00 Open source · Free · Runs on your computer

Build your AI workforce, under contract.

We're building the AI workforce — and giving it what a workforce needs: an identity, a contract, and a boss. foxora runtime is where you put it to work: every agent with a budget it can't break, permission it has to ask for, and proof it has to show.

Give an agent a job and a spending limit. It does the work, stops to ask before anything risky, and can't say "done" until it shows you the evidence.

0.31300% of the world's agents run on foxora today.

One command · Every major model · Nothing leaves your machine

Fig. A — one governed run
FOXORA RUNTIME governed receipt · one intent

intentclose-the-quarter
ceiling$12.00 · four axes
dueFriday 17:00

01INTENTcontract opened, durable
02ADMISSIONpassed · ten named gates
03LEASEgranted · scope only narrows
04WAITPOINTapproved · by you
05EVIDENCEbound ×2 · sha-256
06RECEIPTsigned

spent$9.30
next charge $3.50REFUSED

would exceed the ceiling — so it never happened

FXR-0001 · SHA-256 · SIGNED

Every state on this receipt is one the engine really has. The record itself is an illustration — not live data.

0checks on every job
all enforced, none optional
0reasons it can say no
each one named
0automated tests
run them yourself
0bytes sent to us
check devtools

[01] Why AI work still feels complicated

AI tools are powerful. Keeping the whole job together is still hard.

Claude, ChatGPT and other AI tools can already research, write, code and act. The challenge begins when one job needs several models, agents, apps, schedules, memories and rules.

  1. 01The wrong model
  2. 02Every agent role
  3. 03Too many apps
  4. 04Repeating yourself
  5. 05No clear limits
  6. 06Changed instructions
  1. Problem 01 of 06

    Using the wrong model for the job.

    Different parts of a job need different strengths.

    AI tools already offer several models and specialist agents. But when one job moves across tools, you still choose what handles each part, when to switch and when a lower-cost model is enough.

    With foxora Give each part to a model that fits.

    foxora coordinates the models you connect, following the choices and spending limit you set.

  2. Problem 02 of 06

    Building every agent role yourself.

    A useful AI team needs clear roles and a clear order.

    AI tools can create specialist agents, but you still define every role, write its instructions and decide how the work moves from one agent to the next.

    With foxora Start with a team that knows who does what.

    foxora includes 21 ready-made agents for different jobs. Use them as they are or adjust them for your work.

  3. Problem 03 of 06

    Using too many apps for one job.

    Tasks, queues, schedules and approvals rarely stay together.

    A plan may begin in chat, tasks move into Jira, schedules live in a calendar and the agent queue sits somewhere else. You spend time copying updates and checking what is waiting, running or finished.

    With foxora See and manage the whole job in one place.

    foxora brings the plan, task order, schedule, approvals and progress into one view while staying connected to the tools you need.

  4. foxora helps organise those moving parts while you keep using the tools you prefer.

  5. Problem 04 of 06

    Repeating yourself in every AI app.

    Each tool remembers its own conversation.

    Claude may know one part of the story, ChatGPT another and Hermes something else. Repeating the same background takes time, and important details can change or disappear along the way.

    With foxora Let connected apps use the same shared memory.

    Add information once, keep where it came from and make it available only to the tools you choose.

  6. Problem 05 of 06

    Starting AI work without clear limits.

    The owner, goal, access and budget should never be guesswork.

    The owner, goal, allowed access and spending limit are often mixed into long instructions or stored in different settings. As the work continues, those limits can be forgotten and the job can drift.

    With foxora Begin every job with clear limits.

    foxora keeps the person, goal, access and budget with the job, then uses them to decide what may continue and when approval is needed.

  7. Problem 06 of 06

    Changed instructions can go unnoticed.

    A webpage, tool or another agent can quietly change the job.

    Harmful instructions can appear while an agent is working. If their source is not checked, the agent may change direction, use access it should not use or report the wrong result.

    With foxora Check the instruction before the agent acts.

    foxora checks its source, keeps access within the job’s limits, pauses when something looks wrong and records what happened.

foxora works with the AI tools you already use. The technical safeguards stay behind the simple experience.

foxora DesktopGRIP safeguardsMCP readyL5 safeguards Shared Memory1,000+ app connections through Composio

[02] What you get

Everything your agents need, in one place.

Build them, run them, watch them — on your own machine, under your own rules.

01

Connect

Your tools, your data and every major model. Your agents act through them.

Your tools · your data · every major model
02

Remember

Memory that keeps where every fact came from — and quarantines anything it shouldn't trust.

