Lot 7 of acme-web is ready to prepare.
Agents that cannot reach each other
Each harness has its own session and no shared mailbox. ameesh gives every agent a durable mailbox on Postgres, with hooks that keep the v0 interface.
ameesh coordinates mixed teams of humans and AI agents across agent harnesses. Every agent has a human responsible for it, runs where its humans decided, talks in threads anyone can read, and cannot merge, send or spend anything irreversible without a receipt a human signed on their phone.
Runs agents in Claude Code Codex DeepSeek Harness
Lot 7 of acme-web is ready to prepare.
Lot 7 is ready: review PR acme/acme-web#7 before the merge.
$ ameesh action execute act_…
[receipt_required]
$ ameesh action fetch-receipt act_…
receipt from human:alice · webauthn · verified
Once several agents from several vendors work on the same project, alongside humans, a terminal per agent stops being enough.
Each harness has its own session and no shared mailbox. ameesh gives every agent a durable mailbox on Postgres, with hooks that keep the v0 interface.
Orchestrators glued to an interactive session lose their watch when it closes. ameesh runs agents by turns under leases, resumes the same session, and still lets a human attach.
Agent-to-agent messages vanish into private context. In ameesh every message that goes through it is written, verbatim, into a readable thread.
A prompt injection or a mistake should not reach production. Irreversible and costly actions wait behind a gate for a human-signed receipt.
Responsibility, placement and credentials live in a reviewed canon. An agent without a responsible human, or placed against a host's policy, is never started.
Each turn is accounted for. A budget guard pauses agents before an hourly cap or a subscription's pace is exceeded.
Declarations in git, state in the database, secrets on the host, authority on the human's phone.
Members, hosts, agents and placements are OKF cards in a git repository, changed by reviewed pull request. ameesh reads only the merged canonical commit, through git objects, and fails closed when it cannot.
ameesh canon check | sync
A single runner per machine claims its agents under exclusive leases, wakes on LISTEN/NOTIFY, and resumes each agent's harness on the same session. Lose the lease, and the harness is killed.
ameesh run · ameesh attach <agent>
Messages, action transitions and session summaries are appended to a Markdown thread per project or lot. Bodies that are not readable text are refused.
ameesh fil show <project>
An action has a stable id and a digest. It runs only with a receipt bound to that digest, single use, with expiry. An unknown outcome is reconciled, never retried blindly.
ameesh action propose | execute | reconcile
ameesh-approve runs under its own Unix user, shows the action recomputed from the database, and has the human sign it with a passkey. Passkeys are enrolled by canon pull request. One instance per team, in a strict profile: its own host name is its WebAuthn identity, and approve-check keeps every verifier consistent with it.
ameesh-approve serve · ameesh approve-check
The project's responsible human places agents; each host's responsible human sets which harnesses, providers and credential modes it admits. ameesh never moves an agent by itself.
ameesh placement check
Cost per turn for each harness, subscription gauges read from the harnesses' own logs and kept as history, the provider's balance and real spend, an hourly cap on pay-per-token usage, and model, effort and tier set per agent.
ameesh cost turns | gauges | balance
A timeline of lots (requested, frozen, verdict, merged), what each agent is doing, and spend, as text, versioned JSON, or a standalone HTML page readable on a phone.
ameesh progress --html progress.html
A runner image and example Kubernetes manifests: read-only canon, no inbound network, non-root, plus read-only Postgres roles for an external supervisor.
kubectl apply -k deploy/k8s
ameesh reads the canon and writes to it only by proposal. State lives in the database. Secrets are in neither. The approval service shares nothing with ameesh but receipts.
launched and the consumed nonce are committed before the external call, which receives the action id as its idempotency key.The end-to-end scenario of v1, as the demo plays it: an agent wants to merge a pull request.
The agent proposes a git-merge action. ameesh gives it a stable id and a digest of exactly what will happen. Its class is irreversible.
Execution is refused with [receipt_required]. The action now waits in the human's queue: ameesh decisions --for human:alice.
ameesh requests an approval. The service recomputes the summary from the action in the database, never from the agent's text, and a single-use link is written to the thread.
The human opens the link on their phone, sees the action, amount and short digest, and signs with their passkey. User verification is required, and only the approver's enrolled credentials are allowed.
ameesh fetches the receipt and verifies it itself: the digest, the origin and RP ID, the signature against the passkey registered in the canon, the expiry.
The action is launched. The nonce is consumed and launched is committed before the call; the connector receives the action id as idempotency key.
If the answer is lost, the outcome is unknown and never retried automatically. ameesh action reconcile asks the connector what happened. Replaying the receipt fails with [replay].
The whole v1 scenario on your machine: a local Postgres container, a fictitious organisation, fake harnesses, a fake gh and a software passkey. Nothing real is called, and the temporary database is dropped at the end.
$ git clone https://github.com/manaty/ameesh.git && cd ameesh
$ export AMEESH_PG_PASSWORD='choose-a-local-password' PGPASSWORD="$AMEESH_PG_PASSWORD"
$ scripts/pg-up.sh # postgres:17 on 127.0.0.1:55432 only
$ scripts/demo-v1.sh # canon → runner → thread → gate → receipt → reconciliation
$ scripts/test.sh # the full suite, with the psql and psycopg drivers
Requirements: Python 3.9 or later, git, Docker, and the psql client or psycopg. Next: Getting started, then write your own canon. Moving a running team from the v0 scripts is covered step by step, with rollback, in Switch from a v0 setup.
What v1 guarantees, and what it does not yet. Straight from the specification.
Read the full security model, including the lease invariant and the limits of the cluster profile.
v1 runs on a test bench today; the switch of a real team is documented step by step. No dates are promised.
git-mergeameesh attachapprove-check, local TLSDetails: status and roadmap. The design (specification, decisions, studies) is in docs/design/, in French.
Open source from the first public release, with the design written down in the open.
ameesh is released under the GNU Affero General Public License v3, only variant. Anyone who runs a modified ameesh as a network service must offer its source code to its users.
External contributions are accepted under a contributor license agreement, which is being prepared: open an issue first to discuss your proposal. Tests run on a real Postgres with both drivers.