Conversations, specialist agents, files and knowledge belong to a durable project. Return through the interface that fits your day, with the server keeping the work and its history.
A home for each kind of work.
A project groups definitions, conversations, knowledge, permissions and optional files. Use one for a research collection, a codebase, an integration or an ongoing responsibility.
Personal, for your own work
Every human account has a private Personal project. Start with questions, notes and plans, then develop an evolving knowledge collection. Its files and history remain separate from other accounts and ordinary shared projects.
Registered server projects have explicit members and roles. Creating a project does not make everyone a member. Server workspaces can be managed by Plowshare or independently maintained with declared writable areas.
Attach a local checkout through a fenced client file channel, or use a registered server workspace. A client path and a server path name different files. Git-backed synchronization is a separate choice; attaching a folder does not enable it.
Define the role. Choose its reach.
A bot is an assistant you talk to. An agent is a specialist the system or another agent can invoke. Their definitions select prompts, models, tools, delegates and execution limits.
A / DEFINITIONS
Assistants you can shape
Markdown and YAML frontmatter describe behavior. Start from the shipped conversation, coding, review or research roles and adapt them to your project. Inspect the effective roster to see which definitions are served and why others are disabled.
B / SKILLS
Procedures you can reuse
A skill combines instructions with optional supporting resources. Invoke it under explicit grants and a chosen context mode. Hidden, granted skills can remain available to people through bound slash commands.
C / CONTEXT
Instructions in their scope
Account, project and workspace rules guide work through the existing resolution tiers. More specific definitions can override earlier ones. An invalid authoritative override is refused rather than replaced silently.
Skills do not automatically dispatch by description matching. Model discovery and caller grants are explicit configuration, and skill instructions cannot add tools the executor lacks.
Membership, tool grants, file boundaries, command policy, hooks and approvals all apply to the work. A prompt or a human approval does not replace the other access checks.
Project roles
Viewers read. Contributors can also start and update work. Managers additionally manage definitions and membership. Private conversations and information audiences keep their own ownership checks.
Bounded file access
Declared roots, exclusions, scopes and writable areas constrain file tools. Commands have separate local and server policies. Projects with restricted writable areas refuse server commands that cannot honor those restrictions.
Human decisions
Approvals identify a particular pending operation. Answer the current request, then follow its actual outcome. Hooks and authorization can still refuse the action; a prior approval is not a general-purpose permission.
Service identities
Scoped service tokens have expiry and fixed project-role ceilings. Effective access also depends on current grants. They have no password login or Personal space; a background adapter needs an explicit permitted project.
Long-running work returns a durable handle. Accepted means the server admitted it; completion, refusal, interruption and cancellation are separate outcomes.
Submit and keep the handle
Retain the job, conversation or workflow identity and any request receipt.
Reconnect and inspect
Read or follow the existing work rather than repeating a mutation after a lost reply. Work requiring a disconnected local file channel can fail even when the server remains available.
Read the actual result
Inspect tool effects, terminal outcome and partial output. Cooperative cancellation stops future work and does not undo committed effects.
Authenticated WebSocket operations carry supported client/server work. Authentication, readiness, binary uploads, Git transfers and external protocols retain their documented HTTP boundaries. The runtime uses Java 21, Spring Boot, PostgreSQL and pgvector, with persistent disk state.