Recommended · coordinated path
StrataX
- Multi-engine routing + relearning loops
- Training-lab handoff from SAT outcomes
- Connect a StrataX API or activate the local harness
Checking StrataX…
Sign in - local account
Credentials are hashed on this PC. Stripe handles card payments; entitlements stay local so you can work offline after activation.
Existing Admin / demo users still work. Your browser may offer to save the password after a successful sign-in.
Review features and continue to secure checkout.
Access & privileges only — this hub does not monitor how users work.
Loading ops summary…
Account types are shown side by side. Check or clear a feature to control what each account type can access.
Privilege changes only (create, tier, suspend, keys) — never product usage.
Live fleet nodes from /api/admin/console. This is a status view, not a control surface.
Audit projection from /api/admin/console: integrity, recent events, and chain metadata only.
Accounts in grace or past grace (billing cycle only). No prompt or usage analytics.
.\scripts\run-builder-fleet.ps1
Exports are encrypted Flywheel backups, not plaintext databases. Restores are staged and run before the database starts on the next restart. Support bundles are redacted zips (versions/health) — they do not include prompts.
ENGINE // PERFORMANCE MONITOR
Interactive laboratory projection of the Trident Unified Core Engine (TUCE). Rotate and explode the map, inspect the 21-node role preset, or Switch to Region shell with real installed models packed inside each 3-D boundary. Anatomical names organize the engineering display. Complementary occupancy is nominated, not certified.
Flywheel orbit active. Open tools to tailor the canvas.
Tip: drag to move · pinch / scroll to zoom · double-tap to re-center · arrows/WASD pan · +/− zoom · 0 reset.
Loading durable agent states…
Loading accessible constellation timeline…
No measured events to scrub
No current event
Run Theatre loads measured route/load/generation/validator/repair/tool/artifact events only.
Measured total: …
Loading latency waterfall…
Loading RAM choreography samples…
Loading offload timeline…
Loading context pressure…
Load-time savings: …
Loading model residency timeline…
Loading provider residency…
Loading live model resource facts…
Read-only estimate; no provider call or runtime mutation.
Prompt, image, tool, retrieval, output, and workflow costs stay separate; estimates disclose their sources.
Read-only estimate; no provider call or runtime mutation.
Preview a model combination and concurrency policy. This never loads or unloads models.
No policy previewServer-owned policy; no automatic unload or concurrency change.
Read-only advice; no provider action was taken.
Loading route sankey…
Loading escalation ladder…
Loading repair tree…
Loading validation shield…
Loading trust report…
Loading trust report formula…
Operational improvement index, not an intelligence score.
Loading measured momentum...
Checking 20-outcome display gate…
Loading large model avoidance…
Loading cognitive bridge save…
Loading token treasury…
Loading local cost equivalent…
Loading quality per minute…
Loading quality per watt…
Loading context efficiency…
Loading recovery efficiency…
Loading first-pass yield…
Loading time to first validated outcome…
Loading activation completion rate…
Loading setup friction events…
Opt-in: off (default)
UnavailableLoading user-controlled activation analytics…
Loading ready and degraded capability counts…
Loading pack health and drift status…
Loading disk and memory actual vs planned…
Loading download and install time versus estimate…
Loading privacy posture indicators…
Loading model and tool health freshness…
Loading capability coverage map…
Loading recommended vs customized component comparison…
Opt-in: off (default)
UnavailableLoading optional System Uniqueness map…
Loading repair success and mean time to readiness…
Loading sample-task first-pass yield…
Loading accessible metric tables and exports…
Loading stability streak…
Loading model specialty cards…
Loading model XP/badges…
Loading agent contribution map…
Loading council diversity…
Loading council consensus…
Loading project knowledge map…
Loading citation coverage…
Loading tool activity…
Loading thermal/power strip…
Loading hardware headroom…
Loading usable memory…
Loading memory pressure and process usage…
Loading GPU and VRAM resources…
Loading storage throughput…
Loading host responsiveness…
Loading model load heatmap…
Loading task galaxy…
Loading prompt-to-artifact funnel…
Loading before/after comparison…
Loading benchmark leaderboards…
Loading what-changed diff…
Loading presentation/ambient…
Loading visualization a11y alternatives…
Loading timeline annotations…
Loading compare-two…
Loading alert thresholds…
Loading chart quality gates…
Loading metric/event schema…
Loading durable hub↔spoke pulses…
Loading visual research gates…
Formulas load from the server registry only.
Loading measured model badges…
MoA stages appear here when a cycle is active.
New here? Flywheel checks your PC, skips what you already have, and guides you to working AI agents — no terminal expertise required.
Local readiness overview
Loading your local activation status…
Loading…
Review-then-start · no auto-run
One reviewable sample-task plan per activated capability. Plans never auto-execute,
never invent readiness or latency metrics, and never grant tool authority.
Live durable start uses GET /api/activation-preflight then
POST /api/workflows/runs with require_preflight=true when
ready. When preflight is ready=false, durable Hub/MoA/sample start
stays blocked. Beginner can still open the no-download fake-provider demo path —
that is not Hub/MoA success.
Loading activation preflight…
Building sample-task plans…
Waiting for activated capabilities. Nothing has started.
Server catalog - Flywheel add-ons
Control and Verify stay included as non-removable safety foundations. Optional add-ons (Mesh, Company Operations, Sales/Marketing/CS, Finance/Legal/Ops, Agent Foundry, WordPress) resolve from the server catalog with SKU, price, dependencies, and evidence state. Preview never grants entitlements.
Loading foundations…
Loading server add-on catalog…
Measured observations only — not capability proof
Review readiness across infrastructure, models, tools, workflows, validators, integrations, safety, and project data. Each cell needs an explicit status label plus evidence label and source kind from caller-supplied observations. Unobserved dimensions stay unknown — Flywheel does not invent ready, degraded, missing, TTFT, savings, or health metrics here. Reviewing this panel does not grant permissions, start probes, or mutate local state.
| Dimension | Status | Evidence | Source |
|---|---|---|---|
| infrastructure | unknown | no_observation | none |
| models | unknown | no_observation | none |
| tools | unknown | no_observation | none |
| workflows | unknown | no_observation | none |
| validators | unknown | no_observation | none |
| integrations | unknown | no_observation | none |
| safety | unknown | no_observation | none |
| project_data | unknown | no_observation | none |
Advisory readiness matrix explanation only (FW3-RS-METRS-001). Existing activation and metric controls are unchanged.
Planning validation only — not benchmark execution
Review whether readiness or capability claims reference an actual certified benchmark run id, or are explicitly labeled unlinked or not_certified. Flywheel does not invent TTFT, scores, token savings, or other benchmark metrics on this panel. Metrics appear only when a claim links to a caller-supplied certified run record. Reviewing this panel does not queue benchmarks, grant permissions, or mutate local state.
| Claim | Kind | Linkage | Run id | Metrics |
|---|---|---|---|---|
| No claims loaded — linkage withheld until caller-supplied evidence arrives. | ||||
Advisory benchmark linkage explanation only (FW3-RS-METRS-019). Existing activation, metric, and benchmark controls are unchanged.
Opt-in customization inventory — not a quality score
Opt-in: off (default — map hidden)
Review how your setup diverges from recommended defaults across routing, models, packs, plugins, UI, privacy, automation, memory, training, integrations, safety, workflows, and profiles. Each row needs a measured setting key, divergence label, evidence label, and source kind from caller-supplied observations. This is a planning catalog only — Flywheel does not invent uniqueness scores, grades, rankings, or percentiles here. Reviewing this panel does not grant permissions or mutate local state.
| Area | Setting | Divergence | Evidence | Source |
|---|---|---|---|---|
| Opt-in off — enable System Uniqueness to catalog measured customizations. | ||||
Advisory customization inventory only (FW3-RS-METRS-013). Existing activation and metric controls are unchanged.
Declared relationships, not installed-state evidence
Loading declared capability relationships…
Think of Flywheel like a body: the Brain is your open-source models (thinking), and the Nervous System is the tools they use to act (search, code, files, browsers, vector DBs). Watch system performance on the Dashboard; install brains and tools here so agents can actually finish tasks.
More detail: docs/BRAIN_AND_NERVOUS_SYSTEM.md (also summarized under Help / Directory).
User-visible strings resolve through localization keys with pluralization and locale number/date formatting.
Live localization — loading…
Sets document dir and mirrors navigation/forms with logical CSS. Live resolves direction from locale or preference; Demo forces an Arabic RTL preview and never pretends to be a full translation.
Live layout direction — loading…
Typed DiagnosticCode / RepairAction / RepairPlan contracts. Additive only — existing Fix it and health controls stay put. One-click remedies require server authorization and checkpoint restore on failure.
diagnostics.v1
Repair Center — loading…
Turn system recommendations into previewable one-click Fix it actions. Default is Live evidence; Demo is illustration only.
Live Fix it — loading…
Read-only setup evidence. Sensitive-looking fields are redacted and long values are bounded.
Run a scan to load commands.
Run a scan to load paths.
Run a scan to load versions.
Run a scan to load manifests.
Run a scan to load health results.
Pick a starting point and Flywheel will open the matching workspace. You can change views anytime.
Choose one goal to get started.
Selecting a card only saves the goal and opens its existing workspace. It does not install, download, connect, read files, or grant permissions.
Chat with a local model using privacy-first defaults.
Plan, edit, test, and review code with Cursor-compatible tools.
Draft, revise, and extract structured information from documents.
Investigate questions with sources and reviewable evidence.
Create structured lessons, content plans, and validation checks.
Analyze images and visual interfaces with compatible models.
Create images with an approved local or connected backend.
Plan speech-to-text, text-to-speech, and audio workflows.
Explore tables, analysis, notebooks, and local ML workflows.
Use proof, solver, and high-precision numeric toolchains.
Design reviewable workflows, schedules, and integrations.
Connect a custom model, tool, client, or workflow.
Ready State defines action-agent capability as planning plus typed tools, policies, observations, validators, and approvals — not chat-only autonomy. Reviewing this help does not grant permissions, never starts agents or invokes tools, and never treats bare LAM or generic agent labels as sufficient. Approvals cannot be self-granted; tools remain deny-by-default.
Advisory action-agent capability catalog only (FW3-RS-AUTO-001). Existing automation controls are unchanged.
Ready State lists optional typed connector plugins for local files, Git, webhooks, email, calendars, databases, and n8n. All connectors are deny-by-default and disabled until explicit consent; network connectors also require egress consent and an approved opaque destination ref. Reviewing this help does not grant permissions, never opens the network, never fires webhooks or email, and forbids silent connector enablement.
Advisory typed connector catalog only (FW3-RS-AUTO-005). Existing automation controls are unchanged.
Ready State lists closed integration connectors for the Custom integration goal — OpenAI-compatible SDKs, Cursor, MCP clients, Continue, Aider, Open WebUI, AnythingLLM, n8n, and internal apps. Connector selection and credential setup are planning-only and deny-by-default. Reviewing this help does not grant permissions, never opens the network, never writes or returns secrets, and never invokes integrations. Raw tokens and passwords are rejected; scopes must stay within each connector ceiling.
