Features
One Keystroke Connects the Entire Fleet
Atlas is not a launcher — it is an operating layer. A Swift/SwiftUI macOS app paired with a persistent Python orchestrator daemon that holds a live Claude Opus 4.7 session and active MCP client connections to every AVIAN fleet tool simultaneously. Press ⌘⇧Space and the Command Bar surfaces. Select any text anywhere and press ⌘⇧H for an instant Hover Lens. A dismissible Command Rail lives at the screen edge, streaming live fleet signals. Focus Mode wraps a 90-minute deep-work envelope around your chosen task, coordinating Meridian timers, Slate pinning, notification suppression, and Fulcrum leverage records automatically. Every action routes through the fleet's authoritative tools; Atlas owns nothing — it orchestrates everything.
Command Bar
⌘⇧Space — Natural Language Into the Whole Fleet
Natural-Language Fleet Commands
Type anything — "who am I meeting this afternoon and what should I know about them" — and the Opus orchestrator reasons across Cadence, Tribe, Courier, Envoy, and Pulse in a single pass. Every tool is one thought away; no tab-switching required.
Fast Path, Slow Path, Confirmation Path
A Haiku 4.5 classifier tags each query in <150ms: unambiguous reads (list today's events) skip Opus entirely via direct MCP call; complex reasoning routes to Opus with full tool use; any write operation pauses at a diff-and-confirm screen before executing.
Slash Commands
/task,/meet,/brief,/focus,/deal,/logbypass the classifier entirely for direct intent dispatch. Mnemonic chord bindings (⌘K then T for task) also supported.Rich Inline Result Cards
Responses stream token-by-token. Contact cards, deal cards, incident cockpits, Slate tasks, Cadence events, code blocks, and confirmation diffs render natively in SwiftUI — not HTML. Every card deep-links to its authoritative tool.
Multi-Input Modes
Paste a URL, email address, phone number, or file directly into the Bar. Drop a PDF invoice — Atlas routes it to Trellis. Paste a stack trace — Atlas searches Chronicle. Paste a LinkedIn URL — Atlas offers to populate Tribe. Voice input via ⌥-hold uses on-device WhisperKit.
Tool Call Transparency
Every MCP tool call Opus makes appears as a collapsible indicator:
→ tribe.get_contact(sarah@acme.com) ✓ 142ms. Users can expand any call to see raw input and output. Reasoning is visible but never mandatory to read.
Hover Lens
⌘⇧H — Lift Any On-Screen Text Into Fleet Context
Content-Aware Classification
Select any text anywhere in macOS and press ⌘⇧H. A Haiku classifier identifies the content type in <150ms: email address, phone number, person's name, company, dollar amount, date, URL, error message, code snippet, address, or legal citation — and dispatches the appropriate Lens surface.
Fleet-Routed Overlays
Email address → Tribe briefing + Courier last 5 threads + Envoy deal presence. Company name → Envoy pipeline summary. Dollar amount ≥ $100 → Trellis AR context. Date reference → Cadence availability. Error/stack trace → Chronicle issue lookup. Every detection routes to the authoritative tool.
OCR Fallback for Any Surface
When Accessibility APIs return no selection — PDFs, images, Electron apps, videos — Atlas captures a configurable region (default 400×300pt) around the cursor via Screen Recording, runs Apple Vision framework at
.accuratequality on-device, and proceeds exactly as if the text were selected. Captured imagery is held in memory only; never written to disk.In-Lens Actions
Every Lens surface exposes: Open in <tool>, Pin (keeps Lens visible), Capture (saves to Codex, Slate, or Tribe), and Ask About This (opens Bar with the selection as pre-filled context). One keyboard shortcut; no copy-paste.
Command Rail
Live Fleet Signals at the Edge of Your Screen
Today's Mission Widget
Top 3 highest-leverage Slate tasks, ranked in real time by Fulcrum's
predict_leveragemodel. One click starts a Focus Mode session on the top task. Stays fresh via Slate WebSocket subscription.Pipeline Pulse Widget
Live Envoy summary: deal count at risk, ghosted, overdue next-step. Expand to the inline list with one-click draft outreach per deal — Opus composes the email, Courier opens the draft.
Incident Watch Widget
Chronicle current incident feed + Vigil service-health dots. A red incident expands the Rail into a full incident cockpit mini-view with current commander, SLO burn rate, and one-tap ACK.
Leverage Meter Widget
Fulcrum today-to-date leverage factor, fatigue score, and delta vs. rolling 7-day baseline. Dark red at High fatigue — which also drives Atlas's own autonomous behavior (more autonomous decisions when you're most decision-fatigued).
