Agentic mesh
Available now: local messages, claims, refusals, and watchdog alerts

Coordination is the multiplier.

Several coding agents can share a repository without becoming an invisible race. Canopy gives their messages, ownership, and stalls a place you can inspect.

canopy / agentic mesh
Recent agent traffic stays visible beside live sessions and path claims.
The shipped mesh

Rules before autonomy.

Canopy's mesh is a coordination layer around real agent terminals. It is deliberately specific about what it knows, what it retains, and what it refuses.

01

Identity comes from the terminal

Each Canopy terminal gets its own bridge credential. Agent messages and claims derive the sending terminal from that credential instead of trusting a caller-supplied name.

Why: a sender field is easy to spoof. A terminal credential gives coordination one narrow, enforceable identity boundary.

02

Messages leave a bounded local trail

Recent agent messages keep multiline text, local file references, retained message IDs, reply pointers, delivery state, and queryable work tags. The local store keeps up to 500 messages for seven days.

Why: terminal injection alone disappears into scrollback and cannot answer who sent what after a restart.

03

Claims expose collisions early

Agents can place advisory claims on files and directories. Overlapping requests are refused and the conflict is visible in the Agents panel, including the paths and refusal history.

Why: shared checkouts fail silently when two live sessions edit the same path. Claims make ownership visible without pretending to be filesystem locks.

04

Messaging fails closed

Canopy refuses to inject an agent message into a known shell, a run terminal, or a terminal whose role is still unknown.

Why: sending prose to the wrong PTY can execute a command, corrupt a TUI, or make a coordination request vanish.

Message anatomy

A message is more than terminal text.

Retained messages can point to the message they answer and carry a queryable {kind, id} tag for work such as a task, attempt, or pull request.

Honest boundaryReply pointers are not a full threaded inbox. Work tags are metadata, not verified foreign keys. A successful PTY write is not a read receipt.
m42replying to m39
checkout agent → api-contract agent

Webhook schema is stable. I left the generated client untouched and attached the contract path.

ref / attempt / run_8e2
submitted to target terminal
Shared checkout safety

Ownership you can see.

A claim is keyed to the terminal owner, scoped to files or directories, and released when that terminal exits. Another terminal cannot release it by naming the same display label.

  • Advisory, not a filesystem lock.
  • Paths, not line ranges.
  • Overlap refusals are retained in the live claim history.
  • Claims are app-run state today; they do not survive restart.
Stalls become visible

The watchdog alerts, classifies, and recovers.

Canopy combines agent heartbeats, hook events, terminal activity, and process evidence. Two watchdog rules turn silence into a visible recovery path.

W1 / quietFive minutes unexpectedly quiet

A persistent incident links back to the affected attempt, classifies the failure, and starts the cheapest safe recovery rung.

W2 / unseenTwo minutes blocked and unseen

An existing human question is escalated when the user has not seen the terminal that is waiting. Human-required work never routes around the question.

Heartbeat plus evidenceA missed heartbeat is one signal, not a verdict. Canopy correlates it with lifecycle, terminal, provider, and verification evidence before it acts.
Bounded recovery

From visibility to a safe replacement attempt.

Durable task attempts, failure classification, fleet readiness, model tiers, portable reseed state, verification, and conservative checkpoints work as one recovery system.

detectalert with evidence

Messages, claims, heartbeats, lifecycle evidence, W1, and W2.

classifyname the failure

Distinguish transient, route, task, human-required, and safety stops before choosing a response.

recoverswitch only eligible routes

Retry or replace an attempt from portable task state, with every transition visible.

A hierarchy you can inspectEach lead agent owns a bounded domain. Tasks, attempts, claims, messages, replies, and recovery edges form the graph, while the user can inspect or interrupt every route change.
One local project. Your agents. Your rules.

Work under one canopy.

Free, MIT licensed, local-first, and built in the open.

Get Canopy