Skip to content
497 linesCodeBlameRaw
1# g1t plan
2
3g1t runs your company: people and agents in teams, a forge where agents
4build, and everything else you install.
5
6Open g1t on the web, your desktop or your phone, and you're in your
7company's workspace. People and agents work side by side in channels, DMs
8and teams, and some teams are only agents. Hand work to an agent and it
9does it on a runner, with the skills it came with and the ones you've
10added. It comes back with something you can act on: a pull request to
11merge, a report, an email to approve. Today says what happened and what's
12waiting. Notifications collect everything waiting on you. Code and
13Deployments are built in, because agents build things. Anyone can build a
14tool, a report or an agent in a scratchpad without risking production.
15Everything specific to a business is an extension or an integration from
16the marketplace. g1t can be a whole company, or work alongside the tools a
17company already has. It's MIT-licensed: run it yourself, let us run it, or
18split it.
19
20This file is the plan of record. The docs at `apps/docs` describe what
21works; this says what g1t is becoming and in what order.
22
23## Where things stand
24
25g1t is in alpha. Every feature carries one label, here, in the README and
26in the docs:
27
28| Label | Means |
29| --- | --- |
30| **Live** | Works on g1t.sh for every workspace. |
31| **Preview** | Works on g1t.sh, but is limited to some workspaces or unfinished. Its guide says how. |
32| **Coming** | Planned, not built. No page promises it works. |
33
34A label moves from Coming to Preview to Live in the same change that makes
35it true, with the docs. User-facing text never describes how a feature
36used to work.
37
38## The shape
39
40| Layer | What's in it |
41| --- | --- |
42| Surfaces | g1t.sh on the web, the desktop app, the phone app, MCP at `mcp.g1t.sh`, Slack and Teams |
43| Built in | Today, Chat and Notifications, People and teams, Agents and `@g1t`, Artifacts, **Code**, **Deployments**, Spend, Identity and SSO |
44| Extension contract | Installs and scopes (OAuth 2.1 apps), UI slots served from g1tusercontent.com, tools (MCP), events and webhooks, workspace data, agent roles and skills |
45| Extensions | Official, verified, community, and internal (promoted scratchpads) |
46| Runs on | Runners (g1t cloud, the runner binary anywhere, the desktop app), the model gateway (at cost, your keys, local models), storage (D1 and R2, or SQLite and S3-compatible self-hosted) |
47
48Built in means it ships with every workspace and the core depends on it.
49Everything else is an extension, including what g1t itself builds for
50support, recruiting, on-call or mail.
51
52## The shell
53
54Three surfaces that never blur together:
55
56- **The dock**: a floating, rounded bar down the left, with the g1t mark
57 at its top. Built-in items below it (Today, Chat, Notifications, Agents, Code, Artifacts), then only
58 the apps this person pinned, then the **Apps** launcher. Its foot holds
59 People, Workspace and the account menu, which also holds help, docs,
60 shortcuts and your profile. The dock is per person: nobody sees an app
61 they can't use.
62- **The in-context sidebar**: flat, on the background, belonging to the
63 current app. Its top row is the workspace: its logo, its name and the
64 switcher, with the collapse toggle beside them (Ctrl B). Where there is
65 no sidebar, or it is collapsed, the workspace's logo and name lead the
66 page header's breadcrumbs instead, so the g1t mark and the workspace's
67 logo are always both on screen.
68- **The page**: a rounded inset panel, always the brightest surface, with a
69 full-width header (sidebar toggle, breadcrumbs, search, actions).
70
71Today is the front page and has no sidebar. On phones and narrow browsers
72the dock becomes a bottom bar (Today, Chat, Notifications, Agents, Code,
73More); More opens a sheet with all apps, the Marketplace, pinned apps,
74People, Workspace and you; the sidebar becomes a drawer.
75
76The **Apps launcher** lists every app installed in the workspace that you
77can use, with search and a pin on each, and links to the Apps page and the
78Marketplace. Apps you lack access to show Request access. Anyone can
79browse the Marketplace; owners install; everyone else sends a request,
80which reaches an owner in Notifications.
