One AI teammate whose entire life — thoughts, actions, moods, permissions — is drawn from a permanent diary, so it can be rewound, proven, and trusted. Built on agente's clean architecture; inheriting the best of gspace1.
Snapshot · 2026-07-26. This is the program's plan, architecture and decisions as they stood on that date — not a live status board. Stage 0 has closed since, and most of Stage 1 has landed. For current status see the Program Board.
Why this matters: nothing was filmed. The room on the right is re-calculated from the diary on the left, up to whatever moment you choose — the way a bank explains any balance by re-adding the transactions. No other AI colleague can be rewound and audited like this. That is the product.
In a hotel, the spa can be optional — the elevators and plumbing cannot. The shared canvas (the wall where the AI and people work together) is elevators-and-plumbing, so it goes into the building. What is pack-shaped: the blocks you put on the canvas — polls, charts, forms — like LEGO pieces on one baseplate (Vitto proved this with ~74 blocks), and the behaviors around it, like the Narrator (next page). The "watch it think" screen needs no backend machinery at all: the diary already broadcasts live; it's another departures board on a wall where the flight data already flows.
Trusted packs run in our kitchen. Anything external connects like a food truck at the curb — it serves customers through a controlled doorway (the MCP standard), asks permission for risky actions, and never gets kitchen keys. This doorway already exists and is guarded.
"Our AI writes everything it thinks and does into a permanent diary, and everything you see is drawn from that diary — so you can rewind it like a video and prove exactly what it did and why it was allowed to. We extend it the way Tesla ships features: built-in packs with per-customer switches, because deletable app-store apps would poison the diary our promise depends on."
An AI teammate — the new Vitto — that lives in a shared workspace. It talks, thinks out loud, paints cards on a wall, remembers you, and asks permission before doing anything risky. Its superpower: everything it thinks and does is written into a permanent diary, and you can rewind the whole room to any moment — like a video, except nothing was filmed; it's re-calculated from the diary, so it's proof, not footage.
Trust. It feels human (people want to work with it), it's provable (disputes end in 30 seconds — drag the slider, see who approved what), and it stays smart (a recorded exam blocks any change that makes it dumber). Companies stuck in "security review says no AI" buy exactly this evidence.
Nothing is thrown away, and nothing is risky-migrated. Accounts: your gograb-ID login just gets linked — like linking a Google account; no copies, nothing to fall out of sync. The app: the new colleague appears inside my-vitto-ng as a swappable panel, the same way our other panels already embed. The data: the useful slice (your profile facts, recent memories) is imported with an "imported" badge; everything else stays where it is and is searched live when needed. Old Vitto: becomes the first guest AI in the new spaces — its skills keep working, now under provable rules.
gspace1 taught us expensive lessons (we once deleted 50,000 lines we'd built). So this plan has seven house rules — and every one is checked by the build computer, not by memory: independent review before building · no code without a real user of it · no silent failures · the smartness exam · no giant files · gaps tracked like debts · one wave at a time.
Week 2: green safety report. Week 8: the rewind demo works end-to-end, shown inside our own app. Week 10: ten teams have used it and told us what they'd pay for. Week 16: teams + guest AIs in shared spaces. Odds, honestly: the technology is ~90% sure (verified in our code) · shipping on time ~70–80% · still unique when it lands ~60–70% · the world noticing ~15–30% — which is why "show it to ten teams" is a step in the plan, not an afterthought.
What we're building: an AI teammate you can trust with real work — because it feels human, proves everything it does, and demonstrably keeps getting smarter. How long: ~4 months to a shareable team product; a flagship demo in ~8 weeks. The proof points, in order: a green safety baseline + the gspace1 identity bridge (week 2) → the rewindable colleague demo, delivered inside my-vitto-ng to our existing users (week 8) → ten real teams using it (weeks 8–10) → multi-user spaces with guest AIs (week 16).
The bridge is part of the spine, not a side quest. The gspace1 connection (marked B1–B4 below, detailed on page 4) is woven into the main plan from Stage 0 — because who the user is must be settled before the colleague meets anyone, and because our first audience is the users we already have.
STAGE 0 IS COMPLETE (all steps built; 0.1 DONE on GitHub, ②/③/④/④b/B1 all VERIFY — one founder commit per step flips them DONE). Next is the Stage-1 gate: the 1.D design-direction spec needs its named designer, and the wedge decision (A/B/C card) is yours to pick — the first colleague surface is design-led and waits on both. Done this round: ② ③ ④ ④b B1 · the erasure-paradox note · the wedge decision card.
| # | What we build (plain words) | What you'll be able to SEE when it's done | Time |
|---|---|---|---|
| STAGE 0 — Make the ground safe (weeks 1–2). Nothing else starts first. | |||
| ① | The automated build-checker: every change runs all tests, the file-size limit, the "no silent failures" check, and the smartness exam hook. | A dashboard that's green or red on every change. Red = nothing ships. | 2–3 days |
| ② | Close the known security holes: the webhook that accepts unauthenticated messages, the default admin password — plus the dedup index that ends duplicate-message races. BUILT 07-26 · VERIFY | A short security note: each hole, closed, with the commit receipt — the page we can hand a customer's security team. | 2–3 days |
| ③ | Make rewind unable to lie: fix a rare race that can skip a diary entry, and make old entries readable forever even as formats evolve. | A proof test: replay any history twice → byte-identical result. BUILT 07-26 · VERIFY — the proof harness (rebuildEquivalence) now exists and runs green on all three projections. | 3–5 days |
| ④ | Finish the pack engine: packs can contribute events, views, and background behaviors — not just tools — and every pack's spend is tagged for per-app cost meters (details on the Pack System page). | Our existing Pulse integration re-expressed as pack #1, behavior unchanged; the settings screen lists it. BUILT 07-26 · VERIFY — incl. SR-0: the diary stopped lying about model costs, and prompt caching is on. | 3–5 days |
| ④b | The App Shelf V0 (decided 07-24): the app manifest type, the `app.installed`/`app.removed` events + projector, and the Shelf pane with the Sees·Does·Costs card — Pulse re-wrapped as app #1. | Install an app into a space with one tap; remove it; scrub back and watch it installed again. The plug-and-play experience exists. BUILT 07-26 · VERIFY | ~1 wk |
| B1 | The Bridge Pack — identity link. ALL gspace1 coupling lives in exactly one pack: the gograb-ID verifier (already shipping — it validates logins against gograb's own servers without holding its keys), the embed handshake, and later the recall client. gograb-ID becomes a linkable account in agente's identity system. | Sign into my-vitto-ng → open the colleague → it greets you as you, no second login. The architecture now states, in one module, exactly how the two worlds adapt. | 3–4 days |
| STAGE 1 — The colleague (weeks 2–9). Ends with the flagship demo. A one-time design-direction spec (visual language, motion, the colleague's presence — independently reviewed) lands before the first surface; every surface step's exit gate includes "meets the design direction." That's how "super visual" gets funded, not hoped for. | |||
| ⑤ | The conscience pack: the colleague narrates its thinking as diary entries, has moods from a 35-row table, and reflects a few times an hour (capped ~25¢/run, with a "stay quiet" option). | Turn the pack ON in settings → the colleague starts thinking out loud. Turn it OFF → it stops, history intact. | ~1 wk |
| ⑥ | Vitto Live — vision corrected 07-26: the panel where Vitto is a LIVING BEING — avatar with real expressions, mood, gaze, visible listening/thinking/speaking, eventually full human-grade voice (step VL: design-led, founder-reviewed passes: presence → voice out → duplex). The Live Feed (this step) is the mechanism inside it, not the headline. | A screen you can put on a TV: the colleague visibly working. Unknown future events auto-appear in the "thinking" lane — zero maintenance. | ~1 wk |
| ⑦ | The canvas: the colleague paints cards on a shared wall (checklists, statuses, notes) using the same block vocabulary Vitto proved. | Ask for a plan → cards appear on the wall live, one by one. | ~1½ wk |
| ⑧ | The glass dossier: everything it knows about you — every fact clickable to the exact moment it was learned, every fact deletable. | The "what do you know about me?" page. The trust moment. | ~1 wk |
| ⑨ | "Ask me what you remember," with sources — plus the first smartness exam: ~15 golden conversations that every future change must pass. | Ask about last month's decision → answer with clickable sources. And the exam turns red in CI if any change makes it dumber. | ~1 wk |
| ⑩ | The rewind slider + earned trust. Drag time backwards — canvas, thoughts, moods, permissions all re-derive. Trust levels rise/fall from the recorded evidence and actually gate what it may do. | The flagship demo: paint → ask permission → act → rewind the whole room → watch its autonomy graduate. | ~1½ wk |
| ⑪ | Instant artifacts: "make me a dashboard" → generated in a locked sandbox, born on the wall with a birth certificate (the exact diary range that produced it). | An artifact appears in your space in seconds; clicking its certificate shows how it was made and what it cost. | ~1 wk |
| CHECKPOINT (weeks 8–10) — B2: swap one my-vitto-ng space's chat panel to the colleague (an origin-registry entry, reversible in seconds — the same iframe pattern vitto-live uses, following the family-pattern embed rules: frame-ancestors headers, per-room thread keying, bridged identity). Then stop building and show it to ten real teams — starting with our own gspace1 users, inside the app they already know. Their reactions steer Stage 2. | |||
| STAGE 2 — The team (weeks 9–16). The remaining bridge steps land here as first-class steps. | |||
