Glossary

Every word the Leviath docs use in a particular way, in one place. If a page uses a term you have not met, it should be here.

The basics

Agent: the casual word, and it means two things. "The agents I've built" means blueprints. "The agents I'm running" means runs. These docs say blueprint or run where the difference matters.

Blueprint: the files you write to define what a run does: its agent.leviath file (stages, models, tools, regions) and the tools and scripts in the directory beside it. Some older text says manifest for the agent.leviath file.

Run: one execution of a blueprint, started with lev run, with its own id and its own memory. A blueprint is the recipe, a run is the cooking.

Run id: the name a run is known by everywhere outside the engine, such as coder-1785568852-8b48c0d1e2f3. The CLI, the API, and the dashboard all use it. It is the handle you pass to lev cancel, lev msg, and the rest.

Daemon: the background process that holds every running agent. See the daemon.

Unattended: a run with nobody watching, usually started with --yolo. Tools that wait for a person are removed so the run does not stop for somebody who is not there. It waives approvals, not checkpoints: a stage keeps whatever it lists in required_tools, and an interaction point declaring unattended = "ask" still opens its prompt.

Workdir: the directory a run treats as its project. File tools cannot read or write outside it unless you grant a read path. Defaults to wherever you ran lev run.

Workflow

Stage: one step of a blueprint's graph, with its own model, tools, and context.

Transition: an edge from one stage to another. A hint transition is chosen by the agent. A conditional transition fires on its own, on a runtime signal.

Transform: what an edge does to the context on its way across. direct carries everything, clear drops it, compact summarizes it. See carrying context.

Stuck: a measured condition, such as too many iterations or repeated edits to one file, that lets a stage escape a loop. The agent does not get to declare it. See stuck detection.

Nudge: a short [System] message the runtime adds to a conversation to get an agent moving again, for example when it replies with text instead of using its tools. It is only a message. It never fails or reroutes a stage. See nudging.

Interaction point: a place in a blueprint where the run stops and asks a person something. Some older text calls these checkpoints. See Human-in-the-loop.

Deny with feedback: refusing a tool call and saying what the model should do instead. The text reaches the model inside the refused call's tool result, so its next turn is a redirect rather than a guess. The dashboard offers it on an approval prompt, lev respond takes --feedback, and the API takes feedback. See Human-in-the-loop.

Seed command: a shell command that fills a context region before the run starts.

Spawn: starting a run. Also used for the moment it starts, as in "resolved at spawn", meaning worked out once when the run began rather than repeatedly.

Memory

Context region: a named part of a run's memory (its context window) with its own budget and its own rule for what to throw away first. See Structured context.

Eviction: what happens when a region goes over its budget. Depending on the region's kind, its content is dropped, summarized, or cleared.

Compaction: summarizing a region's content with a model call so it takes fewer tokens, rather than discarding it. Slower than eviction, and keeps more meaning.

Budget: how much of the context window a region may use. Often written as a percentage so the same blueprint works across models with different window sizes.

Journal: the append-only record of what a run did, written as it happens. It is what lets the daemon reload an interrupted run without repeating tool calls that already took effect.

More than text

Part: one typed piece of content. A context region entry, a tool result, a message you send, a model's reply, and a run's output are each a list of parts. A part is a mime type and a body: a text body travels inline, any other body is a stored part. See More than text.

Mime type: type/subtype, naming what a part is, such as image/png, application/pdf or model/obj. It is not a fixed list; the mime registry says what each one means.

Mime registry: the table that says what a mime type is: its family, whether its bytes are text, its file extensions, and its token cost. Compiled defaults, layered under rows from your config, a blueprint, or a provider. See More than text.

Blob: the bytes of a stored part, kept once by content hash under a run's blobs/ directory and referenced from wherever the part appears. Deleted with the run.

Stored part: a part whose bytes live in the blob store rather than inline, because its type is not text: an image, an audio clip, a document, a model.

Stand-in: the short text a stored part shows to a reader, or to a model that cannot take its bytes, such as [image/png 1024x768, 240 KB] hero.png.

Delivery: how a stored part reaches a model: native (the bytes as an image, audio or file block), text (its bytes as text, for a text type), or stand-in (only the description). The registry picks a default and a stage or an attach can override it.

Artifact: a typed file a stage declares and a run submits as output, validated against its declared type and served over the API. See Outputs.

Running many agents

Sub-agent: a child agent started by another one, running in the same process at some depth.

Fan-out: a stage that splits work into items, runs one sub-agent per item, and merges the results.

Tick: one pass of the engine over every agent. See the engine.

Fingerprint: a count of how many agents are in each state, plus a per-agent progress digest that catches an agent leaving and re-entering the same state. When a whole tick leaves it unchanged, nothing moved, so the engine sleeps.

Dispatch: handing work out. A dispatch system starts a model call or a tool batch. A collect system picks the result up later.

Marker: the component that says what an agent is currently doing. An agent has no field for its pipeline phase. It carries one of twelve markers, and each system acts on the marker it cares about.

Permit: a slot in a pool. An agent takes one before calling a model and gives it back when the call finishes.

Inference pool: the per-model cap on how many requests may be in flight at once. See inference pools.

Tool lane: the shared cap on how many agents' tool batches may run at once across the whole daemon. See the tool lane.

Backpressure: what happens when a pool is full. New work is not started yet. Nothing fails and nothing queues up at the provider.

Park: to stop and wait, without holding anything up. It means two related things. A run parks when it is waiting for a person to answer. A tool batch parks when it gives its lane slot back while it waits, so other work can use it.

Wedged: stuck in a state nothing can move it out of. Different from parked, which is a normal wait, and from slow. [limits] wedge_timeout_secs fails wedged runs instead of leaving them reporting as running.

Extending it

Rhai: a small scripting language embedded in Leviath. You use it to add tools, model providers, context regions, and policy rules without rebuilding anything. See Rhai scripting.

Hook: one of the functions your Rhai script provides for the runtime to call, such as render or on_write on a custom region.

MCP server: an external Model Context Protocol tool server that Leviath connects to in order to offer its tools to agents.

Provider: a model backend such as Anthropic, OpenAI, or Ollama. See Providers.

Gateway: a server that speaks OpenAI's chat API in front of whatever models it holds, such as llama.cpp, LM Studio, or vLLM. You add one as a [model_providers.<name>] entry with kind = "openai-compatible" and a base_url. It is a route to models rather than a model family, so Leviath asks it what it serves. See custom OpenAI-compatible providers.

Safety

Sandbox: per-agent or per-stage isolation, using a container, a namespace, or nothing.

Taint: the sensitivity label on each region, one of Public, Internal, or Private. The runtime assigns it. Model output never can.

Clearance: how sensitive a tool is allowed to handle. A tool that could send data off the machine is blocked when the data's taint is above its clearance.

Exfiltration-capable: describes any tool that could carry bytes off the machine, such as an HTTP request or an email. These are the tools the taint gate checks.

Control socket: the local Unix socket, or Windows named pipe, that the CLI uses to reach the daemon. It is not a network port. For network access, run lev serve.