Advisory custom integration connector selector only (FW3-RS-CUSTOM-013). Existing Hub controls are unchanged.
Ready State captures Customization Studio profile revisions as secret-stripped snapshots with operator notes and tags. History is append-only: metadata can be updated without rewriting a snapshot, and rollback restores a prior revision as a new head after confirmation. Reviewing this help does not grant permissions, never opens the network, never writes the host filesystem, and never stores plaintext secrets.
Advisory profile versioning only (FW3-RS-CUSTOM-016). Existing Hub controls are unchanged.
Ready State exports Customization Studio profiles as secret-stripped, Ed25519-signed envelopes. Import verifies the signature and digests, refuses residual secrets, and stays dry-run until confirmation. Reviewing this help does not grant permissions, never opens the network, never writes the host filesystem, and never stores plaintext secrets. Signatures prove authenticity only—not quality.
Advisory signed profile export/import only (FW3-RS-CUSTOM-017). Existing Hub controls are unchanged.
Ready State binds each typed automation connector to a closed least-privilege scope ceiling and plans opaque credential storage references. Reviewing this help does not grant permissions, never opens the network, never writes or returns secrets, and never invokes connectors. Raw tokens and passwords are rejected; scopes outside each connector ceiling fail closed. Default effect is deny.
Advisory connector credential scope catalog only (FW3-RS-AUTO-006). Existing automation controls are unchanged.
Ready State binds each automation tool to an explicit network mode (deny, local-only, or concrete domain allowlist) and a closed data-field read/write policy. Reviewing this help does not grant permissions, never opens the network or invokes tools, and forbids wildcard domains. Default network mode is deny; fields default to none.
Advisory per-tool policy catalog only (FW3-RS-AUTO-007). Existing automation controls are unchanged.
Ready State requires a completed side-effect-free read-only discovery pass before any automation write action can be enabled. Reviewing this help does not grant permissions, never opens the network or invokes tools, and never mutates resources. Discovery alone never enables writes; explicit write consent is required after valid discovery.
Advisory read-only discovery gate only (FW3-RS-AUTO-008). Existing automation controls are unchanged.
Ready State requires owner-scoped idempotency keys for mutating automation actions. Identical retries replay the prior result reference; key reuse with a different fingerprint is rejected. Reviewing this help does not grant permissions, never opens the network or invokes tools, and never mutates resources.
Advisory action idempotency gate only (FW3-RS-AUTO-010). Existing automation controls are unchanged.
Ready State requires an explicit human decision for financial, destructive, external-message, credential, and account automation actions. Models and agents cannot self-approve. Reviewing this help does not grant permissions, never opens the network or invokes tools, never stores secrets, and never executes actions.
Advisory sensitive-action human approval gate only (FW3-RS-AUTO-013). Existing automation controls are unchanged.
Ready State plans saga-style compensating steps for reversible automation actions (undo, restore checkpoint, or compensating call) in reverse forward order. Optional action kinds auto-classify reversibility; irreversible kinds such as send, hard delete, and publish never receive silent automatic compensation. Reviewing this help does not execute rollback, restore checkpoints, open the network, mutate files or Git, or grant approvals.
Advisory compensation/rollback planning only (FW3-RS-AUTO-012). Existing automation controls are unchanged.
Ready State maps each connector failure to a closed error type and a bounded retry policy. Reviewing this help does not grant permissions, never opens the network, never invokes connectors, and never starts retries. Auth, policy, validation, conflict, and configuration failures are terminal; transient network, timeout, unavailable, and rate-limited failures may retry with bounded backoff. Unknown codes fail closed as unclassified and non-retryable.
Advisory connector retry policy catalog only (FW3-RS-AUTO-011). Existing automation controls are unchanged.
Ready State defines notification connectors for completion, approval, failure, and resource alerts. Reviewing this help does not grant permissions, never delivers notifications, never opens the network, and never grants approvals. Local channels stay on-device; webhook and email require explicit consent, egress consent, and opaque destination allowlisting. Resource alerts accept measured evidence only and never invent metrics. Silent delivery is forbidden.
Advisory automation notification connector catalog only (FW3-RS-AUTO-016). Existing notification and automation controls are unchanged.
Ready State shows a digest-bound action plan preview with ordered steps, tools, risks, approvals, rollback, and completion criteria. Operators may edit allowlisted fields before approval; edits regenerate the digest and clear any prior approval. Approval needs explicit confirmation that matches the current digest. Reviewing this help does not grant permissions, never starts agents or invokes tools, and never opens the network.
Advisory action-plan preview explanation only (FW3-RS-AUTO-004). Existing automation controls are unchanged.
Ready State walks an action plan step-by-step in dry-run simulation mode and projects connector-level side effects (filesystem, webhook, email, schedule, n8n, and related kinds) without performing them. Results are explicitly labeled simulated; success metrics are never invented. Reviewing this help does not grant permissions, never fires webhooks, never writes files, never sends email, and never registers schedules.
dry_run_simulation with simulated=true and executed=falseAdvisory action dry-run simulation explanation only (FW3-RS-AUTO-009). Existing automation controls are unchanged.
Ready State runs six harmless local probes for dry-run simulation, sensitive human approval, authorized-execution readiness, idempotency replay, compensation rollback planning, and revoked-credential deny paths. Reviewing this help does not execute tools, open the network, write or return secrets, grant permissions, or invent delivery metrics.
Advisory automation readiness catalog only (FW3-RS-AUTO-021). Existing automation controls are unchanged.
Ready State runs twelve harmless local abuse probes for prompt-injected webhook, file, RAG, and connector content plus unauthorized automation tool escalation. Reviewing this help does not execute tools, open the network, grant permissions, write or return secrets, or invent delivery metrics.
guarded means every probe was blocked — never runtime execution proofAdvisory automation abuse-test catalog only (FW3-RS-AUTO-022). Existing automation controls are unchanged.
Ready State builds typed schedule plans for one-time, recurring, quiet-hours, and overnight automation using opaque task refs and explicit windows. Reviewing this help does not grant permissions, never registers cron jobs, never starts tasks, and forbids inline cron expressions and silent schedule registration. Quiet hours and overnight windows must be declared explicitly; registration stays blocked until operator approval matches the plan digest.
one_time, recurring, quiet_hours, overnighthourly, daily, weekly) — raw cron is forbiddenAdvisory schedule builder explanation only (FW3-RS-AUTO-014). Existing automation controls are unchanged.
Ready State evaluates caller-supplied integration health observations and token-expiry metadata for typed automation connectors. Reviewing this help does not grant permissions, never opens the network, never probes connectors, never refreshes tokens, and never invents health metrics. Expired tokens block until an explicit operator re-auth plan; silent token refresh is forbidden.
healthy, degraded, unhealthy, unknown, not_configured, token_expired, token_expiring_soon)token_ref plus expires_at — raw secrets are rejectedAdvisory integration health and token-expiry explanation only (FW3-RS-AUTO-017). Existing automation controls are unchanged.
Ready State defines an offline/local-only automation variant that keeps planning on-device. Reviewing this help does not grant permissions, never opens the network, never enables connectors, and never starts automation. While the variant is active, only local files and Git connectors are eligible; webhooks, email, calendars, databases, and n8n stay denied. Local actions remain plan-only until operator consent outside this help.
offline and local_only — both required when enabledlocal_files, git (consent still required)webhook, email, calendar, database, n8nAdvisory offline/local-only automation explanation only (FW3-RS-AUTO-019). Existing automation controls are unchanged.
Ready State ships five plan-only starter recipes: organize project files, run backups, generate report, execute tests, and notify. Reviewing this help does not grant permissions, never opens the network, never moves files, never writes backups, never runs tests, and never delivers notifications. Recipes stay local-first; webhook and email notify channels are denied for starter recipes. Confirmation only marks a plan ready — execution stays outside this help.
organize_project_files, run_backups, generate_report, execute_tests, notifyAdvisory safe starter recipe explanation only (FW3-RS-AUTO-020). Existing automation controls are unchanged.
Ready State builds an append-only action audit timeline and binds opaque artifact lineage from each automation action to inputs, tools, approvals, validators, and produced artifacts. Reviewing this help does not grant permissions, never opens the network or invokes tools, never loads artifacts, and never invents wall-clock completion or success metrics. Timestamps are caller-supplied only.
Advisory action audit and lineage explanation only (FW3-RS-AUTO-018). Existing automation controls are unchanged.
Ready State builds plan-only event-triggered workflow plans with explicit debounce/coalesce windows and fail-closed loop protection. Reviewing this help does not grant permissions, never starts workflows, never registers watchers, never opens the network, and never invents fire-count metrics. Self-triggers, chain cycles, excessive chain depth, and rate-limit breaches are blocked before any authorized executor may fire.
file_change, webhook, connector, schedule, workflow_completed, manualcoalesce_key until debounce_ms elapsesAdvisory event-triggered workflow explanation only (FW3-RS-AUTO-015). Existing automation controls are unchanged.
Ready State lists approved local ML inference adapters behind a closed manifest: scikit-learn classical models, ONNX Runtime artifacts, and approved PyTorch/TensorFlow inference. Reviewing this catalog does not grant permissions, never loads artifacts or deserializes pickle/joblib, and does not download weights or open the network. Explicit consent is required before any inference plan; prefer ONNX for untrusted distribution.
Advisory ML-inference catalog only. Existing data-science controls are unchanged.
Ready State records model-card metadata for classical ML artifacts: features, labels, preprocessing, output schema, caller-supplied metrics, training provenance, and license. Reviewing this help does not grant permissions, never loads weights or deserializes pickle/joblib, and does not invent accuracy or training completion. Distinct from LLM registry identity fields.
Advisory model-card metadata catalog only. Existing data-science controls are unchanged.
Ready State catalogs planning-only workflow scaffolds for six classical ML task types. Each template binds stage order to related DATA planners (ingest, split, preprocessing, evaluation validators, lineage). Reviewing this catalog never trains models, opens datasets, computes metrics, or invents accuracy — activation_ready stays false.
Advisory ML workflow template catalog only (FW3-RS-DATA-008). Existing data-science controls are unchanged.
Ready State catalogs Jupyter notebook scaffolds (EDA, sklearn training, ONNX inference), Python scripts (tabular ingest, sklearn pipeline, DuckDB analytics, ONNX batch infer), and multi-file starter projects with content digests. Reviewing this catalog never writes files, installs packages, executes notebook cells, or starts training.
Advisory data-science template catalog only (FW3-RS-DATA-013). Existing data-science controls are unchanged.
Ready State plans CSV, TSV, Parquet, JSONL, and Feather ingestion from source descriptors and sample cell values you supply — inferring schema, applying deterministic type cleaning, and returning a bounded labeled preview. Reviewing this help does not grant permissions, never opens files or loads frames, and does not present sample-derived types as measured profiler output. Silent full-dataset materialization is forbidden.
Advisory tabular ingestion catalog only (FW3-RS-DATA-006). Existing data-science controls are unchanged.
