Today's calendar, open tasks and overnight messages on one page. Small calls it can make from your known preferences, it makes, and says why. Only the two or three real decisions (what time is the pickup, change the flight or not) are listed for you.
A personal AI crew you can just text on Signal
Macheng Shen · for people who don't write code. Everything below actually runs today; anything not built yet is marked “planned”.
live used every day partial works, with gaps planned not yet
1. What it does in a day
New mail is triaged by importance; the important items arrive once a day as a digest in the mailbox you actually read on your phone, and unhandled urgent ones come back the next day. Replies are written as Gmail drafts for you to check and send.
In a work group, it posts a daily “today's brief” link: yesterday's discussion rewritten as event-level points, with the full text on a private web page. When someone asks “how do I hook up my own AI?”, it prepares the open-source repo link and sends it only after you reply “send”. Every message it sends starts with [智子], so people know an AI is talking.
Forward a paper or an idea. The dispatcher writes an acceptance checklist first, builders read and run code, a checker ticks or crosses each item, and the expensive model only does the final review. Your phone gets a one-page result, conclusion first.
Each family member or collaborator gets their own web chat room that opens on a phone. The AI answers first; if it can't, or a red line is involved, it escalates to the main assistant and the answer comes back to the room. What each person can see in memory is separated by labels and is deny-by-default.
A small music web page that plays offline, with live lyrics and a loop mode for a massage room or the car; scan a QR code to open it.
Ideas worth sharing become Chinese/English pages after a public-safety check (see Safety). Social posts are written as drafts and wait for review. This page was made that way.
“The process is running” is not “messages arrive”. On workdays it sends itself a code word and checks that it comes back; quiet when green, degrade-and-alert when not. That is also how an expired Signal link (occasionally you re-scan a QR code on your phone) gets caught.
2. How it connects
3. Architecture: who does what
Instead of hoping for one do-everything AI, AIs from different platforms each hold a seat, like a small team:
| Seat | Held by | Job |
|---|---|---|
| Front desk | Grok Bot | First to answer: understands the ask, decides who takes it, tells you the result in a line. Does no heavy lifting at the desk. |
| Dispatcher | Adam (a task manager running on Grok Bot) | Turns asks into checklists, assigns builders and checkers, runs the always-on server, reports only after acceptance. |
| Builders | Codex, Claude Code | Write code, research, build pages. |
| Checker | Claude Sonnet | Writes the checklist before work starts; judges each item PASS/FAIL after. |
| Reviewer | “Fable” (the fleet’s separate senior judgment seat; a distinct model from Claude Opus) | Architecture and the final ruling. Pay-per-use, so used sparingly and asked for one page. |
| Experience | Eva | Morning brief, turns daily friction into improvement proposals, records long-term preferences. |
| Outreach | Outreach | Public releases and discovery; everything public passes the safety check first. |
| Intel | Overheard | Watches high-signal public accounts on X and Bluesky; weekday morning digest. |
A few design rules
- Shared memory is the one common notebook. Every AI reads and writes through the same memory service (an MCP interface), so switching platform or model loses no context. Outside assistants such as ChatGPT can drop “candidates” through a gateway for the crew to triage.
- Phone first. Phones choke on big attachments, so long reports become web pages, and a link is sent only after it is confirmed to open (HTTP 200).
- “Done” must be re-checkable by someone else. Done needs three things: which machine built it, a fingerprint of the output (sha256), and a re-check that runs on a different machine. We also plant faults to see whether the check catches them.
- Every task has an owner, a deadline and a fallback. Who owns it, when the claim expires, and which always-on machine takes it next — never a laptop that might be closed.
- Finished work reports back by itself. You should never have to ask “is it done yet?”.
4. Safety: what it can't do on its own
- Sending and spending: draft first, act only after your approval. The email connector can only save drafts; social posts go to a draft box; group messages wait for your “send”.
- Content check before anything goes public. No real private identities or inferable details about family and friends; no financial figures; no new identity or brand commitments; only onto registered surfaces that can be taken down within an hour. Any failure comes back to you as a specific, named question.
