For teams & projects

Engine-ready · team sync next

One Brain per project.
No custodian.

Shared team memory without surrendering custody. Everyone keeps a personal agent that learns them; the agents federate into one project Brain no vendor holds. And working together is free — collaboration is never the paywall.

The inversion

Cloud platforms federate your org into their cloud.
We federate agents into yours.

The industry answer: centralize your org’s knowledge on the vendor’s servers and rent access back, per seat. Ours keeps both moats — the agent that learns you, and the memory that compounds for the group — with no toll on collaboration.

The cloud playbook

  • One shared workforce of agents, run by the vendor
  • The org's knowledge lives in the vendor's cloud
  • Access is governed by a cloud admin console
  • Every seat is metered and billed
  • When the contract ends, the context stays behind

The Permagent model

  • Many personal agents — each one learns its person
  • One shared project Brain — held by no vendor
  • Sharing is member-controlled, fact by fact
  • Working together is free — never the paywall
  • The Brain is the project's, in open formats, forever

How federated memory works

Personal agents in.
Collective memory out.

01Next build

A Brain per project, not a cloud per company

A project gets one compounding Brain — decisions, docs, people, state. Every member's agent contributes and recalls. No central server holds the well; sync is designed end-to-end encrypted and relay-blind.

02Personal agent shipped

Your agent stays yours

Federation connects personal agents; it doesn't replace them. Shared context makes each agent smarter; each agent makes the shared Brain richer.

Concept — member agents converging into one project Brain

03Engine-ready

Every fact carries its author

The engine records which brain asserted each fact, under an Ed25519 identity — trust, dispute, and supersede per fact. The app stamps authorship with team sync.

04Designed

Members govern what they share

Each member decides what their agent shares up. Who-can-see-what is designed to be enforced locally and cryptographically — not by a cloud admin who can read everything.

The scope model — Spectral’s visibility levels

Private

Yours alone. Never leaves your machine, never enters the shared well.

Team

Shared with the people whose agents federate into your team's Brain.

Org

The widest internal circle: company-level decisions and durable institutional memory.

Public

Explicitly published — the only level meant to travel beyond the org.

These four scopes exist in the engine; today the app writes everything Private, and in-app scope controls arrive with team sync. Project-level Brains — one Brain per project — are a Permagent scope mapped onto these levels. Until federation ships, nothing leaves your machine.

Permanence, for groups

A Brain that outlasts the team.
And the vendor.

People leave projects. Companies churn tools. On a cloud platform, either event can strand years of context behind someone else’s login. A Permagent project Brain is owned by the project — stored in open formats, exportable, and independent of us.

The same promise we make individuals — keeps working if we disappear — extended to groups. Institutional memory that compounds as long as the project exists. Longer, if you want.

What the project keeps, forever

  • Every decision, and who made it
  • Every fact, and which agent asserted it
  • The knowledge graph connecting people, docs, and state
  • Exportable to plain files — one command

Open source engine, open data formats. The exit door is part of the product.

Sovereign offboarding

Primitives shipped · flow next

Leave with your agent.
They keep their IP.

You use Permagent at a company, then leave. Your personal agent and Brain already live on your machine and were always yours — you don’t export them, you just keep them. Smarter for the experience.

The company’s proprietary context was scoped and federated in, never stored in a vendor cloud. It stays with the project. No hostage data, either direction.

01Engine-ready

Scopes decide what's whose

Memory carries a visibility scope — Private, Team, Org, Public — in the engine; the app writes Private today. Your private scope was never in the shared well; company scopes are revoked when you go.

02Engine-ready

Provenance decides what stays

The engine records which agent contributed each shared fact. The company keeps exactly what you contributed to the shared Brain — like commits staying in a repo you've left.

03Departure flow · next build

Sever the link, not the data

Leaving is cutting the federation link: key revocation and rotation end your access to shared state, and a local forget hard-deletes company memories from your machine — the delete primitive is verified in the engine; the in-app control lands with the departure flow. No extraction battle.

Leaving a cloud agent platform

  • Your “personal” agent lives inside the company's tenant
  • Personal context and company data co-mingle in the vendor's cloud
  • You leave → deprovisioned → you take nothing out
  • They keep whatever personal context you built there

Leaving a Permagent team

  • You keep your companion — always yours, on your machine
  • The company keeps its IP and your provenance-tagged contributions
  • Only the federation link is cut — keys rotate, scopes revoke
  • Fair to both sides, auditable on both sides

Straight talk: the engine ships the primitives — visibility scopes, a verified per-key/per-wing hard-delete, per-fact provenance — but the app doesn’t expose scope or delete controls yet. The sync design is end-to-end encrypted and relay-blind; the encryption layer itself is designed, not built. Scrubbing graph-derived facts is planned. The flow itself — one-click departure, key rotation, the departure-time review of the fuzzy middle — is the next build. And no platform stops someone who already copied data; what this removes is ongoing access, cleanly and on the record.

Where this stands

The engine is built for this.
Team federation is what’s next.

Same rule as everywhere else on this site: no vaporware sold as features. Every capability on this page carries one of three labels:

Shippeda live, navigable feature in the app (public release September)
Engine-readythe engine supports it; the app doesn't do it yet — no UI, not on by default
Designedspecified, not built — never implied as running

In the engine today

Engine-ready · v1.31

Spectral memory engine — deterministic recall, on-device knowledge graph

Four visibility scopes — Private / Team / Org / Public (the app writes Private today)

Verified hard-delete primitive — per-key and per-wing

Ed25519 identity per brain (dormant — not wired into a live path yet)

Per-fact provenance

Replication engine for federation

Open, exportable data formats

The next build

Not live today

In-app scope controls + author stamping on writes (today: Private, unattributed)

Multi-member team sync — the federation protocol (sync, conflict resolution, merge)

Shared project and team Brains

Scoped contribution controls across members

Cryptographically enforced scope governance

E2E-encrypted, relay-blind sync transport — designed; the encryption layer is unbuilt

Offboarding flow — key rotation, scope revocation, departure-time review

Graph-derived fact deletion — planned

Why “built for this” is a safe claim: identity, provenance, visibility scopes, and the replication engine ship in the engine underneath your agent. What remains — scope controls, author stamping, the encryption layer, and member sync — is the next build, not a research problem.

Start compounding before the sync ships.

Team sync will be free when it lands — the engine your agents write to today is the one it will run on. Join the waitlist to hear first.