How Keystone works
Keystone is a runtime and platform for AI-agent work. It sits between coding agents and the systems they change: your repositories, GitHub, model providers, and cloud accounts. You use it through Keystone Studio, a desktop app, and through small command-line tools that agents call directly or over MCP.
This page builds the mental model that the rest of the docs rely on. It follows one ordinary moment, an agent's session ending partway through a task, and shows what Keystone keeps true through it.
Every session ends
An agent works inside a session, and every session ends. The context window fills and gets compacted, a process crashes, or a machine restarts. Whatever the agent was holding in its context goes with it.
With one agent, that's manageable, because you can hold the thread yourself. You remember what the agent was doing, what it was allowed to touch, and whether its last push went through. With ten agents, the thread gets long, and the work starts to depend on your memory.
Keystone moves the thread into records. The goal, the plan, the exact instructions an agent received, the approvals, and the results each live in a record, and each kind of record is kept by one program, its owner. So when a session ends, the work is still there. A fresh agent reads the records and continues, and so can you. Records and owners explains how owners work.
The next agent reads what happened
Now a new agent picks up the task. Before it acts, it needs to know two things: what has already happened, and what it is allowed to do.
What happened comes from the records. The new agent also starts with good material to think with. Memory holds the decisions the project has already made, and Context builds a pack of the files and notes this task needs. Memory and context covers both.
What the agent may do comes from approvals, and only from approvals. Agents can be persuaded by what they read, whether that's a web page or a file in the repository, and they can be confidently wrong about their own work. So an agent's words never grant it anything. Every approval in Keystone covers the exact instructions a person reviewed, and if those instructions change, the approval stops applying. Approvals walks through this.
An action with no answer stays open
Suppose the previous agent's work had reached GitHub: a merge request went out, and the session ended before the answer came back. Did the merge happen? Sending the request again won't settle it, because GitHub's answer would describe the second request and say nothing reliable about the first.
So before any outside action it governs, Keystone records what it is about to do. The new process finds that record of intent, sees that no answer was recorded, and checks GitHub before doing anything else. If the merge happened, Keystone records it. If the evidence can't settle the question, the action stays marked as unknown until someone looks. Effects and uncertainty goes deeper.
The tools talk back
As the new agent works, every command it runs returns text, and that text becomes part of the agent's next prompt. So Keystone writes its responses for the agent to act on. A refusal names the fact that failed and the step that can still work, and a status command says what it couldn't read. The agent spends its turns on the task, because the tools have already told it where things stand. Tool responses shows examples.
You come back to decisions
None of this needed you to watch. When you return, Keystone Studio shows you the work that needs a decision, such as a result to review. Your decision is bound to exactly what you saw, so if the result changes after you looked, Keystone asks you to look again.
The model in short
Work lives in records that outlast any agent, and each kind of record has one owner. An agent's words guide its own work, and permission comes only from approvals recorded for exact content. Before Keystone changes anything outside its records, it records its intent, and an outcome it can't confirm stays unknown. The tools tell agents where things stand, and people come back to decisions. The rest of the docs build on these ideas.
What you use
| Surface | What it's for |
|---|---|
| Keystone Studio | A desktop app for macOS, Windows, and Ubuntu. Talk with the Keystone Assistant and agent roles, follow the work, and review results. |
| Command-line tools | About forty small programs, each with one job, such as ksmem for project memory and kshub for model calls. Every command has --help. |
| MCP servers | ksmem, ksctx, and kshub expose their tools to Claude Code, Codex, and other MCP clients. |
| Keystone Install | A desktop app that installs, updates, repairs, and rolls back the tools. keystone machine does the same from a terminal. |
The command reference lists every tool.
Where Keystone is today
Keystone is in private beta, and its tools are used every day to build Keystone itself. Studio's complete review journey and the hosted cloud workers are pre-production. Security lists the limits that matter before you trust Keystone with sensitive code.