- No secrets in memory. Tokens stay on the machine that created them — never in shared memory, chat, or web pages.
- Permission tiers. Collaborator, household steward, family steward, owner. Root powers — identity, billing, domains, signing keys, account recovery — are never delegated to any tier.
- Deny by default. Each collaborator sees only memory explicitly shared with them; anything labeled private, medical, financial or relationship is hidden.
- Say who is talking. When the AI speaks for you on Signal, the message starts with [智子].
5. Open-source code
All repositories below are public and were each scanned for leaks (keys, tokens, private network addresses, personal information); all came back clean. The idea: everyone's AI crew should belong to them, not to one or two giants that own the data flows.
| Repo | What it is | License |
|---|---|---|
| signal-agent-pipeline | Give your agent a Signal channel: signal-cli as a linked device on your own account, with receive / send / send-attach / send-group. | Apache-2.0 |
| zhizi-agent-os | One command turns Claude Code into a personal assistant (智子); a gentle default mode for non-technical users, with safety red lines built in. | MIT |
| selfhost-chat | Self-hosted web chat for your agent: one room per contact; chat history is plain files on your disk. | Apache-2.0 |
| agent-mail-stack | Email as a durable channel for a personal agent: local send spool, attachment intake, delivery receipts. | Apache-2.0 |
| reference-impl | Reference server for a shared memory hub (FastAPI + SQLite + MCP bridge) so several agents read and write one memory. | see repo |
| starshard-communication | An open, user-owned communication substrate spec for personal agents: inbox, addressing, trust, authority envelopes. | see repo |
| fleet-coordination-protocol | A thin coordination wire between agents: claims, handoffs, receipts. | MIT |
| agent-continuity-demo | Smallest runnable demo of cross-agent memory, handoff and catching a belief conflict. | MIT |
| reviewer-wheels | Five installable verification skills so “done” becomes something another agent can re-check. | MIT |
| skill-provenance | A small standard for honest provenance on agent skills: who made it, how it was checked. | MIT |
| architecture-v1 | Architecture, safety charter, quickstart and philosophy. | Apache-2.0 |
| agent-native-communication | Whitepaper (Chinese): an agent-native open communication architecture. | CC-BY-SA-4.0 |
| ilya-ml-scientist | An ML-scientist persona for Claude Code, for research direction calls. | MIT |
| living-information-system | Public front door to a one-person, AI-assisted research program. | MIT |
| continual-learning-lab | An open log of small pre-registered continual-learning experiments. | see repo |
| reversible-layer-aging | A reproducible re-analysis on public epigenetic datasets. | see repo |
A packaged bundle, fleetwright (these pieces assembled into one installable “nervous system”), has passed our internal gate and is planned — not public yet.
6. Try it / build your own
- Easiest start: install Claude Code and run the one-line installer from zhizi-agent-os. You get a personal assistant on your computer that keeps notes and respects red lines.
- Add Signal: on a small always-on server, use signal-agent-pipeline to link it as a device on your Signal (same QR scan as Signal Desktop). Then talk to it in “Note to Self”. A spare number is a good way to try first.
- A room for family: selfhost-chat gives each person a web chat room.
- Optional: email via agent-mail-stack; shared memory across AIs via reference-impl; re-checkable “done” via reviewer-wheels.
- Set the rule on day one: “Show me a draft before you message anyone, spend money, log in somewhere, or change system settings.”
Most of this code was extracted from a system in real use; it is prototype quality and will have bugs. Don't store anything in it you can't afford to lose.
Related reading
Theory mainline index — Return to the site hub and grouped directory.
- Agent-to-agent communication · privacy-policy gated knowledge share | Macheng Shen — The communication protocol behind the crew: local policy decides what one agent may share with another.
- A spine for multi-agent work — The spine places memory, coordination, communication and safety as the load-bearing parts this overview describes in plain words.
- A day-shaped pipeline for multi-agent work — A 7-stage workflow shows how a request becomes a checked task and a receipt.