81
82**Auth pages stand alone**: sign-in, sign-up, two-factor, password reset,
83email confirmation, invites, device and OAuth consent, and choosing or
84creating a workspace render with no dock, sidebar or header: the logo, a
85centred form and a footer of links. A signed-in person always sees the
86full app inside a workspace, including on public pages. A signed-out
87visitor on a public page sees a small public header.
88
89Workspace settings drop the second sidebar for a row of tabs and a
90settings search, with forms in a centred column.
91
92## Built in
93
94### Today
95
96With a fleet working all day, the first screen is a summary, not a chat.
97Today leads with one sentence about the day and one button for what's
98waiting. Then how much agent work was accepted the first time, with a
99strip where every mark is one of today's tasks; Needs attention, each row
100with what's at stake and its action; spend today, split the way it's
101billed; and one item g1t picked as the place to start, by a rule the guide
102states. Every number comes from a service; a section with no data says so.
103
104| Part | Status |
105| --- | --- |
106| The page, Ask g1t, Needs attention (Code, agents, notifications, chat), Start here | Preview |
107| Accepted first time and the task strip, from agents' pull requests and `revise` runs | Preview |
108| Spend today from the day's statement (UTC days) | Preview |
109| Work by source: Chat, Code, schedules, other agents | Preview |
110| Accepted or fixed for agent sessions (needs a review signal on a session) | Coming |
111| A per-pull-request outcome (changes requested, first pass) and `since` filters on sessions and runs | Coming |
112| Spend by day in the viewer's time zone; due dates on needs | Coming |
113
114### Chat and Notifications
115
116Channels, DMs and threads with people and agents as members. Mention an
117agent, or hand it work with `hand_off`, and progress shows in the channel
118and in Agents; the result comes back as a card you can act on (a pull
119request with Merge, a doc with Publish, an email with Approve). Outside
120email, production deploys and spend over budget wait for a person, in the
121card and in Notifications.
122
123| Part | Status |
124| --- | --- |
125| Channels, DMs, threads, mentions, rich text, live sockets, presence | Live |
126| Agents as members, `hand_off`, cards | Live |
127| Notifications feed, counts, browser push | Live |
128| Cards from extensions | Coming |
129| Push to the desktop and phone apps | Coming |
130| Agents answering in Slack and Teams | Coming |
131
132### Agents: one or forty
133
134A workspace can run on `@g1t` alone, the general agent that does
135everything. As work grows it hires specialists from the catalog. Each
136brings a role, skills, the tools it needs and a runner preference. `@g1t`
137knows all of them: ask it anything and it answers or brings in the right
138agent, and you stay in the conversation.
139
140| Part | Status |
141| --- | --- |
142| Definitions: role, responsibilities, voice, model routing, budget, autonomy | Live |
143| Templates to hire from (7) | Live |
144| `@g1t` orchestrator, DMs with any agent, `hand_off` | Live |
145| Memory at project and workspace level; sessions with live steps and cost; routines | Live |
146| Your own model providers (14), the AI Gateway | Live |
147| g1t's hosted models: open where billing is live or the workspace is listed in `HOSTED_AGENT_WORKSPACES` | Preview |
148| The catalog (about 40 specialists), installed like extensions | Coming |
149| Foundational skills in every agent: documents, research and the web, data, code, communication, files and media | Coming |
150| Memory editor; skills proposed from finished work, published after review | Coming |
151| Effort per agent (auto to max) | Coming |
152
153Skills never add permissions: a skill uses only tools the agent already
154has. Agents act with the lower of their own access and the asker's.
155
156### People and teams
157
158People sits in the dock's foot, because knowing who does what is how work
159gets routed. Teams can be mixed, people only or agents only. A team has a
160lead, a channel, a Code role, a storage level and a budget, inherited by
161everyone on it, and its agents know their teammates from the team page.
162
163| Part | Status |
164| --- | --- |
165| Members, roles, nested teams, invites, teams with Code roles | Live |
166| Directory of people and agents, profiles, reporting lines, local time | Coming |
167| Agent members of teams, all-agent teams, inherited policy | Coming |
168| Org chart | Coming |
169
170### Runners
171
172Every agent's machine is a g1t runner: one binary for Linux, macOS and
173Windows on x64 and arm64 that registers with a one-time token, installs
174itself as a service and only connects out. Use g1t's cloud runners (scale
175to zero, billed by the minute), run the binary anywhere (time on it is
176free), or let the desktop app act as a runner for tasks that need your
177computer, asking before each one.
