Cloud Artifact Runtime
The Cloud Artifact Runtime turns a selected product output into a durable, workspace-scoped artifact version. It is designed for a person to create, follow, preview, download, refresh, and find the same output in the same conversation location later.
An artifact is for keeping, not for showing
Creating an artifact and displaying a result are separate operations, and the first is not how the second is achieved.
A conversation renders structure on its own. Prose, tables, fenced code and — depending on the surface — diagrams, typeset maths and callouts are drawn directly in the reply, with no file involved, no storage consumed and nothing to approve. That is a complete result: the block a client renders is the rendered output, not a source waiting to be converted into one.
An artifact is what a result becomes when it needs to outlive the turn — to be downloaded, versioned, attributed, shared, or handed to another tool. Ask for a file when you want a file. A request to see something produces something you can see.
Each surface declares what it can render inline, and the assistant is told what that surface actually supports rather than assuming the smallest common set. A surface that cannot draw a given format is not sent a broken block: it receives the source, or a downloadable version, whichever is honest for that content.
Immutable source, optional derivatives
Source bytes are immutable. A preview, thumbnail, converted document, or visible attribution is a separate derivative tied to one source version. A derivative can fail, be limited, or expire without changing the source version or its hash.
This distinction makes two things possible at once:
- a person can verify the exact source bytes that were promoted; and
- the product can choose the safest available preview for the content.
Preview capability and fallback
The API decides what preview capability is allowed after inspecting content. The client receives an approved descriptor rather than guessing from a filename or extension.
| Source family | Preferred experience | Honest fallback |
|---|---|---|
| Read-only document preview | Thumbnail and download | |
| Text, Markdown, code | Sanitized text or escaped code view | Download |
| CSV, TSV, JSON | Bounded read-only table | Sample data and download |
| Mermaid | Restricted diagram preview | Source and download |
| Native chart or form | Capability-limited native view | Static representation and download |
| Workbook, presentation, or imported office file | A supported bounded derivative | `preview_limited` and download |
| Static site or app | Isolated production preview | Thumbnail and download |
An unsupported format is not an error in source preservation. It is an explicit preview limitation so people can still download the exact version.
Conversation timeline
Artifact cards, operational activity, and visible reasoning share a conversation timeline but retain their own types:
| Family | What it communicates |
|---|---|
| `artifact.` and `preview.` | Durable artifact and preview lifecycle. |
| `activity.` and `tool.` | Safe operational progress and tool state. |
| `cot.*` | Sanitized visible reasoning for eligible Chao sessions. |
Keeping the families separate means an artifact update cannot erase or replace an eligible visible-reasoning step. The timeline preserves ordering, including think → tool → think sequences, while avoiding raw private reasoning and operational secrets.
Provenance without changing user files
For each immutable version, Chainabit can record a detached attestation that includes the source hash, byte size, recorded surface, execution plane, and creation context. The attestation is separate from the user’s source file.
The provenance labels are intentionally precise:
- `imported_unverified` means a file was brought into the workspace without an authorship claim.
- `promoted_by_chainabit` means Chainabit recorded an explicit promotion.
- `derived_by_chainabit` means Chainabit produced a derivative from a recorded source version.
Safe dependency intake
Preview capabilities are deliberately small. A renderer must be locally bundled, version-pinned, licence-reviewed, listed in the project’s software inventory, and monitored for advisories before it is enabled. Public CDN execution is not used for artifact previews. New preview kinds must include an accessibility, fallback, and test plan before rollout.
Recovery lifecycle
Conversation deletion is more than hiding a card. It begins a recovery window for linked artifacts and related preview content. Restoring during that period is an explicit action. At final purge, retained source and preview content are removed according to the artifact lifecycle, while non-content completion evidence can remain for audit purposes.