Artifacts

When an agent produces something meant to last and be looked at — a rendered report, a chart, a page — it's an artifact: a first-class output with its own durable storage, version history, and safety posture, not a message that scrolls away.

A durable artifact is delivered, then revised in place — a new immutable revision advances `latest` while the link keeps pointing at the report.

A first-class output, not a chat message

An artifact lives in a durable object store, not in the transcript, and its bytes survive the session. It's versioned — each change is a new immutable revision — and it can be revised in place, so "the report" is a stable thing you can point at while its contents evolve. It carries metadata you can annotate, it's rendered inert so it can be displayed without being trusted, and it's delivered as a deliverable the session is accountable for.

Where the bytes live

The store is a pluggable blob backend chosen at install — cloud object storage (gs://, s3://, azblob://) in production, a local volume for a laptop. The platform is fail-closed about it: run without a configured artifact store and it refuses to start rather than falling back to an in-memory store that would silently drop every output on restart. oap artifact inspects them from the CLI.

Go deeper

  • Revisions & versioning — immutable revisions, a moving latest, and revising in place.
  • Annotations & tags — names, descriptions, and named tags that point at a revision.
  • Rendered inert — sanitize, constrain with CSP, and isolate the origin so an artifact's scripts can't run.
  • Delivery & completion — producing isn't delivering, and a session can be required to actually hand its work over.