Ready State plans bidirectional tabular interchange for CSV, JSON (always), Parquet and DuckDB (when optional local stacks are declared), and Excel only after an openpyxl-compatible license acknowledgement. Reviewing this help does not grant permissions, never opens or writes files, and never starts DuckDB. Missing dependencies or missing Excel acknowledgement fail closed. Planning-only catalog — not activation-ready.
Advisory tabular import/export catalog only (FW3-RS-DATA-014). Existing data-science controls are unchanged.
Ready State plans train, validation, and test (holdout) partitions from row identities you supply — default 70/15/15 — and surfaces leakage warnings before any authorized training step. Reviewing this help does not grant permissions, never opens datasets or trains models, and does not invent accuracy metrics. A held-out test set is required; fit preprocessing on train only.
Advisory split and leakage catalog only. Existing data-science controls are unchanged.
Ready State catalogs six classical-ML workflow templates — classification, regression, clustering, anomaly detection, forecasting, and ranking — each with required columns, holdout stages, and DATA-010 primary metrics. Reviewing this help does not grant permissions, never opens datasets or trains models, and does not invent accuracy. Planning consent is not runtime authority; objective libraries alone compute metrics under an authorized executor.
Advisory classical-ML workflow template catalog only (FW3-RS-DATA-008). Existing data-science controls are unchanged.
Ready State assesses caller-supplied row, column, and dtype metadata against fail-closed resource limits and plans bounded sampling previews for large tabular datasets. Reviewing this help does not grant permissions, never opens files or loads frames, and does not present labeled memory estimates as measured meters. Silent full-dataset load is forbidden; full load requires an explicit discouraged acknowledgement.
Advisory dataset resource-limit catalog only (FW3-RS-DATA-015). Existing data-science controls are unchanged.
Ready State checks that measured metrics you supply are appropriate for the declared task type — classification, regression, clustering, anomaly, forecasting, or ranking — and meet explicit baselines. Reviewing this help does not grant permissions, never computes accuracy from predictions, and does not invent scores. Objective libraries alone compute metrics; evaluation must use validation, test, or holdout — never the training split.
Advisory model-evaluation validator catalog only (FW3-RS-DATA-010). Existing data-science controls are unchanged.
Ready State summarizes caller-supplied column and row evidence into missing-value, outlier, duplicate, and drift reports — plus an aggregate data-quality rollup. Reviewing this help does not grant permissions, never opens datasets or profiles tables, and does not invent completeness or accuracy scores. Insufficient evidence withholds a section; drift requires an explicit baseline.
Advisory data-quality catalog only (FW3-RS-DATA-011). Existing data-science controls are unchanged.
Ready State lists approved local explainability adapters behind a closed manifest: scikit-learn permutation and tree importances, SHAP tree/kernel explainers, and LIME tabular surrogates. Reviewing this catalog does not grant permissions, never loads models or datasets, and never presents importance scores as ground truth. Explicit consent and a limitations acknowledgement are required before any explainability plan; all scores are estimates only.
Advisory explainability catalog only (FW3-RS-DATA-012). Existing data-science controls are unchanged.
Ready State binds encoder and masked-language (MLM) models into dedicated embedding and classification roles — never by reusing the generative chat model. Reviewing this help does not grant permissions, never loads models or trains heads, and does not invent accuracy metrics. MLM and encoder artifacts are feature and classification workers, not default chat models.
encoder_embedding — dense vectors / feature extraction from encoder or MLM artifactsencoder_classification — sequence, token, NER, or fill-mask classification headsAdvisory encoder/MLM role catalog only (FW3-RS-DATA-017). Existing data-science and chat controls are unchanged.
Untrusted distribution should prefer ONNX or other safer portable formats. Native pickle, joblib, and framework weight formats require explicit trust acknowledgement before planning — the Hub never deserializes or silently loads artifacts. Planning trust is not runtime authority.
Advisory format preference policy only (FW3-RS-DATA-005). Existing data-science controls are unchanged.
Pickle and joblib can execute arbitrary code when loaded. Ready State plans imports only after you acknowledge that risk and confirm an isolation adapter (container preferred, isolated process fallback). The Hub control plane never deserializes pickle/joblib itself. Prefer ONNX for untrusted distribution.
Advisory safe-import policy only (FW3-RS-DATA-004). Existing data-science controls are unchanged.
Ready State captures ordered tabular preprocessing steps (impute, scale, encode, clip, select/drop/rename) with frozen fit parameters and a content digest so the same pipeline and rows always produce the same outputs. Reviewing this help never starts training, imports sklearn/pandas for side effects, executes arbitrary code, or opens the network.
Advisory preprocessing capture only (FW3-RS-DATA-009). Existing data-science controls are unchanged.
Ready State binds caller-supplied SHA-256 digests into a directed lineage graph: dataset hash → preprocessing pipeline → model artifact → metrics artifact → report. Reviewing this help never opens datasets, loads models, computes hashes from bytes, invents metrics, or grants compute authority.
Advisory artifact lineage planner only (FW3-RS-DATA-019). Existing data-science controls are unchanged.
Ready State runs four harmless local probes for small classification, regression, anomaly, and ONNX fixtures. Reviewing this help does not open datasets, train or load models, start ONNX runtimes, invent accuracy, write files, or open the network.
Advisory data readiness probes only (FW3-RS-DATA-021). Existing data-science controls are unchanged.
Ready State compares caller-supplied measured metrics for synthetic classification, regression, anomaly, and ONNX fixtures across Windows, Linux, and macOS using declared tolerances and fixture digests. Reviewing this help never trains models, opens datasets, starts ONNX runtimes, or invents accuracy. Host OS labels are metadata only — not multi-OS proof.
Advisory cross-OS reproducibility compare only (FW3-RS-DATA-022). Existing data-science controls are unchanged.
Ready State lets a code model draft pipeline sketches, scikit-learn Pipeline outlines, transform suggestions, and repairs from library errors — while sklearn, NumPy, pandas, SciPy, and ONNX Runtime remain the only sources of computed metrics and fit/transform outputs. Reviewing this help does not grant permissions, never executes generated code, never invents accuracy scores, and never lets a model alter library results.
Advisory pipeline code-assist catalog only (FW3-RS-DATA-016). Existing data-science controls are unchanged.
Ready State seals metrics from sklearn, NumPy, pandas, SciPy, or ONNX Runtime with a content digest, then lets a generative model summarize, interpret, caveat, or suggest next steps. Narration never recomputes, invents, or rewrites accuracy, F1, loss, or other library results. Reviewing this help does not grant permissions, start models, or mutate sealed metrics.
Advisory hybrid narration catalog only (FW3-RS-DATA-018). Existing data-science controls are unchanged.
Browse the recommended sample in Live mode. Switch to Demo explicitly before asking the fake provider. Fake output is always labeled and is not live inference; no model download or external network access is required.
Choose one preference. Saving it only guides later recommendations; it does not change network policy, enable egress, or connect a server. Every network or server action requires separate review and consent.
Choose one privacy preference. No network policy is changed.
Loading Privacy Beacon…
Open / classified total: Loading…
Loading Security Pulse…
Loading metric retention controls…
Choose one preference. This guides later recommendations; it does not start background work, use a microphone, or connect a client.
Choose one interaction preference. No action starts from this choice.
Choose one preference. This guides later recommendations; it never grants permission or starts an action.
Choose one risk preference. Read-only remains the safe fallback.
Categories only. Do not enter file names, paths, or content. Flywheel does not open or scan files from this preference.
Choose a size band and at least one broad file-type category.
Choose a broad answer only. Do not enter model names, versions, paths, credentials, or project content. Nothing is scanned from this choice.
Before any probe, review exactly what local discovery would check. A separate privacy preview and consent are still required.
This preview lists the only scopes a later consent-gated discovery pass may check. Opening it does not start discovery, contact the network, install assets, or grant permissions.
local_models — local model inventory candidates only, after separate consent.local_tools — local tool inventory candidates only, after separate consent.No discovery has run from this panel. Continue onboarding or open the separate discovery consent surface when you are ready.
Choose one broad answer. Nothing is scanned from this choice.
Automatic recommendations prepare a ranked plan for review; choosing this preference does not download or install models.
Choose a preference. Manual selection is the safe fallback.
Use the existing model catalog and selection cards. This path does not select, download, install, or bind a model.
No model is selected. Compatibility evidence remains a review-only preview.
Plans the smallest required, safety-approved stack (Minimal Foundation by default). Optional and advanced components stay out. This path does not download, install, or apply configuration; approve separately through existing install controls.
Choose a sample stack to preview. Nothing is downloaded or installed from this panel.
Immediate path for installed, healthy models, tools, and packs. It plans configuration without downloading, installing, or applying changes. Approve separately through existing activation controls.
Choose a sample inventory to preview. Nothing is scanned or changed from this panel.
Save a seven-day restart point. Its opaque bearer token is stored only on this device; the bounded server checkpoint does not include prompts, paths, credentials, or project content.
No restart point has been saved from this browser.
Preview licenses, network access, administrator rights, restart needs, and expected time for a sample plan. This does not install, elevate, restart, or record approval.
Choose a sample plan. Showing the summary does not install, elevate, restart, or record approval.
Preview the one-sentence reason for a model or tool recommendation. Learn more stays closed until you open it. This does not download, install, bind, or grant permission.
Choose a reason to see the one-sentence explanation.
Recommendations stay advisory. Acquisition, binding, and tool grants remain separate, approval-gated steps with digests and policy checks.
This panel never invents speed, quality scores, or readiness. It only explains why a candidate may appear.
Choose a model or tool reason. Learn more stays closed until you open it.
Choose one profile. Selection is stored locally and does not grant permissions, open the network, or start actions. Detailed permission classes arrive in the next safety task.
Choose a safety profile. Read Only is the safe fallback. Selection does not grant permissions.
These thirteen classes are the vocabulary for safety profiles. Reviewing them does not grant permissions, open devices, or contact the network.
file_read — File readfile_write — File writefile_delete — File deletecommand — Commandnetwork — Networkpackage_install — Package installgit — Gitsecrets — Secretsclipboard — Clipboardbrowser — Browsermicrophone — Microphonecamera — Cameraexternal_service — External serviceAdvisory catalog only. Runtime enforcement and project defaults remain separate safety tasks.
New projects start as read-only. Writes and commands stay denied until an explicit approval upgrades the project. This explanation does not create a project or grant permissions.
read_onlyAdvisory default plan only. Existing Create project controls are unchanged.
Candidate paths are resolved against the approved project root. Symlinks and Windows junctions that escape the root are denied. Reviewing these rules does not grant permissions or open files.
Advisory explanation only. Existing file and project controls are unchanged.
Each capability pack and project stack has a deny-by-default executable catalog. The effective allowlist is their intersection. Reviewing this catalog does not grant permissions and never starts a process.
Advisory catalog only. Existing run/test controls are unchanged.
Official tools must use argv arrays with shell disabled. Free-form shell strings and wrappers such as bash -c are denied. Reviewing this policy does not grant permissions or start commands.
shell=True is permanently deniedAdvisory policy explanation only. Existing tool controls are unchanged.
Tool runs use a deny-by-default environment allowlist. Secret-named keys are dropped, and secret-shaped values are redacted in evidence. Reviewing this policy does not grant permissions or start processes.
