9 posts in this category.
Every framework can produce a working demo. The hard part is everything after — running on a schedule, getting better at the same task, and not billing you while idle. Three operational primitives that close the gap, and why the framework — not the user — should own them.
v0.25 lands inbound messaging on five platforms at once — Telegram, Slack, Discord, email, WhatsApp. The hard part wasn't writing five adapters. It was finding the one shape that made all five behave like the same thing.
Most agent turns don't need Opus. The problem is figuring out which ones do — at runtime, before you've spent the money. Here's how Tutti's SmartProvider does it, what we got wrong on the first try, and where it still falls short.
If you can't explain what an agent did six hours after it did it, you can't operate it. Tutti emits OTEL spans for every run, LLM call, and tool invocation — and you wire it into whatever you already use.
Most frameworks make human-in-the-loop something you wire in. By the time you remember to add it, the agent has already shipped a tweet. Tutti gates destructive operations by default — the wiring is the runtime.
If you wait until the model has seen the malicious string, you've already lost. The defence has to be in the architecture: typed tool outputs, sanitised content, boundary markers, runtime isolation.
Most frameworks document a permission model. Tutti enforces one. The difference is the runtime refuses to start when an agent has voices it didn't grant.
Most frameworks treat tools as a flat list. Every team rebuilds the same GitHub wrapper, the same Slack wrapper, the same Stripe wrapper. Voices are how Tutti stops that.
Agent systems aren't general programs. They're a small set of repeating patterns. When you write them as code, the configuration disappears. When you write them as config, the system shape is the file.