| PUB | One-tap Deploy (promoted 07-25 — the infrastructure already exists and is verified live): the Publish button on any super artifact → our proven Cloudflare publish lane → a real public URL in seconds. Guarded like everything else: a permission card asks first, unpublish is always one tap (and really takes it down), private content can never leak public, per-workspace quotas. | Make a dashboard in chat → tap Publish → approve → send the link to anyone on earth → tap Unpublish → it's dark. Whole loop under a minute. | ~3–5 days |
| FP | Face Parity Sprint (from the one-React-face decision): suggestion chips, consent-card polish (their channel/target pickers + "Why?" disclosure ported as designs), attachments UX, model chip, mobile ergonomics — in our React app. | The chat experience matches or beats old vitto-chat, in the same app as the wall and the scrubber. | ~2–3 wk (overlaps ⑫–⑬) |
| ⑫ | Shared spaces: real members, invitations, presence — riding the multi-user identity system Yam is landing right now. | Two people in one space with the colleague, seeing each other live. | ~1½ wk |
| ⑬ | Grown-up infrastructure: approvals survive restarts; many viewers can watch one space at once. | Kill the server mid-approval → nothing is lost. Boring, and exactly what enterprise buyers ask about. | ~1 wk |
| B3 | Recall bridge. The Bridge Pack gains a read-only tool that searches your old Vitto memories and chats live (permission-gated like any tool). Two years of accumulated knowledge stays reachable without migrating a single record. | "What did we decide about pricing in May?" → correct answer citing the old space. | ~4 days |
| B4 | Lazy import. On first meeting, a bounded import of your dossier facts + recent memories, every entry stamped "imported from Vitto" with a source reference. The daily-use slice moves; the archive stays put. | The glass dossier shows old facts with an "imported" badge — clickable to origin. | ~1 wk |
| SDK-1 | The SDK comes home + the React lane revives (SDK-A, 6o — supersedes the consume-only version): the platform-sdk is adopted INTO the agente repo as a first-party package (tests carried over; future SDK development happens here; gspace1's copy freezes at adoption), and a new generation of React elements grows on the same element contracts — the old React libs serve as design donors, not resurrected code. First-party only; anything user- or AI-authored stays sandboxed. | A chart card on the new wall IS the same battle-tested element the old walls use — one element vocabulary, both worlds; a tag not on the curated list is rejected automatically. | ~3–5 days |
| SR | The Governed Router (from the 07-26 census of their best system, ~17k LOC): Vitto picks models by LANE — background work never burns frontier models; approaching a budget cap automatically shifts to cheaper thinking and says so out loud; one kill switch sits above every fallback; prompt-cache pinning cuts cost per long task. Rebuilt as events + folds, so the spend meter can never silently lie (their cost pipeline once went dark for ~250 sessions — impossible here). | Flip the pause switch → every model call refuses in seconds. Watch heartbeats run on efficient models. See "thinking cheaper" appear in Vitto Live when a budget tightens. | ~1½ wk |
| ⑭ | The whistle: the colleague can pull the right person into the room — respecting their preferences, showing exactly as much history as they're allowed. | "Get me someone who can approve this" → the right teammate's phone buzzes with a summary; they arrive in context. | ~1½ wk |
| ⑮ | Visible specialists: the skills the colleague has learned, shown as cards with proof of where each came from; "make this a skill" on any selected moment. | A skills shelf that grows as it learns — every skill traceable to the work that taught it. | ~1 wk |
| M1 | The Desktops app (machines bridge): the colleague drives our Firecracker VM fleet as governed tools — acquire a desktop, look, click, type, run — every step permission-gated and on the record; per-workspace fleet keys. | The "🖥 Vitto's desktop" card live on the wall: watch it work a real computer, approve the risky steps, scrub the whole session later. | ~1½–2 wk |
| M2 | The Universal Resident: every VM self-enrolls the device-agent at boot (one-time code), Hetzner hosts run it via systemd — laptops, cloud desktops, and build servers become ONE fleet, one protocol, one kill switch. Retires three overlapping one-off agents. | A fresh VM boots and appears in the device list, workspace-scoped, seconds later. | ~1 wk |
| ⑯ | Guest agents: outside AIs — old Vitto first — join spaces as members under the same permission rules, each earning its own trust level. | Vitto proposes an action in a colleague space → permission card → approved → on the record. Two AI generations, one set of rules. | ~2 wk |
| STAGE 3 — The frontier (after Stage 2 closes; specs not written before then, on purpose): the Studio (arc codename "Foundry"; the artifact ladder's top rungs — the visual Studio surface, custom SDK elements authored as diary events, named versioned apps, publishing via unguessable capability links, your-domain workspace-apps; versions = diary ranges, git as a materialization lane — end-user clone/push is net-new serving, even in gspace1 today) · switchable personas · care signals · branded venues embedding the colleague · fork-any-moment ("what if?" branches) · retire the old brain + its Angular faces. | |||
gspace1 taught us with numbers: ~50,000 lines built then deleted; quality checks pointing at dead features while the agent quietly got dumber; 487 silently-swallowed errors; a 2,073-line file; one feature needing 8 follow-up sessions. Each rule below kills one of those diseases, and each is checked by the build — not by memory:
| Rule | In plain words |
|---|---|
| 1 · Review before build | No stage starts until an independent review tore the spec apart (the one practice that demonstrably worked in gspace1 — S621 caught 17 problems before a line was written). |
| 2 · Nothing ships unplugged | New code needs a real consumer and a test proving it's reachable. No dead code, ever. |
| 3 · No silent failure | Degradation must announce itself as an event — and the colleague can literally say "I'm working without my memory right now." |
| 4 · A smartness floor | The golden exam runs on every change; if the agent gets dumber, the build goes red. |
| 5 · No file over 600 lines | The build refuses growth past the limit; big things split into packs and modules. |
| 6 · Gaps are debts, tracked | A step isn't done if it quietly opened new gaps; every gap enters one ledger with an owner. |
| 7 · One wave at a time | Only the current stage gets features; new ideas go to the portfolio on paper. |
A pack is a self-contained capability that plugs into the colleague through one fixed contract. This page shows exactly what a pack can contribute, how the on/off switch works (it already ships), and two fully worked examples — including the one you asked for: "Vitto visibly paints what he's doing."
One contract, eight slots. The engine never special-cases a pack by name — it only understands the slots. That's the future-proofing: a pack from next year plugs into the same eight sockets.
| Slot | What it adds | Status in code |
|---|---|---|
| Tools | Actions the colleague can take (each declares its risk level → permission rules apply automatically) | SHIPS TODAY |
| Instructions | A personality/knowledge layer added to the colleague's prompt when the pack is on | SHIPS TODAY |
| Config + secrets | Per-customer settings and API keys, stored in the vault, resolved at call time | SHIPS TODAY |
| On/off switch | Per-customer enable/disable on the settings screen; off = tools hidden from the AI, deny-by-default, fail-closed | SHIPS TODAY |
| Events | New diary entry types (added at build time, permanent — history always readable) | Step ④ |
| Views (projections) | New readable states folded from the diary — must pass the "replay twice → identical" test | Step ④ |
| Loops | Background behaviors (reflect, react, nudge) — cannot register without a spending cap + rate limit + stay-quiet signal | Step ④ |
| Surfaces | New screens — each an independently built, lazy-loaded module plugged into the one shell via a registry (the VS Code model: one window, many extensions). This is how "one React app" and "separated, expandable apps" are BOTH true: one runtime for the rewind spine; separate modules for everything on it. No cross-pack imports (lint-enforced) — the registry is the only door | Step ④ |
What already ships is not a sketch: the settings screen with the pack catalog and per-customer toggles is live in the product (our Pulse integration is pack #1), with deny-by-default, a ~60-second propagation window, and a just-in-time guard so a disabled pack's tool can never run even during the propagation window. Step ④ extends what a toggle covers — the switch itself is done.
| Layer | What it is | Who sees it |
|---|---|---|
| PACK | The unit of code: in-tree, compiled, reviewed — unchanged | Developers only |
| APP | The unit of product & consent: a data-only manifest over 1..n packs — icon, plain-language permissions (generated from the real policy, CI-checked against drift), a hard budget envelope, secrets, surfaces. Installing an app IS an event (`app.installed`, per space) — so the store experience is itself a fold, and even installs are rewindable | Users — on the Shelf (see the Mockup tab) |
| MCP | The unit of external code: out-of-process, digest-pinned, fronted by one generic in-tree adapter. Third parties never ship code into the engine | Partners |
Bright-line rule (what can never be an app): anything whose absence would make past events un-renderable or past decisions un-provable — the kernel, the event store, permissions/budgets/approvals, identity, the canvas engine, the scrubber. V0 is ~1 week on top of step ④: an AppManifest type, two event types, one projector, the Shelf pane — with Pulse re-wrapped as app #1 in ~20 lines. One long-horizon risk logged: every app's projectors fold forever, so CI gets a projector performance budget and snapshots are planned before the catalog reaches ~30 apps.
The three joints that keep the floors clean: creation tools are themselves Shelf apps (the Shelf gates who may create; the Library holds what was created); the SDK is the shared element vocabulary of every wall — old and new (step SDK-A adopts the platform-sdk in-tree: it becomes agente's own package, all future SDK development happens here, and a revived React element lane grows beside the framework-free elements — founder directive 07-26, master-plan 6o); and content renders at its trust tier — anything user- or AI-authored runs in a sandbox, never inside the engine's page (gspace1's own code flags the opposite pattern — we don't copy it). And a rule with no exceptions: no created artifact can ever grant capabilities.
