Kovee — sovereign collaboration for people and agents
Together, without becoming one.
Kovee is a proposed collaboration architecture for people and agents that do not share an operator, credentials, context, or authority — designed to turn a shared situation into accountable work, with goals, permissions, actions, and results explicit and traceable.
Explore togetherCommit explicitlyAct within boundsExchange with receipts
Design target, not a shipped unified product. All three systems: pre-release, under active development · full status
One product, three questions
Every shared effort asks three different questions.
Blur them into one chat window and accountability dissolves. Kovee keeps them separate — and answers each with a part of the system built to own exactly that question, and nothing more.
What are we working on, and what matters right now?
A durable shared Space where people and agents make goals, questions, claims, evidence, alternatives, and results visible — and where an assistant is invoked explicitly, with an exact record of the context supplied to it.
Kovee · shared work & execution
Who committed to what — and what may they actually do?
Voluntary, attributable commitments and bounded authority. Saying "I can" is never the same as "I may," "I will," or "it's accepted" — each stays a separate, inspectable record.
Byom · authority & accountability
What may cross to someone we don't control?
Exact, signed contracts and results that move between independently run installations — without shared credentials, and with results the recipient can validate against the signed contract.
Akson · sovereign exchange
Kovee is the proposed product doorway and shared-work layer: it composes Byom and Akson into one experience — one inbox, one SDK, one provenance view — while each system remains authoritative for its own records. That separation is not an implementation detail; it is what makes the answers trustworthy.
Illustrative scenario · 1 of 8
An illustrative scenario for the proposed design — not a product demonstration. Release 4.2 is blocked by intermittent payments-test failures. Across this page, one small cast takes that bug from open question to accepted fix: Mara, a release engineer; @scout, her team's hosted assistant; Jun, a teammate with doubts about the fix; and atelier, an independent review firm her company doesn't operate. Watch for the same identifiers as you scroll: pledge pl-142, exchange ex-9 — and Jun's dissent, which will matter.
The product · Spaces
A shared situation, not another chat.
Questions, claims, evidence, alternatives, results — a durable Space holds typed contributions and their relations. The records stay fixed; only the lens changes.
The familiar chat stream is one lens among several. Switch to branches and the kept alternatives appear; switch to provenance and every record traces to its origin. A lens changes presentation — never visibility, never authority.
Fork the reasoning. Preserve the provenance.
Illustrative scenario · 2 of 8
The graph above is Mara's Space. Q is "why do the payments tests fail?" — @scout, invoked explicitly under an attention contract with an exact record of what it was shown, contributes claim C, "the retry logic races the ledger commit," pinned to CI-log evidence E. The candidate fixes are branches A₁ and A₂. A₂ is Jun's — with a recorded concern about what a retry does on timeout. A₁ becomes patch.v1 — result R — and A₂ stays in the record, attributed and intact.
The product · Inbox
One inbox to read. No generic approve.
Ordinary navigation is deliberately small — Spaces, Work, Inbox, Connections, Activity. The Inbox is designed to gather every decision waiting on you into one view.
But there is no Approve all button, by design. Each item carries its actual owner, and each button submits that owner's exact, typed action over the precise revision you are looking at. A unified surface — never a unified authority.
Illustrative scenario · 3 of 8
For the first delivery, Mara's inbox presents these decisions in sequence: a position on pledge pl-142, local consent to dispatch exchange ex-9, and — only after atelier's findings return — the review. The mockup groups that first-delivery sequence into one static composite; the items are not simultaneous, and none advances without her exact, typed answer.
Position requested — pledge pl-142
patch.v1 for the payments retry race · frontier sf-7 · budget and deadline shown exactly
subject sha256:9f2c…e1 · rev 3 · expires in 2 d
Local consent — exchange ex-9
Send the patch diff to atelier for independent review · 8 KB · no credentials leave this machine
contract sha256:41ab…77 · peer pinned 2026-05-02
Review — atelier's findings for pl-142
Evidence verified · decide whether the delivery satisfies the pledged terms
delivery sha256:c8d0…3f · verification green
The same discipline is designed into recovery: every view resumes from a durable cursor, so nothing depends on a socket staying alive. Close the tab, switch devices, lose the network — the live connection is an optimization; the record is the truth.
How it works
One journey, every boundary intact.
Work in Kovee moves in a cycle, not a pipeline. Each step is stamped with the system that owns it — and no step can impersonate the next.
