A resumed run never re-charges a card or re-sends an email. Side effects are recorded on the journal, not replayed on recovery.
HA in one process
Thousands of concurrent durable runs survive crashes and node handoffs. No cluster, no separate workflow engine to operate.
Verifiable audit trail
Every run's journal is committed to an RFC 6962 Merkle tree. Build inclusion and consistency proofs for any record on demand and check them offline, without trusting the vendor or the process that produced them.
Provably convergent state
Shared governed state is checked against a machine-checked convergence theorem, not eventual hope, and every machine is re-checked in-process by an oracle generated from that proof. See Known limitations for its scope.
The whole agent surface
Models (OpenAI, Anthropic, Gemini), tools, typed multi-step flows, memory and RAG, MCP, multi-agent coordination, and typed human-in-the-loop.
A library, not a cluster
Plain Go. Import it, bring your own store. Built for ambient agents that run unattended and act under audit.