What we verified in gspace1 (it strengthened the plan): their live "Studio-arc retirement" retires the old universe model, not the Studio — their Studio tab grew during the closeout, and their locked model independently converged on ours: everything born live, apps in a Library, "ask Vitto to build your first App." Their Element Studio (custom SDK elements from one sentence, appearing on walls with no rebuild) is real, live, and the reason the SDK keeps growing — it keeps serving in the venue now and is rebuilt natively on the diary in Stage 3, where element versions become rewindable like everything else. There is no "PE compile server" to depend on — compiling an element is ~100 lines of in-process transpile. Full evidence: docs/Project-analysis/2026-07-26-app-def-spec.md.
| When | Where people build | What that means concretely |
|---|---|---|
| Today | gspace1's Studio keeps serving, untouched | compose_app ("ask Vitto to build an app" → PE HTML → git → wall), the Element Studio (one sentence → a custom SDK element on every wall, no rebuild), the Workbench, canvas publish → Cloudflare Pages. The brain-freeze does NOT touch capability work — this lane stays alive and invested |
| Stage 1 (the colleague) | + agente, chat-first | "Make me a dashboard" → born on the new wall in a sandbox, birth certificate attached, named into the Library (⑪). Versions = diary ranges — no draft state machine, the diary IS the state machine |
| Stage 2 (the team) | + one-tap Deploy · + the SDK on the new wall | PUB: the Publish button rides gspace1's proven CF Pages lane (verified live) — public URL in seconds, revoke = dark. SDK-A: the platform-sdk moves in-tree — the new wall renders the real platform elements natively AND the revived React element lane begins; one element vocabulary, one home for its future |
| Stage 3 (the native Studio) | the Studio on agente | The visual surface (editor/preview), custom SDK elements authored as diary events (born-live like theirs, but rewindable and sandboxed until vetted), the git door (clone/push; commits ingest as events), named apps → your own domain. Old builder lanes retire only at the Stage-3 review |
The two guardrails that hold throughout: we do NOT bridge their studio tools now (their endpoints have no service-auth lane — bridging would mean wielding user tokens or god keys, both banned); and we do NOT copy their wall's element loading (their own code flags it — user/AI code renders sandboxed here until a vetting lane exists). Users lose nothing at any point: the old Studio serves until the new one is strictly better.
The one law that makes this safe forever: a pack's events stay in the product even if the pack is retired — disabling removes behavior, never the ability to read history. That is the difference between our packs and an app store, and it's why the rewind promise survives any future pivot.
The exact feature you named, as a pack. When ON, the colleague narrates its work out loud and reacts visibly on the wall while it works. When OFF, it works silently. Here is everything it contributes:
| Contribution | Concretely |
|---|---|
| 2 event types | NarrationSpoken (a one-line first-person note: "I'm drafting the checklist now") and ReactionShown (a mood pulse tied to a wall card) |
| 1 loop | The reactor: watches recent diary entries, emits ≤1 narration line per minute per space (the rate cap Vitto proved), budget-capped at ~25¢/run, with the "NO_NUDGE" stay-quiet signal — a decline doesn't burn the rate window |
| 1 view | The narration ribbon: a fold of narration + reaction events, rendered above the canvas; also feeds the avatar's mood (35-row table) |
| Instructions layer | "Narrate significant steps in first person, one short line, never more than once a minute." |
| Config | Per-customer: narration frequency (chatty ↔ quiet), which spaces, work-hours only |
What flipping the switch does, mechanically: ON → within ≤60s the loop starts ticking, the ribbon surface appears, the instructions layer joins the prompt. OFF → the loop stops at its next tick, tools/surface hide, the prompt layer drops — and every narration ever spoken remains in the diary, rewindable forever. Cost story: the loop cannot exist without its cap, so "what does the Narrator cost us per customer?" is a line you read, not a bill you discover.
The "watch it think" theater screen. The striking fact: it needs zero backend work — the diary already streams every event live over SSE, and the original vitto-live's fold logic (three lanes: thinking / doing / reacting, with calm-collapse of repeats) is pure, framework-free code we port directly.
| Contribution | Concretely |
|---|---|
| 1 surface | The Live theater: full-screen river of thoughts (real token streams — the old Vitto faked its typewriter; ours is the actual thinking), actions, permissions, moods |
| 0 events, 0 loops, 0 tools | It only reads. Its forward-compatibility rule: any event type it doesn't recognize flows into the "thinking" lane — so every future pack's events appear on the Live screen with zero maintenance |
| Config | Lane muting, calm level, TV mode |
Why this design is strictly better than the original vitto-live: the original simulated streaming from finished strings and its narration history expired after 24 hours. Ours streams the real thing and every frame is a permanent diary entry — which is why the Live screen gets the rewind slider for free. Later (integration step I2), this same surface embeds inside my-vitto-ng as an iframe panel, exactly like vitto-live embeds today.
We censused every tool in both systems (backend-vitto-api: 124 live tools in 39 plugins; agente: 66, all wired). The verdict distribution settles "what does the new Vitto get, and from where":
| Where it lives | What |
|---|---|
| Kernel core (always on) | memory · plan · schedule/reminders · triggers (covers their Room Routines) · skills · secrets · search · sandboxed code · sub-agents/handoffs · introspection — 21 of their 43 tool groups already exist natively, usually stronger-gated |
| Shelf apps (switchable) | Devices (their `user_pc_*` suite, but with our gating) · Desktops (M1) · Canvas tools · Whistle · Groups & Channels · Specialists (re-founded on real trust, no self-grading) · Contacts · Speech · Pulse |
| Old-system creation lanes (keep serving in the venue) | compose_app · Element Studio · PE editing · domains/subdomains · platform query — bridge-later-if-needed: their studio endpoints have no service-auth lane today (APP-DEF) · docs search · supervised computer-use (until M1) |
| Superseded / retired | propose_user_action (our HITL cards ARE that, replayable) · the legacy S188 builder suite · one dead duplicate |
Two census gems: their intent-grounding guard (refuses tool arguments lifted from stale turns — protected their most dangerous tools) gets ported into our kernel's tool path; and their vault pre-auth for computer-use (credentials injected into the VM, never into the model's context) becomes M1's security pattern verbatim. Full mapping: docs/Project-analysis/2026-07-25-vitto-toolbox-spec.md. A second harvest landed 07-26 — the cockpit census (Mind suite · capability matrix · sub-agent registry): see the Absorption Rule on the Integration page and the three new Idea-Atlas rows.
| Edge case | Answer |
|---|---|
| Toggle flips mid-conversation? | The just-in-time guard refuses a disabled pack's tool with an actionable message; visibility catches up ≤60s. Already shipped behavior. |
| Pack retired years later — old diary entries? | Event definitions stay in the product forever (they're tiny). History remains readable and rewindable. Enforced by the "events are permanent" law. |
| 20 packs bloat the app? | Surfaces are lazy-loaded (code-split) — a pack's screen downloads only when opened. Backend cost of an OFF pack: zero (loops don't tick, tools hidden). |
| Who can flip switches? | Today: the customer admin (tenant-level). Per-workspace and per-member switches arrive with the multi-user rollout (Stage 2) — the settings shape is designed so this is an extension, not a migration. |
| The real gap (found in this review): per-pack cost visibility | Budgets cap spending per loop, but the ledger doesn't yet attribute LLM spend per pack. Fix is small and lands with step ④: every LLM/tool event carries the pack name, so a customer's bill can show "Narrator: $1.20 this month." Without this, the pack business model has no receipts — it's now in the step ④ definition of done. |
The honest answer (updated 07-26, founder directive — master-plan 6o): everything converges into ONE platform, inside the agente repo. We get there without a risky big-bang: we link first (bridges that mostly already ship), adopt what's ours to keep (the SDK moves in-tree), and give every gspace1 serving lane a named retirement review — transitional by design, never "theirs forever."
Update — the bridge is now part of the main plan. Steps I1–I4 below appear in the Plan page as B1–B4, woven into Stages 0–2 (identity first, panel swap at the demo checkpoint, recall + import in Stage 2). This page remains the deep-dive: the principles, the authority table, and the full track including its later steps. Architecturally, all of it lives in one module — the Bridge Pack — so every gspace1 touchpoint is in a single, reviewable, toggleable place, and the kernel itself never knows gspace1 exists.
Everything great we mine from gspace1 arrives ONLY as: diary events (permanent, replayable) · pure folds (every cockpit panel is a view of the log, never a second store) · packs under the 8-slot contract (risk-tiered, budget-capped) · or governed bridge calls (scoped keys — never god tokens). Never as: copies of truth, imported runtimes, or foreign code inside our page.
