Matrix Team · Hand–brain separation

The Brain thinks. The Hand executes. Matrix governs the space between.

A Brain is an AI resource together with its credentials: a CLI subscription login or an API key on a device. A Hand is a device that holds a real workspace: files, an uncommitted worktree, local processes, including headless servers. They can be the same machine. They do not have to be.

Matrix leases Brains to Tasks on Hands, relays signed tool calls between them, and keeps the permissions, the audit trail and the usage in one place.

For companiesFor individualsCredentials stay localEvery run traceable
Hand–brain separationsigned channel
Brain: the AI that reasons, with its login or keyHand: the machine that touches filesMatrix: lease, permissions, audit

Why separate them at all.

Your best AI subscriptions live on personal laptops. Your real workspaces live on servers and company machines. Hand–brain separation lets the one work on the other without copying a credential or giving up control of a file.

CREDENTIALS

Logins and keys never move

A CLI subscription login or an API key is used only on the Brain device that owns it. It is not migrated, not held on your behalf and not relayed through the cloud.

LOCAL AUTHORITY

The Hand keeps its files

The device that holds the workspace keeps ownership of its content, secrets and local policy. Each lease is bound to one workspace root; paths outside it are refused with a clear error.

RECEIPTS

Usage follows the receipt

The executing side signs what it did. Usage and accounting follow the lease, claim and epoch receipts, not whoever happens to be logged in.

NO SILENT FALLBACK

Unknown stays unknown

If a Hand is offline, a lease was revoked or a provider refuses, the run says so. Matrix does not retry on another device, swap models or invent a success.

How one tool call travels.

The same path serves a CLI agent, an ACP-connected agent runtime or an API model. Browser and desktop automation reach the Hand through its MCP gateway on the same signed channel.

01 · LEASE

A Brain is leased to a Task

Matrix issues a BrainLease with an intent, a claim, a fencing epoch and a workspace scope. Starting a round reserves capacity only when there is real work.

02 · ENVELOPE

The model asks for a tool

The AI process on the Brain emits a signed tool-call envelope carrying the lease id, epoch and a monotonic sequence number.

03 · EXECUTE

The Hand does the work

The Hand verifies lease, device, workspace, capability and sequence, persists a replay fence, then lists, reads, writes or runs inside the scoped root and returns a signed receipt.

04 · RETURN

The result goes back, the round ends

The result re-enters the model. When the round finishes, capacity returns automatically. Revoking the lease or raising the epoch fences every later call.

Built for a company. Just as useful for one person.

The same objects serve both: accounts and organizations, Devices and Workspaces, Brains, Hands and Tasks. Using a model resource and accessing the files on the device that hosts it are two separate permissions.

COMPANIES

Shared resources, visible work, explicit governance

Organization Owners and Admins manage members, teams, resources and devices in Settings. Nothing is enrolled by accident.

  • A company pool that admins authorize per member and per channel, such as a specific CLI or API provider; with capacity in scope, members use it without per-round approval.
  • An optional monthly execution threshold per member, counted on settled usage in UTC months.
  • Device and Workspace access granted and revoked explicitly; revocation stops new calls and in-flight work on both server and device.
  • Employees' private connections on the same machine never become company resources automatically; admins can enroll them only explicitly, and never read their secrets.
  • Every execution traces to its Task, Run, Worker, model, Device, Workspace and result, so a lead can see what members ran and what it produced.
INDIVIDUALS

Orchestrate the AI and devices you already own

Connect the CLIs and API keys on each of your machines, then drive them from any browser.

  • Use the subscription on your home Mac as the Brain for a workspace on your office PC or a headless server.
  • Browse a remote device's folders from the browser and pick the Workspace; the Hand stays bound to that device.
  • Each resource card shows its owner, channel, slots, shared quota windows and reset times, with unknown states shown as unknown.
  • Request a Brain when there is work, use it while there is capacity, and return it automatically when the round ends. Your own resources are not charged by Matrix.
  • Stop a run and get a confirmed stop; resume from the same Task when a device comes back.

States that mean what they say.

A run reports waiting, verifying, running, failed or delivered with its reason. A model answer never counts as a file written or a test passed.

Waiting for resourceNo authorized, healthy resource with capacity matches the request.
Waiting for deviceThe required Hand or Workspace is offline, with no recoverable condition yet.
Waiting for userInput, a permission change, a choice or an acceptance decision is needed.
VerifyingA result is unclear, a device state is suspicious or cleanup is unconfirmed.
RunningAn attempt with real execution facts is in progress.
Failed / cancelledA terminal state with its reason. Valid artifacts that were produced are kept.
Delivered / acceptedThe result or acceptance contract is met and the evidence can be read back.