More Opt-In Widgets
Calendar Peek (Cadence next 3 events + Tribe attendee avatars), Inbox Triage (Courier unanswered threads + commitments due in 48h), Focus Countdown (active sessions only), SLO Breach (burning SLOs), AR & Cash (Trellis, admin only), Build Status (CodePipeline across AVIAN projects).
Focus Mode
⌘⇧F — 90 Minutes of Undivided Attention
Coordinated Focus Envelope
On activation, Atlas publishes deep-focus status to notification-service. Courier pauses non-urgent drafts. Cadence auto-declines non-urgent meeting proposals. Chronicle lowers severity paging thresholds. Meridian starts a timer on the chosen project. Slate pins the mission task as in-progress. All in one command.
Curtain Mode
An optional translucent gradient curtain covers every display at 20-40% opacity, preserving the foreground app while dimming everything else. Rendered as a borderless
NSPanelatNSScreenSaverWindowLevel - 1— visible over Dock and menu bar but click-through on the foreground window.Emergency Breakthrough Rules
P0 Docket cards, P1 Chronicle incidents, and VIP Tribe senders (tier=strategic) can break through Focus with a two-step confirm. Everything else is deferred to the post-session queue. User-configurable per rule.
Exit Ritual — Automatic Ledgering
At session end, Atlas prompts for outcome (text or voice). Responses propagate automatically: Slate task marked done, Meridian time entry closed with note, Fulcrum leverage record posted (supervisory minutes = Bar interaction time; Claude minutes = focus duration), Chronicle event written, Codex learnings note optionally appended.
Orchestrator
Opus 4.7 Wired Into Every Fleet Tool — Always Running
Persistent Daemon, Persistent Session
atlasdruns as a Launch Agent: starts at login, survives Mac App quits, auto-restarts on crash (launchd KeepAlive). Holds a single long-lived Claude Opus 4.7 session with active MCP client connections to all 21 fleet tools. Target idle RAM: <200 MB.Prompt Caching — 60-75% Input Cost Reduction
Three stable prompt blocks are cached with Anthropic's prompt caching API: system prompt (~3k tokens), 30-day memory block (~5k tokens), and MCP tool definitions (~8k tokens). Target cache hit rate >80%. The
CostAccountanttracks cost per feature and enforces a daily budget with a hard cap fallback to Haiku.Three-Model LLM Router
Opus 4.7 for slow-path reasoning, multi-step tool orchestration, briefing composition, and autonomous action drafting. Haiku 4.5 for fast-path classification, lens content detection, and autonomous rule evaluation. Mercury 2 for bulk classification, non-critical Lens drafts, and OCR text classification.
Morning Briefing & Evening Wrap
At 07:00 local time, APScheduler triggers a briefing: Cadence today + Slate queue + Envoy at-risk + Docket P0s + Chronicle incidents + Fulcrum leverage snapshot — composed into a 60-second spoken + visual card via ElevenLabs. At 18:00, an evening wrap ledgers the day's leverage summary.
30-Day Sliding Memory in Codex
Every significant Bar query summary, Hover Lens capture, autonomous proposal outcome, and Focus session is stored durably in Codex (never in Atlas's own database). Loaded as a cached memory block into the Opus session on startup. User can audit, export, or wipe at any time. Private Mode (⌘⇧P) short-circuits memory writes entirely.
Autonomous Engine
The Fleet Watches Itself — and Asks Before It Acts
User-Editable YAML Rules
Rules live in
~/Library/Application Support/Atlas/rules.yamland bind signals to actions:signal: docket.card.created+filter: card.priority == 'P0'→ macOS notification with one-tap ACK. Every rule has aconfirmation_mode(auto / trusted / always-confirm) and can be disabled without deleting.Fleet-Wide WebSocket Subscriptions
Persistent asyncio tasks subscribe to WebSocket streams from Chronicle, Docket, Courier, Envoy, Slate, Vigil, Pulse, and more. Each incoming signal is evaluated against all enabled rules in real time. Matched rules build typed
AutonomousProposalobjects before any action is taken.Confirmable Proposals — Never Silent Writes
Every autonomous action surfaces as a macOS notification with native action buttons before executing. On the Docket P0 rule: “ACK 1h” / “View” / “Dismiss”. On the Envoy health-drop rule: a proposed Cadence block + draft email, with a diff view before any calendar write. Reads-only actions run immediately; mutations always wait.
Fatigue-Aware Autonomy
When the Fulcrum fatigue score hits High, Atlas autonomously proposes to decline non-urgent calendar invitations (via Cadence) and defer low-leverage Slate tasks, absorbing decision burden at the exact moment the user can least afford it. Configurable thresholds; user retains veto on every proposal.
Accessibility
Built for Everyone
WCAG 2.1 AA Compliance
4.5:1 contrast for body text, 3:1 for large text and UI components, in both light and dark themes.
