spot-checks shows a sample of those actions — what the agent was given and what it did — and asks for a verdict: Looks good or Problem, each with an optional reason. The verdict is feedback, not an approval. No password is asked for, because a spot-check label is not a governance gate. The labels feed the evaluation the agent’s page reports and the demotion triggers its action classes carry.
Agent chat
Agent chat in Tools lets you hold a text conversation with an active agent. When you start one, the kernel pins the agent, its scope and your current entitlements to the conversation. Each agent card shows its available scope before you begin.
Within a conversation you send a message, wait for the response, and may cancel a response in progress or resume one that stopped for an approval. A response that raised a proposal links to it; a response that ran as a run links to the run. You can close a conversation, after which no further messages can be sent.
Chat has limits, stated on its pages, and they are deliberate:
- Text only. Attachments and non-text messages are not supported, and a message is at most 16 KiB.
- You see only your own conversations.
- Content expires after thirty days. Earlier erasure is a governed request: asking for it creates a proposal, and an active legal hold takes precedence.
- A chat message is never a decision. An agent cannot be told to approve something in chat, and nothing you say in chat approves anything. Decisions happen on the proposal’s page.