Email: Gmail, Microsoft, sandbox
Native email-manager skill — list, read, send, categorize, and analyze. Connect via Settings with OAuth, IMAP, or POP for Gmail and M365. Zero-config sandbox mailbox for demos. Send/delete/categorize stay HITL-gated.
Kazma is the reliable multi-agent framework built for real deployment. Cryptographic skill signing, triple-wired human-in-the-loop safety, durable execution, and native Arabic dialect support — all in one full-stack system with live Web UI, TUI, CLI, and multi-platform gateways.
Project timeline: March 15, 2026 – Present · Verified 2026-08-06 · 1c3aa89c Merge branch 'main' of https://github.com/Mubder/kazma (2026-08-06) — figures derived from git-tracked files via scripts/generate_metrics.py
The Kazma dashboard — memory layers, component health, and live governance in one surface.
Built on a production stack
The origin
A name rooted in Kuwaiti history — and engineered into architecture.
Kazma (كاظمة) was an ancient coastal oasis in Kuwait — a network of wells and a gateway for trade between civilizations. It was also the site of the legendary Battle of Chains (ذات السلاسل, 633 CE): the Persian army chained its soldiers into a single, rigid wall, yet Khalid ibn al-Walid shattered it through precise, decentralized maneuvering — and won.
We engineered Kazma on those same pillars — not as metaphor, but as architecture:
Deep memory that holds context across sessions. The agent draws from it when it needs to remember, like caravans drawing from oasis wells.
One supervisor brain routed to Telegram, Discord, Slack, Web, and TUI — the way ancient Kazma routed trade between civilizations.
The chains in that battle were rigidity — and rigidity is what makes monolithic agent pipelines fragile. Kazma runs decentralized swarm patterns and self-healing circuit breakers instead, adapting and recovering where rigid chains would snap.
Secured by design
Never let an LLM run unsafe code or modify production files unsupervised. Kazma intercepts dangerous operations fail-closed at three layers.
Native email-manager skill — list, read, send, categorize, and analyze. Connect via Settings with OAuth, IMAP, or POP for Gmail and M365. Zero-config sandbox mailbox for demos. Send/delete/categorize stay HITL-gated.
Three-tier approval gates — graph interrupt, swarm bus, and pipeline checkpoints. Danger tools require human approval across Web, Telegram, Discord, and Slack. YOLO is hard-blocked in production unless explicitly overridden.
Every downloaded skill and plugin is validated against a timing-safe HMAC-SHA256 checksum matching your secret. Altered signatures trigger an immediate fail-closed abort.
Bearer tokens, custom headers, and configurable trust tiers. Every MCP tool is classified by risk for appropriate gating; untrusted tools force HITL in production.
Real-time status badges — red, yellow, hidden. Automatic recovery with configurable thresholds. Start, stop, cancel, retry with lineage tracking.
Interactive sliding cards over live SSE in the Web client. Inline buttons in Telegram, Discord, and Slack. Approve or deny from any surface.
Bi-temporal belief graph with Local Ego-Graph PPR recall, automatic per-turn RAG, auto-store, and LLM consolidator with prompt fence. Dashboard belief graph explorer + multi-tenant isolation + nightly backups.
Every supervisor iteration is snapshotted to snapshots.db. Restore (/replay) any past conversation state in-place, branch (/fork) into a new thread without modifying original history, and view visual timeline diffs.
Single source of truth (kazma_core/ide) for file operations, pytest execution, and git management. Supports per-task ContextVar workspace scoping and build_env_context awareness across Web, TUI, and Chat gateways.
Send a photo, screenshot, or PDF on Telegram, Discord, Slack, or Web. Images inline as vision blocks; documents are saved and opened with file_read — so the agent actually reads what you attach.
Voice notes transcribed (OpenAI/Groq/faster-whisper) and replies spoken back (Edge TTS/OpenAI) across Telegram, Discord, Slack, and the real-time Web voice WebSocket — one setting controls all platforms.
Native skills that ship in-process: headless browser automation (Playwright), calendar (Google/Outlook), PDF/DOCX/XLSX generation, multi-backend image generation, and read-only database queries (Postgres/MySQL/Mongo).
Chat-triggered swarm research is now a first-class system. Browse all research outputs with cost and duration, compare two runs side-by-side with text diffs, and export any result to DOCX or PDF for academic use.
Advanced features
A real swarm self-improvement loop and an encrypted secret vault — described as the code behaves today.