178
179| Part | Status |
180| --- | --- |
181| Self-hosted runners for workflow jobs; g1t's sandboxes for agents, checks and the merge queue | Live |
182| Agents on any runner, by labels and per-agent routing rules | Coming |
183| Sessions that persist on the runner between tasks; an official agent image | Coming |
184| A runner inside the desktop app | Coming |
185
186### Code and Deployments
187
188Everything an agent makes ends up as code that has to be reviewed, tested
189and shipped, so Code and Deployments come with every workspace. It runs on
190Cloudflare: previews scale to zero, Workers have no cold starts, and
191container apps can be set to always on.
192
193| Part | Status |
194| --- | --- |
195| Repositories, git over HTTPS, issues, pull requests, reviews, why-blame | Live |
196| Checks, rulesets, CODEOWNERS, the merge queue, catch-up | Live |
197| Workflows from `.g1t/workflows` | Live |
198| Packages: seven registries and container images | Live |
199| Security: push protection, history scanning, dependency updates | Live |
200| GitHub import, mirroring, pushing back | Live |
201| A preview per pull request on g1t.page, production on merge, custom domains | Live |
202| g1t's agents on issues, outcomes planned into issues | Preview (hosted agents) |
203| Each preview with its own fork of the data | Coming |
204| Instant rollback, request logs, analytics per environment | Coming |
205| Framework detection; scale to zero or always on for containers | Coming |
206| Comments on previews that land on the pull request | Coming |
207| Git over SSH (needs inbound TCP on Workers) | Coming |
208
209**Code access.** Every workspace has Code, but not everyone has to see it:
210five repository roles, a base permission that can be None, teams, outside
211collaborators and a per-member switch that removes Code are live. A
212workspace setting that makes Code invite-only is Coming.
213
214**A finding that changes Deployments.** Workers previews share the same
215database and bucket unless each is bound to its own, so a preview would
216read and write production data. Every preview, scratchpad and agent test
217gets its own fork instead (see Storage).
218
219### Artifacts
220
221Things people and agents make together: documents now; slides, designs and
222dashboards next; types registered by extensions later. Artifacts open in a
223panel beside any chat.
224
225| Part | Status |
226| --- | --- |
227| Documents: spaces, sharing, live editing, the artifact MCP tool, REST and scopes | Live |
228| Slides, designs, dashboards (contracts exist) | Coming |
229| Reports that keep the query and refresh time behind every number | Coming |
230| Types from extensions | Coming |
231
232The service is `services/docs` today and becomes `services/artifacts`,
233with a doc as one type. The Cloudflare git-store binding and workflow-run
234artifacts get names that don't collide. That rename touches Cloudflare
235resources, so it waits for an owner's go-ahead.
236
237### Scratchpads
238
239A tool, a report or an agent you get by asking. Each has its own
240repository in Code, its own fork of the data it needs, a small budget and
241hard limits: production is read-only, no customer messages, no money
242moving. When it's useful you ask for a review, which shows the code, the
243data it touches and the permissions it wants in one diff. After approval
244it becomes an internal extension. Status: Coming.
245
246### Storage
247
248Each team gets a level, and everything below production is a fork.
249
250| Level | What a team and its agents can do |
251| --- | --- |
252| Locked | Read-only views of production data. Reports only. |
253| Sandboxed | Masked forks of production, deleted after 14 days unless kept. |
254| Builders | Create databases and buckets for development. Production changes go through review. |
255| Full | Change production, with approval for anything destructive and an undo window. |
256
257D1 has no branching and R2 no bucket fork, so g1t builds forks itself:
258export, mask personal data and import into a new database per sandbox; a
259prefix per sandbox that reads from production and writes only its own
260copy. Neon is the first Postgres option, for its native branches. Promotion
261works like a deploy request: a schema and data-access diff, checks for
262conflicts and data loss, required approval, then an undo window. Status:
263Coming.
