super.computedriven.com · local-first · byo engines

The compute surface.

Agents don't run in a chat window here — they occupy a world. Direct them across your machines and the cloud, where each one holds a position with an inspectable state, explicitly scoped authority, and a record of what it did, what it proved, and what it was permitted to change.

In the open: Phases 1–2 (Tauri shell · Elixir runtime) are in progress. The Tauri cockpit builds and runs against the real runtime — there is no installer, so there is still nothing to download. Everything under the light is the real, clickable prototype.
Super (CD)workspace/trvmgates cert ×LIVE PROTOTYPE
live prototype — click in
Not a screenshot — this is app-prototype.html embedded live (simulated runtime state; Phase 2 projects it from OTP). Click in.
loading proof artifact…
Why this exists

Agent panes are table stakes. Accountability isn't.

Everyone else answers
"How do I get agents to do the work?"
Super (CD) answers
"What exactly did the work establish, what was it allowed to change, where did it run — and why may the result be committed?"

A super-surface above interchangeable engines and below you. Claude Code, Codex, whatever comes next — engines run the turns; Super owns the identity, the placement, the budget, and the receipts.

An ordinary Tuesday

You don't need formal methods to want receipts.

Here's the same machinery on a completely mundane goal — one page, four placements, three claims, one obligation standing between the work and production.

GOAL · SHIP_PRICING_PAGE-v2
researchcompetitor teardown, finchCLOUD · cd-west
implementationwren · claude-codeLOCAL · your desk
browser testharrier · 390 / 768 / 1440FLEET · ms02
deploywaiting on the obligation belowHELD
CLAIMS
  • responsive at 390 / 768 / 1440
  • checkout regression 18/18
  • deployed commit = tested commit — pending · deploy held
OBLIGATIONS
  • human approval before production
  • the merge is inexpressible until this closes

Nothing exotic happened here. An agent researched in the cloud because the data was public; another implemented locally because your source stays home; a third proved the page on a fleet box — and the deploy is held, not "probably fine," until a human closes the obligation.

The system never asked you to learn its cosmology. It just refused to confuse done with proved.

And when a goal needs it to go all the way down — it goes all the way down. ↓

Evidence & epistemics · the deep end

Green means measured. And it says where it was earned.

This is the same product dogfooded on our formal-verification work: claims carry receipts, obligations gate merges, and every claim wears its rung on the ladder — never a higher one. Every figure below is read from proof/latest.json, which the verifier generated. Click one; the receipt opens.

spec in_tree live_local live_deployed external
$ ./verify.sh PASS negative battery forgeries caught PASS cross-plane bridge states byte-identical across implementations PASS semantic film · both terminal classes native PASS invariant grid checks attempted · passed · failed · skipped every gate replayed green
film-budget-negative · fix a value film-unknown-flag · fix a spelling authority-revoked · fix a permission refusals name themselves — you always know which one to fix
One world · three surfaces

Not integrations. Projections.

The desktop, the cloud, and the OS are views of the same running world — a lane shown in Super and a lane shown in T&R aren't two synced records. They're one object, seen twice.

SUPER (CD)

The desktop cockpit. Goals, lanes, agents, diffs, evidence, fleet placement, runtime state — your hands on the world.

[WORLD] CLOUD

The control plane. Identity, node membership, encrypted selective sync, presence, restore, hosted capacity, billing.

T&R

The native OS environment, where the same world becomes spatial — machines, roads, tracks, agents, dashboards.

WRL — the shared, inspectable world  ·  TRVM — the law that makes its transitions verifiable  ·  TRAAVIIS carries the provenance · RuneFort draws the topology
Governed placement

Local, cloud, and fleet are sites — not copies.

Attach the machines you already own — desktops, mini PCs, GPU boxes, cloud VMs — and extend with ComputeDriven capacity when you want burst. Moving work is placement, not migration: same supervision tree, different floor.

LOCAL — source and secrets stay put FLEET — an eligible node you own CLOUD — ComputeDriven-hosted burst

Eligibility is computed from capability, hardware, cost, and data policy — and the derivation is citable. A future TRVM layer can verify why a site was allowed.

task: synthesizer-training requires: gpu.cuda may_run_on: [gpu01, computedriven-gpu] source_data: denied_remote artifacts: allowed · max_cost: $5.00 derived placement → gpu01 // source policy excludes cloud // more interesting than a "Run in Cloud" button
Engine ≠ identity

The agent is bigger than its engine.

An agent is not the model animating it. It is an active locus — an established state, the explicit scoped grants whose policy preconditions that state satisfies, and the evidence connecting one state to the next. Identity, memory, worktree, budget, authority and obligations live under a supervisor; the engine is one replaceable child, a reasoning motor the locus thinks with rather than the thing that is thinking. That is what makes swap Claude Code for Codex mid-task a coherent question instead of a category error: the motor changed, and the locus is what would have to continue.

What is built, and what this claim still owes: the supervisor, the ledger and the authority runtime are real Elixir/OTP — ampd/, not simulated. The swap is prototype behaviour. No run in this tree has yet carried a locus across an engine substitution and shown the successor re-established the predecessor's state, so surviving an engine is the design here and not a measurement. The part already true is narrower and still worth having: what the engine was permitted to do never lived inside the engine. That is why this section no longer promises an agent that cannot die — it claims the smaller thing it can show, and leaves continuity as the open experiment it is.
ag_kestrel — what the engine does not own goal       EMISSION_CONFORMANCE-v1 memory     214 claims, citable worktree   wt/lane-a @ 4f21c99 budget     24.8k / 40k · authority · obligations
claude-code◂ SWAP ▸codexanything with a harness
Capability packs · install ≠ authorize

Plugins, without ambient authority.