[REDACTED]Advisory explanation only. Existing env and tool controls are unchanged.
Official tools declare ceilings for time, output size, CPU, memory, child processes, and network. Network defaults to deny. Reviewing these limits does not grant permissions or start processes.
Advisory limit catalog only. Existing run controls are unchanged.
Ready State detects Docker, Podman, Windows Sandbox, and isolated-process adapters by PATH presence. Reviewing this catalog does not grant permissions and never starts a container, sandbox, or subprocess.
Advisory adapter catalog only. Existing sandbox controls are unchanged.
When container and Windows Sandbox runtimes are unavailable, Ready State uses a restricted local isolated-process profile with deny-default network and tighter ceilings. Reviewing this profile does not grant permissions or start processes.
Advisory fallback explanation only. Existing run controls are unchanged.
Ready State defaults to deny. Allowlists use exact hostnames only. Offline mode blocks every domain, including allowlisted ones. Reviewing this policy does not grant permissions or open the network.
Advisory network policy explanation only. Existing egress controls are unchanged.
Package installs require an exact package, version, license, and source preview. Approval needs confirmation that matches the preview digest. Reviewing this flow does not grant permissions or install packages.
Advisory approval explanation only. Existing install controls are unchanged.
Ready State plans digest-bound install, update, uninstall, and rollback transactions with ordered forward steps and compensating rollback steps. Operators confirm a matching digest before an authorized installer may proceed. Rollback planning fails closed when snapshots or compensating steps are missing. Reviewing this flow does not install, update, uninstall, roll back plugins, or open the network.
Advisory lifecycle-transaction explanation only (FW3-RS-PLUG-010). Existing plugin and install controls are unchanged.
Each plugin plans a unique dependency root with exact package/version/license pins. Shared mutable dependency state (global registries, module caches, shared site-packages) is denied by default. Operators confirm a digest-bound approval before an authorized installer may proceed. Reviewing this flow does not install packages, enable plugins, or open the network.
Advisory dependency-isolation explanation only. Existing plugin and install controls are unchanged.
Ready State catalogs two deny-by-default example plugins: a validator scaffold with no permissions and a tool scaffold requesting project read only. Each includes an SDK-valid manifest and Python planning source. Reviewing this catalog does not install plugins, write scaffolds to disk, execute handlers, enable plugins, grant permissions, or open the network.
Advisory validator/tool example catalog only (FW3-RS-PLUG-014). Existing plugin controls are unchanged.
Ready State catalogs offline marketplace repositories for air-gapped planning: mirror roots, digest-bound package indexes, categories, and resolution plans that map package identifiers to local relative paths. Reviewing this catalog does not download packages, install plugins, open the network, verify removable media, or grant install authority.
Advisory offline repository catalog only (FW3-RS-PLUG-022). Existing plugin and install controls are unchanged.
Ready State supports air-gapped marketplace plugin repositories: a local repository.json lists digest-bound plugin artifacts. Import planning verifies path containment and digests (and optional PACK-018 manifests) under approved roots. Reviewing or planning from this panel does not install, enable, or load plugins, open the network, fetch remote catalogs, or grant install authority. Installer media ZIP packs are verify-only transfer formats.
Advisory offline marketplace repository guide only (FW3-RS-PLUG-022). Existing plugin and install controls are unchanged.
Ready State catalogs local plugin marketplace metadata for discovery and planning: categories, illustrative screenshots, documentation links, labeled user-submitted reviews, and advisory compatibility notes. Reviewing this catalog does not install plugins, open the network, fetch remote assets, grant permissions, or present sample ratings as measured truth.
Advisory marketplace metadata catalog only (FW3-RS-PLUG-017). Existing plugin and install controls are unchanged.
Creator Studio lets creators import canonical assets, define compatibility, permissions, resources, provenance, license, pricing, support, and privacy commitments, run required validation, build reproducible creator-signed packages, preview listing policy, submit revisions, respond to findings, and issue recall or deprecation. Private drafts and signing keys stay isolated per creator. Publishing cannot self-certify, bypass quarantine, expand authority, or conceal dependencies. Offline, enterprise-private, and public workflows are supported with audit, rollback, and dispute evidence. Reviewing this panel does not publish packages, grant certificates, install assets, charge payment, or open the network.
Additive Creator Studio guide only (COG-CREATOR-001). Existing marketplace and catalog controls are unchanged.
Market operations sit on existing billing and entitlement authorities. Operators can record listing terms (price, tax evidence, fees, royalty splits), sales, partial refunds with seller clawback, disputes, chargebacks, payout holds, sanctions and jurisdiction checks, private negotiated catalogs, creator suspension, asset revocation, and support commitments. Financial records are append-only and reconcile with ordinary provider events. There is no in-memory wallet or custodial currency. Ranking stays commercially neutral; sponsorship must be disclosed. Reviewing this panel does not execute payments, grant entitlements, install assets, or open the network.
Additive cognitive marketops guide only (COG-MARKETOPS-001). Existing marketplace and catalog controls are unchanged.
Flywheel extends the existing marketplace for certified cognitive assets. Operators can filter by outcome, asset type, capability, compatibility, risk, price, offline availability, and certificate status, then review an install preview with exact dependency and resource totals, permissions, provenance, limitations, composition impact, and administrator policy. Equip, activation, update, rollback, revoke, refund, and recovery delegate to existing package-registry, entitlement, task, and audit authorities. Private, community, partner, and official channels remain distinct. Ratings never certify safety. Incompatible or high-risk assets fail closed or require explicit authorized review. Reviewing this panel does not install packages, grant entitlements, charge payment, or open the network.
Additive cognitive marketplace guide only (COG-MARKET-001). Existing marketplace and catalog controls are unchanged.
Ready State catalogs Python and TypeScript plugin developer SDK packages and scaffolds. Python is preferred for provider, validator, tool, vector, and workflow plugins; TypeScript is preferred for UI extensions. Reviewing this catalog does not install packages, write scaffolds to disk, enable plugins, grant permissions, or open the network. Scaffold plans stay dry-run until an authorized writer runs.
Advisory developer SDK template catalog only (FW3-RS-PLUG-012). Existing plugin controls are unchanged.
Ready State plugin manifests declare identity and version, publisher, deny-by-default permissions, a relative entry point, dependencies, input/output schema refs, and compatibility (hub, SDK, OS/arch, Python). Detached Ed25519 signatures bind the canonical digest to a publisher key—they prove publisher identity and integrity only, never quality or safety, and never grant install or execution authority. Reviewing this help does not install, enable, load, or execute plugins, and does not open the network.
Advisory signed-manifest contract only (FW3-RS-PLUG-002). Existing plugin controls are unchanged.
Ready State defines eleven closed plugin types: provider, model runtime, tool, validator, parser, vector store, workflow step, connector, notification, installer, and UI extension. Types are policy vocabulary only—they never grant install or execution authority. Reviewing this catalog does not install, enable, load, or execute plugins, and does not open the network.
Advisory plugin-type catalog only (FW3-RS-PLUG-001). Existing plugin controls are unchanged.
Marketplace plugins declare a closed trust level: official, verified, community-reviewed, unverified, quarantined, or revoked. Trust is policy metadata only—signatures prove publisher identity and integrity, never quality or safety, and never grant install or execution authority. Quarantine and revocation always override a higher declared level. Reviewing this catalog does not install, enable, or load plugins, and does not open the network.
Advisory trust-level catalog only (FW3-RS-PLUG-018). Existing plugin and marketplace controls are unchanged.
Ready State verifies signed plugin envelopes with detached Ed25519 signatures against caller-supplied publisher and official key rings. A valid publisher-ring signature yields publisher identity; an official-ring signature yields official identity. Unknown keys, bad signatures, and missing envelopes fail closed as none. Signatures prove publisher key possession and integrity only—never quality or safety—and never grant install or execution authority. Reviewing this help does not install, enable, load, or execute plugins, and does not open the network.
Advisory signature/identity verification explanation only (FW3-RS-PLUG-019). Existing plugin and marketplace controls are unchanged.
Ready State evaluates locally supplied revocation and emergency-disable lists offline. Each entry binds a plugin id and artifact digest to a closed severity and reason code. Matching entries block install and enable planning and supply revocation_listed evidence for trust levels. Reviewing this catalog never fetches remote CRLs, never installs or enables plugins, and never mutates installed plugins.
Advisory revocation/disable-list explanation only (FW3-RS-PLUG-024). Existing plugin and marketplace controls are unchanged.
Ready State catalogs two example plugin scaffolds: a math-tool adapter (tool kind) for local formal-math tooling, and a media-provider (provider kind) for local-only multimodal media with network denied and transient media. Reviewing this catalog does not install packages, write scaffolds, enable plugins, spawn solvers, load codecs, grant permissions, or open the network. Scaffold plans stay dry-run until an authorized writer runs.
Advisory math/media example catalog only (FW3-RS-PLUG-015). Existing plugin controls are unchanged.
Ready State provides a local, in-process conformance suite for plugins: manifest schema, closed permissions, network egress gates, sandbox deny defaults, high-risk approval, and no-secret fields. Embedded known-good and known-bad fixtures self-prove the harness. Reviewing this flow does not load or execute plugins, install packages, open the network, grant permissions, or invent coverage metrics.
Advisory plugin conformance harness explanation only (FW3-RS-PLUG-013). Existing plugin controls are unchanged.
Ready State keeps marketplace revenue-share and OEM commercial hooks disabled until security maturity and support maturity evidence both pass. Operators may declare accounting-only revenue-share basis points or OEM co-brand / attribution-preserving white-label / factory-pack hooks, but activation plans stay blocked when review, signature, trust, revocation, import preview, permission, crash/support bundle, or support-contact evidence is incomplete. Reviewing this catalog never executes payments, never grants entitlements, never installs plugins, and never opens the network.
Advisory revenue-sharing/OEM maturity-gate explanation only (FW3-RS-PLUG-025). Existing plugin, marketplace, and billing controls are unchanged.
Operators review a digest-bound four-section card: malware/static findings (caller-supplied verdicts only), exact dependency pins and licenses, plugin license class, and closed permissions with high-risk flags. Malicious or inconclusive malware verdicts, critical findings, unpinned dependencies, and prohibited licenses block. Copyleft/commercial licenses and high-risk permissions require acknowledgement. This review never runs antivirus, unpacks artifacts, invents scan metrics, installs plugins, or opens the network.
Advisory security-analysis explanation only (FW3-RS-PLUG-020). Existing plugin and install controls are unchanged.
Plugins request a closed permission set (project read/write, model invoke, vector access, network egress, process spawn, UI extend). Operators review each permission with risk labels, then confirm a digest-bound approval. High-risk grants (project write, network egress, process spawn) are flagged separately. Reviewing this flow does not grant permissions, install plugins, or open the network.
Advisory permission-review explanation only. Existing plugin and install controls are unchanged.
Before any authorized importer proceeds, operators review a digest-bound preview with five sections: code source (opaque reference only), requested permissions, network mode and domains, declared tool identifiers, and data-access scopes. Reviewing this preview does not import, install, enable, load, or execute plugins, and does not grant permissions or open the network.