Why this is the robustness, not just a rule: we censused their full cockpit (07-26) — the Mind suite, the 131-capability matrix, the sub-agent registry. Half is genuinely live; the broken half fails in six repeating ways: panels dead from silent shape mismatches, filters dropped server-side, finished UIs with zero event writers, pages disconnected from their live stores, hand-copied config drifting from enforcement, and cross-tenant read defects. Every one of those failure classes is impossible by construction when the view is a fold of the same log that enforces. The checks that make this a law, not a wish, run in CI today (step ①): the pack contract, replay-twice, reachability, the ratchets. Full evidence: docs/Project-analysis/2026-07-26-vitto-cockpit-census.md.
| Principle | In plain words | Why not the alternative |
|---|---|---|
| 1 · Link, don't copy (identity) | Users are never duplicated or "synced." A gograb-ID account gets linked to an agente person — like linking your Google account to a new app. One click, permanent, no passwords copied. | Two synced copies of a user always drift. A link can't — there's one of each thing, joined. |
| 2 · Swap the panel, not the platform (functionality) | my-vitto-ng already treats its chat as a swappable iframe with a configurable origin. Pointing one space at the colleague is a config entry — reversible per space, instantly. | Rewiring the shell is months of risk; swapping one panel in one space is an afternoon with a fallback switch. |
| 3 · Import lazily, read the rest live (data) | On first meeting, import a bounded, useful slice (dossier facts, recent memories) stamped "imported from Vitto." Deep history stays in Mongo, read live through a recall tool. | Big-bang migrating 2 years of Mongo is the riskiest project we could pick; most old data is rarely touched. |
Analogy: moving house. You keep the same ID card (link), move the furniture you use daily (lazy import), and keep a key to the old garage (live recall). The old house stays standing the whole time.
| Engine | Its strengths | Its named roles in our world |
|---|---|---|
| PostgreSQL (agente) | Transactions, strict ordering, one-database tenancy, vectors (pgvector) — everything a proof needs | The home of TRUTH, exclusively: the diary (event log), identity, permissions, budgets, trust, memory vectors. Also the default read store (its JSON support covers most document needs at our scale). |
| MongoDB (our existing Atlas) | Document-shaped data, flexible schemas, per-tenant isolation, and — not to be discounted — two years of our data and operating experience already on it | Three named roles (sharpened by the 07-25 data inventory): (1) system of record for the old world — the recall bridge reads two years of memories/spaces live, zero migration risk, and the old cluster otherwise serves strictly read-only behind existing APIs; (2) ONE named read-model exception: materialized canvas scenes + published artifact snapshots — large, deeply nested, patched-in-place documents where Mongo's update operators genuinely beat Postgres JSONB (which rewrites whole values on multi-MB scenes). Opens only when measured size hurts; only projectors write; everything rebuildable from the diary; (3) later: compliance-isolated tenant mirrors if enterprise requires. Everything else new — sessions, decisions, profiles, memories, billing links — is Postgres, full stop: one database, one backup story, for a solo-founder ops budget. |
Storage & edge (added 07-25): our Cloudflare investment carries forward — R2 becomes the new world's object storage (it speaks the same S3 protocol agente already uses, so adoption is configuration + bucket layout, with gspace1's tenant-prefixed-key discipline kept), and Cloudflare Pages stays the publish plane (the proven Direct-Upload path now, Studio-native later). Workers/KV/D1: not by default — portfolio, not plan.
The law that never bends: MongoDB never holds a fact that can't be rebuilt from the diary. Truth has exactly one home; everything else is a disposable, regenerable view — and disposable views may live wherever they perform best. The Mongo read-model lane opens per workload, evidence-first (a candidate list is being compiled from the data inventory), never by default — a solo-founder ops budget is part of the architecture.
| Fact | Owner | The other system… |
|---|---|---|
| Who you are (email, profile, sign-in) | gograb-ID | agente verifies against it live, stores only the link |
| What you may do in colleague spaces | agente (roles, permissions, trust) | gspace1 never edits these |
| Old spaces, chats, memories | MongoDB (gspace1) | agente reads live via the recall tool; imports are stamped copies, never masters |
| Everything the colleague does | agente's diary | gspace1 can display it (embed), never writes it |
| Chat accounts (Telegram / WhatsApp) | agente identity links (the new /link flow) | same mechanism as the gograb-ID link |
| Step | What happens | Proof it worked | Undo |
|---|---|---|---|
| I1 | Identity link. gograb-ID becomes a linkable account type in agente (the embed door already verifies its tokens; we keep the verified user, one row in the links table). | Sign into my-vitto-ng → open the colleague → it greets you as you, no second login. | Delete the link row. |
| I2 | One test space swaps its chat panel to the colleague (an origin-registry entry in my-vitto-ng). | The team uses the colleague inside the familiar shell daily. | Flip the origin back — seconds. |
| I3 | Recall bridge. A read-only tool to search old Vitto memories/chats live (permission-gated like any tool). | "What did we decide about pricing in May?" → correct answer citing the old space. | Disable the tool. |
| I4 | Lazy import. Bounded import of dossier facts + recent memories, stamped "imported from Vitto" with source references. | The glass dossier shows old facts with an "imported" badge — clickable to origin. | A correction event retracts any entry. |
| I5 | Per-space cutover switch. Admin toggle per space: Vitto-brain or colleague. Cohort by cohort. | Two spaces run side by side; users notice an upgrade, not a migration. | The toggle itself. |
| I6 | Channels follow the person. WhatsApp/Telegram route via the identity link (the /link flow that shipped this week). | A message from your phone lands in the right brain for that space. | Re-point the routing entry. |
| I7 | Vitto as guest. Old Vitto joins colleague spaces as a governed guest agent (step ⑯). | Vitto proposes an action → permission card → approved → on the record. | Remove the guest membership. |
The problem, stated plainly: today two complete "super agents" exist. Brain #1 lives in backend-vitto-api and is rendered by the gograb-ai panel + the vitto-chat library family (30+ libraries, 265 source files in vitto-chat alone — a mature, valuable face). Brain #2 is agente's runtime with its own chat UI. Left unaddressed, users would meet two different Vittos with two memories and two personalities — the one outcome worse than either architecture alone.
| Law | What it means in practice |
|---|---|
| 1 · agente is the brain of record | Decided, recorded, not revisited: all new cognition, memory, trust, and reflection is built ONLY on agente. The winner architecture is settled. |
| 2 · Brain feature-freeze in backend-vitto-api — immediately | No new intelligence lands in the old agent loop from today. Capability work (compose_app, canvas, channels plumbing) continues; brain work does not. Every week without this freeze, the two brains diverge further and the migration bill grows. |
| 3 · One brain per space, always | During migration, every space is bound to exactly one brain (the cutover toggle). No space ever hosts both. A user never talks to two Vittos. |
| 4 · One shell, many plug-in surfaces (revised 07-24; clarified 07-25) | The colleague's experience is ONE React runtime (agente/ui) — but "one app" does NOT mean monolith. It's the VS Code model: one window, many extensions. Every app ships its screens as independently-built, lazy-loaded modules that plug into the shell via the surfaces registry; the shell provides the shared spine (event stream, identity, theme, the scrubber). Why one runtime is load-bearing: the rewind slider must re-derive chat + canvas + mood from one event stream in one document — separate SPAs/iframes would need a cross-app rewind protocol nobody should build. Where separate apps ARE right: venues (my-vitto-ng), ops tools (workspace-tools), published artifacts (inherently their own pages), and any future third-party UI (sandboxed artifact iframes — never inside the shell runtime). The Angular faces stay on the old brain and retire with it. |
| 5 · The old brain retires with honor | End state: backend-vitto-api's agent loop stops being a resident brain and lives on as (a) a capability server the colleague calls as tools, and (b) guest agent #1 in colleague spaces — useful, governed, never a second consciousness. |
How the face decision resolved (07-24): we traced vitto-chat's full contract in code before committing (~180 citations, spec on file) — and the evidence killed the "adapter" idea in favor of one React face. The adapter would have meant reproducing ten bug-born invariants forever, maintaining a permanent Angular↔React split, and it still couldn't give us the flagship moment (rewinding chat + canvas + mood together in one view). Instead: B2 delivers agente's React panel into my-vitto-ng via the proven iframe pattern, a ~2–3 week "face parity" sprint brings agente's existing React chat up to product polish (suggestion chips, consent-card UX ported as designs from vitto-chat — their channel/target pickers and "Why?" disclosure are excellent and framework-free as ideas), old spaces stay on vitto-chat + the old brain until their cutover (I5), channels route one-number-one-brain (I6), and both the old brain and its Angular face retire together (Stage 3). Net: ~4–5 weeks of adapter work avoided; the trace that proved this cost two hours of agents and is kept as the reference contract for guest-agent and channel integration.
gspace1's family pattern (its 1,800-line constitution for building branded verticals on shared platform primitives) matters to this plan in four distinct ways:
| Role | What it means for us |
|---|---|
| 1 · It governs our side of every embed | When the colleague embeds inside my-vitto-ng (B2), it is a guest in family territory and follows the family's documented embed law: frame-ancestors security headers, sign-in only via gograb-ID (never a second login form), the cross-app token bridge, ticketed live streams, and — critically — per-room thread keying via the bridge's room id (the family docs record the exact bug that collapses every room into one thread when this is done wrong, and how to avoid it). This is a de-risking gift: the hardest embed mistakes are already documented with their fixes. |
| 2 · It's the distribution machinery, later | The family pattern is a factory for branded customer apps (Pulse is #1) — listings, subdomains, mobile tiers, publish flows. When the colleague is sold per client, families are how each branded venue gets stamped out, with the colleague embedded as its resident. Family = the venue; colleague = the resident; packs = the resident's skills. The two systems compose — neither replaces the other. |
| 3 · One discipline of it we adopt | The "platform-lift" rule: extract shared code only when the second consumer arrives. This is the best anti-over-engineering rule in the whole document and joins our house rules for pack development. |
| 4 · One complexity of it we deliberately do NOT import | Roughly a third of the family constitution exists to manage per-tenant database naming — suffix registries, "ghost database" guards, two naming seams, CI detectors for hand-rolled names. That entire class of complexity (and its incident lineage) comes from the one-database-per-tenant model. agente uses one database with tenant-scoped rows, so these problems cannot exist there by construction. This is not a criticism of gspace1 — it's evidence for why the colleague's core lives on agente. |
The honest read of the document itself: it is an excellent pattern library and a cautionary tale — nearly every row encodes a real production incident, but most rules are enforced by convention and memory rather than by machine (and the doc carries self-flagged stale sections). Our plan takes the same knowledge and gives it teeth: fewer rules, all checked by the build.
