Skip to main content

Scenarios

Ready-made use cases for common jobs. Each is a pack.json under examples/keep-agents/: copy one, change the keywords, deploy it. None of them needs code, and the extractive ones call no model, so the cell reports 0 outbound connections.

Prerequisite: a cell template. Bake node22-agent once on the FluxVM host: ./scripts/keep-bake-node22-agent.sh (template).

./scripts/keepctl deploy examples/keep-agents/<name> --test # deploy, then run its sample

The scenarios​

PackYou drop inYou getReads withSample
status-page-watcha saved vendor status page (.html)what is down, degraded, under maintenance, recovered, and the timeshtmlyes
mailbox-triagea mail export (.mbox, .eml)subjects, senders, and lines about replies, money, meetingsemlyes
api-factsa JSON documentthe fields you named, by pathtext + json_pathyes
expense-sheetan Excel sheet (.xlsx)top categories and vendors, the first rowsxlsxno
nda-reviewa Word contract (.docx)term, confidentiality, liability and governing-law passages; durations and amountsdocxno
invoice-model-briefan invoice PDFrule sections plus a generated summarypdftotext + modelno
meeting-notes-modela transcript (.txt, .vtt)decisions and actions plus a generated summarytext + modelyes

Phone-user packs​

For what a person exports from their phone, and what a phone vendor's app can hand to Keep. All are extractive: no model reads the file, and the cell reports 0 outbound connections.

PackYou drop inYou getReads withSample
chat-export-digestan exported chat (.txt)who talks most, plans and times, open questions, money, linkstextyes
bank-sms-ledgersaved bank and card SMS alerts (.txt)money out and in, every amount, merchants, declined or international lines. One-time codes are not listedtextyes
card-statementa statement (.csv)most common categories and merchants, the first rowstext + csv_columnsyes
calendar-weeka calendar export (.ics)events, start times, places, attendeestextyes
contacts-audita contacts export (.vcf)card count, names with duplicates first, numbers, emailstextyes
travel-itinerarya booking or boarding-pass email (.eml, .mbox)flights, stays, booking references, amountsemlyes
subscription-findera mail export (.mbox, .eml)renewals, trials ending, what will be charged, amounts, who chargesemlyes
receipt-pdfa receipt or warranty PDFtotals, dates, warranty and return terms, amountspdftotextno
receipt-photoa photo or screenshot of a receipt (.png, .jpg)totals, dates, warranty and return terms, amountsocrno
bill-photoa photo or screenshot of a utility, phone or card billamount due, due dates, account and reference lines, chargesocrno

| fuel-receipt-photo | a photo of a fuel receipt | litres, rate, total, date | ocr | no | | school-fee-receipt-photo | a photo of a school fee receipt | receipt number, student and term, fees paid, balance | ocr | no |

More everyday packs:

PackYou drop inYou getReads withSample
payslip-texta payslip as textmonth, earnings, deductions, net pay, amountstextyes
kindle-highlightsa Kindle My Clippings.txtbooks ranked by clippings, highlights vs notes, datestextyes
android-call-loga call-log CSVcalls by type, who you talk to, numberstext + csv_columnsyes
insurance-claim-mailinsurer emails (.eml, .mbox)claim numbers, status, amounts, what they need from youemlyes
takeout-my-activityGoogle Takeout MyActivity.jsonproducts used, what you did, datestextyes

Photos are read by OCR (English, tesseract in the cell), so check the amounts against the original; a scanned PDF and HEIC are not read. Not covered: vendor-specific exports whose layout changes between versions (location history, health, screen time), where a pack would be guessing. These packs read personal data. The cell is sealed and reports 0 outbound connections, but the evidence class is software-test: the host's operator could still read a cell's memory (VENDORS.md).

Mac and Windows packs​

For files a person exports from a Mac or a Windows PC, run by the person or by an IT team. Keep does not connect to the machine or drive its desktop: the cell is a sealed Linux microVM, and the pack reads a file you export. All are extractive (no model), and the cell reports 0 outbound connections.

PackYou run, then drop inYou getSample
mac-system-reportsystem_profiler SPHardwareDataType SPSoftwareDataType > report.txtmodel, chip, cores, memory, macOS and kernel version, firmware, System Integrity Protection, uptime. Serial number, UUID and names are not listedreal layout
homebrew-auditbrew list --versions or brew outdated --verbosepackage count, packages keeping old versions, outdated packages, toolchains presentdocumented layout
mac-log-triage/usr/bin/log show --last 5m --style compact | head -c 190000processes with errors or faults, most repeated errors, sandbox denials, kernel and thermal troublereal layout
mac-update-historysoftwareupdate --historywhat was installed, versions, dates, betas, Command Line Toolsreal output
windows-systeminfosysteminfo > si.txtOS and build, install date, last boot, model, BIOS, memory, domain, hotfix KBs. Host name and IP addresses are not listeddocumented layout
windows-hotfixesGet-HotFix | Export-Csv -NoTypeInformationKB numbers, kinds of update, who installed them, datesdocumented layout
windows-installed-softwarean installed-programs CSV (registry Uninstall keys)top publishers and programs, first rowsdocumented layout
windows-event-logGet-WinEvent ... | Export-Csv -NoTypeInformationcounts by level, provider and event id; the error and warning rowsdocumented layout

