The owner talks to one session. That session talks to the rest: it sends work to named peer sessions by message, opens specs and launches rounds in a factory, checks what comes back against disk and git rather than against a report, and answers with what it found. Everything below is dated, recounted on the day this page shipped, and includes the two times the arrangement was wrong.
Five edges, all of them real. The command post never reaches into a peer's files and never writes to a repository itself. It asks, it reads, it decides what to do next.
Where the command post runs. 16 cores, 62 GB of memory, an RTX 3060 with 12 GB. 9 local models are pulled, one of them a vision model that reads private financial documents, which is why those images never leave the machine. Speech recognition and a cloned speaking voice run here too, as services rather than as scripts someone starts. Reachable only over a private Tailscale network.
Rented boxes that carry factory rounds and coding sessions. They do the work that does not need the local models, and they are where a launched round actually runs.
Both from one day, 2 September 2026, timestamps in UTC, copied from the transcript. Nothing on this page calls anything: press play and the recording steps through.
SendMessage to a session
on the runner: "reply with hostname and whoami"ubuntu-4gb-sf-runner-1 volospec_create for the
spec that describes this page401 unknown session token.
Nothing was written.gh pr create:
factory-specs pull request 492Counted on 2 September 2026, each with its recount named in the page source.
Each keeps its own project and its own memory of it.
The old ones are the point: nothing is re-explained to them.
Reading is free. Writing opens a pull request and never commits.
Written by the command post, reviewed by this project's session.
Two of them, both from the past week, both caught by a second session rather than by the one that erred. This section is the argument, not a disclaimer.
The command post specified a feature that had been running in production for five days. It read a project's status file, found a list of open work, and believed it. The list sat inside a dated entry, so it was true on the day it was written and quietly false afterwards. The project's own session, which had shipped the feature, refused the spec and pointed at the deployment. The spec was rewritten as a correction, and the status file lost the trap.
The command post cited the location of a document by inferring it from how similar files are named. The file was not there. A peer session read the disk and said so.
The common arrangement right now is one planning chat plus several throwaway agent windows, with a person carrying text between them. It is attractive because it needs nothing: open a window, paste the plan, read the answer. What it does not have is memory in the workers, so every window is briefed from scratch. It has no written trail into a factory, so nothing that runs leaves a reviewable artefact. And it has no second session with standing to contradict the first, which is exactly what caught both mistakes above. The arrangement on this page is the opposite trade: sessions that keep their context, a factory that only accepts written specs, and a person who decides instead of copying text between windows.
Only what the specs repository already holds, with the status it holds today.
-32007 Authentication required although the same box logs in fine
from a terminal, so phase one is now that auth problem.
Nothing here is live on this page. The factory holds write access to real repositories and the sessions hold private working context, so neither is exposed to visitors. What you can run lives one page over, on the cockpit. Autonomy is earned, even here.