264
265### Spend
266
267| Part | Status |
268| --- | --- |
269| No seats; compute at cost plus 20%; agent runs at the model's price plus a flat agent rate | Live |
270| Budgets per workspace, agent and task; guardrails; spend limits; itemised invoices | Live |
271| Models at the provider's price with no markup; everything g1t runs at cost plus 20%; own runners, keys and local models free | Coming |
272| Budgets per person and per team; at a limit an agent asks, switches to a cheaper model, or pauses | Coming |
273| Task receipts; spend by agent, person, extension, channel or model | Coming |
274| A spend pill in the header: your own spend, or the workspace's for owners and billing admins | Coming |
275| Recommendations checked against past work ("same verdict on 39 of 40 reviews at medium") | Coming |
276
277Any change to prices or to how billing charges waits for an owner's
278go-ahead.
279
280### Workspaces and sign-in
281
282In the cloud you sign in once and pick a workspace at `g1t.sh/<name>`.
283Self-hosted, the instance runs one workspace or many. Everything inside a
284workspace belongs to its owners: OIDC or SAML, verified domains, SCIM,
285extensions, agents and models.
286
287| Part | Status |
288| --- | --- |
289| Accounts by invite, two-factor, access tokens (including use on the website), OAuth 2.1 apps with dynamic registration, device sign-in | Live |
290| Workspaces, roles, billing managers, the audit log | Live |
291| SAML and OIDC per workspace, SCIM, passkeys | Coming |
292| Self-hosted: one or many workspaces, chosen at setup | Coming |
293
294## Extend
295
296**Integrations add abilities. Extensions add pages.** An integration
297connects something a company already uses (Drive, Gmail, Slack,
298Salesforce) and gives agents new abilities without adding pages. An
299extension brings its own pages, data, cards, agent roles and skills, and
300can join several systems together.
301
302| Part | Status |
303| --- | --- |
304| Integrations: the GitHub App, Sentry, Datadog, Jira, Linear, alerts | Live |
305| The contract underneath: OAuth apps, 43 scopes, signed webhooks with retries, the event bus, MCP | Live |
306| Drive, Gmail, Calendar, Slack, Microsoft 365, each listing the abilities it gives agents | Coming |
307| The Marketplace, the Apps launcher's install flow, install requests to owners | Coming |
308| Mail: email on your own domain, shared inboxes agents work in, run by g1t | Coming |
309| Official extensions: Support, Recruiting, On-call | Coming |
310
311Decided for extensions:
312
313- **Two kinds launch together.** "Runs on g1t" extensions are hosted by
314 us. "Connected" extensions run on the publisher's own servers, with
315 declared domains, an install screen that says "Data leaves g1t to
316 acme.dev" and lists which data, UI in a sandboxed frame from the declared
317 domain, every call in the audit log, a budget and rate limit per install,
318 health checks, and a kill switch for the workspace and for us.
319- **Shared like Actions.** An extension is a public repository on g1t with
320 a manifest. Tagging a release publishes it; its README is the listing.
321 Installs pin a version; updates are offered, never forced.
322- **Free at launch, ready for paid.** Listings carry an empty pricing
323 field and installs record a plan, so paid listings later are billing
324 work, not a schema change.
325- **Community server code waits for the sandbox**: its own dispatch
326 namespace on the Workers for Platforms setup Deployments already uses,
327 an outbound Worker that enforces declared domains, CPU and subrequest
328 limits, and no bindings except the g1t API. Self-hosted, workerd
329 isolates. Until then community extensions publish UI, tools and
330 Connected backends.
331- **UI first.** Extensions, agents and settings are configured in the
332 product. A file in a repository is an optional mirror, kept in sync.
333
334## Everywhere
335
336g1t ships as three apps that behave as one. The desktop app is where you
337sit with the work: a global shortcut for a quick ask, the menu bar showing
338who's working, and a runner an agent can use with permission per task. The
339phone app is where you run the fleet: who's working, approvals with Face ID
340or a fingerprint, delegation by voice, task progress on the lock screen.
341Drafts, unread state and approvals sync; an approval taken on one device
342disappears from the others.
343
344- **Desktop: Tauri 2.** It links `crates/runner` directly, shows the web
345 app in a native window, and gets tray, shortcuts, notifications, deep
346 links and auto-update from plugins. CI renders on WebKit, WebView2 and
347 WebKitGTK. It uses the existing `window.g1tDesktop` bridge.
348- **Phone: Expo.** Native screens, one TypeScript codebase sharing
349 `packages/contracts`, push, biometrics, secure storage and over-the-air
350 updates. Lock-screen progress and widgets are small Swift and Kotlin
351 modules through the Expo Modules API.
