Agent, Memory and approvals
Panel-only Chat
Open Chat, select Panel Chat (no default Workspace) and choose an available model. Panel-only tasks work with zero Daemons and cannot acquire host, Docker or Workspace access. Use the task selector to create, rename, archive or fork a task; another user's private task never appears in search or event replay.
The composer stores a default mode and effort for the task. Agent may execute allowed tools; Plan produces a Plan artifact and does not silently become permission to perform its writes. The Effort selector contains only the profiles supported by the selected model and shows the current quota. A model change, mode change or effort change affects later turns, not historical items.
When the Agent requests Input, answer the displayed text question or choose one of the fixed options. The request is bound to that turn and expires; do not paste a response into an unrelated task as a workaround.
Create a Workspace
An administrator first adds a trusted immutable image in Servers & Workspaces. Select Create Workspace, choose an eligible online Daemon and image, enter the name, CPU, memory, PID and port limits, then select Review placement. Confirm only the final preview with its remaining capacity and expiry. The server rechecks capacity, ports, Daemon state and preview digest at confirmation time, so concurrent placement can safely return a stale or capacity error.
After creation, assign the intended user and open Workspace Chat. Removing the assignment immediately makes pending approvals, stale tabs and SSE streams lose authority; it does not allow the user to finish a previously prepared write.
Approval and Operation Review
An ask action pauses before an Operation or Daemon command exists. Review the redacted action, Workspace, risk and exact input, then approve or reject it. Changing the input, assignment, Workspace generation, policy, Plugin/MCP identity or ExecutionPlan invalidates the approval. Approval confirms risk inside existing authority; it never grants access to another Workspace or host.
For management writes, inspect the final ExecutionPlan, digest, expiry and steps before confirming. After a terminal operation, open Review to inspect the intended plan, observed commands, affected files, evidence, divergence, rollback information and remaining steps. The exported Review is redacted and read-only; a retry or rollback requires a new plan and confirmation.
Private Memory and search
The task search field searches titles and your private indexed task content. Results are reauthorized when read and cannot expose archived data owned by another user or a Workspace you no longer hold.
Open Private Memory from Chat to control retrieval and candidate generation. Add or edit a confirmed preference, profile, project or workflow record, choose Panel or current-Workspace scope, and set retention. Model-proposed candidates are not stored until you select Confirm and store. Suspected secrets are rejected.
Delete Memory removes one record and its search projection. Clear private data requires strong verification and synchronously removes every private Memory record and private task-search document in the current Panel namespace; it cannot be undone.
SSE reconnect and multiple tabs
Chat receives durable task events over SSE. A disconnected tab shows Reconnecting… authoritative state is unchanged, disables new submissions, and reconnects using the last numeric event cursor. Duplicate frames only cause a fresh snapshot; they do not repeat an Operation. If the cursor expired, an access revision changed, or replay reached a bounded product limit, the server sends a reset and the UI loads a new authorized snapshot.
Close unused tabs rather than repeatedly refreshing: connections are bounded per user, session and IP, and reconnects are rate-limited. After reconnect, verify the final task/Operation state before deciding whether to submit new work.