We have something better: a way to never need sync. One person = one gograb-ID account (unchanged) + one agente identity, joined by a link. Log in once in the shell; the colleague verifies that login against gograb's own servers live (this code ships today) and recognizes you. There is no second copy to fall out of date.
Correct on both counts. agente's identity system was built to hold many external accounts per person — that's how Telegram linking works there this week. gograb-ID becomes one more linked account type (I1). The work — spaces, memories, dossiers — associates through that same link: the recall bridge (I3) reads it live, the lazy import (I4) moves the daily-use slice, and nothing is orphaned because the link, not a copy, is the join.
Never merge the databases. Never dual-write one fact to two systems. Never big-bang migrate. Never hand either system the other's master keys. Every step above is individually reversible; that's what makes this safe to start.
| Claim | Confidence | Why |
|---|---|---|
| The technology works | Verified — ~90% | Every foundation was opened and confirmed in our code. The remaining 10% is known, listed repair work. |
| We ship the colleague in ~a quarter | Likely — ~70–80% | Builds sized against real code. The enemy is our documented history of drifting focus — the fix is the house rules. |
| Still distinctive when it lands | Likely — ~60–70%, decaying | The fused experience is unclaimed today (checked live), but incumbents are moving. The window is quarters, not years. |
| The world recognizes it | Uncertain — ~15–30% | Depends on distribution, not code: today there are zero external users. Only showing it to real people moves this. |
What moves the odds most: (1) ship the rewind demo fast — the demo is the marketing asset; (2) put it in front of ten real teams and let reactions steer Stage 2; (3) fix the security items before anything public — we sell trust; (4) one wave at a time.
Status, honestly (as of 07-26): the architecture is fully decided — One-Vitto, one-React-face, the App Model, the two-floors Studio reconciliation, unification (6o) — every decision recorded with evidence. Execution has STARTED: APP-DEF is done (adversarially reviewed; founder ack pending on 3 deltas) and step ① is BUILT — the automated build-checker runs green locally (1305/1305 server tests, all law-checks + negative proofs); it goes fully live the moment the branch is pushed and "ci" is marked a required check. Remaining Stage 0: the two security holes, replay integrity, the pack engine, the App Shelf, the identity link. The bottleneck is now a push, then step ②.
One React app: chat on the left, the living wall in the center, the Vitto Live feed on the right, the rewind scrubber underneath — and every capability an installable app you flip on per space.
The one-screen rule: chat, wall, river, and mood live in ONE app so the scrubber can rewind them together — drag the knob and every pane re-derives from the diary at that moment. This is the shot that no competitor can copy without our architecture.
The collaboration rule: people are mixed and matched per moment, not per app — anyone in the workspace can be pulled into any space or huddle, Vitto included as a first-class member. The whistle reaches them where they are (in-app, WhatsApp, Telegram), each newcomer gets exactly as much history as the inviter allows — as a Vitto-written brief, not a wall of scrollback — and any decision can be replayed later by whoever joins next. That last chip is the culture-changer: "how did we get here?" stops being a meeting.
Why this is the "super" in super artifact: three doors into the same object — conversation, direct edit, and full git-ops on our own Hetzner git host — and all three write to the same diary, so versions never fork into confusion and the scrubber can replay an artifact's whole life. Casual users never see git; power users get the entire toolchain; both edit the same living thing.
What's new vs the old brain: Vitto's memory system (consolidation, decay, dedup) was real but invisible and once broke silently for weeks. Here every memory operation is a diary event — so the brain's housekeeping is inspectable ("view the run"), every recalled fact carries its source, and a degraded memory announces itself instead of quietly making the agent dumber.
Where git-ops fits (refined): gspace1 needed a git server as the state machine for drafts; our diary already is that state machine — versions are event ranges, publish is one squash-fold event. But the Hetzner git host stays, promoted to the Stage-3 Studio's materialization lane (codename Foundry): every super artifact materializes to its own repo (`{workspace}/{app}` — the repo-per-app identity pattern carries over), with the goal that anyone technical can clone, edit, and push, inbound commits ingested back as diary events — noting honestly (verified 07-26) that end-user clone/push is net-new serving work; today's lane, even in gspace1, is an internal relay that cannot serve clones. Log = truth; git = the power-user door into the same truth. Their two best publish inventions port directly: born-live by default and publication-as-capability-row (unguessable link; revoke = instantly dark).
You are implementing one step of a staged plan in the agente repo (primary) and occasionally gspace1 (bridge steps only). This page is your bootstrap: context, laws, anchors, per-step contract, and verification. Human pages 1–6 give rationale; this page gives execution.
| # | Law | Machine check |
|---|---|---|
| A1 | Adversarial review of the step spec BEFORE implementation; findings dispositioned in the spec's ## Review section | PR template checkbox + spec diff |
| A2 | ≥1 wired consumer (route/tool/loop/surface) + a reachability integration test. Lifecycle metadata (LIVE/PARKED/DEPRECATED) on every pack | CI reachability suite |
| A3 | Every fallback emits DegradedModeEntered. No .catch(() => null|{}|undefined), no bare catch {} | biome custom lint |
| A4 | Gold-set eval (record/replay fixtures) green on the LIVE turn path; an eval whose target path is missing FAILS CI. LLM-behavior packs ship ≥5 gold cases | CI eval job + path-exists check |
| A5 | No source file > 600 lines (ratchet vs. committed baseline) | CI ratchet script |
| A6 | Zero untracked gaps at step close: discovered gaps → docs/Project-analysis/GAP-LEDGER.md with an owner-step, in the SAME PR. Review-of-review depth ≤ 2 | PR template + ledger diff |
| A7 | Only the active stage receives features. New ideas → portfolio doc, never code. Platform-lift: extract shared code only when the SECOND consumer exists | Branch naming + review |
Also binding — banned claims (honesty ledger): never write "tamper-proof", "non-forgeable", "cryptographically secure replay", "nobody governs agent actions", "we have users", "AI OS", "super-agent". Replay = deterministic re-derivation of views from recorded events — never byte-exact LLM re-execution.
| Concern | agente anchor |
|---|---|
| Event registry (ONE place to add families) | src/domain/events/index.ts:50 EVENT_SCHEMAS → derived union/types. No versioning yet: events/base.ts:39 (G7 — step ③ adds upcasting) |
| Pack system core | src/domain/plugins/{types,service}.ts · template: src/plugins/pulse/ · wiring: src/boot/domains.ts:523-540 · settings API: src/infra/http/ui/settings.ts:174 · UI: ui/src/features/settings/plugins.tsx |
| Loop templates | cursor-tailer: src/boot/background.ts:446-507 (skill-extractor) · cron+budget: src/domain/scheduler/heartbeat.ts + src/domain/runtime/budget-profiles.ts:37 ($0.25 heartbeat class) |
| SSE + fold (the view pipeline) | server: src/infra/http/ui/conversations.ts:159-240 (resume by global_seq) · client fold: ui/src/features/chat/event-folding.ts:256 · hook: ui/src/shared/hooks/use-event-stream.ts |
| Known SPOFs (fix in listed steps only) | HITL waiters in-memory: src/domain/approvals/waiter.ts:32 (step ⑬) · delta bus in-memory: src/domain/streaming/delta-bus.ts (step ⑬, back with Valkey) · projector race: src/domain/projector/runner.ts:33-51 (step ③) |
| Budgets / quotas | src/domain/control-plane/quota-manager.ts:35 (pre-turn tenant gate) · resumable suspend: src/domain/runtime/turn-events.ts:566 |
| Identity (Yam's F-series — coordinate!) | src/db/schema/identity.ts (users, user_identities, workspace_members…) · src/domain/authz/resolver.ts · /link flow shipped in commit 68b0aeebf |
| Bridge Pack raw material (B1) | src/domain/embed/gograb.ts (verifyGograbIdentity — validates JWT via gograb /auth/profile, never holds secrets) · src/infra/http/embed.ts (POST /api/embed/session) |
| Stage-0 security targets | webhook fail-open: src/infra/http/webhook.ts:54 · default admin token: src/lib/config.ts:75 |
| DNA to port (gspace1 — read-only source material) | Anchor |
|---|---|
| Canvas op vocabulary + pure fold (port semantics verbatim) | libs/libs-canvas/canvas/src/lib/ir-types.ts:100-132 (item.incr :124, alive :45) · APIs/backend-api/src/app/spaces/services/canvas-patch.service.ts:263-455 foldOps |
| The live-feed fold (source name "thinking-river" — pure, port directly; unknown kinds → thinking lane) | libs/libs-ux/vitto-live-lib/src/lib/services/thinking-river.model.ts:62-120 |
| Mood table (35 rows, port as data) + FE decay | APIs/backend-vitto-api/src/app/mind/mood-reaction.seed.ts:41 · libs/libs-anim/vitto-avatar/.../vitto-mood.service.ts |
