Self-hosted autonomous agent
Your agent,
autonomous
by design.
An autonomous agent that runs on your server, remembers useful context, and keeps your work moving. Bring your own keys, choose your models, and resume from saved progress.
Your machine. Your models. Your memory.$PCMD · CA: Soon
>summarize notes/q3-review.md
- instruction receivedtools: read_file, write_artifact
- workspace files inspectednotes/q3-review.md · 4,812 chars
- summary generatedsummary.md · 1.2 KB
- checkpoint savedturn 3 · resumable
>
A scripted example of one task. It is not running anywhere. Real tasks, with events from your own worker, are in the console.
01 / Loop
From instruction to execution.
A task is a bounded loop, not a chat. It moves through four stages, and it can only go around again while it is inside the turns, time and budget you set.
01 / 04 · Instruction
You describe the outcome in plain language and choose what the agent may touch: which tools, how long, how many turns.
> summarize notes/q3-review.mdtools read_file · write_artifactlimits 24 turns · 900 s · 600k tokens
01 · Instruction
You describe the outcome in plain language and choose what the agent may touch: which tools, how long, how many turns.
02 · Plan
The model records a short plan first. Every other tool stays locked until a plan exists, and the plan is updated as steps finish.
03 · Execute
Each tool call is validated against its schema and checked against your permissions, then run on your server. Anything outside your scope waits for approval.
04 · Checkpoint
Every result is written to PostgreSQL before the next step starts. The task can pause, survive a restart, and continue from here.
02 / Memory
Memory you can inspect.
Memory is text you wrote or approved, stored in your database. It is not model training, and there is nothing in it you cannot read, edit or delete.
Preferences · Project Context · Approved Procedures
Summary format
Start every summary with a one-line takeaway. Use at most five bullets. British English.
- Source
- Written by you · pinned
- Retrieval
- Always supplied: it is pinned.
These six entries are an illustration, not your data. Your own memory starts empty and lives in your database.
- Keyword retrieval, stated plainly
- Entries are found with PostgreSQL full-text search. Pinned entries and preferences are always included. It is not semantic or vector search, and the console does not call it that.
- Every task shows what it was given
- Each task records which entries were supplied and why. You can turn retrieval off for a single task. Entries the agent proposes stay inactive until you approve them.
- Delete means out of retrieval
- A deleted entry is removed from the database and from the saved context of tasks that used it. An audit line naming the entry stays with those tasks unless you purge it, and older backups still contain it.
03 / Recovery
Resume where you left off.
Progress is saved after every step, so a pause, a restart or a crashed worker does not send a task back to the beginning.
Task timeline
Illustration- 1update_plan
- 2list_files
- 3read_file
checkpoint saved · turn 3
worker-a stopped responding.
worker-b took over and started at step 4.
- 4analyze_csv
- 5write_artifact
- 6final answer
Completed. Steps 1 to 3 ran once.
- Finished steps are skipped
- Recovery reads the saved transcript and tool results. A step that was recorded as complete is not run again.
- Safe operations run again
- Reading a file or rewriting the same artifact can be repeated without harm, so an interrupted one simply restarts.
- Unknown outcomes wait for you
- If a worker dies while an external request is in flight, nobody knows whether it happened. The task stops for review instead of replaying it. No exactly-once guarantee is claimed for external actions.
04 / Control
Your models. Your rules.
You pick the model for each task, hold the credentials, and decide what the agent is allowed to do with them.
Providers
OpenAI, Anthropic, or a local OpenAI-compatible endpoint.
You enter the model IDs you want to use. A connection is shown as connected only after a real request to the provider has succeeded, and each model is checked for tool calling before it can run a task with tools.
Credentials
Your keys stay on your server.
They are read from environment variables, or stored in your database encrypted with a key you supply. They are not sent to the browser and not written to logs, events or artifacts. The console shows the last four characters only.
Permissions
Nothing runs that you did not grant.
Each task lists the tools it may use. A tool set to ask, or a web request outside your allowed domains, stops the task and shows the tool, the exact target, the arguments and the effect. One approval covers one operation; a changed operation asks again.
Limits
Every task has a budget.
Model turns, runtime, tokens, network requests, tool output and artifact size. At a limit the task stops with its checkpoint intact, and you can raise the limit and continue.
What leaves your server
The agent, its queue, its memory and its files run on your machine. The model may not. When a task uses a cloud model, the context for that task is sent to that provider: the instruction, the memory entries supplied to it, and the tool results it reads, including file contents. A local endpoint keeps that on your own hardware.
05 / Self-host
One Compose file runs all of it.
PostgreSQL, the API, the worker with its scheduler, and this console. The commands below are the ones in the repository; there is no installer to download and no hosted account to create.
No default password
The first visit asks for a setup token that only someone with access to the server logs can read, then for the owner password.
Connect a model
Add a provider in Settings and run the connection test. Until one passes, the console says so and queues nothing.
Developing without Docker
pnpm installthenpnpm devstarts a local PostgreSQL 17, the API, the worker and the console.
06 / Token
$PCMD
The PoietesCMD token. Its contract address is published here and on @PoietesCMD, nowhere else.
- Ticker
- $PCMD
- Contract address
- Soon
- Announcements
- @PoietesCMD
One address, two places
When the token launches, the address appears on this page and on @PoietesCMD at the same time. An address that is not shown here is not ours, whatever it is called.
The software does not need it
Running the agent, the console and the self-hosted stack requires no token, no wallet and no chain. The token is a separate thing from the product you can install today.
Nothing else is claimed
Supply, listings and anything beyond the address are stated only when they are true, and only in the two places above.