Install a skill, connector, UI, or MCP server once. Then grant only the typed capabilities each agent or workspace may exercise. Secrets stay outside the engine, placement stays governed, and meaningful effects leave receipts.

INSTALL

A pack can bundle skills, MCP, UI, hooks, adapters, and tests. Installation gives it zero authority.

GRANT

github.repo.read is not github.pr.merge. Scope abilities by agent, workspace, resource, budget, node, and duration.

RECEIPT

Every committed effect names the pack/version, capability, authority snapshot, placement, approval, and result.

PROTOTYPE CATALOG · NO PACK EXECUTES YET · STATES SIMULATED

GITHUBINSTALLED

MCP · Skill · UI
READ 3 · WRITE 1 · ADMIN 0
secret: gateway-only
LOCALFLEET
conformance 42/42 · simulated

BROWSERINSTALLED

Native · MCP App
READ 3 · PUBLISH 1*
* approval required
LOCALFLEETCLOUD
egress: allowlist only

POSTGRESAVAILABLE

Native adapter
READ 2 · WRITE 1*
* denied by default
LOCALFLEET
destructive SQL refuses by name

MCP IMPORTBUILT-IN

Any MCP server
Tools become requested typed capabilities.
UI renders sandboxed.
Super supplies the authority.

Installed is a fact about disk. Authorized is a fact about the world. Between them sit six inspectable states — available → installed → requested → authorized → exercised → committed → receipted — and the receipt feeds the same evidence ledger as everything else. No second audit system.

When an agent lacks authority, the refusal names itself — authority-missing · mail.send — with the scope, the reason, and the grant it does hold. Never a vague "permission denied."

github 1.4.2 → 1.5.0
code / skill changes  14 files
+ github.issue.writeNEW AUTHORITY
+ api.linear.appNEW EGRESS
+ CLOUDPLACEMENT WIDENED
STATUS: UPDATE HELD — authority surface widened
Updates can change code. They cannot silently change authority.
Identity ≠ engine.  Installation ≠ authority.  Authority ≠ approval.  Attempt ≠ effect.  Effect ≠ proof.
Architecture

Built like it means it.

The runtime is authoritative; every surface is a projection that can crash and resynchronize — it was never the truth. The CLI (amp) and the desktop call the same daemon (ampd); logic exists once.

SHELL
Tauri 2 · TypeScript
the projection — a lightweight desktop over the runtime
BRAIN
Elixir / OTP
the society — supervisors, lanes, agents, ledger, routines, presence
BODY
Rust
the machine — PTY, git, filesystem, hashing, sandbox, OS authority
WORLD
WRL
the description — topology, intent, capability as inspectable records
LAW
TRVM
the enforcement — gates, films, receipts, byte-identical certs
PERSISTENCE
ComputeDriven
the continuity — identity, sync, restore, fleet, hosted capacity
Elixir runs the society. Rust runs the machine. WRL describes the world. TRVM enforces its laws.
ComputeDriven makes that world persistent and distributed.
Plans

One platform. Useful before you pay.

The local client will be genuinely useful with the cloud off. ComputeDriven sells coordination, persistence, visibility, and elastic overflow — over compute you already own.

PLANNED SHAPE · NOTHING IS FOR SALE YET — THIS IS THE PHASE 5 DESIGN

LOCAL

FREE · FOREVER
  • Super (CD) desktop
  • Local agents & WRL world
  • Local receipts & ledger
  • BYO Claude / Codex / engines

DRIVER

ACCOUNT
  • Identity & encrypted sync
  • Restore anywhere
  • Modest cloud storage
  • Modest hosted execution

FLEET

MULTI-MACHINE
  • Attach machines you own
  • Distributed execution
  • Remote runners
  • Richer scheduling

FACTORY

TEAMS
  • Orgs & governance
  • Larger fleets & automation
  • Hosted compute
  • Policy controls
The path

Commercially useful at every phase.

0
Freeze the reference — the Python/HTML draft becomes the behavioral oracle: fixtures, transcripts, conformance.
1
Desktop shell — Tauri wrap, stable behavior, IPC boundary. The cockpit renders one ordered frame stream and submits intents; a successful intent moves nothing on screen until a frame says so. No installer yet.NOW
2
Elixir runtime — workspace, goal, lane, worker, evidence, obligation, routine, presence supervisors.NOW
3
Rust native core — git, worktree, PTY, filesystem, hashing, sandbox authority.
4
Local ledger — durable, replayable; actions bound to receipts and explicit authority.
5
ComputeDriven account + sync — identity, device membership, encrypted world sync, restore.
6
Remote / fleet execution — eligible-node placement across local, owned, and hosted machines.
7
WRL authority — topology, capability, and placement live in WRL, not framework config.
8
TRVM integration — execution semantics under TRVM, differential-tested against OTP.
9
T&R — the same world rendered natively in the OS. No second data model.
One system, three ways in

Super is one of three.

This is a product page, and the product has a studio behind it. ComputeDriven publishes one destination and two ways in: Super (CD) is the way in that leaves your machine as it is, T&R is the way in that replaces what you boot, and [World] Cloud is where a world goes when it is not on your desk. They are not tiers, and neither entry is a trial of the other.

computedriven.com the studio, and the one page that holds the three together

Direct the work.
Own the world.

Super (CD) is the local-first compute surface for a persistent ComputeDriven world: Elixir supervises its living actors, Rust owns machine authority, WRL describes its topology, and TRVM progressively makes its execution verifiable.