| Rate-cap + decline sentinel constants | .../cognitive/slow-loop/space-operator.util.ts:14 NO_NUDGE · .../canvas/reaction/canvas-mutation-reactor.service.ts:78 60s cap |
| Embed seam (B2) | apps/my-vitto-ng/src/app/shell/embed-origins.ts (origin registry + buildPanelSrc) · reference bridge: apps/gograb-pulse-player/src/components/pulse-app/agent-panel.ts · embed law: project-family-pattern.md rows S490.8 (frame-ancestors) + S504.1 (per-room thread keying) |
| Dossier/memory source (B3/B4) | APIs/backend-vitto-api/src/app/memory/dossier/user-dossier.service.ts · askMemory: .../mind/mind.service.ts:489 |
| Step | Deliverable | Exit gate (must run green) |
|---|---|---|
| ① | CI: tsc+vitest+biome, A5 ratchet, A3 lint, A4 path-check | Pipeline green on no-op PR; baselines committed |
| ② | Webhook token mandatory (prod), admin-token reject+timingSafeEqual, dedup index | Integration: unauth webhook 401; default token rejected |
| ③ | G6 cursor fence/gap-detect · G7 upcasting+lenient reads · G8 sandbox-tier fidelity | Concurrent-append test + legacy-read test + rebuildEquivalence all green |
| ④ | ExtensionPack slots (events/projectors/loops/surfaces) + lifecycle + per-pack cost attribution tags | Pulse re-expressed as pack, behavior unchanged; fixture pack registers e2e |
| ④b | App Shelf V0: AppManifest type + APPS catalog beside PLUGINS, app.installed@v1/app.removed@v1 events + projector, Shelf pane (Sees·Does·Costs card, one-sheet install), Pulse as app #1. Per-space grain; envelope auto-pause via loop decline sentinel | e2e: install→use→remove→scrub-back shows app alive at its install range; permission strings CI-checked against Cedar template hash |
| B1 | Bridge Pack: gograb-ID as linked identity (keep verified user from embed flow; link row) | e2e: gograb JWT → /api/embed/session → resolves to linked agente user |
| ⑤ | Conscience pack: ConscienceReflected events, choke-point narration, reflector loop, mood table | Live turn emits conscience events ≤ caps; toggle off stops loop |
| ⑥ | Vitto Live surface (mood presence + Live Feed; ported 3-lane fold, real deltas) | Playwright: run turn → river renders live |
| ⑦ | Canvas core: SpacePainted (PatchOp vocab), paint_canvas tool, foldCanvas, <Space> + 4 elements | e2e: agent paints mid-conversation; fold parity tests vs Vitto op semantics |
| ⑧ | Glass dossier: projection + provenance links + corrections + prompt-layer brief | e2e: every rendered fact click-resolves to source events |
| ⑨ | Ask-memory w/ citations + FIRST gold-set (~15 fixtures) gating prompt/tools/recall | Eval job green in CI and mandatory thereafter |
| ⑩ | Scrubber (fold-to-N) + trust_scores projection hooked into requiresApproval | Property test: fold-to-N ≡ historical state; flagship demo e2e |
| ⑪ | Living artifacts: run_code→canvas card via effect:'attachment' + birth certificate | e2e: prompt → sandboxed exec → card + certificate, under budget |
| B2 | gspace1 session: embed-origins entry + CSP row + AI_AUTH_INIT for the colleague panel in ONE space | Colleague usable in my-vitto-ng test space; revert = flip origin back |
| FP | Face Parity Sprint (React, agente/ui): suggestion chips, consent-card UX (port vitto-chat's picker/"Why?" designs — designs only, no Angular code), attachments, model chip, mobile. Design-direction gate applies | Founder side-by-side: new face ≥ old vitto-chat on the parity checklist |
| ⑫⑬ | Spaces×members (F3) · Valkey buses + durable waiters | Two users live; kill-process-mid-approval survives |
| B3 B4 | vitto_recall read-only tool · lazy import w/ provenance stamps | Cited answer from old space; imported badge resolves to origin |
| SDK-A | Adopt the platform-sdk IN-TREE (6o — supersedes vendored-copy SDK-1) + revive the React element lane as a new generation on the same Scene-IR/manifest contracts; ≤10 presentational tags first; local EventBus, NEVER a DataClient; token bridge both themes; lint ban on Blob/data: imports; user/AI-authored code sandboxed (D5) | t1:chart renders via the in-tree platform-chart AND one React-gen element side-by-side under our tokens + 1.D sign-off; e2e: non-curated tag rejected |
| SR | The Governed Router (6q): lane column + cheap lanes (heartbeat/subagent/judge) · budget-gate ladder (hard-cap → auto-frugal → per-call cap) reading the billing fold · kill switch above all fallbacks (one refusal constant) · per-task pinning · ModelRouted provenance events · precedence CI table. SR-0 (G-9 fix + model catalog + cache_control) rides step ④ | Spend meter matches reality under routing; pause switch → refusal within seconds; background loops visibly on efficient models; degrade emits an event Vitto voices |
| ⑭⑮⑯ | Whistle pack · visible skills · guest-agent principal + A2A adapter (Vitto guest #1) | Per-step e2e in master plan; guest action → HITL → logged → trust moves |
| St.3 | Personas/souls · care+predictive packs · embed distribution · space forking | SPECS NOT WRITTEN until Stage 2 exit review passes (A7) |
If blocked: a missing fact → verify in code before assuming (files move daily in both repos); a genuine scope decision → stop and surface it to the founder; a discovered defect outside your step → gap ledger, not a detour (A6).
Board mirror (snapshot 2026-07-26; the repo file is truth): APP-DEF: VERIFY (spec + A1 review done — 2026-07-26-app-def-spec.md; founder ack pending on: SDK-1 row · Stage-3 rename · 1.3 DoD sentence) · 0.1 CI+ratchets: DONE (pipeline GREEN on GitHub — run 30186954132; founder follow-up: mark ci a required check) · 0.2 grenades: VERIFY (BUILT 07-26 — prod fail-closed webhook + default-admin-token rejection + constant-time secret compares [admin, UI auth, Telegram, WhatsApp verify] + the webhook dedup unique index; A1 review: 3 reviewers, 23 findings dispositioned incl. a real BLOCKER — the index was re-scoped to webhook-born events because Telegram per-chat message ids may legally repeat, even inside one conversation via lane-attach; unit 1320/1320 · ui 49/49 · integration incl. new grenades suite green locally; DONE when the founder commits — the master-plan gate wants hashes) · 0.3 replay integrity: VERIFY (BUILT 07-26 — G6 per-tenant append lock [commit order = seq order for every cursor pager] + single-writer CI ratchet · G7 injected upcasters + OPT-IN lenient reads [A1 blocker: default-lenient would have let junk payloads through the approvals expiry gate] · G8 both sandbox tiers stamped [planned + executed] · the rebuildEquivalence harness BUILT and GREEN on billing/conversations/memory; unit 1324 · integration 465/465; DONE when the founder commits) · 0.4 pack engine + SR-0: VERIFY (BUILT 07-26 — the ExtensionPack contract [events/projections/loops/surfaces slots, mandatory budget profiles + lifecycle, 6n boot validation], the DegradedModeEntered event family [A3 as data], Pulse re-expressed LIVE with a lifecycle badge in Settings, per-pack cost fold [the Shelf's Costs substrate], and the SR-0 routing truth: the diary now records and PRICES the model that actually answered, one model catalog as the single price source, Anthropic prompt-cache breakpoints [immediate cost win], per-model compaction windows; unit 1343 · integration 465/465; DONE when the founder commits) · B1 identity link: VERIFY (BUILT 07-26 — gograb-ID becomes a durable, correctly-reconciled linked identity; embed visitors are now member-grade not owner; a 3-reviewer Opus-5 panel overturned two of my premises [the embed session role IS wielded; the link row IS an authorization key] and the fixes followed the evidence: reconcile-to-verified linking so a future recall bridge never resolves a stale identity, plus race-safe first-mint and a clean 403 on offboarded principals; the deeper email→identity escalation is honestly escalated to F3, not claimed closed; integration 472-green; DONE when the founder commits) · ④b App Shelf V0: VERIFY (BUILT 07-26 — install an app with one tap: AppInstalled/AppRemoved events, the installed-apps fold, pack enablement DERIVED from the log by a reconciler [never hand-written config], the Apps pane with the honest Sees·Does·Costs card [needs-setup + divergence states, blast-radius copy], a bidirectional nav↔route reachability test with proven teeth, and a real Playwright e2e spec — the review's 7 blockers included a pre-existing DEAD WIRE: the plugins settings API answered 503 in production, now fixed and regression-tested; e2e 14/14, unit 1345, integration all-green; DONE when the founder commits) → Stage 0 remaining: · 0.4 pack engine · 0.4b App Shelf V0 · B1 identity link (PENDING) → Stage 1: 1.D design spec · conscience · Live Feed + VL embodiment · canvas · dossier · ask-memory+eval · scrubber+trust · artifacts · B2 embed → Stage 2: PUB deploy · FP face parity · members · buses/waiters · B3 recall · B4 import · SDK-A adopt-SDK + React-lane revival · SR governed router · M1 desktops pack · whistle · specialists · M2 universal resident · guests → Stage 3: Studio (codename Foundry) · M3 queues · personas · care · forking · retirement. Machines detail: 2026-07-25-machines-bridge-spec.md.
One brain, one diary, one face, one Vitto — extended by switchable packs, acting through governed hands, present in every venue our users already live in.
Nothing here is rebuilt. Venues reach the brain through the adapter or the embed bridge — swap-in, not rip-out.