Advisory import-preview explanation only. Existing plugin and install controls are unchanged.
Each plugin is bound to a deny-by-default network mode (deny, local-only, exact-hostname allowlist, or offline). Non-deny modes require the network:egress permission. Plugin allowlists cannot expand beyond host offline/allowlist restrictions. Reviewing this policy does not grant permissions or open the network.
Advisory plugin network policy explanation only. Existing egress and plugin controls are unchanged.
Plugin workers may run in isolated subprocesses using a versioned JSON-RPC 2.0 contract over stdio, Unix socket, or named-pipe transports. Plans require the closed process:spawn permission, digest-bound operator approval, and healthy worker state before invoke envelopes are accepted. Reviewing this contract does not spawn subprocesses, open network connections, install plugins, or grant permissions.
Advisory out-of-process contract explanation only (FW3-RS-PLUG-003). Existing plugin controls are unchanged.
Each plugin gets a deny-by-default sandbox (project-scoped filesystem/network/process, no secret inheritance) plus hard resource ceilings for time, memory, CPU, output, child processes, RPC byte sizes, and invoke timeout. Plans may only tighten within host ceilings; loosening the sandbox fails closed. Reviewing this catalog does not start processes, open the network, install plugins, or enforce OS cgroups.
Advisory sandbox/resource-limit explanation only (FW3-RS-PLUG-004). Existing plugin controls are unchanged.
UI extension plugins may only add non-security-critical Help panels, status text, or noncritical buttons. They cannot replace, remove, rename, relocate, regroup, hide, or disable security-critical controls such as auth, permissions, secrets, network policy, billing, install authority, or emergency disable. Reviewing this catalog does not mutate the live UI, install plugins, or grant permissions.
Advisory UI-extension boundary explanation only (FW3-RS-PLUG-016). Existing plugin and navigation controls are unchanged.
Plugin workers report health observations. Invoke time has a hard timeout ceiling. Crashes may plan a bounded restart; exhausting the restart budget or repeating failures quarantines the plugin until an operator acknowledges clearance. Reviewing this policy does not start or restart processes, open the network, or grant permissions.
Advisory health-runtime explanation only. Existing plugin and install controls are unchanged.
When a plugin worker fails, operators can assemble a local redacted crash/support bundle with identity, crash kind, optional health counters, stderr tail, recent events, and host versions. Secrets are scanned and redacted before write. Creating a bundle never restarts the plugin, never uploads, never opens the network, never includes prompts or project files by default, and never grants install or enable authority.
Advisory crash/support-bundle explanation only (FW3-RS-PLUG-023). Existing plugin and support-bundle controls are unchanged.
Ready State runs fifteen harmless local adversarial plugin probes for sandbox escape, plaintext or cross-plugin secret access, resource-ceiling denial of service, and hub event spoofing. Reviewing this help does not install, load, enable, or execute plugins; does not return secrets; does not open the network; and does not emit hub authority events.
Advisory adversarial-plugin explanation only (FW3-RS-PLUG-026). Existing plugin and install controls are unchanged.
Plugins receive opaque scoped handles (pluginsecrethandle:…) and backend secretref pointers only — never plaintext secrets or ambient environment inheritance. Each handle binds to one plugin, project, and secret alias with closed scopes (network_auth, connector_config, local_signing). Reviewing this gate does not return secret material, read the secret store, grant permissions, or open the network.
Advisory secret-handle explanation only (FW3-RS-PLUG-009). Existing plugin and install controls are unchanged.
Plugins bind closed data-access scopes (project files, vector index, project metadata) to one project root. File paths must stay under that root with optional relative prefixes; symlink or junction escape is denied. Reviewing this gate does not grant permissions, install plugins, read file contents, or open the network.
Advisory data-access-scope explanation only. Existing plugin and install controls are unchanged.
Before import, operators review five closed sections: code source (opaque local, marketplace, offline, signed, or scaffold reference), permissions with risk labels, deny-by-default network mode and exact-hostname domains, declared tool identifiers, and project-bound data-access scopes. Digest-bound acknowledgement marks readiness for an authorized importer only. Reviewing this preview does not grant permissions, install plugins, start tools, or open the network.
Advisory import-preview explanation only (FW3-RS-PLUG-021). Existing plugin and install controls are unchanged.
Developer package installs combine exact package/version/license approval with project lockfile awareness. Locked managers are preferred when a lockfile is present. Reviewing this gate does not grant permissions or install packages.
Advisory lockfile explanation only. Existing install controls are unchanged.
Destructive actions require both a fresh re-authentication window and an expiring confirmation challenge. Reviewing this gate does not grant permissions or mutate resources.
Advisory gate explanation only. Existing confirmation controls are unchanged.
By default, voice flows show an editable transcript after local transcription and before task creation. Correct the text, then confirm. This panel does not grant permissions, retain audio, or create tasks.
Language appears after transcription.
Confidence is labeled when the local engine provides it (not a statistical interval).
Advisory transcript review explanation only (FW3-RS-VOICE-005). Existing Hub Voice controls are unchanged.
Low-confidence, ambiguous, or potentially destructive voice commands enter a bounded clarity loop before task creation. Review or edit the transcript, select among candidates, or type a clear intent. This panel does not grant permissions, retain audio, or start actions.
Intent candidates appear here when multiple actions match.
Clarity loop is advisory only until a host wires live voice flows.
Advisory clarity loop explanation only. Existing Hub Voice controls are unchanged.
High-risk actions from voice require a visible summary acknowledgment and an exact typed confirmation phrase. Spoken yes alone is never enough. Reviewing this gate does not grant permissions or start actions.
Advisory confirmation explanation only. Existing Hub Voice controls are unchanged.
Optional local TTS can speak short status, question, completion, and error summaries. TTS stays off by default. A text alternative is always available. Reviewing this panel does not start playback and does not synthesize audio.
Summary text appears here when a voice flow produces a status, question, completion, or error.
Advisory TTS summary explanation only (FW3-RS-VOICE-011). Existing Hub Voice controls are unchanged.
Speech metrics report mean transcription confidence and correction rate only from observed sessions. Raw audio is not retained by default. Empty samples never invent scores. Reviewing this panel does not open microphones or store audio.
Mean transcription confidence: insufficient samples until observations arrive.
Correction rate: insufficient samples until observations arrive.
Advisory speech metrics explanation only (FW3-RS-VOICE-020). Existing Hub Voice controls are unchanged.
Voice Assistant recognizes voice-to-project, voice-to-run, cancel, pause, status, and approval commands from speech or typed text. Commands are plan-only until a host wires the durable Task engine. Approval never grants permissions alone. Reviewing this panel does not open the microphone or start actions.
Command catalog is advisory only until a host wires live voice flows.
Advisory control-command explanation only (FW3-RS-VOICE-019). Existing Hub Voice controls are unchanged.
Voice privacy controls how temporary recordings and transcripts are retained. Raw audio is not retained by default; temporary recordings delete after transcription unless you choose an explicit opt-in mode. Reviewing this panel does not open the microphone, retain raw audio, or delete data.
Privacy settings are advisory until a host wires live voice flows.
Advisory privacy explanation only (FW3-RS-VOICE-013). Existing Hub Voice controls are unchanged.
Temporary recordings delete by default after local transcription completes. Cleanup is plan-only until a host executor confirms; this panel does not open the microphone, retain raw audio, or delete files.
Temporary recording cleanup is advisory until a host wires live voice flows.
Advisory temp cleanup explanation only (FW3-RS-VOICE-014). Existing Hub Voice controls are unchanged.
Offline mode blocks cloud STT/TTS, network voice routes, and audio egress while keeping local-only capture, transcription, and TTS planning available. Reviewing this panel does not open the microphone, contact the network, or enable cloud voice.
Voice offline mode is advisory until a host wires live voice flows. Audio egress remains blocked.
Advisory offline-mode explanation only (FW3-RS-VOICE-015). Existing Hub Voice controls are unchanged.
Optional local history can keep recent voice commands for review. Sensitive tokens and light PII are redacted before anything is retained. History stays off by default and does not retain raw audio. Reviewing this panel does not open the microphone or start capture.
No redacted history entries yet.
Advisory history explanation only (FW3-RS-VOICE-017). Existing Hub Voice controls are unchanged.
Code-writing packs default to an isolated worktree (preferred) or AI branch before writes. Reviewing this default does not create worktrees or branches.
Advisory Git default explanation only. Existing Git controls are unchanged.
A stable snapshot becomes ready for an authorized executor only after every required validator reports passed evidence. Reviewing this gate does not create snapshots or mark them stable.
Advisory snapshot-gate explanation only. Existing Git controls are unchanged.
Change actions are preview, apply, revert, and rollback. Apply needs a diff preview plus passed validation and confirmation; revert needs an applied change; rollback needs a stable snapshot reference. Reviewing this flow does not write files or mutate Git.
Advisory change-action explanation only. Existing apply/revert controls are unchanged.
Automatic rollback is policy-gated: it applies only after a task fails and files were modified, and only with a stable snapshot reference. Reviewing this policy does not restore files or mutate Git.
Advisory rollback-policy explanation only. Existing recovery controls are unchanged.
git reset --hard and git clean against your existing working tree require an explicit loss preview and approval. Reviewing this gate does not run reset or clean.
Advisory working-tree gate explanation only. Existing Git controls are unchanged.
Anti-loop hashes cover outputs, patches, error signatures, and route states. When the same digest repeats at the limit, further attempts are blocked. Reviewing this detector does not execute tasks.
Advisory anti-loop explanation only. Existing run controls are unchanged.
When the same output or error signature repeats, Flywheel plans a progressive strategy shift (constrain, replan, swap tools, escalate route, compact context, request human, or stop) instead of free-repeating. Reviewing this planner never executes tasks or applies changes.
Advisory anti-repeat strategy explanation only. Existing run controls are unchanged.
Ready State plans a four-stage code loop: plan targeted edits, execute only through an authorized durable executor, run required tests, then repair within a hard attempt budget before success. Reviewing this help never applies patches, starts tools, or calls models.
Advisory code PETR explanation only. Existing code and run controls are unchanged. FW3-RS-FLOW-003
Ready State plans a four-stage document loop: retrieve local evidence, synthesize a draft, attach citations grounded in retrieved chunks, then validate citation and unsupported-claim checks before success. Reviewing this help never runs retrieval, calls models, or marks answers authoritative.
Advisory document RSCV explanation only. Existing document and run controls are unchanged.
Ready State plans MATLAB (matlab -batch) or GNU Octave (octave --no-gui) batch runs and classifies license, startup, and execution failures from captured output. MATLAB planning requires license detection plus explicit user action and proprietary-tool consent; Octave remains the ungated open alternative. Reviewing this help never starts MATLAB/Octave, probes license servers, or grants proof authority.
Advisory MATLAB/Octave batch explanation only. Existing run controls are unchanged.
Ready State plans cross-check workflows where SageMath or MPFR-style numeric results inform — but never substitute for — a subsequent Lean formal statement. Numeric evidence must pass validators (and dual Sage+MPFR agreement when required) before the formal stage unblocks. Reviewing this help never starts Sage, MPFR, or Lean, and never grants proof authority from numeric assist.
