Features
Everything here is in the program you install.
Some screens show a worked example until your own computer reports. Each one is marked below, and the program marks it on the screen too.
- Write actions
- 7, all off
- Engines
- codex · claude · local
- Permissions
- 3 levels, you pick
- Agent roles
- 9 enforced
- Record
- signed, on your disk
- Approvals
- default deny
- Dark patterns
- listed, none used
- Hosted
- 2 computers, 1 session
Refusals
The agent panel shows a section headed “Not controllable, and why”, listing the controls it does not give you, each one with a reason and a line number. Temperature is there because the engines accept the flag and ignore it, with output measured byte for byte.
and a lying one is believed
Hand a brief to a team and a receipt comes back, not an answer. The program will not report that work succeeded because a process started.
never a result
A bounded loop states its own limits before you start it. It runs while the window is open, and closing the window ends the schedule. The process tree is killed when the time cap elapses.
The message board carries a Discord row reading “configured, no token, 0 messages sent”, tagged as a dormant integration. A connector that cannot send says so on the screen instead of looking live.
never as live
Every address in the simulation comes from the block reserved for documentation, so no example can ever resolve to a real host. The source comment says not to replace the addresses with realistic-looking ones.
Approvals
The program refuses a decision on a prompt that was never reported as presented, and it accepts only evidence that the card was mounted and visible. Buttons enable per card as each one scrolls into view.
has not been presented
Any line you leave alone is submitted as a refusal, and leaving the screen submits nothing at all. The program fills in the denial.
A purchase line names the merchant, the purpose, whether it repeats and whose idea it was (yours or an agent's). Approving records the decision and spends nothing.
never a guessed figure
Approvals are a screen you go to and not a modal that takes your focus. There is no dialog, no toast and no sound.
quoted in the source
Seven actions can change anything (hand out work, approve, claim work, reply, read reports, run a session, launch a cloud task). All seven arrive off, and turning one on makes its control appear.
has all 7 off
Every switch states what it grants and what it risks, including the switches with nothing at stake.
Agents
Press an empty spot in the tree. Two answers get it running (what kind of agent this is and what you want done) and dragging a node onto another changes who it reports to.
would ask a person
Pick any message you sent and the agent forgets everything said after it, keeping its place in your tree and its brief. You can also interrupt the turn it is writing now without closing the session.
A session profile is a name and a folder you pick in your own file dialog. Agents in a tree using that profile start there and read its instructions, keeping separate work in separate folders.
A session is built from the level you chose at setup, and that level is translated into whatever the engine underneath calls it. At the narrowest, writes are refused by the operating system and not by the agent.
anywhere this account can.
Nine roles ship with rules attached, including a controller that is the only one allowed to accept finished work and an observer that has to say how it knows. You can write your own with the fields “Owns”, “Must not” and “Hands off to”.
are never read as the same
Change a model tier mid-conversation and the program warns you first, because restarting re-sends the saved conversation, and that costs tokens. When the engine keeps the thread instead it says nothing had to be re-sent.
not billed after
The Record
Every agent run started from the program is written down on your computer before it begins and signed with a key held on that machine. The chain re-verifies in full every 200 entries.
If the chain stops verifying the program says so on the screen where you read the list.
Closing a queued item asks for proof you are looking at the current list. A checksum of the queue you were just shown is filled in for you and cannot be edited, stopping anyone from closing work against a list that has moved on.
The program asks what should happen to your credentials, linked accounts, signed record, agent history and settings when it is removed. The default answer is to ask you then.
Remove everything
Yours vs Example
Starting and stopping agents, the tree you build, the signed record, the approvals queue, settings, setup, roles and session profiles all read and write your own computer.
The metrics, comms and ledger screens read a report written by an agent host, and no host ships with the program. On a new install they hold a labeled example and say so on the screen.
The simulation here is the same build with its back end removed, running in your browser on data it generates. No real customers, no real activity and no network reached.