352- Self-hosted servers send phone push through a g1t relay with end-to-end
353 encrypted payloads: the one piece a self-hoster can't run, a toggle in
354 "Who runs what".
355
356Status: Coming.
357
358## Run it your way
359
360The whole product is MIT-licensed and, as the goal, fully featured
361self-hosted: Docker, or the customer's own Cloudflare account, where it
362runs as g1t.sh does. Each part is "yours or ours" as a setting: runners,
363the model gateway, storage, phone push. Self-hosted with our gateway or
364runners costs the same as the cloud; fully self-hosted, we earn nothing.
365
366| Part | Status |
367| --- | --- |
368| The core forge in Docker Compose (`deploy/self-host`): repositories, push and clone, issues, pull requests, the API and MCP | Preview |
369| Agents through runners rather than in-server sandboxes | Coming |
370| Search, context and deployments self-hosted | Coming |
371| Setup in the browser, one workspace or many, "Who runs what" settings | Coming |
372| Deploy to your own Cloudflare account in one step | Coming |
373
374Self-hosting never makes the cloud worse: every Cloudflare-only binding
375sits behind an adapter, with the hosted path unchanged. The inventory and
376design are in [SELF_HOSTING.md](SELF_HOSTING.md).
377
378## Architecture
379
380| Component | Language | Responsibility |
381| --- | --- | --- |
382| `crates/contracts`, `packages/contracts` | Rust, TypeScript | Every service's interface, the event catalogue, shared types. Services depend on these, never on each other's code. |
383| `services/identity` | Rust | Accounts, workspaces, roles, teams, sessions, tokens, OAuth apps |
384| `services/repos` | Rust | Repository registry, contents, forks, diffs, landing, git over HTTPS |
385| `services/work` | Rust | Issues, pull requests, reviews, check runs, sessions |
386| `services/events` | Rust | The event bus and its log |
387| `services/billing` | Rust | Usage, the price book, limits, budgets, invoices, payments |
388| `services/actions` | Rust | Workflows, runs, caches, self-hosted runners |
389| `services/security`, `services/packages`, `services/search`, `services/integrations`, `services/webhooks` | Rust | What their names say |
390| `services/chat`, `services/notify` | TypeScript | Chat and its sockets; Notifications, counts and push |
391| `services/agents` | TypeScript | Agent definitions, templates, desks, memory, routines, runs |
392| `services/docs` | TypeScript | Artifacts (becomes `services/artifacts`) |
393| `services/runner`, `crates/runner` | TypeScript, Rust | Sandboxes; the runner binary |
394| `services/projects`, `services/deployments`, `services/pages` | TypeScript | Projects, builds and previews, serving g1t.page |
395| `services/models`, `services/context`, `services/og` | TypeScript | The model proxy, the context hub, social cards |
396| `apps/web`, `apps/docs`, `apps/api`, `apps/status`, `apps/sudo` | TypeScript, Rust | The site, the docs, REST and MCP, the status page, staff tools |
397
398How they fit:
399
400- **Each service is its own Worker with its own database.** Callers reach
401 it through a typed RPC binding to its interface in the contracts.
402- **Expected failures are values.** Every call returns a `Result`.
403- **Side effects travel as events.** A service publishes what happened and
404 doesn't call others to react; each subscriber has its own queue.
405- **Every read takes the viewer.** The service that owns the data decides
406 who may see it.
407- **APIs are snake_case** in request and response bodies, webhooks and MCP
408 results, converted at the edge.
409- **Ids are TypeIDs**: a prefix naming the kind of thing, then a UUIDv7 in
410 lowercase base32, made by the service that creates the record.
411
412Domains: g1t.sh for the app, API and MCP; g1t.page for deployments and
413hosted scratchpads; g1tusercontent.com for uploads, raw files, avatars and
414extension UI; models.g1t.sh for the gateway.
