System health and spend at a glance.
Authentication and app preferences.
A read-only Big Board for the TV on the shop wall — coders, merge tray, queue, printers and alarms, auto-refreshing, no login. A display token opens it and can do nothing else: it reaches two read-only pages and is refused everywhere else in the system, so it can never merge, approve, dispatch or discard. It never expires — revoke it here when a TV leaves the shop.
The board shows work status only. Financials, bank, email, customer details, secrets and tokens are excluded server-side by an allowlist — anything not on it is never sent to the TV at all.
Which brain routine work uses when a desk doesn't have its own override. Takes effect on the next task/message — no restart.
🔒 Crown-jewel work (Manager, CAD/product-IP, VA advisor) always stays on Claude, US-hosted only — enforced server-side, no setting here can change it. Per-desk overrides live in each desk's Capabilities panel.
What each desk effectively runs right now. inherit master means no override; a 🔒 desk is crown-jewel-locked to Claude. Edit any desk's brain in its Capabilities panel.
AI-model accounts. Each card shows its cost type and live usage. Secrets are stored server-side, encrypted, and never shown back.
Outside-world connections: Google accounts, email mailboxes, your Obsidian vault, and printers/devices.
Connect one or more Google accounts. Each gets its own Calendar, Gmail, and Drive. Sending, deleting, or modifying always asks you first. Tokens are stored server-side, encrypted, never shown back.
Connect any non-Google mailbox with an app-specific password. Desks can then search + read across every connected mailbox at once (or scope to just one by name). The password is stored server-side, encrypted, never shown back.
Which Google accounts a desk/thread may use. The ★ primary is what a tool call lands on
when it doesn't name one; a call can target any other granted account with account: "Sublime",
or account: "all" to read across all of them. An account NOT granted here is refused, even if the
desk names it. A desk with no grants falls back to the active account (unchanged behaviour). Picking a Drive
folder in an account (📁 → Google Drive) grants that account here automatically.
Bambu Lab printers on your network. Add one here or from the printer dashboard.
Most specific wins: desk → role → tier. Assign a brain to override routing for a specific desk, role, or tier.
What each desk can DO, one desk at a time. Pick a desk, then toggle any capability on or off — the change takes effect on that desk's very next message, no restart. A ⚡ metered capability (Gmail, Drive, Calendar, product search, bank, OCR) moves the desk onto the paid cloud API lane; a 🌐 free one runs on the box lane, inside the Max subscription. A locked row is a hard safety rail (e.g. run_bash on the Manager) no toggle can override; write/destructive tools still confirm before they run.
Runs on the box over the same signal channel as Restart Fleet. STRICT ALLOWLIST only —
pm2 (restart/delete/start/stop/list/save/logs/jlist), git
(fetch/pull/status/checkout main/stash/log), npm (install/ci). Anything else is rejected
here, before it ever reaches the box.
Pick the voice, speed, and pitch used every time a message is read aloud (🔊). Saved on this device only — other devices keep their own pick. Neural voices sound natural as-is and cost a fraction of a cent per reply; speed/pitch below only tune the free browser voices.
Provisions a REAL worker that claims + runs coder tasks through the router on the brain you pick — not a chat thread.
Snap or upload a part photo, add a one-line description, and get a 2.5D part brief back — the proposal for the DRAW stage.
Pick this desk's home folder