Napier · An inspectable runtime
An evidence ledger that connects execution, recovery, and replay.
What it does
Napier is a local-first agent runtime organized around an ordered evidence ledger. Messages, model calls, tools, goals, branches, artifacts, and control decisions are recorded together; chat and inspection views are projections of that record.
Its focus is making long-running work inspectable and recoverable. Compared with Anera's task-to-artifact desktop workflow, Napier places more emphasis on the runtime contracts for recording, continuing, branching, and verifying work.
Section sources
Durable evidence
SQLite WAL is the durable local source of truth. Event commits use BEGIN IMMEDIATE transactions, check idempotency and the expected revision or run head, and validate admission before appending. A repeated event can resolve to its existing record rather than becoming a second effect.
Terminal transitions also check tool-effect authority. A run should not be declared settled while a live tool still owns the right to produce an external effect. JSON and JSONL are compatibility projections, not competing authoritative ledgers.
Resume, branch, replay
Resume continues eligible interrupted work; a branch creates a continuation from an explicit recorded boundary; replay reconstructs and verifies recorded evidence. Replay does not rerun a model or repeat tool side effects.
Interruption recovery reconciles durable terminal evidence, lost execution leases, and orphaned interactions. If an external effect crossed a durable boundary but its outcome is unknown, the state can be indeterminate. It must not be silently treated as a safe operation to replay.
Policy and context
Tool-policy preflight runs immediately before execution and applies mode restrictions and browser-interaction confirmation rules. Policy decisions belong to the runtime, rather than being optional prose the model may ignore.
Context compaction preserves the objective, changes, artifact paths, verification, failures, and next actions. Older summaries and excerpts remain untrusted source material, and compaction participates in the same run and its budgets.
Access and limits
The repository was public at review time and includes an MIT license. This corrects an older website description that called the repository private. The architecture is local-first and uses Node.js, TypeScript, and SQLite, with Web and CLI inspection surfaces.
Recorded evidence can be verified and eligible work can resume, but these are not guarantees that arbitrary external actions are reversible or that every interrupted run is safe to continue.