01Headless by designanv --no-tui reads a prompt or prompt file, writes to stdout and exits like a Unix citizen: 0 success, 1 error, 2 approval denied. That exit contract is what makes an agent step gateable in CI.
02A read-only planning pass--plan-only blocks write and exec tool calls at dispatch, so a pipeline can ask what would change without risking the tree. Pair it with a required human approval before the mutating run.
03Long jobs that do not hangThe monitor tool (up to 8 armed) tracks long-running processes; run_script executes saved scripts through the same sandbox; --wait-monitors keeps a headless process alive until the last monitored job ends.
04Confinement at the tool layerSandbox profiles (project, computer, strict) gate reads, writes, exec and network for every tool, including all three exec paths (run_command, run_script, monitor). --yolo bypasses approval but does not widen the sandbox.
05Sessions survive crashesA crash-safe session store with retention limits (20 sessions / 512 MiB) lets a pipeline resume rather than restart; anv -s list and --continue address prior runs by code.
06Swarms for batch workFor fan-out jobs, `anv swarm up` runs a supervised fleet with per-task verification, repair limits and an integration branch. The production E2E delivered three SaaS apps with zero conflicts and green integration suites.
07Memory-aware runsHeadless runs can read and write the same local Mind graph, so yesterday's failure is in today's context, the compounding lever, scoped to your measured records.
08Everything observableStructured JSON where it matters (`anv swarm status --json`), append-only run directories under .anvaya/swarm/, per-task logs via tail, and exit codes that distinguish failure from approval denial.