Skip to content

Nerve Cortex

The runtime that never loses its place

Nerve Cortex is the runtime Nerve built for its own Agents. It records every step before it acts, parks for approval without holding a worker, and recovers from a crash by reading its own ledger, so work finishes once and finishes right.

Nerve Cortex · run ledger

  1. queued
  2. running
  3. waiting approval
  4. completed

No worker yet

  1. Run createdRecorded before any work starts#1

Try it:

Demonstration with sample data

01Built by Nerve, not borrowed
Cortex is Nerve's own runtime. It does not sit on an agent framework, so its guarantees are Nerve's to keep and its behaviour is the same in every deployment.
02One runtime for everything
Agents, Nerve Command, workflows and the API all run on Cortex. One ledger, one set of limits, one place where authority is checked.
03The ledger is the memory
Every model call, tool search and tool call is committed before and after it happens. The conversation is rebuilt from the ledger each turn, so there is no hidden state to lose.
04Approvals that cost nothing to wait for
A high-risk call parks the run and releases the worker. Waiting time is not working time. When a person approves, the exact stored call resumes.
05Bounded by design
Turns, tool calls, tokens, time, repeated actions and delegation depth are all limited. When a limit is hit the run ends with a named reason, never a silent loop.
06Any model, your keys
OpenAI, Anthropic and OpenAI-compatible providers sit behind one port. Keys are stored write-only and read just in time.

How it is different

Built for the part where agents usually fail

Most agent loops are written for demos: they work until a process dies, an approval takes a day, or a model is tricked. Cortex is designed around those moments.

  • State

    A typical agent loop:Kept in the process, or in a second checkpoint store that can disagree with the business record.

    Nerve:One store. Each step is the checkpoint, committed in the same transaction as the run's next state.

  • A crash mid-action

    A typical agent loop:Re-run the step, or ask the model what happened. A sent email may be sent twice.

    Nerve:Recovery reads the records. A recorded outcome is taken as is and never called again. An effect that cannot be proven becomes OUTCOME_UNKNOWN and a person decides.

  • Waiting for approval

    A typical agent loop:A worker or connection stays tied up, or the step runs again from the top on resume.

    Nerve:The run parks, the worker is released, and resuming re-issues the stored call. The approval is bound to those exact arguments and is consumed once.

  • Illegal moves

    A typical agent loop:Enforced by application code that every path must remember to call.

    Nerve:A database trigger mirrors the transition table, so no code path can make an illegal move.

  • Prompt injection

    A typical agent loop:Tool output flows back into the prompt as trusted text.

    Nerve:Tasks, tool descriptions and results are wrapped as untrusted. Untrusted text cannot add a tool, widen a policy or change approved arguments.

  • Tool access

    A typical agent loop:The model is shown every tool, or one broad key.

    Nerve:The model sees three functions. Its tools are the person's grants, narrowed by the agent's policy. An empty policy admits nothing.

  • Tenants

    A typical agent loop:A free-form thread id, checked by the application.

    Nerve:Row-level security on every Nerve table, as everywhere else in the product.

A comparison of design approaches, not a benchmark.

One run, start to finish

  1. 1

    Record

    Every step is written down before it happens, and its result after.

  2. 2

    Check

    The Tool Gateway re-checks authority at every call. Consequential calls wait for a person.

  3. 3

    Recover

    If a worker dies, another continues from the ledger. Nothing is repeated.

Deploy your first Nerve Agent

Start with one conversation your team handles every day. Give the Agent what it needs to know, connect the tools it should use, and decide where a person steps in.