Agents
Five kinds of bot sit on the desk — four vendors and your own endpoints. Each vendor connects over ACP (the Agent Client Protocol, the pipe its own CLI already speaks) and runs as its own process; custom bots are plain HTTP.
| Vendor | How it connects | Notes |
|---|---|---|
| Grok | ACP over stdio | Runs the local Grok CLI |
| Claude | ACP over stdio | Runs the local Claude Code CLI |
| Codex | ACP, plus an App Server | App Server adds native history and capability discovery |
| Cursor | ACP over stdio | Runs cursor-agent |
| Custom | HTTP | Any Anthropic Messages or OpenAI Chat Completions endpoint, hosted or local |
Each vendor runs under its own login. Subscriptions, context and sandboxes are never pooled.
Workhorse Link is how any outside app calls this desk — Codex, Claude Code, Grok, Grok Bot, OpenClaw, Hermes, or any MCP client. Settings → LLMs → Workhorse Link connects each with one button, and every app gets the same versioned contract: read and ask chats, query leftover and availability, delegate work, continue it, and follow worker status. The same helper is a JSON CLI, workhorse, for a harness without MCP. Connecting an app adds no vendor, no login, and no Usage ring.
Grok Bot is a cloud computer harness. Like OpenClaw and Hermes it carries its own agents — and unlike them, its agents live and work on Grok Bot's own remote computer, and it carries its own usage. Over Link it calls the desk like any other app; on the desk it rides as a bot of its own, with a local shim, its own weekly ring, and an optional instant-reply webhook so the desk can wake it. Grok over ACP stays a separate vendor and login. Connect Grok Bot.
OpenClaw and Hermes are harnesses — apps on this machine that carry their own agents. The desk can call those agents without owning them. Settings → LLMs shows whether each is installed and lets you select its callable agents. A plan can grant selected agents for one wave (one round of workers), or you can name openclaw/main or hermes/<profile>; their tasks join the lineup beside the desk's own workers. They get no Usage ring, and delete, rename, credentials and elevate stay blocked. A spawn that arrives without naming a chat makes a new one, titled from the prompt.
Chats and projects
- A project is a name. Folders and references are optional, added later.
- Chats belong to a project. Rename, archive, delete, or drag one to another project.
- Vendor, model and thinking effort are set per chat, not per app.
- Fork a chat to try a different model on the same history. When the project has a Git folder, the fork gets a managed worktree — the same isolation subagents use.
- Rewind to an earlier turn.
- A portable transcript follows a chat when its vendor changes.
- Search runs over chat titles and message text across every project.
- A parent with workers folds them on the count button; they ease open and closed.
- A turn's work stays on one compact line while it runs. Open it for the ordered detail: think, tools, think. Consecutive tool calls share one fold; a later thought starts a new hop.
Files you can hand a chat
Drag them onto the window, or paste them in.
- Images — png, jpg, jpeg, webp, gif, bmp
- Audio — mp3, wav, m4a, aac, flac, ogg, opus, webm
- Video — mp4, mov, m4v, webm, avi, mkv
- Documents — pdf, doc, docx, ppt, pptx, xls, xlsx, rtf, odt
- Text and code — txt, md, json, csv, tsv, ts, tsx, js, py, rs, go, java, rb, php, c, cpp, cs, sql, yml, toml, sh, and the rest of the usual list
- Folders — dropped whole, with dotfiles and build output skipped
A chat can also read media the agent wrote, so a generated image shows in the transcript rather than as a path.
Control
- Permission modes — ask, accept-edits, always-approve, plan.
- Sandbox profiles — off, workspace, read-only, strict.
- One permission inbox. Every prompt lands in the same place and is translated to each vendor's own protocol.
- Execution directory — a chat runs in a linked folder or in a managed git worktree, isolated from your working copy.
- Terminal — chat-scoped, in that same directory.
- Git review — a compact Changes control opens the changed files and diffs for the work a chat did. Click a row to open the file beside the chat.
- Change instances — a created file's lines stay green. A later prompt that deletes some of them keeps those lines as red instances in the review.
