Praxis Agents OS
Open development roadmap

Roadmap

See what is available now, what is being built next, and which safety and governance foundations come before higher-risk capabilities.

Public pre-release build. Last reconciled with the public repository on 7 August 2026. Production suitability must be assessed rather than assumed.

Available now

Foundations implemented in the repository

The current build provides an end-to-end runtime, context, integration, governance, file, artifact, scheduling, and audit path for governed agents.

Available now

Runtime and conversations

Agent execution, durable streaming, bounded history, automatic context compaction, delegation, retries, token caps, tracing, and cooperative cancellation.

Read runtime architecture
Available now

Governance and operations

Workspace identity, roles, invitations, TOTP and OAuth sign-in, approval controls, schedules, audit and security views, side-effect envelopes, and behavioural evaluations.

Read governance architecture
Available now

Tools and skills

A typed tool registry, one audited dispatch path, effect and egress declarations, tool catalogue, web search and fetch, and progressively disclosed skills.

Review completed plans
Available now

Files, artifacts, and storage

Per-workspace cloud-storage boundaries, file revisions and tools, multimodal input, and versioned artifacts with previews, restore, and revocable share links.

Review completed plans
Available now

Integrations

Thirteen governed tools across Gmail, Google Ads, Airtable, and BigQuery, with discovered resources, multi-target context, typed results, and policy per tool.

Explore the integrations
Available now

Knowledge and persistent memory

Hybrid document retrieval, provenance-tracked persistent memories, prompt-injection framing, and surfaces to inspect, correct, archive, and purge stored context.

Review completed plans
Active and planned

What the project is working on next

The repository separates the work currently being designed or built from later capabilities. None of these cards describes functionality available today.

In active development

First tagged release

The public repository and release workflow exist, but v0.1.0 has not been tagged or published. Launch bookkeeping and the maintainer-controlled release gate remain open.

Open the roadmap
In active development

Code Mode orchestration

The next harness lane lets a model compose existing governed tools inside a constrained script while preserving validation, audit, approvals, and resumable execution.

Open the roadmap
In active development

User-developed applications

The applications programme is being re-baselined around versioned packages, workspace installations, explicit resource bindings, and the same identity and dispatch boundaries as the rest of Praxis.

Open the roadmap
Planned

Production deployment and recovery

Production currently requires cloud storage and a cloud secret manager. Public cloud deployment guides, email transport, and self-service password recovery remain incomplete.

Open the roadmap
Planned

Sandboxed native computation

Provider-native code execution is a separate planned capability from Code Mode. Until its isolation and egress probes land, agents use the typed tools already exposed to them.

Open the roadmap
Planned

Failover and replay

Model failover and durable stream replay remain planned. Today a provider failure ends the run, while durable jobs, schedules, approvals, completion evidence, and audit records preserve the surrounding operational state.

Open the roadmap
Architectural gates

Higher-risk capabilities have prerequisites

Integrations, memory, retrieval, and external actions only move forward when the controls around them are ready.

Side effects need eyes

Operational governance must exist before integrations ship tools that can spend money or change external systems.

Assemble context once

Skills, files, integrations, knowledge, and memory must compose through one budgeted prompt-assembly design.

Evaluate before tuning

Retrieval, memory, and harness behaviour need scenarios and expected outcomes before optimisation changes land.

Treat external content as untrusted

New content sources require a threat model and adversarial fixtures before their output reaches model context.

Follow the work

Explore detailed milestones on GitHub

Follow completed work, upcoming capabilities, and the technical decisions shaping each phase.