-
Kovee
Explore together
A question becomes visible in a shared Space; people and agents contribute context.
-
Byom
Commit & authorize
A participant pledges to an outcome; a bounded mandate says what it may do.
-
Kovee
Execute locally
A confined run receives only explicitly recorded context, not ambient access.
-
Akson
Cross a sovereign edge
If work involves an independent installation, a signed contract crosses; consent stays local on each side.
-
Kovee
Admit evidence
Results return with receipts; every byte is checked against what was signed before it is admitted.
-
Byom
Review fulfillment
A delivery is not acceptance: a reviewer decides whether the delivery satisfies the pledged terms and records that judgment.
Illustrative scenario · 4 of 8
One lap of the loop, in the scenario: Mara's question surfaces (1). @scout pledges patch.v1, and a separately issued payments-only mandate bounds what it may do (2). A confined run produces the patch (3). The diff crosses to atelier for independent review (4). Findings and signed evidence return and are verified (5). Mara accepts — or doesn't — against the pledged terms (6).
Why it can be trusted
Words keep their meaning here.
Many agent products compress collaboration, permission, execution, and success into one conversational gesture. Kovee begins by refusing that compression — no inbound message, model output, or signature can manufacture consent, a commitment, or a "done."
Permission for a bounded class of action. Not agreement to act.
A voluntary, attributable commitment to an exact outcome.
One bounded attempt is underway — nothing more is implied.
A claim that outputs and evidence were produced.
Named checks passed on exact bytes. Still not acceptance.
A reviewer decided the delivery satisfies the pledged terms.
Six small words, six separate records — and no API, screen, or convenience workflow is allowed to collapse them into a generic "approved" flag. That is a core part of the interaction model, stated plainly.
Illustrative scenario · 5 of 8
In the example, the six words are six records. @scout may touch the payments module — its mandate says so, and nothing more. It pledged it will deliver patch.v1. A run means it is doing the work. Its delivery claims it did. Verification shows the bytes checked. Only Mara's review makes it accepted.
Byom · accountable agency
A society, not a managed swarm.
Byom is the authority layer: a deterministic governance kernel through which humans, agents, and formed collectives make voluntary pledges, receive bounded mandates, and act accountably.
It is not the intelligence above a swarm. It never calls a model, invents a plan, or picks a worker. A call invites — it cannot assign. Delegated authority only ever narrows. And the root authority in every society remains, explicitly, human.
The plan is a lens. The pledge is attributable.
Illustrative scenario · 6 of 8
Nobody assigned @scout. Mara initiated an endeavor from the Space's recorded frontier sf-7 and opened a call for offers. Another hosted assistant never answered at all — an invitation obligates no one. @scout's own assent created pledge pl-142; a separate, authorized decision issued the payments-only mandate — the pledge itself grants no permission.
Owns
Societies, standing, assemblies, endeavors, calls, pledges, mandates, decisions, governed episodes, and institutional memory.
Never becomes
The planner, the model host, the worker picker, or the effect runner. Intelligence stays at the edges; the kernel stays deterministic.
Where you see it
On decisions, receipts, and provenance — the BYOM stamp on an inbox item tells you exactly whose rules are being applied.
Akson · sovereign connection · akson.cc
Connected; authority stays local.
Akson is the edge: signed work crosses between independently administered installations while authority stays local and the return stays checkable.
Two endpoints pair directly — no hosted account, no relay — and everything that crosses is a signed contract or its signed result. Arrival is quiet: receiving a task never starts a model, never grants access, never runs anything. Each side decides for itself.
- signed request
- inert arrival
- local decision
- bounded work
- checkable return
Owns
Endpoint identity and pairing, exchange-specific local consent, signed contracts, and result-and-evidence carriage with independent validation.
Never becomes
An orchestrator or an ambient remote shell. The design requires approved work to run in a sandbox limited to supplied inputs — no network access, no host filesystem.
Where you see it
On connections and exchanges — the AKSON stamp means a sovereign boundary was crossed, with receipts you can re-verify yourself.
Illustrative scenario · 7 of 8
The outbound payload contains only the 8 KB diff — no credentials, no repository access. atelier receives the signed request as inert data and consents independently before its own agent analyzes the diff in a confined sandbox. Findings return with signed evidence, and Mara's endpoint re-verifies every digest before anything is admitted as exchange ex-9's result.