The Angular faces (vitto-chat, gograb-ai, vitto-live) stay bound to the old brain and retire with it — never re-pointed, never rebuilt piecemeal. One framework (React), one app, one rewind.
THE DIARY (append-only event log — the single source of truth) · pure folds turn it into every face above · identity & multi-user (one person, many linked accounts: gograb-ID, Telegram, WhatsApp) · Cedar permissions, deny-by-default · HITL approval cards · hard budgets & quotas on every thought · the earned-trust ladder, fed by the diary itself · the smartness exam guarding every change
| Object | What it is for the user | What lives at this level |
|---|---|---|
| Workspace | Your team/company — there is usually one | members & roles · billing · the Brain's scope · the device fleet · which apps are allowed |
| Space | A project room — create one per project | the wall · the chat thread · the library · the apps YOU installed here · its own rewindable history |
| Home | Your personal space with Vitto — automatic | DMs, "while you were away" briefs, personal artifacts — the solo→team on-ramp |
| Everything we already built → its new home (nothing skipped) |
|---|
| Space: Routines (today's Schedules/Goals/Triggers, space-scoped) · Files → the space Library · per-space app switches (today's Plugins) · the Brain lens ("what Vitto knows here" — exactly the panel we already ship in my-vitto) · approval chips in-context |
| Workspace Settings: Members+Network · Channels · MCP · Secrets · Quotas · Model tier · Devices (incl. VMs) · Policies · App catalog · Search · Preferences — today's tabs, 1:1, re-homed not rebuilt |
| Workspace → "Vitto" profile: Soul · Skills · Brain/Memory · trust standings — the colleague's own page |
| Home: briefs · DMs · personal routines · the old flat Conversations list becomes Home's history |
| Cross-cutting: Approvals = a workspace Inbox + chips wherever you are |
| Reality check (fidelity rule, 6l — surveyed against ui/src 07-26): the real app already ships MORE than our mocks showed — Skills is a full SKILL.md review workflow (proposed/approved/rejected/archived, editor with Save & approve, tool-trace provenance, use/success counters) plus a Match playground that scores which skills a message would trigger; chat is a control surface (inline approvals that write Cedar "Always allow" policies from a chat button, ask_user option pickers, live plan checklist, device-pairing cards, Stop); the Inspector shows per-turn cost/latency/tokens with nested subagent turns and soft replay — the proto-scrubber, shipping today; Memory exposes hybrid-recall scores; Settings spans 11 tabs incl. Telegram deep-link pairing, MCP JSON import, and multi-provider model routing |
The terminology law: one word per object, forever — Space (never "room"/"universe"), Workspace (the internal "tenant" shell never appears to users again — today's tenants/ten_… URLs are an implementation detail to bury). The growth path IS the product logic: Home → Spaces → invite per space → the Workspace grows around you. Tracking follows containment: scrub a Space to replay a project; the Workspace holds the brain, people, and money. Today's prod nav (Soul, Memory, Schedules…) remains as workspace-level panels; Spaces become the primary object when step ⑦ lands.
Between the two repos we run five different ways of "doing work on a machine." Here's each in one line, and what happens to it:
| What we have | In plain words | Becomes |
|---|---|---|
| agente's gVisor executor | The sealed test tube — runs untrusted code snippets in a locked sandbox (no network, read-only, seconds of life). For "run this code safely," nothing more. | KEEPS ITS JOB — untrusted code execution, core |
| sandbox-orchestrator (gspace1, Hetzner) | The rentable full computers — a Firecracker microVM fleet: real desktops with screens, per-user persistence, snapshot/restore, click/type/see primitives, plus the git host. | CAPABILITY SERVER — the brain rents desktops as governed tools |
| home-vm-agent (gspace1, S305) | The concierge inside each rented computer — a small process living in each VM, wired to the old brain (Mongo, Dragonfly, a local LLM). Your and Yam's "Vitto in every VM" idea — first draft, already built once. | SUPERSEDED — by the universal resident below |
| vitto-coder-worker (gspace1, S456) | The factory worker at one bench — a headless process on the big engineering host, pulling coding jobs from a durable queue with heartbeats and clean handback. | PATTERN PORTS — durable job queues become kernel work; the bench stays |
| agente's device-agent (Go) | The standard-issue radio + keycard — one small signed binary any machine runs: dials home (no open ports), enrolls with a one-time code, every action permission-gated and diary-logged, remote kill switch. | PROMOTED — the universal resident |
The decision your idea points to (and we agree, with one refinement): install a Vitto presence in every VM and every Hetzner machine — yes. But the thing installed is the device-agent, not a brain. One brain, one diary (the One-Vitto Law); what every machine gets is the same radio+keycard: the VM boot script enrolls it with a one-time code, the Hetzner hosts run it under systemd, user laptops already run it. Then every machine in the workspace — laptop, cloud desktop, build server — is a device in one fleet, speaking one protocol, under one permission system, on one rewindable record. It also retires three overlapping one-off agents (home-vm-agent + both dormant local bridges) into a single battle-tested binary. Installing full brains per machine would fracture the diary into N truths — the exact disease we're curing. And the UX bar is set by what we already shipped: enrolling a laptop today is one downloaded file and one code — managing a VM must feel the same: one sentence in chat ("give me a desktop"), one card on the wall (booting → enrolled → ready), every phase a diary event. No consoles, ever.
| gspace1 asset (verified) | What it becomes on agente | When |
|---|---|---|
| Vitto Brain — episodic/semantic memory, consolidation, decay, dedup, "ask me what I remember," memory→Docs export | The Brain, provable: vector memory in core + a Brain app whose consolidation/decay runs are auditable events; every answer cites the diary; knowledge graph = a fold, later | Stage 1–2 |
| Dossier (facts, corrections, relationship decay, ~200-token brief) | Glass Dossier — every fact links to the moment it was learned; delete is an event | Step ⑧ |
| Conscience + the 35-row mood table | Conscience app (table ported verbatim) | Step ⑤ |
| vitto-live "watch it think" | Vitto Live — the embodiment (step VL): Vitto as a living presence — assembled from assets we already own: the framework-free avatar engine (zero port), the Rive avatar's 14 emotional states + gaze, the 35-row mood table, native TTS for spoken replies, real token deltas for speech timing; later passes add voice IN + paralinguistics — Vitto adjusts to HOW you sound (their voice-analysis DNA; portfolio #14, 6o). Bar set by the founder: human-grade, iterated honestly | Step ⑥ |
| Canvas / WALL + PatchOp vocabulary | Canvas engine (core) + element apps (the LEGO) | Step ⑦ |
| compose_app "born-live" apps | Living Artifacts with birth certificates — born in your space, no deploy step (their best invariant, kept) | Step ⑪ |
| Workspace-apps (formerly universes) + publish flows | The Artifact Ladder: wall card → living artifact → named app in the space Library → published to the world. Their best mechanism ports directly: publication-as-capability-row — the public web can only name an unguessable publication id; revoke it and the page is instantly dark; tenant identity never crosses the anonymous boundary. 07-26 verified: their locked model converged on ours — born-live, a Library, chat-first creation (APP-DEF) | P4 → Stage 3 |
| Studio git-ops (draft branch → squash-merge → deploy; repo-per-app on our own git host) | The Stage-3 Studio (codename Foundry) — with a simplification their code itself points to: they derive draft state FROM git because git is their only log; our event log already is that state machine. Versions = event ranges; "publish" = a squash-fold event; git becomes an export format, not infrastructure — and, verified 07-26: their git host serves no end-user clones today (internal HTTP relay only), so the clone/push door is net-new serving work either way. Their identity-as-pure-function pattern (one identity → derived branch/deploy/paths) is adopted as the app-id convention | Stage 3 |
| Whistle · Sub-agents + self-training · Personas · A2A/relay · Observatory · Care prompts · Predictive assembly · Voice mood | Whistle app ⑭ · Visible specialists on the shipped skills loop ⑮ · Versioned souls · Guest agents ⑯ (Vitto = guest #1) · the Scrubber ⑩ · Care app · Warm-start app · Voice app | Stage 2–3 |
| The Capability Matrix (131 caps × roles · overrides · decision audit) — cockpit census 07-26 | Permissions on glass: a read fold in Policies deriving live from Cedar + tool risk tiers + role ceilings — the page and the gate read the SAME store. Their page drifted by design (an FE-bundled constant while the HTTP guard ignored overrides and a legacy gate ran in series); a fold cannot. Their per-call gems port: the unattended-run capability mask (as Cedar policy), the un-bypassable consent gate (ours ships: inline-only approvals), decision-tree audit (native — causation ids, and no 90-day expiry) | ④·⑤ + Policies · portfolio #11 |
| The Mind suite (Knowledge Base · Health · Graph · Map · Thought Trace · Diary · Introspection · the recognition moment) — cockpit census 07-26 | Each panel becomes a fold of the diary. Their finished Thought-Trace UI had zero event writers — ours streams real turn/tool/recall events by construction (⑥). Memory health = degradation events on glass (A3). Write-time consolidation, class-aware decay, quarantine, and ≤3-facts-per-exchange extraction port as Brain mechanisms; the alert lifecycle (fire on state change → channel delivery → 6h escalation → auto-resolve) ports into triggers; "I recognized Demo the moment they walked in" — their most alive moment — becomes the dossier-driven entry brief | ⑤⑥⑧⑨ · portfolio #12–13 |
