Agents · a mode of Meosu
A team that works on your Mac
and asks first.
Durable AI teammates live in direct and group conversations. They show their work in the transcript, hand off to each other with one clear owner, and stop to ask you before anything consequential happens. Your Mac is the computer they use. Your own model key is the only thing they call out to.
The workspace
A conversation, not a dashboard.
Everything an agent does is legible from the conversation it happened in. There is no separate operations console where the real state lives. Mention several agents and the work routes to their lowest common accountable manager; exactly one still owns the answer you get back.
-
Who is working
Every agent has a stable mascot and a plain job title. Working, waiting for approval, attention, unread and idle are five states you can read at a glance.
-
What is happening
One transcript holds messages, tool calls, verification, created files, questions, failures, handoffs and approvals. Nothing important happens in a panel you have to go find.
-
What it is touching
A surface beside the chat shows the team with live handoffs, or This Mac — the embedded browser and the native apps an agent has been allowed to operate.
Before it acts
A model may propose.
Only code decides.
A model can suggest a typed plan. Deterministic code owns hierarchy, authorization, execution, persistence, recovery and verification — so the question is never "did the model behave?" but "did the runtime let it?"
- 1
Observe
Read the current state and record the version it was read at.
- 2
Prepare
Bind one exact action: target, arguments, effect, expiry, and the postconditions that will prove it worked.
- 3
Authorize
Evaluate deterministic policy, then ask you inline when the action is consequential. The approval is exact and expires in five minutes.
- 4
Execute once
Spend a single-use capability token, journal the start, act, journal the receipt.
- 5
Verify
Check the postconditions and report done, failed, or — honestly — outcome unknown.
-
Crashes do not double-execute
A start journalled with no receipt is reconciled or marked unknown; it is never blindly repeated.
-
An append-only record
Run events are hash-chained in a local SQLite journal that can be verified after the fact.
-
Your key stays in the Keychain
The provider secret never reaches the database, prompts, diagnostic bundles or the generic HTTP tool.
-
Bounded by construction
Team depth, fan-out, response bytes, file bytes and storage all have ceilings. Retries stay off unless an operation is safe to repeat.
Bring your own key
Your provider. Your bill.
Point it at any OpenAI-compatible chat-completions endpoint: URL, model identifier, authorization header, timeout. The key goes into the macOS Keychain and nowhere else. Prefer to run it dry? A deterministic local planner works with no key at all for a constrained command grammar.
Questions
Asked before switching modes.
Is Agents a separate app?
No. Agents is a mode of Meosu. Switch between Voice and Agents in the top bar; both share one install, one settings window and one design.
Which model does it use?
Whichever one you point it at. You supply an OpenAI-compatible chat-completions endpoint, a model identifier and a key. The key is stored only in the macOS Keychain. A deterministic local planner also runs with no key at all, for a constrained command grammar.
Can an agent change files or drive apps on its own?
Not without you. A consequential action is bound to an exact target, arguments, state version and expiry, then waits for your inline approval and a single-use capability token. Denying it is a normal outcome, not an error.
What does it cost?
Your provider bills you for the model calls. Meosu does not meter Agents today; Meosu plans cover dictation and meeting notes.