Kazma-wide: after every chat turn (Web / Telegram / …) and every swarm task, Kazma analyzes the outcome and updates the main agent Soul or the worker Soul — automatically, no hand-tuning.
Store API keys and tokens with AES-256-GCM in a separate vault.db. Tools: vault_store, vault_list, vault_retrieve, vault_delete. Retrieve and delete require HITL approval.
IDE Subsystem
A single source of truth (kazma_core/ide) for file operations, test execution, and git management across Web, TUI, Telegram, Discord, and Slack.
A 3-pane interface — file tree, multi-tab editor (CodeMirror with find & replace), and integrated AI chat. Runs in the browser, zero setup.
A full-screen Textual editor inside the TUI. Edit files, run commands, and review diffs — without leaving the terminal.
ls, edit, read Browse and modify files across any channel
run Execute code and see results
grep, search Search across the entire repository
git, diff, clone Full Git operations agent-driven
/ide commands work on
Web · TUI · Telegram · Discord · Slack
Workspace awareness
Automatically injects the current repo and branch (build_env_context) — the agent always knows where it's working.
Time Travel & Replay
Every supervisor iteration is snapshotted into snapshots.db. Kazma lets you rewind mistakes and explore alternate paths without destroying original history.
Rewind the conversation to any previous snapshot. This rewrites the current session from that point forward.
Clone the conversation from any point into a brand new thread. Leaves the original history untouched for safe exploration.
Thanks to safe thread forking, you can try alternate solutions and compare them without losing your original context.
SSH command console
Monitor and command your swarm directly over lightweight SSH sessions or terminal panels. Track multi-step workflows without screen corruption — Kazma isolates complex Mermaid.js rendering to explicit DOM nodes, neutralizing style leakage.
Clone, configure, deploy — three entry points for every workflow.
Clone the repo, run uv sync, point at your LLM provider. Web UI, TUI, or CLI — your choice.
Plug in Telegram, Discord, or Slack via the headless gateway. One backend, many adapters.
Pick a persona, enable RAG, set safety gates, spawn swarm workers. Watch it live via SSE.
The product
A single LangGraph supervisor drives the dashboard, chat, swarm playground, skills, and MCP servers — bilingual, RTL-ready, live.
File tree, multi-tab editor, and integrated AI chat.
Streaming agent chat with HITL approval cards.
Dispatch patterns with live aggregation.
Signed, validated skill registry.
Authenticated external tool servers.
Observability, cost, tokens, and system health.
The live Arabic dashboard — monitoring, pending HITL approvals, cost tracking, and swarm status. No signup.
Architecture
Immutable security, triple-wired HITL gates, and self-healing dual-UI telemetry — layered, decoupled, and independently replaceable.
FastAPI dashboard — chat, swarm panel, circuit breakers, lineage, bilingual RTL, and a full in-browser IDE. Default bind 127.0.0.1:9090.
Lightweight SSH console. Scrolling metrics sparklines, ASCII NOC topology, and a full-screen code editor.
Unified control plane — banner, status, hub, gateway, swarm management, and cross-platform /ide commands.
From the workshop
These aren't products “powered by” Kazma as a runtime stack — they grew up next to it. Each one taught us something about agents, trust, and real interfaces, and that craft shaped the framework in return.
A portable personal vault for secrets, API keys, tokens, and notes. Auto-extracts multiple values from a single paste, organizes scattered credentials, and answers queries in English and Arabic. Works fully offline (Ollama) or cloud (Gemini).
An AI-powered delivery platform that runs entirely through WhatsApp — text or voice notes in Khaleeji Arabic. Tracks orders, predicts arrivals, auto-dispatches couriers, and screens for fraud (NVIDIA Morpheus) with full GCC data sovereignty.
An Institutional Intelligence System — an operating layer above an organization's tools. Genesis (validation), OS (execution/memory), Guardian (risk/governance), Network (connections), Evolution (growth). Turns institutional know-how into a measurable asset.
Three commands — clone, install, serve. Up and running in under 10 minutes.
git clone https://github.com/Mubder/kazma && cd kazmauv sync --all-extraskazma servekazma-tuiFor builders, enterprises & programs
Kazma is open-source, MIT-licensed, and production-tested. Whether you're evaluating for an enterprise pilot, a startup program, or contributing as a developer — there's a clear path forward.
Clone, install, and serve. Free, open-source, MIT licensed.