What exactly does Chronos fire?
A published, immutable Spark agent version. The Chronos action is AI agent run (task type ai_agent_run): you pick the agent slug and version, a prompt template with allow-listed {{dotted.path}} tokens from the trigger payload, optional structured agent_input, and an idempotency key template. The run then follows the same lifecycle as any other run: QUEUED, ROUTING, RUNNING, then SUCCEEDED, FAILED, CANCELLED, or AMBIGUOUS.
How do I stop a workflow from looping?
Chronos ignores AI_RUN_* platform events as triggers for AI agent runs, so a run can never fire the chain that started it, and a webhook-triggered chain is allowed one hop. Inside the run, the loop policy bounds steps, identical-call fingerprints, failure streaks, duration (1 second to 1 hour), and cost, and records a stop reason when it intervenes.
Can a scheduled agent change my pipelines or data?
Only through tools on its allow-list, with the permissions of the owner it runs as, and never silently. Writes started by an API key or by Chronos pause at WAITING_APPROVAL until someone signed in approves or rejects them. Destructive tools park in chat with Confirm or Cancel. Read-only deployments hide every write tool with one setting.
What happens when a webhook is delivered twice?
The idempotency key returns the existing run instead of starting a new one, and a conflicting payload under the same key is rejected with 409. Trigger bodies are capped at 64 KiB, and only payload fields on the allow-list ever reach the prompt template.
How do I bound what an automated agent can spend?
Budgets per owner or per platform key with soft and hard limits; a hard limit returns 402 BUDGET_EXCEEDED before the provider is called. Scoped gsa_ keys carry agent and model allow-lists, requests-per-minute limits, and expiry. Every run records the selected model, usage, and a redacted outcome you can audit.
Can a workflow live outside Gluesync?
Yes. Your own scheduler or application can start runs through the native /api/ai/v1 contract or the OpenAI-compatible endpoints, follow progress on the SSE event stream, and read results back. External MCP clients such as Claude or Cursor can call start_agent_run and get_agent_run with the caller's token.