Let agents learn and act. Keep authority in the runtime.Governed learning. Bounded action. Recorded evidence. Comis is an Apache-2.0, self-hosted, security-first runtime for AI agents that learn and act across sessions. It is built for agents that work on a schedule, use real tools, build up context, or need to recover after a failure. The promise is simple: learned guidance can influence what an agent proposes, but it cannot grant permission. Comis keeps identity, capabilities, credential scope, tool policy, and configured limits in the runtime, outside prompt text. It also keeps important run state and bounded evidence available for recovery and review. Comis is under active development. Start with one agent and one limited workflow. Test the controls on your host before you add broader access.
Why Comis
Comis is designed for work that continues beyond one chat window.Keep authority outside the model
Apply capability, origin, credential, tool, and configured budget controls
in runtime paths rather than relying on prompt instructions.
Govern learning across sessions
Use source records, trust signals, configured corroboration, usefulness, and
correction history to govern which experience can return as guidance.
Recover and explain the work
Recover selected context and review run outcome, cost, policy failures, and
a rule-based likely cause when the recorded evidence matches one.
What the runtime brings together
Long-running workflows
Coordinate sequential and parallel work with dependencies, retries,
budgets, and configured node-boundary recovery.
Learned memory with history
Record sources and trust signals, require configured evidence, and preserve
prior history when eligible learned state is corrected. Learned text can
guide proposals, but it cannot expand runtime authority.
Channels and interfaces
Start work from schedules, messaging channels, the web dashboard, CLI, or
APIs, then inspect it through the same runtime.
Start here
Explore the documentation
How It Works
Follow a request through routing, execution, controls, state, and evidence.
Use Cases
Start with an overnight research brief or a limited, read-only investigation.
Security Boundaries
Review defaults, opt-in controls, deployment assumptions, and residual risk.
Operations
Deploy, monitor, back up, recover, and troubleshoot the daemon.
