The standard model, inverted
The harness is the loop your agent runs in. In the common setup that loop is the LLM — it decides what to do next and reaches for whatever tool it wants. Praxec makes the loop a deterministic kernel the model plugs into.
The usual pattern puts the LLM on top: give it tools, ask it to plan, hope it stays on task, patch the misses with prompts and retries. When that breaks on real work — the agent invents a step, calls a tool it shouldn’t, drifts off task — you’re patching nondeterminism with more prose. Praxec flips the stack. The kernel comes first — workflows, state, locks, legal moves — and the model executes bounded reasoning inside it.
LLM-first (the norm) Kernel-first (Praxec)
───────────────────── ─────────────────────
LLM decides the process → the workflow defines the process
LLM gets a bag of tools → the kernel exposes legal next moves
LLM owns the context → the store owns context; the LLM gets a slice
best model for everything → cheapest sufficient model per step
The model as a worker inside the kernel
The sharpest expression of the inversion is the in-runtime llm executor. Praxec hosts the model call itself, and the tool surface the model sees is the current state’s transitions — nothing more — under enforced iteration and cost caps, with its reasoning captured to the audit log.
triaging:
goal: "Decide: bug, feature request, or noise."
transitions: # these three ARE the model's whole tool surface
mark_as_bug:
target: investigating
executor:
kind: llm # praxec hosts the call
model: anthropic:claude-sonnet-4-6
max_iterations: 3 # bounded; nothing but these transitions in scope
mark_as_feature: { target: planning }
close_as_noise: { target: closed }
The LLM no longer owns the process. It’s a replaceable reasoning engine the kernel calls when a step needs judgment.
Why this matters
That’s why older, cheaper, local, and specialized models become useful — they don’t have to understand the whole mission, only perform one bounded, state-specific task. The kernel leads. The models execute.