This is the only forward-looking page for Seed Agents. It lists what is open, in rough priority, as of 2026-09-16. The reference pages (tools, triggers, persistence, security, and the rest) describe everything that shipped. The design records and build logs that used to sit beside this page are in git history. The larger open designs each have their own page under plans.
What exists today
These parts are complete enough to build on:
a standalone Bun service with a signed CBOR HTTP API and signed WebSocket subscriptions (signed API, WebSocket subscriptions);
SQLite persistence behind a schema gate, and encrypted provider secrets;
registry-driven model providers (OpenAI, Anthropic, Google, OpenRouter, DeepSeek, Groq, xAI, Ollama, custom) executing through the Pi SDK, with reasoning levels and ChatGPT subscription sign-in;
agents, sessions, collaborators, public read, and public chat;
the runs tree as dispatch queue, with leases, boot-sweep recovery, fair-share ordering across accounts, and cancellation over subtrees;
tools as content-addressed tool documents with touch-expand and promotion;
remote MCP servers;
model and script children with typed results and journaled replay;
budgeted delegation with thoroughness presets;
parked runs and every wake source;
six trigger sources and four continuations;
the symmetric log with the wrench palette;
session continuation in place of compaction;
per-agent memory, attachments, self-hosted web search and reading, and sandboxed execution with an opt-in warm microVM pool;
the shared desktop and web UI (desktop UI), and the local agents server embedded in the desktop app;
delegated signers proven by a published capability blob.
Highest priority
1. Trigger documents
Triggers are the one piece of standing authority an agent holds. They are still SQLite rows behind CRUD actions, plus the ~/triggers/ verb surface. The planned work:
content-addressed trigger documents versioned by CID, like ~/tools/;
a migration off agent_triggers that carries firing keys forward so nothing re-fires;
a document-change source and an appendTo continuation;
deleting the CRUD actions;
a desktop editor that replaces the dialogs. The dialogs cannot create a run-completed trigger today, but the API and the agent's write ~/triggers/<name> can.
The earlier draft-then-activate consent proposal is not wanted.
2. Delegation budgets: pauses, tree budgets, cost
A run that uses up its fan-out budget is told to finish alone, and nobody is asked. The follow-on project, in delegation budgets, makes three changes. A pause card that the person answers replaces the refusal. The budget moves to the root of the tree, so a grant is one write and a meter is one query. Budgets are counted in tokens, and later in money. Prod runs 8 model runs at a time, so a fan-out of 16 finishes no faster than 8. The prompt should say so.
3. Speed and cost of every turn
Every provider request re-uploads the whole session, and a cold microVM boot takes most of the time in short execute calls. Instrumentation (/api/perf, per-stage spans) and the warm pool are done. The pool stays opt-in (SEED_AGENTS_EXEC_WARM_POOL=1) until it is the proven default. Open: prompt caching and server-side conversation state per provider, context compaction of old tool results, byte-stable prefixes, and the dispatch and prep path (speed, model comms latency). Two smaller follow-ups from the 2026-08 production investigation: per-agent log files, and spilling oversized tool outputs to files at append time so a multi-megabyte event no longer costs every model turn.
4. Real parallelism
The server runs the API, the WebSocket fan-out, the poll loops, and every run on one JavaScript event loop, so a CPU-bound run stalls /api/health for seconds. The workflow VM already runs in a worker behind SEED_AGENTS_WORKFLOW_WORKER=1 as a proof of concept. The staged plan to move agent runs off the main thread is worker-isolated execution. Beyond one box, multi-server architecture describes sharding by account.
5. Provider hardening
Anthropic and Google run through Pi with mocked coverage only. They need real-provider smoke tests, a provider test action, capability status in the UI, and a decision on whether modelDefaults stays a raw payload override. cost is zeroed for every non-subscription model, so usage is counted in tokens and never in money. Per-provider reasoning quirks (deepseek, openrouter) are not wired up. See model providers.
6. Live-model gates
The deterministic gates pass, but the recorded cassettes predate the verb collapse (agents/e2e/recordings/STALE.md), so e2e-replay.test.ts skips and no scenario has run against a real model since the surface changed. Re-record, and write the missing battery scenarios.
Medium priority
Grants for query and attributes. Both callables exist in the registry. The app's Tools tab offers only search, web search, execute, and publish, and an agent created from the app stores exactly that list in its grants. The UI normalizer also drops the two names when it resaves. Only an agent whose tools array is undefined gets them. Either add the toggles or make them ungated.
Idempotency for an interrupted ctx.call. A call journaled without a result re-executes on resume. That is fine for reads and a hazard for writes.
WebSocket protocol v2. Heartbeat, explicit unsubscribe, CBOR server events, subscription limits, backpressure, reconnect cursors, metrics. Agent-run text partials remain ephemeral across a disconnect.
Provider and secret lifecycle. Providers can be deleted. Secret rotation and a general secret-deletion action do not exist.
Streaming subscription regression tests for the omitUndefined signing fix and CRLF SSE parsing.
Desktop packaging coverage. The smoke workflow runs on macOS only. Linux and Windows binaries are compiled but never executed in CI.
Rich tool results. Document previews rendered as documents, and the requested URL beside the resolved one.
Security hardening
Nonce caching on top of the signed-action timestamp window (5 minutes; duplicates inside it are accepted).
KMS or OS-keychain storage for the secret encryption key, which today lives in the same SQLite file as the ciphertext.
Rate limits and quotas. A reachable server accepts agents from any self-signed account.
An audit log for secret, provider, tool, and trigger events.
An outbound network policy for tools and an account-level tool policy above the per-agent one.
Documentation
Signed-envelope examples as runnable scripts, the delegated-signer flow end to end, a production deployment guide, and a threat model. The signed API page documents every action, but no client library exists outside the frontend monorepo. The protocol package is private.
Finished projects
Each of these was a plan page. The plan is in git, and the result is in the reference pages. Shared protocol package (agents/protocol). Pi SDK migration (every turn runs through Pi). Anthropic and Google backends (through Pi). Stop and cancel (StopSession, CancelRun over subtrees). Run records and the runs tree. Domain-aware reads (resolveIdWithClient with a domain resolver). Desktop agent unification (the local server as a desktop subprocess; the old assistant runtime deleted). Agent triggers phases 1 to 3, the event-bus first slice, the introspection slice, and headless continuations (triggers). Workflows v1 (runs, children, scripts, progress UI). The five-verb harness and tools as documents. The write tool with CLI parity (now the write verb). Tables round-tripping through markdown. The warm microVM pool. Execution timeouts, leveled logging, session wire-size caps, and fair-share dispatch after the 2026-09-07 queue-wait incident.
Definition of done
A milestone is done when all of these hold:
the code is implemented;
tests pass for the touched areas;
the reference pages describe the result, and this roadmap no longer lists it;
security and logging implications are reviewed;
the desktop smoke test has run, if UI or runtime behaviour changed.
Do you like what you are reading? Subscribe to receive updates.
Unsubscribe anytime