For teams & projects
One Brain per project.
No custodian.
Shared team memory without surrendering custody. Everyone keeps a personal agent that learns them; the agents federate into one project Brain no vendor holds. And working together is free — collaboration is never the paywall.
The inversion
Cloud platforms federate your org into their cloud.
We federate agents into yours.
The industry answer: centralize your org’s knowledge on the vendor’s servers and rent access back, per seat. Ours keeps both moats — the agent that learns you, and the memory that compounds for the group — with no toll on collaboration.
The cloud playbook
- One shared workforce of agents, run by the vendor
- The org's knowledge lives in the vendor's cloud
- Access is governed by a cloud admin console
- Every seat is metered and billed
- When the contract ends, the context stays behind
The Permagent model
- Many personal agents — each one learns its person
- One shared project Brain — held by no vendor
- Sharing is member-controlled, fact by fact
- Working together is free — never the paywall
- The Brain is the project's, in open formats, forever
How federated memory works
Personal agents in.
Collective memory out.

A Brain per project, not a cloud per company
A project gets one compounding Brain — decisions, docs, people, state. Every member's agent contributes and recalls. No central server holds the well; sync is designed end-to-end encrypted and relay-blind.
Your agent stays yours
Federation connects personal agents; it doesn't replace them. Shared context makes each agent smarter; each agent makes the shared Brain richer.
Every fact carries its author
The engine records which brain asserted each fact, under an Ed25519 identity — trust, dispute, and supersede per fact. The app stamps authorship with team sync.
Members govern what they share
Each member decides what their agent shares up. Who-can-see-what is designed to be enforced locally and cryptographically — not by a cloud admin who can read everything.
The scope model — Spectral’s visibility levels
Private
Yours alone. Never leaves your machine, never enters the shared well.
Team
Shared with the people whose agents federate into your team's Brain.
Org
The widest internal circle: company-level decisions and durable institutional memory.
Public
Explicitly published — the only level meant to travel beyond the org.
These four scopes exist in the engine; today the app writes everything Private, and in-app scope controls arrive with team sync. Project-level Brains — one Brain per project — are a Permagent scope mapped onto these levels. Until federation ships, nothing leaves your machine.
Permanence, for groups
A Brain that outlasts the team.
And the vendor.
People leave projects. Companies churn tools. On a cloud platform, either event can strand years of context behind someone else’s login. A Permagent project Brain is owned by the project — stored in open formats, exportable, and independent of us.
The same promise we make individuals — keeps working if we disappear — extended to groups. Institutional memory that compounds as long as the project exists. Longer, if you want.
What the project keeps, forever
- Every decision, and who made it
- Every fact, and which agent asserted it
- The knowledge graph connecting people, docs, and state
- Exportable to plain files — one command
Open source engine, open data formats. The exit door is part of the product.
Sovereign offboarding
Leave with your agent.
They keep their IP.
You use Permagent at a company, then leave. Your personal agent and Brain already live on your machine and were always yours — you don’t export them, you just keep them. Smarter for the experience.
The company’s proprietary context was scoped and federated in, never stored in a vendor cloud. It stays with the project. No hostage data, either direction.
Scopes decide what's whose
Memory carries a visibility scope — Private, Team, Org, Public — in the engine; the app writes Private today. Your private scope was never in the shared well; company scopes are revoked when you go.
Provenance decides what stays
The engine records which agent contributed each shared fact. The company keeps exactly what you contributed to the shared Brain — like commits staying in a repo you've left.
Sever the link, not the data
Leaving is cutting the federation link: key revocation and rotation end your access to shared state, and a local forget hard-deletes company memories from your machine — the delete primitive is verified in the engine; the in-app control lands with the departure flow. No extraction battle.
Leaving a cloud agent platform
- Your “personal” agent lives inside the company's tenant
- Personal context and company data co-mingle in the vendor's cloud
- You leave → deprovisioned → you take nothing out
- They keep whatever personal context you built there
Leaving a Permagent team
- You keep your companion — always yours, on your machine
- The company keeps its IP and your provenance-tagged contributions
- Only the federation link is cut — keys rotate, scopes revoke
- Fair to both sides, auditable on both sides
Straight talk: the engine ships the primitives — visibility scopes, a verified per-key/per-wing hard-delete, per-fact provenance — but the app doesn’t expose scope or delete controls yet. The sync design is end-to-end encrypted and relay-blind; the encryption layer itself is designed, not built. Scrubbing graph-derived facts is planned. The flow itself — one-click departure, key rotation, the departure-time review of the fuzzy middle — is the next build. And no platform stops someone who already copied data; what this removes is ongoing access, cleanly and on the record.
Where this stands
The engine is built for this.
Team federation is what’s next.
Same rule as everywhere else on this site: no vaporware sold as features. Every capability on this page carries one of three labels:
In the engine today
- Spectral memory engine — deterministic recall, on-device knowledge graph
- Four visibility scopes — Private / Team / Org / Public (the app writes Private today)
- Verified hard-delete primitive — per-key and per-wing
- Ed25519 identity per brain (dormant — not wired into a live path yet)
- Per-fact provenance
- Replication engine for federation
- Open, exportable data formats
The next build
- In-app scope controls + author stamping on writes (today: Private, unattributed)
- Multi-member team sync — the federation protocol (sync, conflict resolution, merge)
- Shared project and team Brains
- Scoped contribution controls across members
- Cryptographically enforced scope governance
- E2E-encrypted, relay-blind sync transport — designed; the encryption layer is unbuilt
- Offboarding flow — key rotation, scope revocation, departure-time review
- Graph-derived fact deletion — planned
Why “built for this” is a safe claim: identity, provenance, visibility scopes, and the replication engine ship in the engine underneath your agent. What remains — scope controls, author stamping, the encryption layer, and member sync — is the next build, not a research problem.
Start compounding before the sync ships.
Team sync will be free when it lands — the engine your agents write to today is the one it will run on. Join the waitlist to hear first.