[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:qm":3},"\u003Ch1>qm\u003C\u002Fh1>\n\u003Cp>A multiplayer agent harness for work. In Slack and on the web.\u003C\u002Fp>\n\u003Cp>\u003Cimg src=\"https:\u002F\u002Fraw.githubusercontent.com\u002Fyc-software\u002Fqm\u002FHEAD\u002Fdocs\u002Fscreenshots\u002Fweb-ui-hero.png\" alt=\"The QM web UI: two concurrent sessions, a sidebar of personal files, crons, keychain, deploys, memory, and skills\" \u002F>\u003C\u002Fp>\n\u003Ch2>What is QM?\u003C\u002Fh2>\n\u003Cp>Most agents are designed like personal assistants. You can make one work for a whole\ncompany, but it quickly gets complex. QM is designed for startups. Employees each get\ntheir own isolated workspace and work independently without affecting each other, and\nthey can also collaborate with the agent in channels, group messages, and projects.\u003C\u002Fp>\n\u003Cp>Each person and each room has its own scoped memory, files, keychain view, permissions,\ncrons, web apps, and durable sandbox.\u003C\u002Fp>\n\u003Cp>It's built with open source in mind. Pick your own harness and model and switch between\nthem — Pi, OpenCode, Codex, and Claude Code all drive the same core, so a deployment\nisn't tied to any single vendor.\u003C\u002Fp>\n\u003Ch2>Features\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Personal and shared scopes.\u003C\u002Fstrong> People customize the agent to be \u003Cem>theirs\u003C\u002Fem>, and still\nwork with it collaboratively in Slack channels and projects.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Slack and web.\u003C\u002Fstrong> The same identity and configuration carries between Slack and the\nweb app.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin control.\u003C\u002Fstrong> Set org-level configuration, a security posture, and which\nharnesses and models are available.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Web apps.\u003C\u002Fstrong> Spin up custom internal apps and publish them to the right people.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shared skills.\u003C\u002Fstrong> Skills are scope-owned and shareable by grant, with admin-gated\npromotion to the whole org and skill packs imported from git repositories.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Background work.\u003C\u002Fstrong> Crons and watches run work while nobody's watching.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>What you can do with it\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Search internal notes, email, documents, databases, and the web together\u003C\u002Fli>\n\u003Cli>Retrieve information from your company brain\u003C\u002Fli>\n\u003Cli>Build internal apps, publish them to the right people, and keep their data current\u003C\u002Fli>\n\u003Cli>Learn your writing voice from past sends, then triage your inbox on a schedule —\nlabels and reply drafts included\u003C\u002Fli>\n\u003Cli>Work in an existing repository: run tests, open PRs, monitor CI, check system logs\u003C\u002Fli>\n\u003Cli>Track a project in a shared channel and post updates and follow-ups\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Architecture\u003C\u002Fh2>\n\u003Cpre>\u003Ccode class=\"language-mermaid\">flowchart LR\n  DB[(\"Postgres&lt;br\u002F&gt;sessions · memory · queue\")]\n\n  subgraph CORE[\"Headless core\"]\n    API[\"API · identity · policy · scheduler\"]\n    LOOP[\"Agent loop&lt;br\u002F&gt;(Pi, OpenCode, Claude Code)\"]\n    API &lt;--&gt; LOOP\n  end\n\n  SBX[\"Per-scope sandbox&lt;br\u002F&gt;files · tools · logged-in services\"]\n\n  DB &lt;--&gt; API\n  LOOP &lt;--&gt; SBX\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Every turn runs through a central core, which can use a variety of models and harnesses\nto generate the response. A Postgres persistence layer holds user data, session history,\nand other durable state. The agent has a small, fixed tool surface; one of those tools is\n\u003Ccode>execute\u003C\u002Fcode>, which runs commands in the scope's own isolated sandbox — its durable computer,\nwhere installed tools stay installed. The web UI, the admin panel, and the public portal\nare optional plugins over the core's HTTP API;\nSlack is an optional in-process plugin that core starts\nand supervises through a direct service client.\u003C\u002Fp>\n\u003Cp>The core runs TypeScript directly on Node and uses Fastify for HTTP. The Slack plugin\nuses Bolt; the web UI builds with Vite and renders with Lit.\u003C\u002Fp>\n\u003Cp>The core itself is generic. Everything specific to one company — org config, custom tools\nand skills, sandbox image, infrastructure — lives in a \u003Cstrong>deployment directory\u003C\u002Fstrong> that the\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fyc-software\u002Fqm\u002Fblob\u002FHEAD\u002Fcli\u002FREADME.md\" rel=\"nofollow ugc noopener\">\u003Ccode>qm\u003C\u002Fcode> CLI\u003C\u002Fa> validates and deploys. Every substrate (harness, session\nstore, sandbox, memory) sits behind an interface, so production implementations swap in\nvia one wiring file.\u003C\u002Fp>\n\u003Ch2>Security and secrets\u003C\u002Fh2>\n\u003Cp>QM's approach follows local coding agents like OpenCode, Codex, and Claude Code: the\nagent acts as the person it's working for, with their credentials and permissions, and\neverything it does is audited. An org picks one security posture, which narrower scopes\ncan only tighten:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Strict\u003C\u002Fstrong> — every harness tool call pauses for human approval, except the two\nno-effect turn\u003C\u002Fli>\n\u003C\u002Ful>\n",1785715925198]