A company brain that is also an operating board

Give your company a memory. Then teach it to act.

Every meeting, email, file, call and text becomes one living memory graph. A resident agent reads it, steers it, and proposes what to do next. Humans approve. The whole thing runs on nothing but Cloudflare.

Get early access
The Jeffery window is live. He's the resident agent — he remembers everything in the overview, and nothing else.
Jeffery
auto · workers ai
jeffery ·I'm the resident agent. This deployment remembers one thing — the Living Code OS overview — and I'll tell you plainly when I don't know something. Ask me anything about it, or press the mic and talk.
Every feature ships as an app. Every app is a window. Eleven of them live in the dock.
What it is

Seven things, working as one system.

Most tools in this space do one of these. The point of Living Code OS is that they are the same system: every agent reads from, and writes back to, one memory — and every real-world action waits for a person.

One memory

Everything you already produce, kept whole.

Meeting recordings, mail threads, calendar, Drive files, Notion pages, uploads, texts, calls and daily conversation pass through one ingestion function into one graph of people, companies, projects and topics.

How the search works

Every query fires four legs in parallel — a title match, a vector search, a full-text BM25 search and an entity-anchor search — filters each by room access, and fuses them with reciprocal rank fusion. An agent reads a short snippet to rank, then the whole original in 14,000-character pages.

A resident agent

A colleague with a belt and a doctrine.

About eighty tools, a written system of rules, and a voice: spoken replies of one to three sentences, the graph steered live, and a hard rule never to report an action it didn't see succeed.

What's on the belt

Memory (search, ask, remember, read original), the graph (neighbours, briefs, timelines, show_on_graph), cards and artifacts, web search, the fleet, machines, phone and texts, calendar, self-modification through pull requests, and a council that can put the same question to up to four models.

Humans approve

Agents request. People fire.

Anything with a real-world effect — an email, a calendar move, a merged pull request, a new agent, a paid build — lands on a tray as a card with the exact payload that will run. Edit the fields, then approve. Spend above a money line asks for a PIN.

Why this isn't a toggle

The line between reading and acting is structural, not a setting. Every surface that wants an effect calls one function that inserts a pending row; nothing executes until a resolve runs with approval. A thrown executor becomes a visible failure — "Approved, but it did NOT execute" — because silent failures are the thing the team had already lived through.

A fleet with budgets

Background workers, listed like a team — not like sessions.

Each worker is its own Cloudflare Worker, born from a spec, with its own cron, working memory, a flight recorder, and a metered daily budget — fifty cents by default. Budget means a cost ceiling, nothing more.

How a hire happens

A spec goes to the Foundry, which opens a sandbox, materialises the loop template, deploys from inside the container, health-checks the newborn, commits its source, and registers it — every step streamed live to the Hive so the birth is watchable.

It ships its own features

A Shipwright that builds, tests, and asks.

A planner picks the files to study, writes a plan, builds each file in a sandbox, opens a pull request to staging, waits for CI, drives a browser test judged by a different model lineage — then files a merge request for a person. Production merges are never automated.

What it refuses to touch

Workflow files, the schema, auth, the Worker config, and anything matching secret are protected paths the planner will not modify. Every run has a budget guard that stops on overrun, and every call is metered under the run's own surface.

Every channel

Board, voice, bot, two phone lines, SMS, iMessage, iOS.

Whoever is asking, and by whatever channel, they're searching the same brain and reading the same originals. Realtime voice over WebRTC; a messaging bot with approve and deny buttons; a companion app that listens and syncs health data.

The receptionist line

The private line is the resident agent with memory — a trusted caller goes straight in, everyone else enters a PIN. The switchboard line is a memoryless receptionist that opens with an AI disclosure and carries a task brief per call.

The writeback rail

What's in the fields at approval is what runs.

Jeffery can draft the email, pick the slots, write the pull request, spec the hire. He cannot send, move, merge, or spend. That card on the right is the shape every one of those requests takes — and the operator edits it before it fires.

Pending · email · filed by jeffery
to hayden@example.com subject Three slots for Friday's review body Hayden — three options that don't collide with the launch prep: Fri 10:00, Fri 13:00, Mon 09:30. Reply with one and I'll hold it. tracking on · signature operator's · cost $0.00
ApproveDenyEdit fields
Cost, in the open

Tens of dollars a month. Not a sales call.

Every model call is metered into one table with its surface, provider, model, cache reads and writes, and cost. The numbers below are the overview's own, at a single operator's volume.

$0.50
per worker · per day
Default budget for a fleet worker. The gateway returns 429 when it's spent.
$5
per Deep Think
Two to five research passes, a synthesis, and a contrarian pass that tries to break the answer.
$10–20
per Shipwright build
Plan, build, machine-gate, browser test, hand off for a human merge.
$25
the money line
Above it, approving asks for a PIN. A leaked key can work the tray but cannot spend.
Runs on nothing but Cloudflare

One Worker is the server. There is no build step.

D1 holds the index, R2 holds the originals, Vectorize holds the embeddings, Workers AI does embeddings, extraction, transcription and some image generation. Durable Objects coordinate the board, phone calls, machine links and live audio. Workflows run the long jobs. Cron is the heartbeat.

Read the architecture →
Worker D1 · 60 tables + FTS5 R2 · originals Vectorize · 1,024-d Workers AI Durable Objects ×4 Workflows ×5 Cron ×7 Browser Rendering Access → model providers
Early access

It isn't available yet. This list hears first.

Leave an address and, if you like, a line about what you'd point it at. Nothing else happens — no drip campaign, no sales call. When there's something to hand you, you'll know before anyone.

Your address goes to one inbox at Duval Software. That's it.