Advisory cross-check workflow explanation only. Existing run controls are unchanged.
Ready State catalogs proof templates (Lean, SMT-LIB2, DIMACS), scientific script templates (Sage, MPFR, Arb, Octave, Python wrappers), and multi-file starter projects composed from those templates. Reviewing this catalog never writes files, installs tools, runs solvers, or grants proof authority.
Advisory proof/script starter explanation only. Existing project controls are unchanged.
Formal-math anti-loop detection hashes proof artifacts, source files, and error signatures. After duplicate digests, Flywheel plans progressive strategy shifts (repair from feedback, replan proof, swap tool, escalate route, compact context, request human, or stop). A hard block applies at the repeat limit. Reviewing this detector never executes solvers or grants proof authority.
Advisory formal-math anti-loop explanation only. Existing run controls are unchanged.
Overnight proof mode bounds formal-math repair sessions with wall-time and attempt limits, a thermal exposure budget, checkpoint cadence, and quiet overnight notifications with critical escape and a morning digest. Reviewing this help never starts solvers, writes checkpoints, delivers notifications, or grants proof authority.
Advisory overnight proof mode explanation only. Existing run controls are unchanged.
Formal-math generation defaults to worktree isolation. Flywheel records content-addressed snapshots of declared Lean/SMT/DIMACS/Sage/script artifacts under approved roots, then restores or removes them only with verified isolation and explicit consent. Planning never creates Git objects; rollback never writes the primary branch or grants proof authority.
Advisory math-artifact snapshot explanation only. Existing run controls are unchanged.
Ready State math certification requires real captured tool exit codes and output plus task-specific validator classification matched to digest-bound benchmark expectations. Synthetic or simulated success cannot pass. Reviewing this gate never starts Lean, SAT solvers, Sage, MPFR, Arb, MATLAB, or Octave, and never grants proof authority.
Advisory math readiness certification explanation only. Existing run controls are unchanged.
A successful compiler or checker exit (code 0) certifies only the checked artifact that was validated — for example that a Lean file typechecked. It does not prove every informal claim in chat, notes, or marketing copy, and never grants absolute mathematical truth or proof authority.
Advisory proof-scope explanation only. Existing run controls are unchanged.
Ready State treats Latent Consistency (LCM) as a generation architecture/acceleration profile only — never as a universal model category or model family. Bare “LCM” labels stay ambiguous until mapped. Reviewing this help does not start backends or invent metrics.
Advisory policy only. Existing vision controls are unchanged.
Ready State exposes a consent-gated provider interface with two architecture profiles — diffusion and latent_consistency (LCM acceleration). LCM is not a unique model family. Plans bind approved local backends only. Reviewing this help never starts a backend, downloads weights, invents generation metrics, or opens the network.
Advisory provider interface only. Existing vision controls are unchanged.
Ready State plans three local Vision Understanding workflows: screenshot analysis, document-image analysis, and UI analysis. Each binds a route role, project-scoped image ref, checklist validators, and durable Task stages. Reviewing this help does not start a VLM, retain image bytes, invent visual metrics, or open the network.
Advisory workflow catalog only. Existing vision controls are unchanged.
Ready State binds classification and object detection to local-only adapters: VLM structured labels, TorchVision/PIL classifiers, ONNX detectors, YOLO-compatible detectors, and OpenCV cascade tools. Reviewing this catalog does not grant permissions and never starts a model, downloads weights, or opens the network.
Advisory adapter catalog only. Existing vision controls are unchanged.
Ready State binds Segment-Anything-compatible local segmenters (sam-service, segment_anything, MobileSAM, SAM 2, ONNX SAM) and validates structured masks plus metadata. SAM is not a chat model. Reviewing this catalog does not grant permissions and never starts a model, downloads weights, or opens the network.
Advisory segmentation adapter only. Existing vision controls are unchanged.
Ready State mask ops accept structured local masks (pixels, binary RLE, polygon, or bbox metadata). You can preview coverage, edit or combine occupancy, validate structure, and plan exports. Reviewing this catalog does not grant permissions and never starts a model, writes export files, or opens the network.
Advisory mask-ops catalog only. Existing vision controls are unchanged.
Ready State plans local OpenCV-compatible transforms such as resize, crop, rotate, flip, color convert, blur, threshold, and morphology, and computes measurements from structured geometry or samples. Reviewing this catalog does not grant permissions and never imports OpenCV, writes image files, or opens the network.
Advisory OpenCV-ops catalog only. Existing vision controls are unchanged.
Ready State plans local FFmpeg and ffprobe commands for media probe, transcode, remux, extract, scale, concat, mux, and slideshow assembly, and computes inspection summaries from structured stream/format descriptors. Reviewing this catalog does not grant permissions and never starts FFmpeg, writes media files, or opens the network.
Advisory FFmpeg-ops catalog only. Existing media controls are unchanged.
Ready State lists approved local image backends behind a closed manifest: ComfyUI, InvokeAI, Automatic1111/Forge, Diffusers local, and a generic image-backend binding. Reviewing this catalog does not grant permissions, never starts a backend, and does not download weights or open the network. Explicit consent is required before any generation plan.
Advisory image-backend catalog only. Existing generation controls are unchanged.
Ready State records prompt, seed, resolution, steps, and model identity for local image generation. Prompt text is digest-only unless you consent to retention. Reviewing this help does not start a backend, store image bytes, or open the network.
Advisory provenance explanation only. Existing vision controls are unchanged.
Ready State checks local image outputs for safety ceilings, allowed format, resolution, corruption, and bounded metadata. These are structural checks only — not a content-moderation oracle. Reviewing this help does not start a backend, retain image bytes, or open the network.
Advisory format, resolution, corruption, and metadata validation only. Existing vision controls are unchanged.
Ready State compares two vision artifacts with closed modes (side-by-side, overlay plan, difference summary, settings diff, metric table, mask overlap) using digests and metadata only. Reviewing this help does not store image bytes, invent SSIM/PSNR scores, start backends, or open the network.
Advisory visual comparison catalog only. Existing vision controls are unchanged.
Ready State compares vision and image-generation artifacts side-by-side using structured metadata (ids, digests, dimensions, provenance links) and keeps a project-scoped gallery of those references. Reviewing this help does not store image bytes, invent similarity scores, start backends, or open the network.
Advisory visual-compare and gallery catalog only. Existing vision controls are unchanged.
Ready State allocates multimodal context capacity for image-memory digests/refs and visual tokens, then runs a labeled resource preflight for decode working memory and context fit. Reviewing this help does not decode pixels, start models, retain image bytes, or invent measured TTFT/TPS.
Advisory image-memory/context budget only. Existing vision controls are unchanged.
Ready State plans bounded thumbnails and metadata preview cards for media batches so galleries can show small previews first. Reviewing this help does not decode pixels, start FFmpeg, write files, or invent measured transfer meters.
Advisory batch thumbnail/preview only. Existing vision controls are unchanged.
Ready State applies a deny-by-default privacy policy for vision and media: face identification and biometric enrollment are off, EXIF/GPS strip on export, local media stays project-scoped without byte retention or training use, and external uploads require consent plus an allowlisted destination. Reviewing this help does not decode media, start models, open the network, or act as a moderation oracle.
Advisory vision/media privacy policy only. Existing vision controls are unchanged.
Ready State ships Avatar Workflow Plugin and Media Workflow Plugin Pack as optional plugins, not core dependencies of Vision Understanding, Segmentation, Image Generation, or Media Processing. They stay disabled until explicit project-scoped opt-in and plugin SDK review. Reviewing this help does not enable plugins, start backends, download models, or invent capability metrics.
Advisory optional-plugin catalog only. Existing vision controls are unchanged.
Ready State compares caller-supplied VRAM, system RAM, GPU presence, and local media-toolchain evidence to labeled planning floors for local diffusion and video. Missing evidence yields unavailable warnings — never invented VRAM figures or speed claims. Reviewing this help does not probe hardware, start backends, download models, or open the network.
Advisory honest-capability warnings only. Existing vision controls are unchanged.
Ready State catalogs synthetic fixtures for UI inspection, document images, object localization, segmentation, and visual consistency. Cases use expected observation checklists only — no real photos, faces, or PII. Reviewing this help does not start models, invent perceptual scores, or treat captions as visual authority.
Advisory synthetic fixture catalog only. Existing vision controls are unchanged.
Ready State converts structured vision-workflow results (analysis plans and checklists, detections, masks, region annotations, comparison reports, and gallery lists) into plain text, ordered lists, tables, HTML fragments, and screen-reader summaries. Reviewing this help does not load image bytes, invent visual scores, start models, or replace existing visual controls.
Advisory nonvisual alternatives only. Existing vision controls are unchanged.
Ready State is local-first: optional remote VLM, image-generation, media-analysis, and OCR connectors stay off until explicit user consent, separate egress consent, an opaque destination allowlist entry, redaction, and a declared egress budget. Reviewing this help does not enable connectors, open the network, upload media, or start backends.
Advisory remote-connector policy only. Existing vision controls are unchanged.
Ready State runs five harmless local probes for image transport, segmentation masks, generation artifacts, FFmpeg conversion plans, and VLM reports. Reviewing this help does not start models or FFmpeg, write media files, open the network, or treat captions as visual authority.
Advisory vision readiness catalog only. Existing vision controls are unchanged.
Ready State runs six harmless local probes for indexing defaults, retrieval variant selection, citation inspection, retrieved-content isolation, deletion planning, and offline privacy gates. Reviewing this help does not start indexing or retrieval, purge files, open the network, or invent coverage metrics.
Advisory knowledge readiness catalog only. Existing knowledge controls are unchanged.
Ready State runs seven harmless local probes for recording controls, local transcription plans, transcript edit/review, typed-task intent extraction, clarity-loop resolution, cancellation planning, and optional TTS summaries. Reviewing this help does not open microphones or speakers, start STT/TTS backends, retain audio, submit tasks, or invent speech metrics.
Advisory voice readiness catalog only. Existing Hub Voice controls are unchanged.
Ready State budgets cover attempts, wall-time, tokens, model loads, thermal pressure, and tool calls. Reviewing these ceilings does not start models or tools.
Advisory budget explanation only. Existing run controls are unchanged.
After repeated errors, a compression plan may become ready only while preserving the current objective and evidence references. Reviewing this policy does not mutate conversation context.
Advisory compression explanation only. Existing chat controls are unchanged.
Ready State plans compaction intensity from the current workflow stage and model size class. Smaller models and repair stages compact more aggressively; validate and finalize preserve evidence. Retention targets are labeled estimates. Reviewing this planner never mutates conversation context or invents measured token savings.
Advisory stage×size compaction explanation only (FW3-RS-FLOW-014). Existing chat and run controls are unchanged.
Ready State inserts clarity nodes for ambiguous goals and approval nodes for high-risk, destructive, egress, privilege, irreversible, or install actions. Models and agents cannot self-approve. Reviewing this planner never executes tasks, grants permissions, opens the network, or invents metrics.
Advisory clarity/approval gate explanation only (FW3-RS-FLOW-016). Existing controls are unchanged.
