Supplier compliance doesn’t end at onboarding. Most tools do.

Certificates expire months after a supplier is onboarded, and every onboarding tool retires the day the ERP record is created (enterprise resource planning: the business’s system of record for suppliers and purchasing). The ongoing work of noticing the expiry, chasing the renewal, and deciding whether it is still safe to buy goes back to a person with a calendar reminder.

Keplaria stays. One durable case per supplier wakes months later on its own clock: it requests renewed evidence, places a reversible purchasing hold when a certificate lapses, checks the renewal against the source document, and releases the hold. A language-model coordinator proposes which specialist agents should run; a deterministic policy layer decides, against a versioned catalog.

45.1sof machine work, one deployed run of the whole lifecycle
663.5sfor the same work by hand, timed (author-timed, not practitioner-reviewed)
19of 20 manual steps removed; the last is the approval policy requires
380simulated business days of renewal, hold and release in one recording

It stops exactly where policy requires a human decision — and nowhere else. Nothing reaches the ERP except through an outbox (a queue of pending ERP writes, released only on approval).

Every number on this site is bound to the run that produced it. The verification page is generated from the evidence files, not written by hand, so it cannot quietly disagree with them.

The case console is a real deployment. The suppliers in it are synthetic demo data.

Evaluate this in three minutes

1 · Case console

No sign-in. Cases are grouped by supplier; each row is one payload, one supplier’s case. Open one: a context strip and a lifecycle indicator (onboarded → active → renewal requested → held → released) show where it stands, and the status line says exactly what has been written to the ERP so far. For a parked case, stopped for a human decision at any stage, that is nothing yet.

2 · Review console (Ground Control)

Google sign-in, enforced by Cloud IAP, Google’s identity check in front of the service. Cases the policy stopped wait here with their ERP writes held; approving is what releases them.

3 · Demonstration video

https://youtu.be/YXCgRq_HVQ8 (3:43). What it shows: one continuous, unedited take. A stop for a human, an approval that releases the held writes, then a simulated year and a half of renewals, a hold, and a release.

Named for the law, not the planets

An agent that runs for minutes can afford to improvise. One that stays accountable for months cannot. That is why the model only proposes here, and a versioned, deterministic policy decides. The name marks that line. Kepler’s breakthrough was not noticing that planets move; everyone could see that. It was showing that their motion obeys law: predictable, calculable, correctable. That is what lets you launch a case once and have it stay up without constant thrust. When compliance decays and a certificate nears expiry, policy fires a small correction: a renewal request, a purchasing hold, a hold release. Spacecraft engineers call those corrections station-keeping. So do we.

The fleet and the payload

The fleet is the crew and its rulebook: three departments, a coordinator that proposes, two specialist agents, and the five ERP commands they may issue. A payload is one supplier’s case, carried through that fleet for months: onboarded, then renewals, a hold, a release.

The fleet: departments, agents and commands. One payload: a supplier's case carried through the fleet across five lifecycle stops.

The console is public and read-only. A case shows what the coordinator proposed, what policy actually engaged, the candidates from screening against a sanctions watchlist and why one of them needed a person, and every command, including the ones policy refused. A case stopped for a human says so plainly, and says that nothing has been written. The fleet page is the rulebook, with a count of how many cases exercised each rule.

The security model, in six claims

No agent holds a credential

No agent holds a credential or a write tool, and a clock event never reaches a language-model agent at all.

The executor is scoped

The one ERP credential belongs to the deterministic executor, under a role that cannot delete, cannot widen its own permissions, and cannot read a financial document. Those limits are read back off the live ERP by the health check, not assumed.

Tainted documents stay outside

A document flagged as tainted is never shown to any agent, and its case is forced to a blocked verdict, so a tainted document cannot cause an ERP write.

Identity is verified, not asserted

The reviewer’s identity comes from a signed IAP assertion, never from a header a caller could set.

The engine has no internet path

The reasoning engine has no route to the public internet: it reaches the screening service over Private Service Connect only, and secrets come from Secret Manager, per service identity.

Failure becomes durable state

Never a silent exception: a failed ERP command stays durable and an unattended sweep re-drives it to exactly one record.

Each claim is enforced by a test or a deployed check, itemised in the README’s security section. Two limits, stated rather than hidden: a parked case is durable state, not a suspended run; and a supplier who becomes sanctioned after onboarding cannot yet be held.

Built on

Agent Development Kit · Gemini · Agent Runtime · Cloud Run · Firestore · Pub/Sub · ERPNext · OpenTelemetry