About the samples. The macOS samples follow output captured from a real Mac (with placeholder names and identifiers); brew was not run because of a local toolchain licence prompt, so its sample follows Homebrew's documented layout. The Windows samples were written from the commands' documented layouts and have not been checked against an export from a real Windows machine. Try a pack on your own export before relying on it, and adjust the patterns in pack.json if your Windows language or version words a label differently.

Not covered: a live desktop (an agent clicking through a Mac or Windows session), .evtx and .reg files (binary or UTF-16), and Keep running on a Mac or Windows host: FluxVM needs Linux/KVM, and macOS guests are only permitted on Apple hardware. The output describes a real machine and can name hosts, accounts and software, and the evidence class is software-test, so treat it as sensitive (VENDORS.md).

Office packs​

For the paperwork around invoices, purchase orders, staff and claims. They read a file you export or save, on a Mac or a PC alike, and they summarise it: they are not your books of account. They do not validate a GSTIN, work out tax, post to an accounting or payroll system, add or compare figures, or send mail. The official invoice, ledger or return stays in your own systems. Amounts recognise ₹, Rs, INR, USD, EUR, GBP, $, € and £, including 1,25,000 grouping.

PackYou drop inYou getSample
receivables-ageinga mail export (.mbox, .eml)invoice numbers (most mentioned first), overdue and unpaid lines, payments received, due dates, amounts, who is writingyes
po-line-itemsa purchase order as text (.txt)PO number, GSTINs by format, HSN or SAC codes, lines with amounts, open pointsyes
employee-ledgera monthly ledger CSVrows per employee and month, the first rowsyes
reimbursement-claimsa mail export (.mbox, .eml)who is claiming, amounts, approved or paid, pending or declined, categoriesyes

Samples use made-up ids and figures. These files carry business and personal data (amounts, tax ids, salaries), so keep Aadhaar, full bank numbers and PAN out of them, and note the evidence class is software-test: the host's operator could still read a cell's memory (VENDORS.md).

Developer-tool packs​

For what developers and teams already export: GitHub CLI output, Xcode logs, VS Code settings. Keep does not call GitHub or drive the tools: you run the command, save the output and drop it in. They list and count; they are not scanners, linters or reviewers.

PackYou run, then drop inYou getSample
github-prsgh pr list --state all --json number,title,author,state,createdAt,mergedAt,labelsstates, authors, labels, merges per month, titlesreal layout
github-issuesgh issue list --state all --json number,title,author,state,labels,createdAtopen vs closed, authors, labels, issues per monthreal layout
github-actions-loggh run view <id> --log-failed##[error] lines, failing job and step, exit codes, repeated compiler errors and warningsreal layout
dependabot-alertsgh api repos/OWNER/REPO/dependabot/alertsstates, severities, ecosystems, packages, manifests, advisoriesreal layout, trimmed
git-log-digestgit log --pretty=format:'%h|%an|%ad|%s' --date=shortcommits per author and month, commit prefixes, mergesreal layout
xcodebuild-logxcodebuild ... > build.logbuild result, errors by file:line (no directories), repeated messages, failed targets and testsdocumented layout
xcode-crash-loga legacy .crash report (text)app, version, OS, exception, crashed thread, framesdocumented layout
vscode-extensionscode --list-extensions --show-versionscount, publishers, namesdocumented layout
vscode-settings-auditsettings.jsonsettings that are set, telemetry and trust lines, secret-looking setting names (values not shown)documented layout

Browser and desktop-app packs​

PackYou drop inYou getSample
bookmarks-digesta bookmarks HTML export (Safari, Chrome, Edge, Firefox)top sites, folders, titlesdocumented layout
browser-history-takeoutGoogle Takeout BrowserHistory.jsontop sites, how pages were reached, titlesdocumented layout
mac-apps-inventorysystem_profiler SPApplicationsDataTypeapps, where each came from, first signer, kind, top-level folderreal layout
mac-launch-itemslaunchctl listnon-Apple items, exit statuses, labels with a non-zero statusreal layout
windows-servicesGet-Service | Export-Csv -NoTypeInformationstatus and start-type counts, namesdocumented layout
windows-scheduled-tasksschtasks /query /fo csv /vtasks, state, last result, run-as accountdocumented layout
sales-register-sheet, inventory-sheet, attendance-sheetan Excel sheet (.xlsx, first sheet)rows per customer, location or employee and status; the first rows. No arithmeticbuilt by CI (no text sample)

Already covered by earlier packs: Apple Mail and Outlook mail exports (.mbox, .eml) work with mailbox-triage, receivables-ageing, subscription-finder, reimbursement-claims and travel-itinerary; Apple and Outlook calendars (.ics) with calendar-week; WhatsApp exports (Android and iPhone layouts) with chat-export-digest; Excel with expense-sheet and the sheets above.

