Agent Atlas / Runtimes and workbenches

yc-software/qm

A cloud-first organization agent runtime that gives people and shared rooms distinct scopes for sessions, memory, files, credentials, skills, schedules, and durable agent computers while routing several coding-agent harnesses through one core.

Organization agent runtime Full dossier Reported + sourced Reviewed July 31, 2026
Intended operator

Startups self-hosting one agent system for individual and shared work across Slack and the web.

Primary surfaces

Slack / web workspace and admin panel / headless HTTP core / organization deployment CLI

Tracked repository

yc-software/qm

Teaching mechanism

The conversation address selects the tenant

A direct message resolves to a personal scope, a group message to a group scope, and a channel to a channel scope; the resolver then mounts organization state read-only and the active scope read-write before a harness runs.

Evidence limitThe project calls itself early and experimental; its security policy documents incomplete audience filtering, conditional egress enforcement, plaintext in-use credentials, durable-data retention gaps, and other controls that are not yet complete.
Inspect the source

System Map

Eight inspection boundaries
Model boundary

Pi, OpenCode, Codex, and Claude Code adapters implement one typed harness contract, while organization and scope configuration constrain approved harness and model choices.

Context and memory

Personal, channel, group, team, and organization scopes separate writable and recalled memory, workspace layers, instructions, and session records.

Tools and execution

A small core tool surface delegates commands and file effects to a scope-routed sandbox with local, Fly Sprite, and AWS MicroVM backends.

Permissions and isolation

Organization policy composes with narrower scope policy; ACL handles, security postures, approvals, credentials, audience floors, and sandbox routing form separate enforcement layers.

Sessions and recovery

Leased durable sessions, tapes, model-request records, background run stores, scheduler claims, and resident disks are designed for multi-instance and blue-green operation.

Delegation

The stronger current evidence is shared human-agent tenancy and background work rather than a fixed hierarchy of role-playing agents.

Human control

Slack and web surfaces expose scoped conversation, approvals, admin policy, model selection, shared skills, schedules, and published app artifacts.

Evidence surface

Public TypeScript interfaces, Postgres stores, threat model, deployment contract, tests, release workflows, and unusually detailed commit messages expose both mechanisms and known gaps.

Learn Through This Project

10 lessons

Compare Its Boundaries

8 labs

Latest Reporting

1 article

Primary Sources

Open Questions

  • Can scope ownership remain legible and enforceable as shared rooms accumulate credentials, memories, schedules, apps, and agents from several harnesses?

Evidence state describes what this Atlas profile can support today. It is not a product score and it is not evidence that uninspected capabilities are absent.