| The Sub-Agent Registry (definitions · training · trust ladder; its cockpit FE silently broken since June) — cockpit census 07-26 | ⑮ Visible Specialists absorbs the three gems: corrections as first-class events folding into the next dispatch; the algorithmic training quality gate (dedup/echo/floor — zero LLM) validating training events; earned autonomy derived from dispatch outcomes + user-override affinity — no self-grading (their own seeds warn synthetic training data is "the #1 cause of model-lie pathologies"). The card grid ports as design; on a fold, "0 definitions" over a full grid is unrepresentable | ⑮ + skills loop |
| The Smart Router (~17.4k LOC — their single most-engineered, mostly-live subsystem: task-type/lane taxonomy, effort levels, budget-gate ladder w/ auto-frugal, kill switch above all fallbacks, prompt-cache pinning, measured-scores learning loop, canary auto-revert) — censused 07-26 | The Governed Router (6q): their governance model on our event log — structural LANES (background work never burns frontier models; no text classification), budget-steered degrade that announces itself ("I'm thinking cheaper right now" — law A3 as product), one kill switch above every fallback, per-task pinning for prompt caching, and the learning loop as a fold of the same events that record the calls — which makes their two production blindness incidents (a silently-dead call ledger, a load-bearing cost bridge) structurally impossible here. Bonus find: our routing had a real mispricing bug under multi-provider routing (G-9) — fixed in SR-0 | ④(SR-0) · St.1(SR-1) · SR St.2 |
| platform-sdk + the frontend treasury (Opus inventory, 07-25) — platform-elements (~70 registered zero-framework web components, 40 wall-usable — census 07-26 — + the agentic surface) · catalyst-ui-kit: 71 real React/Tailwind components, unfrozen · theme-system/core (pure-TS OKLCH theming engine, spec-covered) · vitto-avatar-engine (framework-agnostic Canvas 2D) · tenant-projections (claim/backoff/dead-letter projection semantics) · chat-plugin-core, core-models (155 files), all of libs-api & libs-core (Angular-free) | The shared visual DNA layer keeps growing, serving BOTH worlds — same element on old Angular walls and the new React wall. catalyst-ui-kit is the day-one React component base; theme-system/core seeds the design workstream; the avatar engine is the colleague's body with zero port work. Note: the pe-react-* libs are FROZEN by founder ruling S525.1 — un-freezing is a founder decision, not an assumption. 07-26 (6o): ADOPTED IN-TREE — the SDK's future development moves into agente; the React element lane is REVIVED here as a new generation (founder override of S525.1, scoped to agente; the frozen pe-react-* libs become design donors; the freeze stays in force inside gspace1) | Step ⑥–⑦ on |
| The heavy capability servers (Opus inventory, 07-25) — the Firecracker microVM fleet with computer-use primitives, per-user persistent desktops, snapshot/restore, VNC streaming (sandbox-orchestrator) · the computer-use/browser-automation loop (backend-ai-api) · the docs corpus as a live search API (6,143 files, backend-docs-api) · Stripe billing, shared JWT auth, tenant provisioning (backend-api) | They keep serving — the new brain calls them as governed tools. The VM fleet is the hardest-to-rebuild, most valuable non-LLM asset in either repo: the colleague gets real desktops as HANDS via the capability-server lane, permission-gated like everything else. Billing/auth/tenancy — don't rebuild DURING the transition; end-state settled 07-26 (6p, census-based): auth — agente is its own identity root, gograb-ID stays the family's sign-in and becomes a linked, verified account (their fleet secret never enters agente); billing — agente's event ledger is the billing brain + a thin Stripe adapter when the first customer needs an invoice (invoices become clickable folds of the diary); their systems keep billing/signing-in THEIR world until each lane's retirement review | Woven in |
| The learning pack (backend-ai-api/learning) — outcome-detector, calibration, decision-time-machine, self-healing patterns, consent-gated collective intelligence | Highest idea-density find of the inventory: these are native event-log concepts — outcomes, calibration, and decision replay become packs on the diary where they finally get the substrate they were designed for | Stage 2–3 packs |
| Channels (WhatsApp/Telegram) · gograb-ID · S620 cost-routing ideas · IQ decisions brain · Pulse family factory | Channels core + one-number-one-brain routing (I6) · the B1 identity link · per-app cost meters & envelopes on the Shelf · decision blocks in every spec + one-time convention mining · branded venues embedding the colleague | Woven in |
Reading this table honestly: the left column is two years of your ideas, verified in code this week — including which parts work end-to-end today and which quietly died (their GitLab pipeline is dead code; their two subdomain registries never met; module-gen was deleted). The right column is the same ideas on a substrate where each becomes provable, budgeted, and rewindable. That is what "reuse everything incredible" means in practice: ideas and mechanisms port; entropy does not.
The whole brain in backend-vitto-api, traced mechanism by mechanism. Three kinds of moves: mechanisms are re-founded as events + folds (so they become provable and rewindable), the data stays reachable and its daily slice moves with provenance, and nothing waits on a big-bang migration.
| Their brain piece | Its new home | When |
|---|---|---|
| Memory store (importance, org/space/user scopes, embeddings) | Postgres + pgvector — shipping today; scope filters become fold parameters (their cockpit's scope filter was silently dropped server-side — impossible on a fold) | now · ⑨ |
| Auto-learning (≤3 facts per exchange, mirrored to the dossier) | Post-turn fact extraction feeding the Glass Dossier, provenance-stamped | ⑧ |
| The housekeeping pipeline (write-time consolidation · nightly consolidate/decay/dedup · quarantine) | Brain pack loops, budget-capped — every run is an event, so "view last night's consolidation" is a click, not an ops query | ⑧⑨ + Brain app |
| Corrections (importance 0.95, protected from decay) | Correction events — first-class, rewindable history | ⑧ |
| The Dossier (facts + prompt brief + enrichment questions) | The Glass Dossier — every fact click-resolves to the moment it was learned; "forget" is an auditable event | ⑧ |
| Recall + "ask me what you remember" | Hybrid recall shipping (the Memory page already shows match scores); ask-the-brain answers cite the diary, permission-scoped | ⑨ |
| Knowledge graph & Memory Map (real stores, fake semantics — co-occurrence edges, hash-based "projection") | Ported as designs; shipped only over real relations and real embeddings — we do not ship fake geometry | portfolio #13 |
| The Diary cron (writes consolidation blurbs labeled "diary") | The diary IS our log; a real daily reflection = one scheduled fold+summary turn | portfolio #12 |
| Memory Health (born from their invisible-degradation incident) | Law A3: degradation is an event → health is a fold, and Vitto says it out loud in Vitto Live | ⑤ · ⑥ |
| Recognition — "I recognized Demo the moment they walked in" | Dossier-driven entry briefs on space entry (already demoed in the Playground) | ⑤ · W1 |
| Identity synthesis + Character/Core Values pages (one live, one a hand-copied drifted literal) | The Soul — versioned, event-sourced, shipping today; personas = versioned souls later | now · St.3 |
| Trust scoring (the live service their own dashboard never connected to) | The trust ladder: a projection of tool/policy events that gates approvals — the page and the gate read the same fold, so they can never disconnect | ⑩ |
| Conscience + Introspection + the proactive-alert lifecycle | ⑤ conscience pack + ⑥ Live Feed; the alert lifecycle (fire on change → deliver → escalate → auto-resolve) ports into triggers | ⑤⑥ |
| The 2 years of memories themselves (Mongo) | B3: live read-only search of old memories, permission-gated · B4: bounded import of your dossier facts + recent memories, every entry badged "imported from Vitto" and click-resolvable to origin. Nothing wholesale-migrated, nothing lost | Stage 2 |
| The learning pack (outcome detection, calibration, decision time-machine) | Native packs on the diary — these are event-log concepts that finally get their right substrate | Stage 2–3 |
Why this is more power, not a rebuild-lite: on the old brain these were 15 separate services over mutable collections — half their cockpit pages had already drifted from them. Here every row is the same three primitives (event family · fold · pack loop) under the same budgets and permissions, which is why each one arrives with rewind, provenance, and honesty built in. Full mechanism-by-mechanism detail with code evidence: docs/Project-analysis/2026-07-26-vitto-cockpit-census.md §2b.
The claim this picture makes: growth without entropy. gspace1 grew by adding rooms to the house until the corridors tangled; Super Agente grows by plugging modules into sockets that never change shape. The diary means nothing is ever lost; the switches mean nothing is ever forced; the laws mean the mess we lived through cannot structurally recur.
The interactive drafting table — the complete Super Agente vision as a working, full-viewport simulation — now lives as an independent artifact so it gets real estate, realistic proportions, and its own iteration pace:
🕹 Open Super Agente — Playground →
What's inside: two spaces (build up Launch HQ yourself; explore Ops 24/7 where Vitto already earned DIRECT trust) · working Wall/Brain/Library/Apps views · app installs that gate abilities · consent chips · one-tap Deploy with symmetric Unpublish · staged desktop provisioning under the M0 contract · typed chat with streaming replies · the trust ladder and spend meter, live · the rewind slider over everything · and Blueprint mode overlaying plan-step tags for design reviews. It now also models the decided object model (Workspace → Spaces incl. your personal Home) and real collaboration: teammates with names who reply in chat, approve proposals themselves (“✅ approved by Yam” — every actor named on the record), and a whistled member who arrives and speaks. It links back here via the 📘 Briefing button.
Division of labor: this briefing = the decisions, plans, and evidence; the playground = the place we feel and iterate the product. Point at anything there and I redraw same-day; what survives becomes step 1.D's layout brief.