415
416The new pieces land here:
417
418| Workstream | Where the work lands |
419| --- | --- |
420| Shell: dock, sidebar, panel, Today, Notifications, phone bar, standalone auth | `apps/web` (`components/rail.tsx`, `shell.tsx`, `mobile.tsx`, `lib/workspace-nav.ts`) |
421| Marketplace and installs | New `services/extensions`; contracts in `packages/contracts` and `crates/contracts`; builds on OAuth apps in `services/identity` |
422| Agent catalog and hiring | `services/agents` (`templates.ts`, `definition.ts`) |
423| Spend | `services/billing` (`budget.rs`), `services/models` (effort per agent) |
424| Runners as agent machines | `crates/runner` (`harness.rs`, resume), `services/runner`, the agent image |
425| Extension UI slots | The `apps/web` shell, plus a bridge for frames on g1tusercontent.com |
426| SSO and SCIM; teams with agent members | `services/identity` |
427| Artifact types, reports | `services/docs`, renamed `services/artifacts` |
428| Storage forks and masking | New `services/storage` (D1 export, mask and import; R2 prefixes; Neon branches) |
429| Scratchpads | `services/repos` and `services/work`: a repository per scratchpad, review as a pull request with a data and permissions diff |
430| Agent builder and tests | `services/agents`: instructions, per-tool limits, test runs on forks, required review |
431| Mail | New `services/mail` |
432| Integrations | `services/integrations` |
433| Desktop app | New `apps/desktop` (Tauri, bundles the runner) |
434| Phone app | New `apps/mobile` (Expo) |
435| Docs | `apps/docs`, in the same change as each feature |
436
437## Build order
438
439Each stage leaves g1t.sh working.
440
4411. **Alpha.** The docs, README and site describe g1t as this product with
442 every feature labelled. The shell: dock, in-context sidebar, page panel,
443 Today, Notifications, the phone bar and More sheet, standalone auth
444 pages. Code with Deployments and Packages in its sidebar. The Apps page
445 and launcher over what's installed. Then the Marketplace page with
446 today's connectors as official listings, the agent catalog from the
447 templates with hiring, the Spend page over billing, and a Runners page
448 over self-hosted runners.
4492. **Launch.** Install records, the install screen, UI slots on
450 g1tusercontent.com and the builder; Support, Recruiting and On-call as
451 the first official extensions; persistent agent sessions and the agent
452 image; SAML, OIDC and SCIM; the desktop and phone apps; the memory
453 editor, learning with review, slides and dashboards; storage forks;
454 pricing at cost plus 20% with models at provider price.
4553. **Next.** Verified publishers, then community extensions; workspace
456 data collections and database bridges; scratchpads promoted to
457 extensions; self-hosting with agents, deployments and search; agents in
458 Slack and Teams.
4594. **Later.** Revenue share for publishers; agents with their own email
460 addresses and phone numbers; hand-offs across workspaces; confidential
461 runners for regulated teams.
462
463## Decisions
464
465- **MIT, all of it.** Open source and self-hostable, or we run it.
466- **g1t is the name.** Code and Deployments are built in; everything else
467 is an extension. Flagon, Inc. makes it.
468- **Code access is configurable**: open, invite-only or read-only, on the
469 roles that exist plus an invite-only switch.
470- **Agents work on runners**: g1t cloud, the binary anywhere, or the
471 desktop app.
472- **Self-hosting is fully featured and hybrid**: every part can be yours or
473 ours.
474- **Tauri 2 for desktop, Expo for phones.**
475- **Pricing**: models at provider price, everything g1t runs at cost plus
476 20%, no seats, own runners, keys and local models free.
477- **Notifications** is the built-in place for what's waiting on you;
478 **Mail** is an official extension.
479- **People and teams are front and centre**, and agents know their
480 teammates.
481- **Every agent ships with foundational skills.**
482- **Connected extensions at launch**, shared like Actions, free, ready for
483 paid, with a sandbox for community server code later.
484- **The dock is per person and its own surface**; the Marketplace isn't in
485 it.
486- **Auth pages stand alone**, and the full app is always inside a
487 workspace.
488- **Before anything risky, ask**: deploys, migrations on live data,
489 renames that touch Cloudflare resources, and anything that changes
490 billing.
491
492Open:
493
494- How the agent catalog is curated and versioned once publishers can add
495 agents.
496- Which official extensions follow Support, Recruiting and On-call.
497- The phone push relay's pricing for self-hosters.