Ready State visual workflow cards explain each prebuilt agent loop's stages, initial model role, deny-by-default tools, required validators, and limits (repair budgets, supreme thresholds, pack loop budgets). Reviewing these cards never starts workflows, grants permissions, binds providers, or invents metrics. Selection is advisory only.
Stages sense→plan→act→validate→finalize; role general; tools plan/observe; validators format/policy; bounded repair and pack budgets.
Stages action→observation; role code; tools tool_call/tool_result; validators tool_result/format; bounded repair.
Stages plan→execute→test→repair; role code; sandbox tools need approval; validators include test_pass and repair_budget.
Stages retrieve→synthesize→cite→validate; role general; citation and unsupported-claim validators required.
Stages extract→schema→validate→finalize; role general; json_schema and format validators; schema_rebind repair.
Stages vision→inspect→measure→report; role vision; consent/inspect/no_invented_scores validators.
Stages transcribe→clarify→act→confirm; role fast_chat; consent/clarify/confirm_before_act validators.
Stages formalize→solve→compile→prove; role reasoning; compile/prove/format validators.
Stages generate→render→inspect→refine; role general; inspect/format validators; refine_loop repair.
Stages plan→approve→execute→audit; role cognitive_hub; approval/audit/policy validators; human-gated.
Advisory visual workflow card catalog only (FW3-RS-FLOW-019). Existing run controls are unchanged.
Ready State plans overnight-safe variants of prebuilt agent loops using the overnight_restricted profile, SAFE-022 blocked actions, narrowed tool allowlists, and quiet notifications with critical escape plus a morning digest. Supreme escalation is deferred to morning review. Speech loops that need a microphone are not overnight-eligible. Reviewing this planner never starts workflows, delivers alerts, or grants permissions.
Advisory safe overnight flow variant explanation only (FW3-RS-FLOW-017). Existing run controls are unchanged.
The morning digest projects declared overnight outcomes into completed, failed, and blocked items plus resources, artifacts, validators, and next actions. Reviewing this help never executes tasks, delivers notifications, invents metrics, or expands overnight permissions. Results require evidence and artifacts when the durable runner declared them — not logs alone.
Advisory morning digest explanation only (FW3-RS-NIGHT-015). Existing overnight and run controls are unchanged.
Overnight mode prohibits new network domains, package installs, destructive actions, and main-branch writes. Reviewing these restrictions does not grant permissions or start actions.
Advisory overnight explanation only. Existing policy controls are unchanged.
Approval notifications for remote or mobile review use a content-bounded summary only. Reviewing this flow does not send notifications, open the network, or grant approvals.
Advisory notification explanation only. Existing approval controls are unchanged.
Safety events are structured records. The project-level policy simulator dry-runs outcomes for profiles such as read-only, ask-before-actions, and trusted-project. Reviewing this simulator does not mutate live policy.
Advisory audit/simulator explanation only. Existing policy controls are unchanged.
Ready State adversarial coverage includes path traversal, empty variables, command injection, symlink escape, plugin abuse, and rollback failure. Reviewing this catalog does not execute attacks or mutate resources.
Advisory adversarial catalog only. Existing security controls are unchanged.
Express Setup links existing review and verification controls; it never auto-approves, installs, downloads, or claims readiness.
Create a project, review recent workspaces, validation commands, memory index status, and activity. Existing menus stay unchanged.
Browse committed guides. Availability means the guide files exist; requirements and runtime readiness are not checked.
Choose Browse starter projects to load the local catalog.
Review only; nothing is created, installed, downloaded, or run.
Lightweight FTS is the default. Embeddings/vector and graph are checked only after you select one and are offered only when the Hub's current measured hardware meets the documented minimums. Checking does not start indexing.
Select a mode and check availability. No index work starts here.
Open this section to load recent projects.
Project-aware branch, status, diff, and validation/test projection from supplied evidence. Existing Projects controls stay unchanged.
Evidence-only; no invented metrics or repository mutation.
Search Hub settings, switch basic/advanced mode, and restore defaults per section. Existing Settings chrome stays unchanged.
No invented metrics; section reset restores catalog defaults only.
Demo samples use fake output, not live inference. No model download or external network access is required. Live lists the committed scenarios only; Demo runs the offline in-process fake provider.
The scenario uses only text you enter. It reads no project files, retains no prompt, and starts no download.
Live lists the sample. Switch to Demo to ask the fake provider (no download).
Optional product tours. Skip anytime, restart anytime. When a tour version changes, progress is marked outdated and re-offered. Existing menus stay unchanged.
Tours are optional. Progress stays on this browser; catalog versions re-offer after bumps.
Record and undo reversible settings, model, profile, and project changes. Destructive actions are not recorded. Existing controls stay unchanged.
Undo restores bounded before snapshots only; stack stays on this browser.
Loading official Ollama guidance…
Recommended one-click pack for Lite / 16 GB class machines.
Review the install, pull, setup, connection test, and first-task evidence path.
Review path not loaded.
Coding-intent one-click pack for Studio / 32 GB class machines.
Brain
Open-source models that think. Organize by type, size, usage, age, or recommendation. Click the body of a compact card for researched details; installed-model delete sliders remain separate controls.
Model not in the catalog? Discover and add unlisted models — available on Pro tiers and above (Lite & Studio see this message).
Nervous System
Open-source tools that let brains act — search, code, containers, RAG, automation. Flywheel detects what you already have so you don’t reinstall.
Live Tool Center — loading…
Scan lists tools only — it never grants access. AI use requires Accept or Deny per tool fingerprint. Missing license shows a warning; it does not auto-deny. Revoke clears a prior grant.
Limit autonomous file writes to approved paths under the selected repo root.
Declare allowed data roots before analysis prompts. Paths outside these roots are rejected.
Analytics SQL defaults to read-only. Enable write queries only when you need mutating statements.
Mode: read_only
Reasoning Layer
Boolean SAT/UNSAT work can run through StrataX (coordinated harness + relearning) or direct open-source solvers. The catalog below never silently installs binaries.
Recommended · coordinated path
Checking StrataX…
Open source · no paywall
StrataX opens the app when connected; otherwise the API setup panel appears so you can add it.
Paste your StrataX API base URL to install the remote connection. Prefer the local harness when you want the in-Hub app without an external service.
Run coordinated SAT/UNSAT loops and report outcomes into Training Lab. Local fallback stays available when the remote API is offline.
Send CNF clauses to StrataX or the local DPLL fallback.
Completed loops can be reported into Training Lab.
Always available without StrataX. Results require accept/deny before they become evidence.
No run yet. Results require your accept / deny before they become evidence.
Use a SAT solver for DIMACS CNF, a MaxSAT solver for weighted clauses, an SMT solver for theories such as integers or bit-vectors, and a proof checker when you need an independent UNSAT certificate check.
Optional capabilities
Turn on focused capability plugins when you want the AI to use them. Each plugin is a small, isolated microkernel contract that activates its declared dependencies; it does not grant permissions or bypass existing safety checks.
Loading optional capability plugins…
Hardware packs match your RAM band and edition. Workflow packs group models and tools by job — coding, visual effects, documents, vision, and more.
Models on this PC. Orchestrator score picks the default hub agent — change preset or pick manually below.
Models moved to trash remain recoverable during their grace period. Permanent purge is irreversible and requires typed confirmation, password re-authentication, and a one-time server challenge.
Trashed models have not been loaded.
Durable download queue with pause/resume/cancel, schedule, bandwidth, logs, error repair, and labeled disk projection. Progress rates/ETAs are estimates when shown.
Cloudflare receives normal network metadata/IP during the bounded connection test.
Planning only: Ollama traffic shaping is unavailable.
Live Download Center — loading…
Paid feature (Studio+). Build your own spoke combination and save a user config. Resource guards still apply. Admin/testing unlocks this now.
Feature implementation status for this topic. States are read from the canonical feature matrix.
Bundled explanations, not capability evidence
Loading bundled glossary…
These guides are bundled with Flywheel; opening one does not require network access.
Prepare a secret-redacted report tied to an error correlation ID. This does not upload, email, persist, or create a ticket. Review the draft again before sharing it.
Flywheel aims to keep the Hub usable with keyboard navigation, screen readers, zoom, reduced motion, high contrast, and left-to-right or right-to-left layouts.
Known limitations: some visual telemetry and the canonical three-dimensional canvas still need an external browser and assistive-technology review. Use the text summaries and keyboard alternatives when a non-visual path is needed.
Feedback channel: Configure this deployment with your established project support or issue-reporting path. Use the local report draft below to prepare the report. Include the task, browser, assistive technology or input method, and expected result. Do not include passwords, API keys, or private prompts.
Remediation policy: barriers that prevent task completion are prioritized and rechecked with the relevant keyboard, screen-reader, visual, and automated checks before release when those checks are available.
No report prepared.
Review, edit, pin, archive, export, or permanently delete project memory with typed confirmation. Live data only — Demo samples stay behind the Demo switch.
Enter a project id to review its memory.
Save what an agent learned after a completed task, or record a blocker separately so it can be loaded later for better routing, tool discovery, and training review. The two exports are intentionally separate.
Live source/index status, ingest errors, reindex, search traces, and accepted-interaction privacy. Counts and traces are stored values only — nothing invented. Demo fixtures stay behind the Demo switch.
Enter a project id to inspect its index.
Permission-filtered nodes, edges, multi-hop paths, provenance, and freshness with source/task/artifact drilldowns. Existing Knowledge Map controls above stay unchanged. Vault Markdown import is untrusted preview only.
Unavailable| Kind | Label | Freshness | Summary |
|---|---|---|---|
| Load a project-scoped graph to view lineage. | |||
No vault preview yet.
Loading graph lineage…
Live monitoring for active campaigns, last route, and export bundles. Demo mode is illustration only.
Live marketing dashboard idle.
Enterprise super-system — interconnect up to 20 Flywheel nodes. Seed demos are ephemeral previews (computers + local model orbits). Refresh restores your real connected machines.
Fleet controls ready. Seed demos preview only — Refresh returns to your live setup.
Connect spokes to expand the ring.
Every computer keeps its own local AI downloads. Fleet coordinates tasks between them.
Links are one-way. Add the reverse link when both computers or departments should send work.
Use a one-time link instead of copying a permanent node password. The link expires after 10 minutes and works once.
On the computer being added, install and open Flywheel Hub, then paste the master's secure address and the one-time link here.
—
Enterprise max scale 20×15. Live loads reported Fleet nodes/agents; Demo shows a labeled fixture only. No invented metrics.
Live by default. Demo is optional fixture inventory. Refresh / seed / topology controls stay available.
Builder Control Plane — Cursor/human agents implement upgrades. Local Ollama analysis runs via the Agents tab + flywheel-worker.cmd.
Loading capability readiness…
Planning only. Local-only is the default. Marking a task or agent eligible for an approved cloud/API provider shows preflight identity, destination, redaction, consent, budget, and provider rate estimates — it does not grant egress authority or execute cloud calls. Private task material stays local unless you change policy.
Select local-only or an approved provider, then Build preflight. Estimates only — no cloud execution.