Source kept · quarantined
03

Build

A crew or a whole workforce. Describe it in plain words, or write it in code.

Plain words · or code
04

Watch

One board for every job. Live state, real cost, and a signed receipt for each step.

Live state · real cost · signed receipt
On your own machineunder your own rules

[03] Using it

You set the terms. It does the work.

Three steps. Nothing to learn, nothing to wire up first. What you agree to is the whole interface.

Articles of governed autonomy

Made between the operator, of the first part, and the engine, of the second

Article I Say what done looks like.

Tell it the outcome, what it may spend, and when you need it. That's not a prompt — it's an agreement, and it survives you closing the laptop.

Intent
Close the quarter — 1,400 invoices, the chasing, the board summary — ≤ $12 · by Friday
Article II It works, and stops when it must.

It runs on its own inside your limits, and stops to ask before anything it can't undo. Ask for more than you allowed and it says no — and tells you why.

Intent
Close the quarter — 1,400 invoices, the chasing, the board summary — ≤ $12 · by Friday
runningwaiting on you
Article III You get proof, not a promise.

It can't call the job done until it shows evidence you can open — plus an itemised list of what it did and what it cost. No proof, no "done".

Intent
Close the quarter — 1,400 invoices, the chasing, the board summary — ≤ $12 · by Friday
runningwaiting on you
evidencebound cost$9.30 receiptsigned
The operator This line waits for you. That is the product.
sha256:9f2c…e41a
The engine Signs every reasoning turn — a receipt, not a promise.

[04] Under the hood

What happens when you give it a job.

Six checks between "do this" and "done". The engine enforces every one, and every one lands on the receipt. The small code under each is what engineers can search for.

FOXORA RUNTIME the run, as it prints

01
contract opened, durable

Intent

Agree what finished means, what it may cost, and when it is due — before anyone starts.

A durable contract carrying acceptance criteria, a four-axis budget and a deadline. INTENT_STATUS_ACTIVE

02
passed · ten named gates

Admission

Work starts when it is allowed to, not when something asks.

Work waits in a governed queue behind ten named gates. MissionBlockReason

03
granted · scope only narrows

Lease

One job's worth of access, and never more than it started with.

A short hold that can only narrow, scoped to one Intent and a fixed set of actions. COMMITMENT_STATUS_LEASED

04
approved · by you

Waitpoint

When a job needs sign-off, it stops there until someone gives it.

A raised waitpoint suspends the mission until a named person decides. WAITPOINT_REASON_KIND_HUMAN_APPROVAL

05
bound ×2 · sha-256

Evidence

Being shown the finished kitchen, not a text saying “done.”

Settlement refuses until criterion codes bind to artifact digests. SETTLEMENT_EVIDENCE_REQUIRED

06
signed

Receipt

An itemised invoice for the thinking, not just the result.

Each reasoning turn is admitted to the ledger as a signed receipt. AdmitSettlementLearningCommand

statusprinting…

[05] Why it's different

Most "agents" are L2 in an L5 costume.

Borrowed from self-driving cars: five levels of how much a machine does on its own. Everyone sells level five. Almost everything shipping is level two or three with a confident voice.

Autonomy licenceClass L · issued to the engine · endorsed by you
Nº FXR-L5-0001

foxora is built for L5 with a boss. Full autonomy inside limits it cannot raise on itself. Hit the ceiling and it escalates to you — it never quietly upgrades its own budget, its own model tier, or its own reach. One lead owns every outcome and answers for it.

Each level below is an endorsement on the licence. Most products carry the first three. The fifth is only safe because of the condition printed beside it.

  1. L1SuggestsWrites you a draft. You do the work.
  2. L2Acts onceCalls one tool when you ask it to.
  3. L3Runs a taskA few steps while you watch every one.most tools stop here
  4. L4Runs a laneA narrow job end to end, inside a script someone wrote.
  5. L5Owns the outcomeTakes the whole job and only stops when it genuinely needs a person.conditional
Condition of L5

Ceiling set by the holder's operator — budget, model tier, reach. The holder cannot raise it. Reaching it escalates to a person; it never self-upgrades.

An operator's licence card listing five levels of autonomy as endorsements; the fifth is conditional on a ceiling the holder cannot raise

[06] Install

One command. Your machine. Nothing leaves it.