Spend
- Usage recorded per vendor and per chat, from each vendor's own count: the ACP turn total, or the HTTP response's usage block. A turn is estimated at four characters a token only when the vendor sent no count.
- In is fresh input — what the model read for the first time. Cached is context served back from cache, named apart so a long chat does not read as millions of new tokens. Out is what it wrote.
- Compact shrinks the context meter; leftover moves only if that bot ran a billed summary. A spent daily bank can hold your next send until tomorrow — a full context window never does. One is money, the other is context.
- Budgets per vendor.
- A weekly pace that tells you when you are ahead of it, before the bill does.
- A daily bank that hands every bot a slice of its plan per day and carries forward what it did not spend.
- A usage view by day, week, month, or all time.
Work that outlives a turn
- Schedules — one-shot and recurring, journalled by the desktop process and recovered after a restart.
- Goals — long-running intent that survives the chat that started it. A desk goal continues in rounds after a turn ends, until pause, clear, or the round cap; each round is one turn on that chat's vendor. Grok's own
/goalis still that vendor's one-shot driver. - Loops — spawn a worker cold with only a bounded handoff (
seed: fresh). The worker gets no parent conversation and keeps its own vendor, leftover ring and sandbox. - Turn log — a chat can rebuild model history from its own turn and step log. The log is per chat and never shared across vendors.
- Subagents — lifecycle records, runtime and token ceilings, cascading cancellation, changed-file review, and worktree isolation where the project supports it. A worker gets a worker's context: the short worker rules and only the desk tools it may call.
- Plans — multi-step work that continues after a worker joins.
- Routing — your own chat keeps the model you picked until you set it to Auto; Auto picks the bot and effort for each message. When a chat spawns a worker without naming a bot, the desk picks the bot and effort for the slice. Settings → Routing turns that off, and tunes how any routing weighs leftover, reserve, and local models.
Memory
- A private learning store on your own disk, in SQLite.
- The compiler is a custom bot. Settings → Learning can backfill the last day of human prompts from saved chats.
- Human intent, agent performance, and mismatches between them compile as separate private lanes.
- Settings shows index counts and inferred memories, not raw prompt text.
- Export it, or wipe it, from Settings. Nothing is sent anywhere to hold it.
Extending it
- Skills — two ship with the desk,
deskfor chat-to-chat control andsetupfor adding bots and references. Skills are also listed from Grok, Codex, Claude and Cursor homes, and can be pushed back to a vendor. - MCP servers — attached to a runtime, with the same approval and result path as built-in tools.
- Custom bots — a pasted URL and key become a first-class bot with its own name and colour. Add a bot ships presets for MiniMax, Synthetic, OpenRouter, Groq, DeepSeek, Together, Fireworks, Hugging Face, Novita, Cerebras, AI/ML API, Vercel AI Gateway, Kimi Code, Gemini API, and Grok Bot, grouped as subscription plans, gateway credits, direct API billing, and on this Mac. Large catalogs are grouped, frontier-first, searchable, and explicitly approved. One key keeps one leftover ring with separate model rows.
- The
/palette — new, project, link, model, effort, compact, plan, sandbox, usage, watch, schedule, goal, loop, skills, review, context, rewind, export, memory, hooks, plugins, workflows, and more.
Settings
Profile, connected LLMs, skills, routing, learning, usage, watch.
- The profile shows the Workhorse mark as tiny moving blobs of the bots you have called. Spend sets how many of each colour.
- Settings can export a support report that excludes prompts, messages, file contents, environment variables, URLs and credential values.
- Settings → Profile can check GitHub for a newer desk. A Mac installer downloads that release's disk image, replaces the app, and opens it. A Windows installer downloads the Setup exe, installs after Workhorse quits, and opens the new build. When one is ready, a blue update control appears at the far right of Settings; hover it for Update now and the version it will install.
Platforms
Windows and macOS. Both installers are built and tested on their own machine for every release. No Linux installer yet.
The source of truth is docs/FEATURES.md in the public repo. Every release updates it.