Dedicated worktrees. Isolate mission changes
from your primary checkout, with supervised child processes
and cleanup.
Roles with distinct authority. Separate
planning, implementation, and review permissions; record
denials and human command grants.
Explicit credentials. Clear child
environments and admit only sanctioned backend credentials and
declared secret channels.
Filesystem & network boundaries. Enforce
supported sandbox profiles and filtered network access. Worker
sandbox enforcement currently requires Claude Code.
Contained validators. Review in disposable
snapshots with the real source tree denied; unsupported
containment fails closed by default.
Secret protection. Scan and redact at log
ingestion, scan before merge, and audit fingerprint-based
waivers. Separate read and mutation tokens protect the API.
Contract checks. Engine-run commands capture
test, build, and lint results; judgment assertions are checked
against the mission diff.
Two independent review roles. Functional
validation judges captured results. Scrutiny checks intent,
weak tests, and integration seams.
Reviewer independence. Optionally require a
different model family for review, pinned at approval and
enforced across fallback choices.
Functional UI review. Configure browser or
computer-use QA for repositories with a runnable, scriptable
application.
Bounded recovery. Cap repair cycles and
worker respawns. Unresolved work becomes blocked; a mission
with no feature deliverable fails.
Gated local merging. Run base-owned gates in
a scratch worktree against the pinned integration commit. The
human triggers the merge; local Kranz never pushes.
CLI, web & desktop. Plan, approve, run, and
inspect missions in the terminal, Mission Control dashboard,
or Tauri desktop shell.
Slack control. Plan in threads, approve,
steer, configure, and receive mission notifications with
authorized-user spend controls.
Even Realities G2 glasses. A lightweight
client uses the mission API for glanceable status and
controls. Hardware validation is still pending.
Live steering. Message, interrupt, pause,
resume, unblock, or abandon; queue role and model changes for
subsequent sessions.
Multiple repositories. Serve a host catalog
with repository-specific missions, queues, configuration, and
Slack routing.
Optional parallel workers. Dispatch
independent features in separate worktrees and integrate in
declared order. Sequential execution remains the default.
Crash recovery & hygiene. Resume from logged
progress, recover provably dead locks, and clean or archive
old missions. Core CLI support spans macOS, Linux, and
Windows.
Backend choice by role. Claude Code, Codex
CLI, Factory Droid, Kimi Code, Cursor, ACP-compatible agents,
and OpenAI-compatible local inference.
Tracked routing policy. Base-owned rules
select backends and models within declared role, readiness,
and containment constraints.
Divergent candidates for review.
Heterogeneous dispatch compares agent outputs as evidence,
with explicit cost consent and no automatically merged winner.
Headless automation. Feed a plan to
kranz exec; receive distinct complete, failed,
blocked, or underspecified exit codes.
API & event streams. Build clients against
the REST API and live WebSocket/SSE mission feeds.
External work intake. Integrate Gas City /
Beads work, import OpenSpec changes, and configure workspace
bootstrap and data hooks.
AVAILABILITY Core workflows run locally. Cloud missions
are a preview; the Even Realities G2 glasses client awaits hardware
validation. Backend, model, and sandbox capabilities vary.