Skip to content

Cloud Artifact Runtime ​

The Cloud Artifact Runtime turns a selected product output into a durable, workspace-scoped artifact version. It is designed for a person to create, follow, preview, download, refresh, and find the same output in the same conversation location later.

An artifact is for keeping, not for showing ​

Creating an artifact and displaying a result are separate operations, and the first is not how the second is achieved.

A conversation renders structure on its own. Prose, tables, fenced code and — depending on the surface — diagrams, typeset maths and callouts are drawn directly in the reply, with no file involved, no storage consumed and nothing to approve. That is a complete result: the block a client renders is the rendered output, not a source waiting to be converted into one.

An artifact is what a result becomes when it needs to outlive the turn — to be downloaded, versioned, attributed, shared, or handed to another tool. Ask for a file when you want a file. A request to see something produces something you can see.

Each surface declares what it can render inline, and the assistant is told what that surface actually supports rather than assuming the smallest common set. A surface that cannot draw a given format is not sent a broken block: it receives the source, or a downloadable version, whichever is honest for that content.

Immutable source, optional derivatives ​

Source bytes are immutable. A preview, thumbnail, converted document, or visible attribution is a separate derivative tied to one source version. A derivative can fail, be limited, or expire without changing the source version or its hash.

This distinction makes two things possible at once:

  • a person can verify the exact source bytes that were promoted; and
  • the product can choose the safest available preview for the content.

Preview capability and fallback ​

The API decides what preview capability is allowed after inspecting content. The client receives an approved descriptor rather than guessing from a filename or extension.

Source familyPreferred experienceHonest fallback
PDFRead-only document previewThumbnail and download
Text, Markdown, codeSanitized text or escaped code viewDownload
CSV, TSV, JSONBounded read-only tableSample data and download
MermaidRestricted diagram previewSource and download
Native chart or formCapability-limited native viewStatic representation and download
Workbook, presentation, or imported office fileA supported bounded derivative`preview_limited` and download
Static site or appIsolated production previewThumbnail and download

An unsupported format is not an error in source preservation. It is an explicit preview limitation so people can still download the exact version.

Conversation timeline ​

Artifact cards, operational activity, and visible reasoning share a conversation timeline but retain their own types:

FamilyWhat it communicates
`artifact.` and `preview.`Durable artifact and preview lifecycle.
`activity.` and `tool.`Safe operational progress and tool state.
`cot.*`Sanitized visible reasoning for eligible Chao sessions.

Keeping the families separate means an artifact update cannot erase or replace an eligible visible-reasoning step. The timeline preserves ordering, including think → tool → think sequences, while avoiding raw private reasoning and operational secrets.

Provenance without changing user files ​

For each immutable version, Chainabit can record a detached attestation that includes the source hash, byte size, recorded surface, execution plane, and creation context. The attestation is separate from the user’s source file.

The provenance labels are intentionally precise:

  • `imported_unverified` means a file was brought into the workspace without an authorship claim.
  • `promoted_by_chainabit` means Chainabit recorded an explicit promotion.
  • `derived_by_chainabit` means Chainabit produced a derivative from a recorded source version.

Safe dependency intake ​

Preview capabilities are deliberately small. A renderer must be locally bundled, version-pinned, licence-reviewed, listed in the project’s software inventory, and monitored for advisories before it is enabled. Public CDN execution is not used for artifact previews. New preview kinds must include an accessibility, fallback, and test plan before rollout.

Recovery lifecycle ​

Conversation deletion is more than hiding a card. It begins a recovery window for linked artifacts and related preview content. Restoring during that period is an explicit action. At final purge, retained source and preview content are removed according to the artifact lifecycle, while non-content completion evidence can remain for audit purposes.

Built with purpose.