Rensei
DOC R-001 · RENSEI PLATFORM OVERVIEW · REV 2026-06-11sha256:e49c…e116

00 · ABSTRACT

The deterministic runtime that makes agent-authored code defensible in production.

Declarative workflows compile to a durable execution graph. LLMs run as bounded operators inside workflow steps; the control loop is deterministic code. Cedar evaluates policy in the hot path, every event lands on an Ed25519 hash-chained audit trail verifiable against per-workspace keys without trusting Rensei, and decision provenance binds every action.

curl https://rensei.ai/.well-known/audit-keys.json

verification protocol and key-discovery endpoints, published · the runtime is open source →

3,849

commits, founder and fleet, across 15 RenseiAI repos, public and private · fetched 2026-06-11

1,317 of them in public repos you can count yourself

REC 00sha256:0772…c797prev e5c0…df7abuild 2026-06-12T03:34Z

Engineers should not have to --dangerously-skip-permissions their way to the next promotion or termination.
from the manifesto →

REC 00bsha256:1116…2a8cprev 0772…c797build 2026-06-12T03:34Z

01 · SYSTEM

One request path. Five layers. Every layer auditable.

One request path runs Compose to Verify: Compose declares the workflow, Compile turns it into a durable execution graph, Scale routes work across providers, Intelligence persists what the fleet learns, and Verify keeps every step on the record.

FIG 1.0
FIG 1.0 - SDLC v2 workflow definition, 46 nodes. One scripted run lights research through acceptance.

Figures are live component renders, not screenshots. Demo data.

REC 01sha256:0a9b…9e59prev 1116…2a8cbuild 2026-06-12T03:34Z

02 · OPERATE

The loop closes bounded and on the record.

Acceptance fails. The issue is auto-rejected. Refinement dispatches in about five seconds, parked behind the active session, capped at eight dispatches per issue. Every transition lands on the audit chain. Governor-level hard caps and holds are on the roadmap and listed in the claims ledger.

FIG 2.0Replay 2026-06-09
FIG 2.0 - Fleet topology and sessions stream, looping over a captured demo run.
FIG 2.1
  1. T+00.0sacceptance gateFAILEDsmoke assertion failed on retry policy
  2. T+00.4sissue auto-rejectedREJECTEDtransition lands on the audit chain
  3. T+05.1srefinement dispatchedDISPATCHEDparked behind the active session
dispatch 3 of 8 · hard cap: 8 dispatches per issue
FIG 2.1 - Acceptance fails, the issue auto-rejects, refinement dispatches. The cap holds at eight.

REC 02sha256:a79e…4d89prev 0a9b…9e59build 2026-06-12T03:34Z

03 · ROUTE

Routing is a posterior, not a preference.

Thompson-sampling posteriors per provider and work type. Exploration is policy-bounded: strict-mode pools pin approved models, and posteriors update from observed session outcomes only; per-line survival joins that signal when the integration closes. Per-line provenance and survival measurement are live; the survival-to-posterior wiring is in active integration and closes during the design-partner phase.

FIG 3.0
FIG 3.0 - Thompson posteriors per provider. Survival-to-posterior wiring: in active integration.

REC 03sha256:3743…5872prev a79e…4d89build 2026-06-12T03:34Z

04 · REMEMBER

The learning compounds. The data does not.

The platform extracts a knowledge graph from agent activity. Reads are Cedar-authorized, every access lands on the hash-chained audit trail, and feedback weights decay on an exponential moving average. Cross-tenant aggregation covers anonymized model-performance priors only.

FIG 4.0
FIG 4.0 - Knowledge-graph explorer over a fictional codebase. Layout precomputed at build.

REC 04sha256:d72a…c21cprev 3743…5872build 2026-06-12T03:34Z

05 · VERIFY

Four primitives. Properties of the engine.

Cedar policy enforcement, hash-chained audit, fail-closed egress, and decision provenance are properties of the deterministic execution graph. The security disclosure walks each one.

FIG 5.0
FIG 5.0 - Audit-chain verification with one expanded provenance row. Mock hashes.

REC 05sha256:554d…00e8prev d72a…c21cbuild 2026-06-12T03:34Z

06 · RUNTIME

The execution layer is open source.

Donmai (どんまい) is the MIT-licensed runtime under the platform: one Go binary, a persistent daemon, a dispatch loop. The same runtime powers Rensei in production. The star count is live and small; the git history is the interesting part.

donmai

5 GitHub stars · fetched 2026-06-11

brew install RenseiAI/homebrew-tap/donmai

REC 06sha256:a80e…8063prev 554d…00e8build 2026-06-12T03:34Z

07 · RECORD

Published numbers. Declared status.

3,849

commits across 15 repos, public and private · fetched 2026-06-11

298

releases across the org · fetched 2026-06-11

121

days since first commit · fetched 2026-06-11

Full claims ledger on the evidence page →

REC 07sha256:f099…8820prev a80e…8063build 2026-06-12T03:34Z

08 · CONTACT

Review the architecture with us.

One founder reads this inbox, and every message gets a reply. Bring us the runtime thesis you came here for: the workflow whose git history would tell you whether an agent can be trusted with it.

Confirm your email and the founder replies directly.

REC 08sha256:888a…e8bfprev f099…8820build 2026-06-12T03:34Z