00 · ABSTRACT
The deterministic runtime that makes agent-authored code defensible in production.
Declarative workflows compile to a durable execution graph. LLMs run as bounded operators inside workflow steps; the control loop is deterministic code. Cedar evaluates policy in the hot path, every event lands on an Ed25519 hash-chained audit trail verifiable against per-workspace keys without trusting Rensei, and decision provenance binds every action.
curl https://rensei.ai/.well-known/audit-keys.jsonverification protocol and key-discovery endpoints, published · the runtime is open source →
3,849
commits, founder and fleet, across 15 RenseiAI repos, public and private · fetched 2026-06-11
1,317 of them in public repos you can count yourself
REC 00 ▸ sha256:0772…c797 ▸ prev e5c0…df7a ▸ build 2026-06-12T03:34Z
“Engineers should not have to --dangerously-skip-permissions their way to the next promotion or termination.”
REC 00b ▸ sha256:1116…2a8c ▸ prev 0772…c797 ▸ build 2026-06-12T03:34Z
01 · SYSTEM
One request path. Five layers. Every layer auditable.
One request path runs Compose to Verify: Compose declares the workflow, Compile turns it into a durable execution graph, Scale routes work across providers, Intelligence persists what the fleet learns, and Verify keeps every step on the record.
Figures are live component renders, not screenshots. Demo data.
REC 01 ▸ sha256:0a9b…9e59 ▸ prev 1116…2a8c ▸ build 2026-06-12T03:34Z
02 · OPERATE
The loop closes bounded and on the record.
Acceptance fails. The issue is auto-rejected. Refinement dispatches in about five seconds, parked behind the active session, capped at eight dispatches per issue. Every transition lands on the audit chain. Governor-level hard caps and holds are on the roadmap and listed in the claims ledger.
- T+00.0sacceptance gateFAILEDsmoke assertion failed on retry policy
- T+00.4sissue auto-rejectedREJECTEDtransition lands on the audit chain
- T+05.1srefinement dispatchedDISPATCHEDparked behind the active session
REC 02 ▸ sha256:a79e…4d89 ▸ prev 0a9b…9e59 ▸ build 2026-06-12T03:34Z
03 · ROUTE
Routing is a posterior, not a preference.
Thompson-sampling posteriors per provider and work type. Exploration is policy-bounded: strict-mode pools pin approved models, and posteriors update from observed session outcomes only; per-line survival joins that signal when the integration closes. Per-line provenance and survival measurement are live; the survival-to-posterior wiring is in active integration and closes during the design-partner phase.
REC 03 ▸ sha256:3743…5872 ▸ prev a79e…4d89 ▸ build 2026-06-12T03:34Z
04 · REMEMBER
The learning compounds. The data does not.
The platform extracts a knowledge graph from agent activity. Reads are Cedar-authorized, every access lands on the hash-chained audit trail, and feedback weights decay on an exponential moving average. Cross-tenant aggregation covers anonymized model-performance priors only.
REC 04 ▸ sha256:d72a…c21c ▸ prev 3743…5872 ▸ build 2026-06-12T03:34Z
05 · VERIFY
Four primitives. Properties of the engine.
Cedar policy enforcement, hash-chained audit, fail-closed egress, and decision provenance are properties of the deterministic execution graph. The security disclosure walks each one.
REC 05 ▸ sha256:554d…00e8 ▸ prev d72a…c21c ▸ build 2026-06-12T03:34Z
06 · RUNTIME
The execution layer is open source.
Donmai (どんまい) is the MIT-licensed runtime under the platform: one Go binary, a persistent daemon, a dispatch loop. The same runtime powers Rensei in production. The star count is live and small; the git history is the interesting part.
donmai
5 GitHub stars · fetched 2026-06-11
brew install RenseiAI/homebrew-tap/donmaiREC 06 ▸ sha256:a80e…8063 ▸ prev 554d…00e8 ▸ build 2026-06-12T03:34Z
07 · RECORD
Published numbers. Declared status.
3,849
commits across 15 repos, public and private · fetched 2026-06-11
298
releases across the org · fetched 2026-06-11
121
days since first commit · fetched 2026-06-11
REC 07 ▸ sha256:f099…8820 ▸ prev a80e…8063 ▸ build 2026-06-12T03:34Z
08 · CONTACT
Review the architecture with us.
One founder reads this inbox, and every message gets a reply. Bring us the runtime thesis you came here for: the workflow whose git history would tell you whether an agent can be trusted with it.
REC 08 ▸ sha256:888a…e8bf ▸ prev f099…8820 ▸ build 2026-06-12T03:34Z