Not covered, and why: Siri (it has no export; see RECIPES.md for calling Keep from a Shortcut), PowerPoint (.pptx needs a new reader, not a pack), legacy .ppt, Outlook .msg / .pst, .evtx and browser history databases (binary), passwords and keychain exports (never read), and live GitHub or Xcode access. "Real layout" samples follow output captured from a real run with names replaced; "documented layout" samples were written from the tool's documented output and have not been checked against a real export, so try a pack on your own file first.

Bank operations packs​

For a bank's payments, collections, reconciliation, care, credit and compliance teams. All are extractive: no model reads the file, and the cell reports 0 outbound connections. What they do not do (no OCR, no decisions, no compliance claim) is in BANK-OPERATIONS.md.

PackYou drop inYou getReads withSample
neft-rtgs-returnsa returns / rejects report (.txt, .csv)returned and rejected lines, beneficiary problems, UTRs, IFSCs, amountstextyes
nach-return-reporta NACH debit return report (.csv)returns by reason, status and sponsor, first rowstext + csv_columnsyes
recon-exceptionsa reconciliation exceptions export (.csv)exceptions by type, channel and ageing, first rowstext + csv_columnsyes
upi-dispute-maildispute mail (.eml, .mbox)what customers report, reference numbers, amounts, escalation asksemlyes
loan-sanction-lettera sanction letter PDFterms, conditions, charges, amounts, rates, datespdftotextno
rbi-circular-briefa regulator circular PDFreferences, applicability, deadlines, "shall" lines, repealspdftotextno

The two model packs send the extracted text to an endpoint you allow, after you approve it once. Out of the box they are refused, because the vault has no such credential. See MODEL.md.

Already built in (no pack needed): pdf-brief, contract-clauses, security-questionnaire, meeting-actions, log-triage, sbom-summary, csv-clean. See demos/.

Ways to feed them​

You wantUse
One file nowthe console at /app/keep, or keepctl run <pack> <file>
A month of fileskeepctl run <pack> a.xlsx b.xlsx c.xlsx (one cell per file), or one zip of them
Files that arrive in a directorya folder trigger: keepctl trigger add-folder <pack> inbox 30
A system that can POSTa webhook trigger: keepctl trigger add-webhook <pack>
To see what changed since last timeKeep history → Runs → Compare selected
A ping when it finishesset ZYVOR_AGENT_APPROVAL_WEBHOOK; runs send run.finished / run.failed

All of it is described in TRIGGERS.md.

Recipes​

Incident log bundle. Zip the logs from a host, then keepctl run log-triage incident.zip. Each .log and .txt inside runs in its own sealed cell, and you get one triage.md per file under one batch id.

Vendor contracts in bulk. keepctl run contract-clauses a.pdf b.pdf c.pdf for PDFs, or deploy nda-review for Word files. Compare two versions of one contract in Keep history.

What am I paying for? A user shares a month of billing mail (an .mbox) and runs subscription-finder: renewals, trials about to end, and every amount that will be charged. Run it again next month and compare the two runs in Keep history.

Daily status check. A cron job fetches the vendor status page and posts it to a webhook trigger for status-page-watch. Keep does not fetch pages itself; you give it the file.

A drop folder for expenses. Set ZYVOR_AGENT_WATCH_ROOT, add a folder trigger for expense-sheet, and save each month's .xlsx into that folder. Each file runs once.

Test them on a real host​

agent-runtime/tests/demos-ci.sh uses a FluxVM stand-in. To run the scenarios in real cells, bake the template and point the live script at your runtime:

export KEEP_API=http://127.0.0.1:9096 KEEP_TOKEN=...
./scripts/keep-live-scenarios.sh # built-ins, scenario packs, batch, zip, webhook trigger, history
./scripts/keep-live-scenarios.sh --quick # a smaller run

It deletes the custom use cases it created. Evidence class stays software-test: a passing run shows the runtime, the cell and the extractors work, not that the host cannot read the VM. The model step is not part of this script because it needs an endpoint you allow; MODEL.md describes how to test it.

Making your own​

Copy the closest pack, change title, accepts and the rules, and follow Tutorial 19. The extractors and rules are listed in PACKS.md.