⚠️ Scheduled upgrade in progress — brethof-brain is moving to its new architecture. Signups and new installs are paused for the moment; nothing is lost and everything returns shortly.

Projects & rules

Your work lives in projects, and your projects run on rules. The Brain gives you both without asking you to build or manage either. A project is a name you say once. A rule is a sentence you write once, and from that moment it is in every session, on every machine, inside every agent that touches that work. You never set a project up again, and you never tell your story twice.

A project is a name. It's also a specialist.

Say the name when you save or search, and the project exists from that moment — no folder structure, no setup, no limit on how many you can carry. Your app's memory is just another project, running on the same machinery.

Each project is a specialist. It carries its own memory, its own rules, its own history of decisions. When you open a session in it, your agent arrives already briefed — the rules, where things stand, what was decided last week. You don't re-explain. You don't remind it. The briefing is already there.

The minute that pays for the rest of the project

The highest-value minute in the product is the one you spend setting a project's rules. Write them once — how this project is done, what matters, what to avoid — and every session that opens afterward automatically knows them.

# say to your agent: "create a brain project for my payment service — track architecture decisions, deploy state, and incident causes"

You never tell your project's story twice, not to a new agent and not on a different machine. That one minute is spent once, and the agent that walks in tomorrow already knows.

The team layer, on your terms

When you share, you share on your terms. A key does not have to be all-powerful. Scope it to chosen projects, read-only or read-write — the right shape for a contractor, a CI job, or a single-purpose agent that has no business seeing the rest of your work. Your brain, your rules, your keys.

Human teams. A contractor gets a key that sees the client project and nothing else. When the engagement ends, you revoke one key — not untangle a shared memory.

Agent fleets. A CI job, a research bot, a single-purpose agent — each gets exactly the memory its job needs. An agent that only reads can never delete.

Multiple harnesses, one memory. Run Claude Code, OpenClaw and Codex against the same Brain — but give each its own key, shaped to how much you trust it. The always-on autonomous agent that talks to the outside world gets read-only on one project; your daily driver gets everything. Shared memory without shared blast radius — the problem every multi-agent setup hits, solved where it belongs.

Deleting is deliberate

Deletion is deliberate Everything you store is yours to delete. Deletion runs on many levels across two systems — the account panel with a human confirmation on every step, and the derived data an agent may touch. But the raw conversation archive is the only thing no other agent may reach. No agent can delete a single message, and no agent can touch the last three months at all. The threat modelled is your own agent — a mistake, or a malicious instruction hidden inside something it was asked to read. Curated memory is derived; the archive is the original.

Every project keeps a pile of the undecided

The gap between saying you'll do something and doing it is where work quietly dies. The Ledger catches that gap. As your conversations are archived, it watches for intentions and turns each one into a row waiting for you.

Say “check the ledger” and your agent walks the rows with a verdict already attached — done, with the evidence; pointless now; still worth doing — and you answer in single words. Fifteen rows takes about two minutes. There are no statuses and no stale board; every decision removes its row, and the pile only shrinks. The rows you keep become goal briefs your agent runs to completion on its own.

Projects are separate. Procedures are shared.

The distinction matters. A project's memory is private to that project — the deploy, the weekly report, the translation run — but a procedure is shared across everything you do. Write a markdown playbook once, store it for your whole account, and any agent in any project on any machine can fetch it and follow it. The Brain stores and serves playbooks; it never runs them. There's no execution backend, no terminal, no access to your machines — the playbook is the instruction, and your agent does the work.

The Brain stores them and serves them; your agent executes them in its own environment. Save, get, list, delete — four doors, yours entirely.

Write the law once. Every agent obeys it.

Rules are the one thing that loads into every session automatically. Everything else — the memory, the playbook, the decisions — is found when searched. Rules are already there. Set them for everything you do, or for a single project, and they shape how every agent works, everywhere.

The rules are the curator's syllabus

After every exchange, a curator reads the turn and rewrites your memory: decisions saved, changed facts folded in, the claims reality has overtaken deleted. Your rules are the syllabus that tells it what matters. The memory is run by a model taught the way you'd teach a new hire — not configured through extraction rules and filters. You write the law once, and the curator applies it without being asked.

You never file one

No save, no tag, no “remember my context” ritual. The curation happens in the seconds after the exchange, not when you remember to ask. You never file anything — and the memory does its work whether or not anyone remembers to query it. A store your agent has to be asked to check is only as good as the model’s willingness to ask; this one does the work itself.

The one thing no model may touch

The raw conversation archive is the original record, and it is out of reach of every agent. No agent can delete a single message, and no agent can touch the last three months at all. The threat modelled is your own agent — a mistake, or a malicious instruction hidden in something it was asked to read. The curated memory is derived; the archive is the original, and it stays yours.

← How it works Install in 60 seconds

Hear it when it ships

New releases, real benchmarks and the occasional deep-dive. No spam, unsubscribe in one click.

Everything we build

External:   YouTube · GitHub