Give the mission.
Keep the command.
Cerebro is a native operating surface for Claude and Codex agents. Choose the top-level boundary, let the Conductor run the operation, and inspect or redirect the work at any time.
Watch every agent work, live.
Mission is one operating surface for project territories, agent stations and nodes, terminal cards, workflows, attention signals, and the Conductor at the core.
- See motion, not a roster. Running, blocked, resolving, and completed work has a place in the operation.
- Open the real terminal. Follow the response that belongs to the visible run.
- Keep the fleet in frame. Project territories, agent stations, terminal cards, and handoffs remain understandable together.
- Pick the skin. The Organism skin grows territories into living membrane creatures; Classic keeps quiet cartography. Swap from the canvas HUD.

Your agents, organized like a team.
Agents live in projects, and projects can hold sub-projects. The org tree shows who belongs where, which provider each one runs on, and what it was given to do.

Structure that mirrors the work
A large effort can hold its own sub-projects, each with its own agents.
A provider per agent
Every card shows whether that agent runs on Claude or Codex, and you can change it at any time.
Add where it belongs
New agents and sub-projects start inside the project you are looking at.
One AI runs the whole team.
Tell the Conductor what should be true when the mission is done. It coordinates projects, agents, assignments, workflows, and handoffs while maintaining its own durable context.
- Delegate from one seat. Create the operation and let named agents own its parts.
- Keep momentum. The next useful phase can start when its dependency resolves.
- Intervene at the mission level. Pause, stop, redirect, or clarify without supervising each turn.

You set the limits, once.
After you select the autonomous top-level boundary, agents and the Conductor receive full operational control inside the chosen workspace and connected services. Authority does not extend beyond what you deliberately selected.
One top-level choice
Choose the operating posture instead of tuning a matrix for every action kind.
Mission-level command
Pause, stop, redirect, or change the small number of top-level settings.
True exceptions
A question appears for missing information, missing authority, or a protected high-impact boundary.
Multi-step work that runs itself.
A goal contract defines the outcome. Planning, review, build, verification, and summary phases then progress autonomously on a readable layered graph, with visible state and mission-level pause or stop controls.
A workflow cannot push or open a pull request on the strength of its own confidence. The outward step runs only if a dominating system verification actually ran and exited clean, with HEAD and the working tree unchanged at the moment of execution and the GitHub command bound to the exact repository and commit. That is a structural gate, not a prompt asking a model to be careful.

See exactly what each agent did.
A shared execution layer records key actions and outcomes across Conductor and agent work. Audit and run history tell you who acted, what route ran, and how it resolved.
- Named actor. Conductor or agent identity follows the recorded action.
- Concrete outcome. Success, failure, or stopped work remains visible.
- One operational truth. The app does not make you reconstruct the mission from terminal fragments.

They remember your project.
Each agent can carry forward decisions, a next step, open questions, files, and recent activity. A fresh provider session does not have to rediscover the mission from scratch.
// carried between sessions, not retyped objective: "ship the launch checklist" decisions: "waitlist first", "defer pricing" next_step: "verify the signed build" open_question: "which region first?" files: 4 touched this run
They ask only when it matters.
When useful work cannot continue without an answer, the agent asks a specific question and waits. Your reply resumes the same run with its state intact.
- Exception, not routine. Questions represent genuine missing context or authority.
- No lost session. The answer returns to the active thread.
- Visible in Mission. Attention state shows why progress paused.
// Scout, mid-run blocked_on: "which region should the index cover first?" reason: "the brief names no default" state: waiting_for_input run: held open
// your reply, in the same thread answer: "EU first, then US" recorded: true state: running context: intact, same run
They get better at your work.
Cerebro can capture a proven pattern as a skill with evidence and source-run provenance. Scope it to Cerebro, a project, or an agent, then keep the capability where agents can load it.
- Pattern plus evidence. The source of the learning remains visible.
- Clear scope. Reuse does not blur project boundaries.
- Real files. Skills stay inspectable outside a hidden prompt.

Your notes become their memory.
Connect an Obsidian vault and linked notes become typed, bounded context for the fleet. Projects, people, decisions, tools, and sources stay under your ownership.

Your work stays on your Mac.
Cerebro is a native macOS app over the Claude Code and Codex tools you install. Workspace state, working memory, receipts, and connected notes remain locally owned; provider traffic follows the provider account you chose.
Native app state
Projects, agents, runs, and settings live in the selected app data root.
Local execution layer
Typed tools and durable state connect the fleet to real work on your machine.
Your own subscriptions
Cerebro runs on the Claude Code and Codex accounts you already pay for. It never resells tokens or stands between you and your provider.
Honest network use
Claude Code, Codex, connected services, the waitlist, and updates use their stated network paths.
The kernel hands them the right context.
Agents reach your projects, files, and history through one doorway Cerebro owns. The kernel hands each one the slice that fits its job, keeps what it learns, and receipts what it was given, which is why memory and context hold up here.
The same doorway is what makes the cost legible: granted and used accounting per category, spend reconciled while the run is still going, a preview of the prompt before it is sent, and the outcome joined back to it afterwards. That instrumentation is how we caught a handoff block quietly taking half of a prompt.
goal · current phase working state · relevant files project memory · selected notes budget · source receipts
Switch models mid-conversation.
Switch between Claude and Codex during a conversation. Cerebro records the handoff and preserves the surrounding state instead of pretending every provider is interchangeable.
Provider choice is per agent, so a fleet can be mixed. One delegation can fan out to Codex and Claude workers running at the same time and come back with a receipt for each of them, which we have watched complete live.

Helpers that just report back.
A Project Worker belongs to its page and project, runs on demand or a schedule, and returns a concise report with provenance. It does not become another visible agent in Mission.

Every claim here is verified.
The project keeps a golden-path checklist for the app's critical flows. The site shows the actual checklist and current evidence, not invented success rows. When a loop is added, the score goes down until it is watched firing live.
The app can also demonstrate itself. A headless harness boots its real wiring and asserts against the store, so the behavior described on this page can be exercised rather than promised. It has caught bugs in itself that way, which is the point of having it.

Ready to brief the mission?
Join for important release notes and the public-beta launch when email delivery resumes.
Join the waitlist