For teams & projects
Engine-ready · team sync nextShared team memory without surrendering custody. Everyone keeps a personal agent that learns them; the agents federate into one project Brain no vendor holds. And working together is free — collaboration is never the paywall.
The inversion
The industry answer: centralize your org’s knowledge on the vendor’s servers and rent access back, per seat. Ours keeps both moats — the agent that learns you, and the memory that compounds for the group — with no toll on collaboration.
The cloud playbook
The Permagent model
How federated memory works
A project gets one compounding Brain — decisions, docs, people, state. Every member's agent contributes and recalls. No central server holds the well; sync is designed end-to-end encrypted and relay-blind.
Federation connects personal agents; it doesn't replace them. Shared context makes each agent smarter; each agent makes the shared Brain richer.
Concept — member agents converging into one project Brain
The engine records which brain asserted each fact, under an Ed25519 identity — trust, dispute, and supersede per fact. The app stamps authorship with team sync.
Each member decides what their agent shares up. Who-can-see-what is designed to be enforced locally and cryptographically — not by a cloud admin who can read everything.
The scope model — Spectral’s visibility levels
Yours alone. Never leaves your machine, never enters the shared well.
→Shared with the people whose agents federate into your team's Brain.
→The widest internal circle: company-level decisions and durable institutional memory.
→Explicitly published — the only level meant to travel beyond the org.
These four scopes exist in the engine; today the app writes everything Private, and in-app scope controls arrive with team sync. Project-level Brains — one Brain per project — are a Permagent scope mapped onto these levels. Until federation ships, nothing leaves your machine.
Permanence, for groups
People leave projects. Companies churn tools. On a cloud platform, either event can strand years of context behind someone else’s login. A Permagent project Brain is owned by the project — stored in open formats, exportable, and independent of us.
The same promise we make individuals — keeps working if we disappear — extended to groups. Institutional memory that compounds as long as the project exists. Longer, if you want.
What the project keeps, forever
Open source engine, open data formats. The exit door is part of the product.
Sovereign offboarding
Primitives shipped · flow nextYou use Permagent at a company, then leave. Your personal agent and Brain already live on your machine and were always yours — you don’t export them, you just keep them. Smarter for the experience.
The company’s proprietary context was scoped and federated in, never stored in a vendor cloud. It stays with the project. No hostage data, either direction.
Memory carries a visibility scope — Private, Team, Org, Public — in the engine; the app writes Private today. Your private scope was never in the shared well; company scopes are revoked when you go.
The engine records which agent contributed each shared fact. The company keeps exactly what you contributed to the shared Brain — like commits staying in a repo you've left.
Leaving is cutting the federation link: key revocation and rotation end your access to shared state, and a local forget hard-deletes company memories from your machine — the delete primitive is verified in the engine; the in-app control lands with the departure flow. No extraction battle.
Leaving a cloud agent platform
Leaving a Permagent team
Straight talk: the engine ships the primitives — visibility scopes, a verified per-key/per-wing hard-delete, per-fact provenance — but the app doesn’t expose scope or delete controls yet. The sync design is end-to-end encrypted and relay-blind; the encryption layer itself is designed, not built. Scrubbing graph-derived facts is planned. The flow itself — one-click departure, key rotation, the departure-time review of the fuzzy middle — is the next build. And no platform stops someone who already copied data; what this removes is ongoing access, cleanly and on the record.
Where this stands
Same rule as everywhere else on this site: no vaporware sold as features. Every capability on this page carries one of three labels:
In the engine today
Engine-ready · v1.31Spectral memory engine — deterministic recall, on-device knowledge graph
Four visibility scopes — Private / Team / Org / Public (the app writes Private today)
Verified hard-delete primitive — per-key and per-wing
Ed25519 identity per brain (dormant — not wired into a live path yet)
Per-fact provenance
Replication engine for federation
Open, exportable data formats
The next build
Not live todayIn-app scope controls + author stamping on writes (today: Private, unattributed)
Multi-member team sync — the federation protocol (sync, conflict resolution, merge)
Shared project and team Brains
Scoped contribution controls across members
Cryptographically enforced scope governance
E2E-encrypted, relay-blind sync transport — designed; the encryption layer is unbuilt
Offboarding flow — key rotation, scope revocation, departure-time review
Graph-derived fact deletion — planned
Why “built for this” is a safe claim: identity, provenance, visibility scopes, and the replication engine ship in the engine underneath your agent. What remains — scope controls, author stamping, the encryption layer, and member sync — is the next build, not a research problem.
Team sync will be free when it lands — the engine your agents write to today is the one it will run on. Join the waitlist to hear first.