Concepts
Early access: these docs cover the concepts, with guides and the API reference on the way.
Agents and badges
How an agent's identity, owner and access are defined.
Every Kosem agent is its own identity. Its commits, requests and questions are its own, never the identity of the person who started it, so you can always tell who did what.
What a badge holds
An agent's badge is everything it is allowed to be and do:
- Owner: the person responsible for the agent.
- Repositories: the code it works on.
- Network: the destinations it may reach. Everything else is blocked.
- Secrets: what it may ask the vault for. It gets short-lived keys, never the real ones.
- Questions: the channel its questions go to.
- Model: the model it runs by default.
Why a badge instead of approvals
An agent on your laptop usually shares your machine and your keys, so it has to ask before every command. A Kosem agent works in its own microVM with only its badge's access, so there's nothing to approve file by file. You decide what it may do once, when you set up the badge, instead of at every step.