Claim a task to see prompt…
.\scripts\agent-next-task.ps1 or click Claim next.\scripts\agent-complete-task.ps1 -TestsPassed.\scripts\start.ps1)Full guide: tasks/BUILDER_AGENT_LAUNCH.md
Start a local agent from Flywheel — no PowerShell needed. Pick an agent (or use Hub Start for a mid-tier default), add tasks, and click Play. Flywheel routes work to your Ollama spokes using the built-in rules.
No pending tasks — add one below or sync builder backlog.
—
Agent output will appear here…
Describe the outcome first. This review step does not queue or execute work, read files, grant tools, or enable network access.
Local review only. Nothing has been queued, persisted, read, or authorized.
Estimates are labeled; nothing invents TTFT or savings.
Why selected, rejected alternatives, expected escalation, and evidence. Existing Run Center controls stay unchanged.
Evidence-only; no invented TTFT, savings, or trust scores.
Desktop, laptop, tablet, and narrow remote status/approval. Existing menus, tabs, and approval actions stay available at every width.
Layout mode follows viewport width; no controls are removed.
Optional metadata-only status, alerts, approval, and cancellation. Off by default. Approve/cancel use the secure device-bound companion API; no prompt content.
Companion is optional and off by default. Existing Hub controls stay available.
Run a local content validation check and inspect server-owned model updates. These controls are read-only and never install, apply, or mutate provider state.
No validation run yet.
No update check run yet.
Portfolio of generated assets with model and prompt metadata. Image bytes stay in artifacts; prompts require consent to retain.
Gallery is metadata-only. Existing Hub controls stay available.
Optional onboarding, activation, error, and feature-discovery events. Off by default. Demo sample events do not flip the live opt-in. Never includes prompts or completions.
Analytics are optional and off by default. Existing Hub controls stay available.
Loading, empty, partial, degraded, offline, permission, rate, low-resource, and provider-down. Existing Hub controls stay unchanged.
Evidence-only UI states; no invented TTFT, savings, or trust scores.
Toast, inline status, dialogs, and local notification history. Browser alerts remain a tested fallback until parity is proven.
Inline status host.
Accessible channels are additive; alert fallback stays available.
Create a durable pending direct-model or full-route run. This queues only; it does not contact a provider or start execution.
No benchmark queued yet.
Live Run Center — loading…
Timeline uses supplied durable evidence only; no invented metrics.
Queue / active / history with pause, cancel, retry, and fork flags.
Chat, pull, MoA, and fleet jobs from the durable engine.
Mutating actions require explicit confirmation; external downloads stay blocked.
Patch artifacts include a scope-checked preview and test evidence. Expand a row to review it.
/api/artifacts - linked to task IDs
No plan variants loaded. Two variants are shown as Before and After.
Select feedback to update the plan projection. No install or download is started.
Your account type controls slots and features. Use ← → to browse tiers; Enter or click Get this plan to purchase.
Secondary planning material — provider usage rates are estimates, not Flywheel prices.
ROI assumptions are estimates based on provider rates — not Flywheel pricing — and are not measured from your deployment. Provider usage-price calculations remain secondary planning inputs only.
Additive user-controlled categories. Existing ping, chart, and export controls are unchanged.
Live Privacy and Trust Center — loading…
Facts only — no invented TTFT, trust scores, or synthetic savings. Select a registered artifact to inspect.
Live Model Center — loading…
Live Recipe Gallery — loading…
Administrative control center — enable or disable features per account type, manage users, and run time-limited promotions. Routing and CPU/GPU controls are marked proprietary.
Inventory diff, digest approvals, and measured health probes. No invented scores.
Review destructive operations, significant installs, and tool runs. Requests expire and approvals remain bound to the original action digest.
Checkboxes grant access for that account type. Live promotions can add temporary extras.
Grant higher-tier features for a limited window (launch / holiday trials).
Train locally: pick a base model, recipe, and dataset, then start a durable job. Fake dry-run completes immediately for CI; local stub stays running until you cancel or a trainer finishes. Metrics are never invented — status and artifact paths only.
Full fine-tune creates a verified pre-train backup before mutating staged base weights. Prefer LoRA/QLoRA when you only need adapters.
Tesseract / SAT-UNSAT geometry ideas can inform future formal-training tooling; they stay Labs-optional.
When a training job needs operator diagnostics, Flywheel can assemble a local redacted support bundle with job identity, run manifest digests, sanitized stage/step/warning/checkpoint/evaluation/resource/failure events, and environment state (framework versions, hardware profile, runtime context). Secrets are scanned and redacted before checksum binding. Creating a bundle is planning-only and sanitize-only — it never starts trainers, never uploads, never opens the network, never includes prompts or project files by default, and never grants execution authority.
Advisory operator-support-bundle explanation only (FW8-TRAINCORE-025). Existing Training Lab controls are unchanged.
List weight-adapter sidecars for a base model — not orbit pipeline MoA combos. Local observations only; refresh does not download, train, hotswap, or open the network. Optional folder scan reads adapter JSON metadata under approved project/data roots only.
| Name | Base model | Status | Source |
|---|---|---|---|
| Loading… | |||
Digest-bound offline adapter repository entries for air-gapped browsing. Plan-only resolution — no download, hotswap, HF egress, or activation this pass.
| Title | Base model | Kind | Mirror |
|---|---|---|---|
| Loading offline catalog… | |||
T3 Hugging Face registry browse is policy-gated (ADMIN-019/ADMIN-020) — preview only, no download.
| Title | Base model | Kind | Mode |
|---|---|---|---|
| Loading HF browse preview… | |||
Optional future panels: piano-key ring WebGL (opt-in), AdapterForge IPC telemetry, MoA active blend preview, VRAM defender estimates. List/table remains canonical; reduced motion shows no mandatory orbit animation.
Pipeline combo (orbit MoA) ≠ weight adapter (PEFT sidecar). See
docs/ready_state/TRAINING_ADAPTER_FLYWHEEL_DEEPER_VIEW.md and DEC-20260720-114.
Import versioned external training-run manifests for inspection. Loss and reward are optimization signals only — never product quality. Pause / cancel / train stay read-only unless a separately authorized execution task exists.
Additive Studio workbench for imported datasets, external runs, adapters, and certificate prep. Dry-run inventory never writes or executes; unsafe files never render; training stays off. Labels: imported - measured - simulated only.
TUCE Lab is the behavior-modulation research surface for the Trident Unified Core Engine. Its labels are engineering proxies, never clinical facts. Stream uses the local Hub behavior-modulation API.
Read-only visualization of the MOA anatomical piece map (21 sections: 19 base plus 2 PP shards when active). Each piece corresponds to a bound model/adapter
from /api/moa-cockpit/nodes. Selecting a piece shows its binding status; the explode slider
separates pieces for inspection and never changes runtime state. Empty and error states appear inline
when the cockpit API is unavailable.
Enter a task or prompt; the MOA pipeline classifies it, selects a path across the 21 pieces, and returns
node bindings and provenance. This surface only previews the plan through POST /api/moa-pipeline/run;
it does not execute or route real work. Badges surface residual drift, SAT lock state, and speculative
look-ahead/look-back checks when the API returns them. An optional read-only valuation snapshot
(GET /api/moa-cockpit/valuation/dashboard) is available below the results — every field it
marks illustrative is a placeholder estimate, not real accounting.
Browse the MOA epic index and its onion-layer taxonomy. Each row expands to show layer, description,
related pieces, and topic links. Search filters titles and summaries locally after the initial fetch
from /api/moa-epics. Registration and validation happen in a separate governed surface.
"Cross-validate roles" runs a heuristic Boolean-SAT constraint check over the epic's tags via
POST /api/moa-cockpit/epic/sat/resolve — not a certified safety authority.
Documentation roster for the 18 MOA Cockpit review roles (A/B subroles).
This does not launch the Dashboard MoA work-cycle (/api/moa/*).
If /api/moa-help/topic/agent_roles is available the roster is enriched from that topic.
Read-only view of the MOA Cockpit compute marketplace (listings, bids, matches, settlements).
Data comes from /api/moa-cockpit/market/stats and
/api/moa-cockpit/market/listings. Posting bids, matching, and settlement remain
governed API operations — this tab does not mutate market state.
Read-only governance preview of the labs.tuce-labs module: explicit proposal scoring
(/api/tuce-labs/gov/catalog), formula-versioned handoff metrics from validated
traces (/api/tuce-labs/metrics/catalog), and advisory-only research artifacts.
Missing evidence always defers; nothing here is marketed as intelligence, and artifacts never
grant runtime permissions.
Additive guided composer for certified brain / asset / tool / workflow stacks. Auto selects the smallest valid certified stack; Advanced exposes only bounded settings. Preview compatibility, authority, egress, resources, entitlements, certificates, unresolved evidence, failure paths, and rollback before transactional activation. Arbitrary adapter stacking and cross-project assets fail closed.
No preview yet. Load registry JSON and compose.
Expert graph appears after a successful compose preview.
LOCAL-FIRST WORKSPACE
Choose what local AI can see, keep evidence beside the work, and opt into remote providers only for tasks you explicitly route there.
Session recovery is ready.
Flywheel: Start locally. You decide if a bounded task may use an approved remote provider.
Draft text is persisted only after you enable recovery and save. Remote execution is never selected automatically.
YOUR DURABLE TASK QUEUE
These are your tasks. Administrators also see the installation migration backlog. The Dashboard queue is only the active execution window assigned to local models.
| Task | Epic | Priority | State | Protection | Worker |
|---|---|---|---|---|---|
| Open this page to load the full task backlog. | |||||
Quick stop is off. Confirm before unloading — from RAM.
Slide all the way right to enable Unload
Quick stop is off. Slide to confirm — this prevents accidental shutdown of running agents.
Slide all the way right to enable Stop Hub
Checking invitation…
A copied invitation is a temporary bearer credential. Accept it only if you trust its sender.
Accept grants only the listed low-risk capabilities for this tool version. Downloads, installs, elevation, secrets, new network destinations, and destructive actions always need a separate approval.
Open Open-Source Tools to install or grant the specific capability. Nothing is installed automatically.
This starts local agents on your PC using your signed-in account.
You are about to permanently remove — from disk. Large models can take a long time to re-download.
Confirmation text does not match yet.
Re-authentication is required before the server issues the confirmation.
The server issues a short-lived, single-use confirmation after the text matches.
You are about to permanently remove Builder task —.
Confirmation text does not match yet.
Re-authentication is required before the server issues the confirmation.
The server issues a short-lived, single-use confirmation after the text matches.
This permanently revokes the selected administrator-issued access key. Existing redemptions are not changed.
Target: —
Confirmation text does not match yet.
Re-authentication is required before the server issues the one-time confirmation.
This permanently removes — from the administrator promotion catalog.
Target: promotion:—
Confirmation text does not match yet.
Re-authentication is required before the server issues the one-time confirmation.
The server issues a short-lived, single-use confirmation after the text matches.
The current database and WAL files will be preserved. The selected encrypted backup will be restored before database startup after a restart.
Confirmation text does not match yet.
—
Keyboard: Tab moves between Deny and Accept; Escape denies and returns focus to the download control.
—
Review size, license, and dependencies, then Approve anyway or Deny.