Your assistant needs more than a chat

An Operating System for AI Agents

Caedos (said KAY-dos) is the OS your agent works on. Your agent installs synths that watch or react to the world — a page, an API, a feed, a database, an event — and then walks away. The synths keep running on Caedos. If nothing changes, they cost nothing. A model is only called when something truly needs reasoning. And nothing goes to your channels or APIs until you allow it.

caedos start · localhost:2233 · your keys, your machine

Illustrative data.
name pipe status leash last ok ticks cost
hn-watcher — running required 2m ago 48 $0
release-watcher — running auto 14m ago 12 $0
health-sentinel — running auto 1m ago 288 $0
page-watcher — running required queued 9m ago 24 $0.0021
keyword-pulse ↑ team.findings running auto 22m ago 12 $0.0004
relay-bridge ↓ team.findings ↑ team.digest running auto 22m ago 3 $0
courier ↓ content.draft running required never 0 $0

You keep asking. It keeps forgetting.

You ask your assistant. It looks, it answers, and the moment the chat closes, the work stops. So every morning you ask again: did the upstream ship a release? Did the status page go red? Did anyone mention you on Hacker News?

The usual workarounds, and what each one costs:

Keep asking.

You become the scheduler. Anything that changes between chats waits until you think to ask.

costs: your attention

Put a model on a timer.

It reads the same unchanged page every hour and tells you nothing happened.

costs: a model call per check

Hand it to an agent.

Give it a webhook and a loop and it acts on its own. The first you hear of a bad idea is from whoever received it.

costs: a send you never saw

Ask once. Leave. It keeps watching.

The same checks, without the asking.

  1. 01 · Ask. Tell your assistant what to keep an eye on. In Claude Code or any MCP client, that's one ordinary sentence.
  2. 02 · It writes a synth. A small program, usually 30 to 60 lines of config: where to look, what counts as a change, when to think, what to do. Data, not generated code.
  3. 03 · Shadow. One real run against the real world, with every action muted. You see what it read, what it would remember and what it would have sent.
  4. 04 · Deploy, leashed. It becomes a process and starts ticking. Anything that would touch the outside world waits in your approval queue.
  5. 05 · Allow. When you trust it, press Allow in the control room. That's a human act. It isn't one of your AI's tools.
  6. 06 · Leave. Close the chat. The process keeps its schedule, its memory and its budget. Every tick leaves a trace.
you ›  Keep an eye on Hacker News for new stories about "bun"       and post them to my Slack webhook. ai  ›  caedos_validate  { synth: { name: "hn-bun", schedule_seconds: 1800 }, … }       ← { "ok": true, "issues": [] } ai  ›  caedos_shadow  { … }       ← { "mode": "live-sample", "outcome": "idle",           "fast_path_triggered": false,           "would_act": [],           "would_remember": { "seen_titles": [ …20 titles ] },           "findings": [], "cost_usd": 0 } ai  ›  First tick is a baseline: it read 20 titles and will remember       them. Nothing was sent. ai  ›  caedos_deploy  { …, credentials: { WEBHOOK_URL: "••••" } }       ← { "status": "running", "approval_mode": "required",           "credentials_set": true,           "note": "Leashed — side effects queue until the operator                    Allows in the control room." } ai  ›  Running every 30 minutes. New stories will wait in your       approval queue until you press Allow.
Illustrative session. Fields match the MCP server's responses; values shortened.

HOW A TICK WORKS

Most ticks are silent. That's the design.

A tick is one run of a process. It starts whenever the trigger fires: on a schedule, when a webhook arrives, when a signal lands on the Relay, or when you press Run.

Every tick walks the same 6 phases. A deterministic gate in the middle decides whether a model is needed. If nothing changed, no model is called: the tick costs nothing and leaves one line in the journal that says idle.

  1. LOAD Config, memory, today's spend. Over a daily cap? The tick doesn't run.
  2. OBSERVE Fetch, parse, count, compute. Deterministic, every time.
  3. FILTER The fast path: diff, threshold, pattern, new items. Nothing new? Stop here.
  4. REASON Only now, a model, with a strict output schema and a daily dollar budget.
  5. ACT Webhooks, APIs, MCP tools, signals. Outbound actions wait for your OK.
  6. SAVE Memory, trace, cost. What caused the tick and what it was allowed to do.

Two ticks of the page watcher, an hour apart. Illustrative data.

13:00 nothing on the page changed

  1. LOAD memory loaded
  2. OBSERVE page read
  3. FILTER no change
  4. REASON skipped
  5. ACT nothing sent
  6. SAVE idle · $0

14:00 the page changed

  1. LOAD memory loaded
  2. OBSERVE page read
  3. FILTER page changed
  4. REASON model · $0.0003
  5. ACT queued for Allow
  6. SAVE acted · $0.0003

Built for work you'd rather not think about.

Every send waits for your OK.

Processes that can touch the world deploy leashed. Outbound actions queue for one-tap approval until you Allow.

Allow required
notify_webhook

alert: New HN stories for your keyword · new_titles: ["Show HN: …"]

Illustrative data.

approval_mode: required

A bill you can predict.

Deterministic checks are free. Model calls get a daily dollar budget, a hard cap, and a monthly estimate before you deploy.

budget_usd_per_day · limits · estimate

Every tick, accounted for.

What caused it, what it saw, what it cost, what it did, which version ran. Replay any tick against an edited config.

