Questions about Submilli

Clear answers about runtime permissions, integrations, customer scope, and code execution.

What is Submilli?

Submilli runs agent-written TypeScript programs under explicit permissions. A Blueprint defines the available Packages, capabilities, resources, and limits. The runtime checks gated operations against that policy before they proceed.

How does it differ from isolation alone?

Isolation separates running code from its host. Submilli also checks the meaning of operations, including their capability, caller, resource, and arguments. A rule can allow one customer ID, path, host, or amount while denying another.

Can I use my existing APIs and MCP tools?

Yes. Packages expose service operations as typed functions with explicit capability checks. MCP tools configured in a Blueprint are also exposed as typed functions, with permission checks applied before calls are sent.

Can permissions use context supplied by my application?

Yes. Your application binds trusted values when it opens a session, such as a customer or tenant ID, an allowed resource, or a transaction limit. Permission rules compare an operation’s resource and arguments against those values before it proceeds. For example, a rule can restrict access to the current customer’s records or cap an amount at the limit supplied by your app. The generated code cannot change these bindings. Your application remains responsible for authenticating users and supplying the right values.

How does Submilli keep startup fast and server overhead low?

Submilli runs WebAssembly instances inside the host process. You can embed the runtime in your application or use the server through HTTP or MCP. Each run gets an isolated instance without starting a separate VM or container. Fast instance creation and a small per-run memory footprint let more concurrent runs share a server. Total latency and capacity still depend on compilation, workload, and configured limits.

Does code execution reduce cost or improve performance?

It can: code can orchestrate several calls, process intermediate responses, and return a concise result without a model round trip for every step. Results depend on the workload and integration. Published third-party results describe the general pattern, not a benchmark or guarantee for Submilli.

What does the permission system not guarantee?

Permissions govern operations covered by runtime and trusted Package checks. Package authors must implement the relevant capability checks. Permissions do not prove that a program’s result is correct, replace application authentication, or determine which personal fields a permitted service should return.

Is Submilli open source, and where do I start?

The runtime, CLI, and server are open source under Apache 2.0. Start with the quickstart to install the tools, register a Blueprint, and run a program. The public repository contains the implementation, examples, and documentation.