AIec

Roadmap

Every capability the project has, labelled with what it actually is. The point of publishing the whole list — including the parts that are only designed — is that a reader can tell the difference without asking.

What the status words mean

stable
Implemented, regression-tested, and exercised by a recorded live acceptance artifact.
alpha
Implemented and tested, but the proof is a test rather than a recorded live deployment, or the interface may still move before 1.0.
experimental
Implemented and deliberately not relied on. Read its caveat before using it.
planned
Designed and documented. Not implemented. Nothing on the website may present this as available.
Planned means not implemented

Nothing on this site presents a planned capability as available. If you need something from the planned list, it is a design conversation, not a configuration change.

The inventory

stable

12

alpha

10

experimental

2

planned

3

Every capability with its reviewed status and the file that implements it.
Capability Status Note and implementation evidence
Firecracker microVM sandboxes
Isolation
stableForced by runtime policy for untrusted workloads. A tenant cannot request a weaker runtime to downgrade their own boundary.
crates/aiec-runtime/src/lib.rs → FirecrackerRuntime; benchmarks/guard-core-acceptance.json
Docker sandbox runtime
Isolation
alphaAvailable for trusted self-hosted deployments, local development and operator tasks. Not offered to untrusted public workloads.
crates/aiec-runtime/src/docker.rs
Bubblewrap development runtime
Isolation
experimentalLocal development. Workspace snapshots have been exercised by restoring into a distinct sandbox; it is not the untrusted-workload boundary.
crates/aiec-runtime/src/lib.rs → BubblewrapRuntime
External hosted isolation provider
Isolation
alphaThe isolation boundary would be owned by the provider, not by AIec, so this kind never runs on a managed worker node. NOT exercised against a real provider; no live evidence exists.
crates/aiec-core/src/lib.rs → RuntimeKind::Hosted
Create, exec, files, pause, resume, destroy
Sandboxes
stableWorkspace paths are confined and reject traversal and symlink escapes. Directory listings are bounded rather than truncated.
crates/aiec-api/src/lib.rs; scripts/smoke.sh
Bounded CPU, memory, disk and wall clock
Sandboxes
stableQuotas are enforced in the same transaction as placement, under a per-tenant advisory lock.
crates/aiec-core/src/lib.rs → QuotaLimits; enforcement in crates/aiec-storage
Runs: submit, results, events, artifacts, cancel
Durability
stableEvents, attempts and artifacts for one run are bounded by construction, not by pagination.
crates/aiec-api/src/runs.rs; scripts/firecracker-coding-dogfood.sh
Lease and generation fencing
Durability
stableA superseded worker cannot execute, write, stop, destroy or complete against a reassigned sandbox.
crates/aiec-core/src/scheduler.rs; enforcement in crates/aiec-storage
Cross-worker recovery from a workspace archive
Durability
alphaPostgreSQL leases plus an S3-compatible workspace archive. Running VM memory is not the portable recovery unit, and multi-host recovery has not been validated by the recorded evidence.
docs/DEPLOYMENT.md; benchmarks/snapshot-acceptance.json
Workspace snapshot, destroy source, restore into a new sandbox
Snapshots
stableThis is the portable kind.
benchmarks/snapshot-acceptance.json (12/12 against real S3 storage)
Full VM and memory-only Firecracker snapshots
Snapshots
experimentalWorker-local recovery artifacts. Do not present them as portable workspace snapshots; compatible host and device-path portability is unproven.
docs/SNAPSHOTS.md; crates/aiec-core/src/snapshots.rs
Guard: out-of-guest network, DNS and credential boundary
Governance
stableDefault is no network. A sandbox asking for a network without selecting a policy is refused, not quietly filtered.
benchmarks/guard-core-acceptance.json (48/48); docs/GUARD_THREAT_MODEL.md
Watchdog, dead-man switch and quarantine
Governance