  • 12:30:04 idle scheduler live $0
  • 12:00:03 acted scheduler queued $0
  • 11:58:41 idle authoring shadow $0

Illustrative data.

trace · origin · mode · replay

Synths that talk to each other.

Synths run as processes that publish and subscribe on the Relay. One watches, one decides, one sends, each with its own leash.

publish_signal · signal_subscribe

Failure you can read.

Repeated failures halt the process. Stalls get a bounded repair, proven before it's adopted. When Caedos gives up, you get an autopsy, not a red dot.

circuit breaker · repair · autopsy

Brings your tools.

MCP servers over HTTP or stdio, REST APIs, RSS, web pages, webhooks. Credentials stay in an encrypted vault and never appear in a trace.

mcp_source · mcp_action · rest_api · rss_read

Yours to leave.

One SQLite file on your machine, your own model key, and a workspace export any time (secrets excluded).

GET /export

One table. Everything that's running.

name · pipe · status · leash · last ok · ticks · cost. Open a row for its journal, approvals, vault, connections and spend. The Live Feed shows the fleet ticking. The Relay view shows which processes talk to which.

Processes$0.0025 today

+ Install a Synth

  • Blueprints
  • Live Feed
  • Signals
  • Connections
  • Knowledge
  • Settings

Processes

Illustrative data.
name pipe status leash last ok ticks cost
hn-watcher — running required 2m ago 48 $0
release-watcher — running auto 14m ago 12 $0
health-sentinel — running auto 1m ago 288 $0
page-watcher — running required 9m ago 24 $0.0021
keyword-pulse ↑ team.findings running auto 22m ago 12 $0.0004
relay-bridge ↓ team.findings ↑ team.digest running auto 22m ago 3 $0
courier ↓ content.draft running required never 0 $0

hn-watcher running

Allow required
notify_webhook

alert: New HN stories for your keyword · new_titles: ["Show HN: …"]

Look

  • 12:30:04 idle scheduler live $0
  • 12:00:03 acted scheduler queued $0
  • 11:58:41 idle authoring shadow $0
Illustrative data. Real layout.

Start from something that already works.

9 blueprints ship with Caedos and are validated in CI. Clone one, shadow it, deploy it. Or ask your AI to.

By the numbers

model calls on a quiet tick
0
phases per tick
6
primitives in the catalog
27
MCP tools
13
model providers, your key
3
SQLite file
1

Local by default. Leashed by default. Honest about the rest.

  • Binds to 127.0.0.1 unless you say otherwise, and warns loudly if you do.
  • Secrets are encrypted at rest (AES-256-GCM), resolved only inside the step that uses them, and never written to a trace.
  • No telemetry. The only calls out go to your model provider and the places your processes are told to reach.
  • Worth knowing up front: Caedos is single-user and has no authentication yet. Don't expose it to a network you don't trust.

WHERE IT FITS

Not an agent framework. Not a Zap.

Caedos is built for work that repeats: watch something, notice a change, maybe think, maybe send. Here's how it differs from the tools you might reach for first.

Agent frameworks

How they work

A model decides what to do next, every step of every run.

What Caedos does

Your AI writes the synth once. A deterministic engine runs it the same way every time and asks a model only when something changed.

fast_path → reasoning only on change

Zapier and n8n

How they work

You draw the workflow yourself, step by step, and it runs what you drew.

What Caedos does

You describe the job and your AI writes the synth. Every send waits for your Allow.

Already on n8n or Zapier? The courier blueprint hands approved drafts to your webhook.

approval_mode: required

Scheduled chat tasks

How they work

A model is called on every run, whether anything changed or not.

What Caedos does

A check that finds nothing makes no model call and costs nothing. The model is asked only when something changed.

outcome: idle · cost: $0

Cron and a script

How they work

Your script runs on a timer. Memory, budgets, approvals and logs are yours to build.

What Caedos does

Memory, a budget, a leash, a trace for every tick and a control room come built in.

write_state · budget_usd_per_day · traces

6 questions a skeptical engineer asks.

Is this another agent framework?

No. There's no model deciding what to do next at runtime and no library to wire up. Your AI writes a synth, a small declarative program, once; Caedos runs it the same way every time.

Does a model run on every tick?

No. Every tick runs a deterministic gate first. If nothing changed, the tick ends with no model call and no cost. A process only reasons on every tick if its config explicitly says triggered_by: always, like the daily brief does once a day.

What stops it from posting something dumb?

The leash. Processes that can touch the world deploy with every outbound action held for your approval, with a summary of what they'd send. You can also shadow any synth first: a real run with actions muted.

Where do my API keys live?

In an encrypted vault in the local database (AES-256-GCM), with the key stored beside it. They're resolved only inside the step that uses them, and never written to traces, exports or public pages.

What does it cost?

Caedos is free, for personal use and for work. Model calls are billed by your provider on your key, and only happen when something changed. Each process has a daily budget and an estimate before deploy.

Is it production-ready?

It's pre-1.0 and single-user, and it's better you hear that here than find out later. The engine is well-tested, but 0.1.0 is the first release, and there's no sign-in and no hosted option yet. Use it for your own standing work first, and get in touch before you bet a business process on it.

Give your AI somewhere to leave work running.

Install it, open it, connect your AI. 5 minutes to your first running synth.

curl -fsSL https://caedos.com/install.sh | sh

Windows, in PowerShell: irm https://caedos.com/install.ps1 | iex

Free for personal use and for work.