Humanize 2: Agent Flow System
One flow, ten coding agents, and a timeline of everything they did. Humanize 2 drives the coding-agent CLI you already log into, in the order a flow asks for, and writes the whole run down as it happens. Every other project on this site stands on it.
The documentationEvery feature, every flow, every commandThe install, the quickstart, and every feature and flow, atdocs.humanfia.ai/humanize.↗pip install git+https://github.com/humanfia/humanize.gitInto the environment you are already in.
Python ≥ 3.12 · drives the coding agent CLI you already log into · no API key of its own
- Ten coding-agent CLIs, one flow
- Work lands in a container or on an ssh host
- Every run, a trace you open in Perfetto
- A loop that stopped on Thursday carries on
- 01Check it landed
One binary, no service, no key of its own.
hmz --version - 02Log into an agent you already have
It drives your CLI under your own subscription. Any one of ten will do.
claude auth logincodex login - 03Run a flow
A published flow, several agents, and a trace of everything they did.
hmz exec -f official/flame_chase
One flow, many agents, one trace
A flow is a directory of Python that says which agents it drives, what each is asked, in what order, and when to stop. The runtime opens the sessions, takes the turns, puts the work where it should land, and records it.
The recording is the part people underestimate. Every turn's tool calls go onto one clock — every agent, every sub-agent, every program those turns ran — and come back as a Chrome trace you open in Perfetto. On an eleven-hour run that is the difference between knowing what happened and believing the last message.
hmz exec -f official/flame_chaseWhat it does
The deep end
The agent runs here. Its syscalls land there.
Every syscall the agent makes is decided one at a time — replayed on another machine, or answered on this one. It is told none of it.
Two accounts of one CLI
A CLI signs in once. Humanize 2 runs it as an account it was never signed into, by answering the paths it opens with other paths.
One timeline
Every agent, every sub-agent and every program those turns ran, on one clock, in one document you open in Perfetto.
A line typed mid-turn
It goes into the turn that is running. Not queued behind it, and never quietly counted as said.
Answers in a shape
A turn given a pydantic model answers with that model. The model is the whole of the question, and the answer is read back through it.
The shape of a run
Ten CLIs, one agent
Ten coding agents and anything speaking the Agent Client Protocol, each driven through whatever it actually offers.
A flow is Python
A loop, a subprocess call, a file read between turns. The agents are its arguments, and the shapes a loop takes are few.
Many turns at once
Turns are sequential only inside one session. Two hundred conversations are two hundred turns.
Picked up where it stopped
A loop meant to run for a week is a loop that will be stopped. What it was keeping track of survives; the conversation does not.
Who is at the other end
It decides when it is done
The backend's own goal feature: a turn that would have ended starts another, until the model says the objective is met.
You, as one of the agents
A flow asks a person the same way it asks a model — which is how a human stays the architect rather than the bottleneck.
Hooks, capabilities, surfaces and the daemon are in there too: every feature, one picture each ↗.
The agent runs here. Its syscalls land there.
The anchor is the piece we would point at if we were only allowed one. A seccomp-filtered ptrace supervisor sits between the coding agent and the kernel and decides every call it makes: replay it on the target, or answer it here.
There is no plugin, no configuration and no cooperation, because the agent is never asked. It opens a file; the file it gets is the target's. It runs pytest; the process is the target's, in the target's working directory, reaching whatever the target reaches. It reads its own credentials, and those are answered here.
this machine
The agent, and what it is not told
claude · codex · dsh · … unchanged, and told none of this
- credentials
- state
- the model provider
answered here
syscalls
openat("kernel.cu")the agentwrite("kernel.cu")the agentexecve("pytest")the agentconnect("pypi.org")pytestconnect(the model provider)the agentopenat("~/.claude/…")the agent
the target
ssh · docker · tcp · a pipe
hmz anchor serve
- files contents, renames, modes — the target's own errors
- processes everything the agent spawns, in the target's cwd
- the network whatever those commands reach
replayed there
Twelve layers, one direction
The runtime drives ten different CLIs without becoming ten different products because the layering is a rule rather than an intention: everything points downward, nothing points both ways, and a test fails a build that bends it.
tests/test_layering.py holds the exact table, and fails a build that bends it. The whole tree, and the exemptions ↗The real thing, recorded
Not drawn — recorded from hmz itself, in a container with a stand-in coding agent in it.

The interface: / for the commands, and a flow picked from the sheet. read the guide ↗
The flows it runs
The runtime runs flows; it does not decide what a good flow is. That split is deliberate, and everything else at Humanfia is built on it.
A flow is a directory of Python that says which agents it drives, what each is asked, in what order and when to stop. The ones that ship with the runtime, plus the flowverse it fetches, cover most of the loop shapes the field has converged on:
Forget every round, or remember all of them
ralph_loop opens a session of its own each round; stateful_ralph and continue_loop hold one and keep going. Same loop, opposite trade.
Take turns on the same tree
flame_chase alternates two agents on one task, each reading the repository rather than a history — so neither compounds the other's blind spot.
The review is the next prompt
rlar gives the actor one session and the reviewer none. What the reviewer noticed is what the actor hears, word for word, and the reviewer is what ends the run.
Humanize 1, as three flows
An idea opened into a draft, a plan two sides converge on, and a build under review — Humanize 1's three commands, on their own agents.
Three lanes, one writer
A coordinator plans three isolated lanes. Lane 1 alone owns your working tree; the other two work in private snapshots and publish artifacts rather than writes.
Every flow, with its loop drawn ↗
A page each: the hmz exec line, what it takes, what ends it, and what a run picked up a week later carries in.
Flows live in a flowverse — a git repository anybody can read, fork, publish or beat. The loops the field already converged on are in there beside ours, so comparing one method against another is a flag rather than a reimplementation. Which is actually better is FlowBench's question, and the answer is allowed to delete ours.
humanfia/flowverse ↗ · FlowBench
What it is not
Not a model. We do not train one, serve one or resell one.
Not an API client. Humanize 2 holds no API key and talks to no model provider. It drives the CLI you already log into, under your own subscription. The frontier moves every few weeks; a wrapper around one vendor is the least durable thing we could build.
Not a coding agent. It does not replace claude or codex — it takes turns on them. If a better one ships next month, it is a name in a list.
Permissions
Humanize 2 runs every agent with permission prompts disabled, and nothing turns them back on. Read Security ↗ before pointing one at a repository you care about.