Agents don't run in a chat window here — they occupy a world. Direct them across your machines and the cloud, where each one holds a position with an inspectable state, explicitly scoped authority, and a record of what it did, what it proved, and what it was permitted to change.
A super-surface above interchangeable engines and below you. Claude Code, Codex, whatever comes next — engines run the turns; Super owns the identity, the placement, the budget, and the receipts.
Here's the same machinery on a completely mundane goal — one page, four placements, three claims, one obligation standing between the work and production.
Nothing exotic happened here. An agent researched in the cloud because the data was public; another implemented locally because your source stays home; a third proved the page on a fleet box — and the deploy is held, not "probably fine," until a human closes the obligation.
The system never asked you to learn its cosmology. It just refused to confuse done with proved.
And when a goal needs it to go all the way down — it goes all the way down. ↓
This is the same product dogfooded on our formal-verification work: claims carry receipts, obligations gate merges, and every claim wears its rung on the ladder — never a higher one. Every figure below is read from proof/latest.json, which the verifier generated. Click one; the receipt opens.
The desktop, the cloud, and the OS are views of the same running world — a lane shown in Super and a lane shown in T&R aren't two synced records. They're one object, seen twice.
The desktop cockpit. Goals, lanes, agents, diffs, evidence, fleet placement, runtime state — your hands on the world.
The control plane. Identity, node membership, encrypted selective sync, presence, restore, hosted capacity, billing.
The native OS environment, where the same world becomes spatial — machines, roads, tracks, agents, dashboards.
Attach the machines you already own — desktops, mini PCs, GPU boxes, cloud VMs — and extend with ComputeDriven capacity when you want burst. Moving work is placement, not migration: same supervision tree, different floor.
Eligibility is computed from capability, hardware, cost, and data policy — and the derivation is citable. A future TRVM layer can verify why a site was allowed.
An agent is not the model animating it. It is an active locus — an established state, the explicit scoped grants whose policy preconditions that state satisfies, and the evidence connecting one state to the next. Identity, memory, worktree, budget, authority and obligations live under a supervisor; the engine is one replaceable child, a reasoning motor the locus thinks with rather than the thing that is thinking. That is what makes swap Claude Code for Codex mid-task a coherent question instead of a category error: the motor changed, and the locus is what would have to continue.
Install a skill, connector, UI, or MCP server once. Then grant only the typed capabilities each agent or workspace may exercise. Secrets stay outside the engine, placement stays governed, and meaningful effects leave receipts.
A pack can bundle skills, MCP, UI, hooks, adapters, and tests. Installation gives it zero authority.
github.repo.read is not github.pr.merge. Scope abilities by agent, workspace, resource, budget, node, and duration.
Every committed effect names the pack/version, capability, authority snapshot, placement, approval, and result.
Installed is a fact about disk. Authorized is a fact about the world. Between them sit six inspectable states — available → installed → requested → authorized → exercised → committed → receipted — and the receipt feeds the same evidence ledger as everything else. No second audit system.
When an agent lacks authority, the refusal names itself — authority-missing · mail.send — with the scope, the reason, and the grant it does hold. Never a vague "permission denied."
The runtime is authoritative; every surface is a projection that can crash and resynchronize — it was never the truth. The CLI (amp) and the desktop call the same daemon (ampd); logic exists once.
The local client will be genuinely useful with the cloud off. ComputeDriven sells coordination, persistence, visibility, and elastic overflow — over compute you already own.
PLANNED SHAPE · NOTHING IS FOR SALE YET — THIS IS THE PHASE 5 DESIGNThis is a product page, and the product has a studio behind it. ComputeDriven publishes one destination and two ways in: Super (CD) is the way in that leaves your machine as it is, T&R is the way in that replaces what you boot, and [World] Cloud is where a world goes when it is not on your desk. They are not tiers, and neither entry is a trial of the other.
computedriven.com the studio, and the one page that holds the three together
Super (CD) is the local-first compute surface for a persistent ComputeDriven world: Elixir supervises its living actors, Rust owns machine authority, WRL describes its topology, and TRVM progressively makes its execution verifiable.