Keyboard Navigation
Every interaction reachable via keyboard. Logical tab order, visible focus indicators, Escape-to-dismiss for modals.
Screen Reader Support
VoiceOver, NVDA, and JAWS tested. Semantic HTML, ARIA labels, live regions for dynamic updates.
Reduced Motion
Respects
prefers-reduced-motion. Usable at 200% zoom. Touch targets meet 44x44 minimum.
How It Works
Summon, Reason, Confirm, Commit
Step 1: Summon
A global hotkey or background fleet signal surfaces the right Atlas surface — Command Bar, Hover Lens, Rail widget, or autonomous notification. macOS never needs to be left; no browser tab required.
Step 2: Reason
The Orchestrator classifies the input and routes it: fast-path direct MCP call for unambiguous reads (<500ms); Opus 4.7 with full tool use for complex multi-step reasoning; Haiku classification for Lens content and autonomous rule evaluation. Every tool call streams back to the UI with latency and raw I/O visible.
Step 3: Confirm
Any fleet write — create task, book meeting, send email, log time, advance deal stage — pauses at a diff-and-confirm surface before executing. The PermissionGuard evaluates safe-lists, amount thresholds, and target trust levels. The user has full veto with a single key.
Step 4: Commit & Ledger
Confirmed actions execute through the authoritative fleet tool. Every Bar invocation, Lens activation, tool call, autonomous action, and Focus session emits an OTel span to Chronicle and optionally a Fulcrum leverage record. The “My Day” view reads back a chronological timeline of what Atlas did and saved.
Technical Specifications
Under the Hood
macOS App
- Swift 5.10 + SwiftUI + AppKit
- Universal binary — Apple Silicon + Intel
- macOS 14 (Sonoma)+
- Rendering: SwiftUI (chrome) + Metal (live data viz) + Rive (state-machine animation)
- NSPanel-based surfaces (non-activating, vibrancy, borderless)
- CGEventTap global hotkeys; AX API selection reader
- Voice: AVFoundation + WhisperKit (on-device CoreML small-v3, ~250 MB)
- OCR: Vision framework
VNRecognizeTextRequestat.accurate - Notarized, Sparkle auto-update, direct download from
atlas.renkara.com
Daemon
- Python 3.12+, FastAPI diagnostics on
127.0.0.1:3439 - Installed as Launch Agent (
KeepAlive: true) - IPC: Unix domain socket + JSON-RPC 2.0, length-prefixed frames
- APScheduler for morning briefing, evening wrap, hourly autonomous sweep
- SQLCipher-encrypted local SQLite (
~/Library/Application Support/Atlas/state.db) - OTel spans emitted directly to
chronicle-api.renkara.com - Fulcrum leverage records posted on Focus session completion
- Idle target: <200 MB RAM, <1% CPU
- Python 3.12+, FastAPI diagnostics on
Orchestration
- Claude Opus 4.7 (slow-path reasoning + tool orchestration)
- Claude Haiku 4.5 (classification, autonomous rule evaluation)
- Mercury 2 (bulk Lens classification, non-critical drafts)
- Anthropic prompt caching on system prompt + 30-day memory + MCP tool defs
- Target prompt cache hit rate >80%; 60-75% input cost reduction
- Daily token budget with soft-cap warning + hard-cap Haiku fallback
- BYOK: user-supplied Anthropic API key, stored in Keychain
Fleet Integration
- 21 fleet tools via persistent MCP client connections (MCPClientBus)
- Per-tool: cadence, tribe, courier, envoy, slate, docket, chronicle, vigil, fulcrum, meridian, trellis, herald, beacon, pulse, narrative, codex, packed, dossier, auth-service, purchase-service, notification-service
- WebSocket subscriptions per stream-capable tool (Chronicle, Docket, Courier, Vigil, Pulse…)
- mTLS client certs for all fleet REST/MCP calls
- PermissionGuard + ConfirmationQueue on all mutation operations
Security
- Native Swift OIDC client: Authorization Code + PKCE + DPoP
- Tokens in Keychain with biometric ACL (
biometryCurrentSet) - DPoP private key in Secure Enclave (fallback to Keychain)
- UDS socket mode 0600 + SO_PEERCRED owner check
- App Sandbox + Hardened Runtime + Notarization
- Kill switch ⌘⇧⌥Q: instantly deregisters all hotkeys, stops IPC, hides Rail
- Private Mode ⌘⇧P: current session not written to Codex memory
Development
100% Built by Claude
Every tool in the Renkara fleet was built by Claude (Anthropic) working alongside a single human supervisor. Every line of code, every test, every deployment: AI-authored with human direction. The leverage factor across the fleet runs in the 20x–50x range, with individual sessions regularly exceeding 100x.
See the daily leverage records for per-task numbers across the full build history.