Skip to content

Repository files navigation

TOWER — the control tower for your coding agents

One resident mind above Claude Code, Codex, opencode, zcode — holding every session, the machine's own vitals, and the disk's actual record in a single attention state. It clears what's safe. It says wait to what isn't. And when you grant it the writ, it presses tab so you don't have to.

Product page: accessintellect.com/tower · opnaorta.ai/tower — substrate: fusor1.com — thesis: the reactor you can talk to

Status — REV 0.1 · T0 complete, H0 in progress — honestly labeled

The skeleton runs. T0 closed 2026-08-16; the cortex was extracted from the FUSOR-1 reference build on 2026-08-17 and runs on real weights on this box. What is true today, per the estate's law — measured, or labeled a bet:

  • towerd --selftest — tail → ring → floor → hash-chained ledger → verify() localizes a planted tamper. PASS end-to-end; ctest green, 8/8 (ring, blake2b, ledger, floor, hook, fswatch, vitals, format).

  • towerd --watch — the H0 shadow: tails live Claude Code transcripts + tick onto the tape, model-free floor beside them. Surfaces nothing, blocks nothing.

  • towerd --judge — the fence, live over HTTP hooks: a PreToolUse-shaped POST gets floor ∧ resident (rm -rf → DENY, clean → SILENT); verdict + operator-facing detection on the tape; model-load failure ⇒ floor-only with the ABSENCE ledgered.

  • towerd --think — the resident on real weights: the 9B loads in ~3.8 s on an RTX 4070 Ti SUPER and answers a constrained verdict probe in 30–33 ms (TOWER-measured, 2026-08-17).

  • towerd --soakthe H0 shadow soak, running on the reference box since 2026-08-17: fleet-wide Claude Code HTTP hooks POST every prompt, narration chunk, and tool boundary to one resident loop (hooks + fswatch + vitals + tick, single cortex/ledger caller); every boundary is probed at dial 0 and ledgered shadow:true with margin, latency, and the exact envelope H1 would have sent — and the wire always answers SILENT. WATCH blocks nothing.

  • The trunk molts (v1, TOWER-measured): at capacity the board folds — prologue + pinned verdict-spans + verbatim tail survive, chatter drops — 4,064 → 2,069 tokens in 383 ms on the 9B, post-molt probe healthy; every fold is a MOLT tape event, and a fold that didn't decode is a ledgered ABSENCE, never trusted.

  • train ≡ serve holds (F-FORMAT, D-T14): the probe serves the tune's byte-exact format — captured from the reference build's live serve, pinned as per-element blake2b hashes by two independent surfaces, asserted at startup (drift ⇒ the cortex refuses to serve, the drifted element named; tune/tower.fingerprint is the receipt). Margins are signed and carry the trained calibration: on the smoke board, rm -rf emits at +5.06 where the untrained format held, routine narration holds at −3.56.

  • Not yet: the parallel command-hook fallback · cryptographic signing of the policy file (the declared-roots policy itself is live, blake2b-hash-ledgered at startup) · the rolling dual-trunk molt (v1 is a ~0.4 s blocking fold) · the novel-lane confound metric (pct_boundaries_with_novel_lane_types) that must ride beside any quoted margin · the verdict tune itself (gate 0, F-VISE, before a training dollar — TUNE.md) · the H0 exit numbers (F-KEEPUP@N, fires/hr, first live catch). Rungs are earned by the ledger; no rung past T0 is claimed.

  • TOWER_ARCH_SPEC_v2_UNIFIED_2026-08-16.mdthe canonical spec: reconciles DESIGN.md v0.1, the Supervisor platform findings, and the NEWTOWERSPEC governor into one, provenance-tagged, with a reconciliation ledger.

  • ROADMAP.md — rungs as build phases with exit criteria + the §Decisions log.

  • DESIGN.md — the v0.1 architecture narrative the unified spec grew from.

  • TUNE.md — the verdict-disposition tune: recipe, corpus fences, and the falsifier battery that gates it (F-VISE runs before a dollar is spent on training).

What it will be

towerd            a resident Windows service: every harness stream + machine vitals +
                  filesystem reality, ingested onto ONE shared attention state (9B-class
                  open weights on your own RTX; 27B-class on 24–32 GB, same binary)
the scope         one glass surface: every session, its state, its burn, its last verdict —
                  and a proposed next input awaiting one tab
the ledger        append-only, hash-chained, local: every action, every verdict, every
                  override. "What did the agents do, and who approved it" = a file.

Verdict vocabulary: SILENT · FLAG · ASK · DENY. There is no "allow" — by construction, TOWER can only ever narrow what your harness config already permits.

The ladder: watch → contest → advise → drive — each rung earned by the ledger of the rung below it, never skipped to. The last tab you press is the writ.

Build (true today)

cmake -S . -B build -G "Visual Studio 17 2022" -A x64
cmake --build build --config Release
ctest --test-dir build -C Release
build\Release\towerd.exe --watch    # rung zero: sees everything, touches nothing

Requires Visual Studio 2022 (C++ workload). C/C++20, deps vendored, no package manager. Windows 10/11. GPU optional: the cortex auto-enables when llama.cpp import libs are vendored under third_party/llama.cpp (DLLs delay-loaded at runtime); without them the same tree builds and runs floor-only. One NVIDIA RTX card for the resident (16 GB → 9B-class weights; 24–32 GB → 27B-class).

Doctrine (non-negotiable)

  • C/C++ only. No managed runtime anywhere in the product.
  • Local spine. Runs whole with zero network. Your sessions never leave this machine. The optional deep tier is your own key, text-only egress, through a local privacy filter, behind your toggle — remove the key and the full product remains.
  • Never "allow." TOWER writes no code, runs no tasks, and can only narrow permissions.
  • Split verdicts. The agent sees the constraint; only you see the detection that fired. A naive supervisor trains its agents to hide; TOWER is built not to.
  • The ledger is the trust mechanism. Hash-chained, local, yours. Every rung is earned by the ledger of the rung below.
  • Bare-metal hot path. SPSC rings between threads; one thread owns the GPU.

Lineage

TOWER is a fit of FUSOR-1 — the open resident-kernel substrate (the loop, the bus, and the laws) — pointed at the operations seam. Same engine as PROMPTER (the meeting seam), aimed at your agents. The substrate's bench ratings (thought-boundary 0.97 vs 0.02 · ~44 ms probe · 13 µs abort · three seats at 1.208× · ≥98,304-token recall) are measured and receipted in the reference build's runs ledger. TOWER's own first numbers exist as of 2026-08-17 — the ~3.8 s model load and the 30–33 ms constrained verdict probe on this box's RTX 4070 Ti SUPER — and stop there: verdict margins stay uncalibrated until the byte-exact tune serve format is reproduced and assert-hashed at startup (F-FORMAT, D-T10). Inherited substrate ratings stay labeled inherited; TOWER quotes nothing its own tape can't back.

MIT · Bo Chen · claims in this repo carry receipts or say plainly that they don't.

About

The control tower for your coding agents — one resident mind above Claude Code, Codex, opencode, zcode: every session, the machine's vitals, and the disk's actual record in one attention state. Verdicts SILENT·FLAG·ASK·DENY — never allow. Watch→contest→advise→drive. C/C++20, local spine, hash-chained ledger, 9B on your RTX. FUSOR-1. MIT.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages