Argos

Delegate the work.
Keep execution
under control.

Argos sits between autonomous coding agents and consequential changes, allowing expected work, holding uncertain actions, blocking protected operations, and independently checking the final result.

Request a controlled pilot

Codex 0.143.0 alpha / Supported apply_patch operations

Illustrative execution path
01 / AI operationARGOS
Execution boundary
02 / Repository
write_file src/payments.tsALLOW
Through the boundary.

Expected scope / Authorized operation executes.

Changed by the allowed operation

Sample operations. No repository is connected.

In the execution path. Before the change.Follow a Task
01 / The execution pathOne Task. Separate facts.

01/ 07

Delegate a task. Not unlimited authority.

Fix the checkout timeout. Keep authentication unchanged. The human defines the work before the agent begins.

TASK
Task / checkout-timeoutIllustrative
CodexProposed operation
ARGOSBefore mutation
RepositoryUnchanged
EXPECTED src/checkout.tsREVIEW src/config.tsPROTECTED src/auth/session.ts
Fix checkout timeoutIntent declared

Illustrative lifecycle. Only instrumented operations cross this boundary.

02 / Control before mutation

The right action.
The right amount of attention.

EXPECTED, REVIEW, and PROTECTED are Task-relative scope. ALLOW, REVIEW, and BLOCK are the decisions at the execution boundary.

ALLOWEXPECTED scope

Keep moving.

An expected supported operation proceeds without a human interruption.

src/checkout.ts
Not attempted
REVIEWREVIEW scope

Bring in a human.

Hold the operation before mutation. A separate human identity makes the decision.

src/config.ts
Not attempted
Illustrative human decision
BLOCKPROTECTED scope

Stop before the change.

The proposed operation cannot execute through the controlled boundary.

src/auth/session.ts
Not attempted

Interactive illustrations only. No repository is connected. Argos controls supported, instrumented operations, not every action on your machine.

03 / Inside a controlled session

See where the work stops.
And where it keeps moving.

One Task, three proposed changes. Run the example and make the human decision when shared configuration needs review.

Illustrative session
$ argos run
No live repository connected

Example paused.

Current alpha: Codex 0.143.0 through the supported apply_patch boundary. Invited workspace and package access required.CLI setup

04 / Execution is not verification

Execution succeeded.
The task didn't.

The agent says Task complete. Execution is recorded. Then an independent check fails. Argos preserves all three facts instead of turning a successful patch into a successful Task.

Independent verificationIllustrative record
AUTHORIZED EXECUTED INDEPENDENT CHECKS

Execution / recorded

EXECUTED ≠ VERIFIED

The patch ran. Did the declared engineering outcome actually happen?

FAILED

A focused test failed. Execution remains recorded. No automatic repair.

  1. 01Required repository outcomePASS
  2. 02Protected paths unchangedPASS
  3. 03TypecheckPASS
  4. 04Focused testsFAIL
  5. 05BuildPASS
Source / independent repository stateAgent completion claims are not evidence.
What the independent verifier actually checks
  • Required repository change independently observed.
  • The changed-file set matches the declared task scope.
  • Protected paths remain unchanged.
  • Dependency changes match the frozen plan.
  • Required typecheck, focused tests, lint, and build run where declared.

Deterministic verification proves the declared contract, not broad semantic business intent. Ambiguous execution remains unresolved instead of being retried blindly.

05 / The execution record

Not another dashboard.
A record you can inspect.

The request, the authority, the attempted change, the human decision, and the checked result. Connected to one Task.

TASK 01842Illustrative record / sample dataVERIFIED
Requested

Fix checkout timeout.

Keep authentication unchanged. Run the declared checks.

Agent
Codex 0.143.0
Execution
2 operations recorded
Human decision
1 approved REVIEW
Verification source
Independent repository checks
Operation / targetWhat happened
ALLOWsrc/checkout.tsExecuted
REVIEWsrc/config.tsApproved / executed
BLOCKsrc/auth/session.tsBlocked / not executed
Required outcome observedTypecheck passedIntegration test passedProtected state unchanged

Real Task and Evidence links require authentication. Possession of a URL grants no access.

06 / Alongside your existing controls

Keep your controls.
Add a Task boundary.

Native sandboxes, Git, CI, and security tools still have their jobs. Argos adds task-scoped execution control and separate verification at the supported integration boundary.

Your existing controlsSandbox / Git / CI / security tools
ArgosTask scope / interception / verification

Separate identities. The agent execution key cannot make a human approval.

Fail-closed launch. Required interception components are checked before the controlled session begins.

Inspect the trust boundary

07 / Controlled pilot

Start with work worth delegating.

The current alpha is founder-assisted. Agree the repository workflow, access, and commercial terms before a pilot begins.

Founder-led engagement

One repository.
A clear starting point.

Work with the Argos team to connect a real Codex workflow, define its scope, and inspect the outcome together.

Let's talkScope and terms agreed before the pilot.
Apply for early access

No fixed public package or per-seat price is currently offered.

What our team brings

  • Task and scope mapping
  • Integration-boundary assessment
  • Intervention design
  • Verification design
  • Pilot validation
  • Direct founder involvement
Already have access? Open Quickstart
In the execution path. Before the change.

More work delegated.
Authority still defined.

Start with Codex, one repository, and a boundary you can inspect.