Capabilities and boundaries#
Rat Things accepts work into a durable control plane and runs agents in isolated AWS workers using dedicated EC2 instances or Lambda MicroVMs. Start with the operating model for the core objects and the architecture for their implementation.
Current maturity#
Rat Things is an engineering preview for owner-operated deployments. Its isolation and recovery mechanisms do not make it a production-ready, untrusted multi-tenant service. Choose deployment identity, retention, network policy, and operational limits for the environment that will use it.
| System | What it provides | Learn more |
|---|---|---|
| Sessions and Turns | Owner-scoped input, ordered execution, cancellation and saved Items | Agents API |
| Agents and schedules | Reusable standard Agent configurations and AWS schedule inputs | Agents, schedules |
| Connections | Provider-verified accounts, host-owned credentials, grants, and account-specific operations | Integrations |
| Capability envelope | A fixed intersection of provider, deployment, profile, account, and Session permissions | Permissions |
| Session history | Durable outbox, runtime journal and saved Items in the console and SDK | Session durability |
| Execution | Private EC2 or MicroVM harness; saved Session history survives worker loss | Agents execution |
| Files and publications | Private retained bytes, immutable Session artifacts, and expiring file/site/video share grants | Files, publishing |
| Browser | Declared function/MCP integration and an optional Playwright MCP configuration | Browser use |
| Channels | Signed GitHub, GitLab, Teams, and optional Slack ingress with separate result delivery | Channels |
| API authentication | AWS IAM issuance and owner-bound, scoped bearer tokens | API permissions |
| Model authentication | Operator-configured ChatGPT credential bridge or Bedrock access | Credential lifecycle |
| Recovery | Queue repair, generation-fenced liveness, cancellation settlement, and per-destination delivery fences | Runbook |
Known gaps#
- Multi-tenant operation: destination authorization, output redaction, per-owner budgets and rate limits, and independent security review remain incomplete. The control API's ownership checks do not replace these controls. See the security model.
- Credential isolation: the ChatGPT file bridge exposes reusable account credentials to code running as the agent UID. Use it only with trusted agents and accounts. Generic source bindings also require a trusted operator; arbitrary provider selectors are not provider-verified.
- Channels: Teams uses an outgoing-webhook/Workflow or reply-gateway bridge. A native Entra/Bot/Teams gateway remains future work. Linear provides account tools but cannot start conversations through native mentions, delegation, or Agent Session events.
- Browser scope: an ordinary Session has no browser provider. The optional provider must be installed in its execution environment. The console has no live browser viewer or takeover; authenticated browser-profile restoration is not a supported continuity guarantee.
- Memory and collaboration: native Codex state and bounded replay are durable. Rat-specific semantic memory, fallback summaries, explicit agent handoffs, and shared-conversation membership are not implemented. Storage retention is finite and is separate from a backup policy.
- Capacity: startup latency, quotas, concurrency, and cost depend on the deployment. There are no sustained-load or cross-Region recovery guarantees. See cost drivers and startup diagnosis.
- Extensibility: provider adapters are trusted code. There is no public plugin marketplace, arbitrary runtime plugin loader, or general visual workflow builder.
Roadmap#
The next system improvements center on four areas:
- Add usage budgets, per-owner limits, destination authorization, and output controls around the existing fixed capability envelope.
- Extend host-owned provider integrations and define a contributor SDK before expanding the connector catalog.
- Improve browser credential isolation, interaction coverage, and recording finalization without exposing a general remote desktop.
- Define shared-conversation authorization, semantic memory, and explicit handoff contracts on top of the durable Session history and outbox.
Enterprise administration remains outside the current product scope. Dedicated EC2 workers support persistent harnesses; Lambda MicroVM workers have a bounded lifetime.
Reference provenance#
The AWS Lambda MicroVM sample at
2a574ea
informed lifecycle/image behavior. Sentry Junior at
cc9bd53
informed the composition-root, provider-plugin, ingress, identity/credential, execution, delivery,
and durable-mailbox boundaries. Neither codebase is vendored; attribution is in
NOTICE.