For builders
One SDK. Explicit ownership and next steps.
The proposed Experience API is one high-level surface at the Kovee gateway — a small resource model over Spaces, Runs, Pledges, Exchanges, and the Inbox — composing the three underlying protocols without flattening them.
Every response is specified to answer the same three things: which owner holds the record, what is required next, and which receipts already exist. No fictional atomicity, no invented "done."
{
"operation": { "id": "op_7f3", "state": "needs_action" },
"resource": {
"owner_protocol": "byom",
"kind": "act_intent",
"revision": 3,
"subject_digest": "sha256:9f2c…"
},
"requirements": [
{ "kind": "byom.human_position", "expires_at": "…" },
{ "kind": "akson.local_consent", "expires_at": "…" }
],
"receipts": [],
"trace_ref": "trace_b21"
}
class Reviewer(Assistant):
async def run(self, ctx):
# exact, recorded context — never ambient history
goal = ctx.context.goal
findings = await ctx.model.complete(prompt_for(goal))
await ctx.contribute(claim=findings.summary)
await ctx.relate(findings.evidence, supports=findings.claim)
# identity, authority, budget, and fences are supplied
# by the supervisor — assistant code never holds credentials
Points at a record; grants nothing. Every use re-checks visibility at the owner.
Says exactly what is needed next, from whom, by when — typed, never generic.
An owner-issued, verifiable record of the action or decision it reports.
The causal story across all three systems — readable, never an authority.
A typed failure that keeps its source and retry guidance. Ambiguity stays visible.
Illustrative scenario · 8 of 8
The response above captures an earlier snapshot of the scenario: at that moment, sending the diff still waits on Mara's Byom position on pl-142 and sender-side Akson consent for ex-9 — and atelier will still make its own local decision. What happens when the findings come back — and one of them bites — is act two, below. Either way, one trace_ref connects every record without ever merging their authority.
One UX, one SDK, and one trace — but never one omnipotent token, one generic approval, or one source of authority.
Illustrative scenario · act two
The bad day is the point.
Any demo can ship a happy path. The design is for the other days — when a finding bites, a run dies, and the record has to hold.
Kovee · verification
The report passes verification — and one finding bites.
atelier's report comes back and every digest matches what was signed. But one finding is real: on a retry timeout, the patched path can post a ledger entry twice. Verification proved the bytes are exactly what atelier produced — it never claimed the work was good.
Byom · review
Mara rejects the delivery.
She records a review against the pledged terms: not satisfied, finding attached. The delivery is not erased and nothing retries by itself — the pledge stands, and the rejection is now part of the record.
Kovee · runtime
The next run dies halfway.
@scout's second confined run crashes mid-write. Recovery records its outcome as ambiguous — neither failed nor done. After a separate retry decision, a fresh run starts with a new fence from the durable record. The stale run can never write again.
Kovee · provenance
Jun's dissent pays off.
The double-post risk is exactly the concern Jun recorded on branch A₂. Nobody had to remember it — the Space kept it, attributed and pinned to the exact revision. The revised patch folds A₂'s guard into A₁'s fix.
Byom · review
Accepted — on the second delivery.
Before the revised diff crosses to atelier, Mara records fresh sender-side consent for that exchange; after it arrives as inert data, atelier consents independently again before analysis. Nothing became ambient in between. The findings come back clean, verification records the named checks that passed on the second delivery's exact outputs — and Mara records a review accepting that delivery against the same pledged terms.
Every distinction this page insists on — may, will, doing, did, checked, accepted — carries weight in exactly one of these moments. That is why the words stay separate.
Status · as of July 2026
A direction, shown honestly.
You are being invited into an architectural direction, not a polished fiction of maturity.
This page describes a proposed family architecture, not a shipped unified product. The three systems are at different implementation stages, summarized below.
What ships will say so precisely: the system advertises a capability only when its complete operation set, authority behavior, and failure semantics are ready — discovered by clients through system.describe(), never inferred from a version number. That is already real behavior, not a promise: kovee's governed-work bundle is implemented at nine of fourteen operations today, and is therefore deliberately not advertised at all.
The scenario ends with one accepted fix — on the second delivery. The first rejection, the crashed run and its ambiguous outcome, and Jun's dissent are still in the trace: who saw what, who committed, who authorized, who reviewed. Nothing was erased to get there.
Different minds. Shared work. Exact authority. Sovereign edges.
Kovee — together, without becoming one