stableLoss of the watchdog is fail-closed and latches. The guest is not destroyed, so a forensic capture is still possible.
benchmarks/guard-phase2-acceptance.json (29/29)
Guard tool-approval proposals and operator decisions
Governance
alphaAn agent can propose a policy change and cannot approve one. Proposal ownership is tenant-checked.
benchmarks/guard-phase3-acceptance.json (47/47); benchmarks/guard-approval-acceptance.json
Per-VM identity, image trust and canaries
Governance
alphaTrusted host file APIs can observe reads; arbitrary in-guest exec reads are not observable through those APIs.
benchmarks/guard-phase5-acceptance.json (37/37)
Durable lifetime reaper
Governance
stableThe second run goes through the external-database relay.
benchmarks/guard-reaper-acceptance.json (16/16); benchmarks/guard-reaper-external-db-acceptance.json (16/16)
Layer 7 visibility (method, path, tool) for governed traffic
Governance
plannedNot implemented. Opaque TLS is not inspected. A CONNECT tunnel needing Layer 7 visibility is REFUSED rather than forwarded ungoverned, and TLS interception is not claimed as a validated deployment mode.
docs/GUARD_THREAT_MODEL.md
Eval batch, repetitions and matrix
Evaluation
stableEvery cell gets its own machine and is kept whole. A bounded request returns the runs.
crates/aiec-api/src/evaluations.rs; sdk/python/agentforge/evals.py
Suite expansion and baseline-versus-candidate compare
Evaluation
alphaCounts and measurements over the same runs. No pass rate dressed up as a score, and no percentiles invented from a handful of samples.
evaluations/omp-regression.json; sdk/python/agentforge/evals.py → Comparison
Run Capsules and trajectories
Evaluation
plannedNot implemented. Do not advertise as shipped.
docs/ROADMAP.md
Python SDK
Interfaces
stableKnown gap: `run_cells` chunking is unimplemented because changing it breaks the `#[tool]` macro boundary.
sdk/python/agentforge; scripts/check-sdk-contract.py
Rust client and CLI
Interfaces
stableJSON output, so anything pipes into jq.
crates/aiec-client; crates/aiec-cli
Local MCP server
Interfaces
alphaExposes the same lifecycle as tools. The owned-sandbox listing is bounded and prunes finished machines.
docs/MCP.md; crates/aiec-mcp (a Rust binary, not part of the Python SDK)
`aiec doctor`
Interfaces
alphaReports OS, runtime, bubblewrap, Docker, KVM, database configuration and the Firecracker binary, kernel, guest artifact and wire protocol. It REPORTS; it does not refuse to start.
crates/aiec-cli/src/main.rs → doctor
Tenant-scoped API keys with scopes
Tenancy
alphaKeys are stored hashed and compared in constant time. Granting scopes and revoking keys both require the caller to hold the authority being granted or destroyed. API may change before 1.0.
crates/aiec-api/src/lib.rs (the /v1/keys routes); crates/aiec-api/tests/routes.rs
Per-tenant usage accounting and Prometheus export
Tenancy
alphaUsage events are append-only and idempotent, so retries do not double-count.
the GET /v1/usage route in crates/aiec-api/src/lib.rs; the Prometheus exporter in crates/aiec-api
Aggregate per-tenant snapshot and persistent-storage byte quotas
Tenancy
plannedPer-request size ceilings exist. Aggregate byte quotas do not.
docs/known-defects.md

The evidence column names the file and symbol that implements each capability. If a row looks wrong, that file is where to check it.

Designed but not built

These are the capabilities whose status is planned. They are not available, not configurable, and not imminent. They are here so the design is reviewable before anyone depends on it.

Deliberately out of scope

A hosted AIec

There is no managed service and no sign-up. Capacity comes from the hosts you run. This is a self-hosted product and its distribution is the source code.

Moving your work to a cloud provider

When every local worker is at capacity, AIec refuses the placement. It does not quietly spill a workload somewhere else, because a silent change of isolation boundary and jurisdiction is not a reasonable default.