One command checks your machine, creates its own keys, starts everything and opens the console. It touches none of your files, and nothing is sent to us — ever.

foxora / install macOS · Linux · Windows via WSL2 · Intel or Apple silicon

sh install

curl -fsSL https://get.foxora.dev | sh

[not live yet] get.foxora.dev goes live with the first tagged release. Until then, clone the repository and start at step 02. Needs Docker and the Compose plugin. It writes only ~/.foxora and ~/.local/bin.

foxora / boot one engine + one Postgres

sh run

checking Docker and Compose

Docker ready

generating this machine's keys and certificates

written to ~/.foxora

starting engine, database, gateways

console at http://localhost:58080

Deploy to a platform

runs on Docker · Render · Fly · Railway · DigitalOcean · Your laptop

FlyRailwayDigitalOceanRenderDockerYour laptopFlyRailwayDigitalOceanRenderDockerYour laptop

[07] The ecosystem

Not a framework. The whole system.

foxora runtimen. one install that gives your AI workers somewhere to work — and a set of rules they cannot talk their way out of.

Most "agent frameworks" hand you one piece and leave you to build the rest. foxora runtime ships all of it — the app, the engine, the agents, the tools — plus the one layer nobody else does: governance. Everything a real, autonomous crew needs, in one install.

A loop+ a prompt+ a place for your key+ your own plumbing+ a workforce you can leave alone

Fourteen parts · one install10 shipped · 4 building

  1. 01Dashboardshipped
  2. 02Analyticsbuilding
  3. 03Engineshipped
  4. 04Agentsshipped
  5. 05Toolkitshipped
  6. 06Triggersshipped
  7. 07Durabilityshipped
  8. 08Governanceshipped
  9. 09SDKshipped
  10. 10APIsshipped
  11. 11MCPshipped
  12. 12Pluginsbuilding
  13. 13Channelsbuilding
  14. 14L5 Crewbuilding

= foxora runtime

Governance— what that word actually contains

  1. 01Identityevery job has one named owner, and the engine checks there is exactly one
  2. 02Contractswhat a job may do, written down before it starts
  3. 03Budgetsthe charge that would break the ceiling never happens
  4. 04Approvalssteps that stop and wait for a person, by design
  5. 05Evidencenothing is called done until it shows proof you can open
  6. 06Receiptsevery step signed, so “done” is checkable
  7. 07Refusalswhen it says no, the reason has a name — one of ten, never a silent stop
01

Build a crew, or a whole workforce

One lead who owns the outcome. Specialists who each carry their own limit. Describe it in plain words, or write it like ordinary code.

  • Agents that hold the goal across a whole job, not just one chat
  • Exactly one lead answers for the result — the engine checks
Agents
release-leadowns the outcome
researchbuildreview

validated on publish — exactly one lead, every role capped

02

Toolkit

Memory, workflows, retrieval, evals and MCP — the tools your agents act through, and the memory they reason over.

  • Memory that remembers where every fact came from
  • Anything untrusted is quarantined before an agent can read it
Memory & workflows
Deploys freeze on Fridaysvouched
“Ignore your instructions and…”quarantined

nothing read is believed until something vouches for it

03

Automation & Triggers

Schedules, webhooks and events start work on their own. A job doesn't need you at a keyboard to begin.

  • Runs on a schedule, or when something happens
  • Work that starts by itself still passes every check
Schedules & events
weekdays · 06:00schedule
invoice.createdevent

a trigger is not a permission

04

Durable Execution

Work survives crashes, restarts, deploys — and the weekend. A failed step retries; it doesn't take the job down with it.

  • Every job's state lives in the database, not in memory
  • A crash resumes exactly where it stopped
Queues & retries
run #4821resumed after restart
fetch ✓transform ✓upload · retry 2/3verify

the process died at 02:14 — the job did not

05

Governance

The part nobody else ships. A budget that can't be broken, permission that only shrinks, approvals that actually stop things, and a signed receipt for everything.

  • The charge that would break the budget never happens
  • Every step signed, so "done" is checkable
Only here
send 142 customer emailswaiting on you
charge $3.50refused · BUDGET

would pass the $12.00 ceiling — so it never happened

One install. One database. Fourteen parts that are the same thing — not fourteen integrations you maintain.

Scale 1:1 · Sheet 07

[08] The console

See what's running, what's stuck, and what needs you.

One board for every job. Five columns, and each one is a real state the engine is in — not a label someone dragged a card into. Watch the live card walk through its life.

Ready

Admitted. Dependencies met, budget held.

release.verify
cmt_9c41unpriced
Running

Leased to a worker.

catalog.observe
cmt_4be00.18
lease ends in 4m 12s
Waiting on you

Nothing proceeds until you decide.

Settled

Closed on evidence.

intent.assess
cmt_1a770.42
evidence ×2
Blocked

Failed or escalated, with the reason.

egress.dial
cmt_02d50.00
BUDGET_EXHAUSTED

You can't drag a card to "done". The engine decides when work moves, based on the rules you set — a drag handle would promise a power nobody has. The board is an illustration of real states, not live data.

Fig. 08 · Mission board — localhost:58080

[09] Every refusal has a name

When it stops, it tells you why.

When an agent stops, it should be able to say why. foxora has exactly ten reasons it can say no — each one named, each with a plain explanation and what to do about it. Never a silent failure, never a log line you have to go hunting for.

0named reasons

Table 08 — MissionBlockReason · closed set

The identifiers live in attention.proto — grep for MissionBlockReason and count them yourself.

CLOSED SET OF TEN
01 Waiting on earlier work DEPENDENCY Waiting on another commitment this one depends on. Settle the dependency, or drop it from the plan.
02 Too early NOT_BEFORE The commitment names a time that has not arrived yet. Wait, or move the not-before earlier.
03 Someone already has it LEASED Already held by a worker under an active lease. Wait for the lease to expire or resolve.
04 Already finished TERMINAL The commitment already failed or completed. Nothing to do — read the settlement.
05 Would blow the budget BUDGET refused in the same transaction as the charge Would push consumed spend past a limit on some axis. Raise the limit on that axis, or spend less.
06 At capacity ADMISSION_LIMIT The mission or org is at its concurrent-lease ceiling. Wait for a lease to free, or raise the ceiling.
07 Cleaning up first RECOVERY The Intent is paused under RECOVERY_ONLY pressure. Resolve the pressure the self-model flagged.
08 The what-if said no COUNTERFACTUAL Foresight scored this ALTERNATIVE or NO_ACTION. Review the branch evaluation before forcing it.
09 A dependency is unhealthy OPERATIONAL_READINESS A dependency the self-model tracks is not healthy. Clear the deficit the self-model named.
10 The system is under pressure HOMEOSTASIS System-wide pressure is above NORMAL for this Intent. Wait for pressure to clear, or raise it by hand.
0silent drops

[10] Spend

Same work. Half the bill.

foxora sends each step only what it needs, and routes it to the cheapest model that's good enough for that step. The same job costs 50–60% less than running all of it on OpenAI, Claude or another frontier model. And a hard ceiling means the bill can never surprise you.

Where this goes: agents that don't depend on frontier models at all. Each agent chooses the model for each piece of work itself — the most efficient one that clears the bar, and the cheapest — including small models built for the job.

intent budget · close the quarterceiling $12.00
MoneyA hard cap in real currency.
Tokens inWhat it is allowed to read.
Tokens outWhat it is allowed to write.
TimeHow long it may hold the job.
$9.30 spent ⃠ next charge $3.50 — refused, would exceed ceiling

Four limits — money, words in, words out, time — and every one is enforced by the engine, not by a warning email after the invoice. Fig. C · intent budget

50–60%less than one frontier model doing the whole job
80%less for the same job in the foxora desktop app
$0ever spent past a ceiling you set

[11] What can be checked

Nobody has said anything about foxora yet. Here is what you can check instead.

No customer quotes, no logos, no adoption numbers — there are none, and inventing them would be the first thing this project claims to prevent. Everything below is a fact you can verify yourself in the time it takes to clone the repository.

  1. 010 crates in the open the whole engine, Apache 2.0 — not a demo of it
  2. 020 tests you can run cargo test — the count of test functions in crates/
  3. 030 protocol contracts every boundary in contracts/proto, written down before the code
  4. 040 decision records why each choice was made, including the ones that were wrong
  5. 050 bytes sent to us open DevTools ▸ Network on this page and watch

Drafts · sent for approval, none confirmed

Draft · awaiting Fran’s word

“It stops when it says it will stop. That turns out to be the whole thing.”

Fran · [role]

Draft · awaiting Andy’s word

“It waits. That sounds small until you’ve had something not wait.”

Andy · [role]

Draft · awaiting Royal’s word

“It runs on our own machines and sends nothing anywhere. That was the end of a much longer conversation with our security people than I expected to have.”

Royal · [role]

Draft · awaiting Dr. Milo’s word

“What I care about is being able to reconstruct, afterwards, why a system did what it did. This is the first agent runtime I’ve seen that treats that as a requirement rather than a feature request.”

Dr. Milo · [role]

Every statement above is a draft written for that person to approve, reject or rewrite — none of them has said these words yet. Each becomes a real statement only when its subject confirms it in writing, and the counter above stays at zero until then.