HivemindOS manual

Hivemind Bots

A Hivemind Bot is a first-party always-on HivemindOS agent. It combines the existing managed cloud workspace with a persistent browser computer, hosted schedules and event routines, independent action review, exact approvals, human takeover, managed model access, and cloud-safe integrations.

Use a cloud agent when the work genuinely needs to be always on. For normal interactive work or private local files, an agent on your own machine is usually simpler and cheaper.

Create A Cloud Agent

  1. Open More → Hivemind Bots.
  2. Choose Deploy agent and review the currently available size, storage, running price, stopped price, and setup cost.
  3. Give the agent a name and fund only the amount you intend to use.
  4. Wait for deployment to report healthy before starting work.
  5. Connect Hive Superbrain, a private machine network, or external tools only when the agent actually needs them.

Deployment can take a few minutes. HivemindOS shows the real service state instead of presenting the agent as ready while its workspace or runtime is still starting.

The Persistent Computer

Each running Bot has a browser profile on its retained managed volume. Cookies, approved sessions, and normal browser state survive a stop and later start. The Bot sees the browser through a dedicated computer tool; it does not need a personal laptop to remain online.

The Computer tab provides a current screenshot, URL bar, takeover controls, an exact-action approval card, and an ephemeral secret handoff:

  1. Load the screen in view-only mode.
  2. Choose Take over to pause agent input and acquire a short renewable lease.
  3. Click the screenshot, type into the focused field, press Enter, scroll, or navigate.
  4. For a password or other sensitive field, choose the field from the latest observation and use Enter without saving.
  5. Release takeover so the Bot can resume.

Takeover is exclusive and expires after one minute unless the open panel renews it. The lease credential remains in that panel’s memory. A secret value is relayed only to the selected field and immediately cleared from the form; it is not added to computer policy, hosted routine receipts, or audit metadata. Screenshots necessarily contain whatever is visibly rendered in the browser and should be treated like a live screen share.

Computer Policy And Approvals

The Policy tab can allow or deny domains, require approval for consequential actions or every interaction, and enable an independent model review for actions not already decided by deterministic rules.

Denied domains always win. Sensitive fields and actions that appear capable of sending, publishing, purchasing, transferring, deleting, installing, uploading, changing an account, or accepting terms pause instead of silently executing. Approval binds to one exact action fingerprint; changing the action requires a new approval. Pending approvals also appear in Alerts.

Computer policy is one layer, not the financial authority. An exact approval can authorize one browser interaction at a checkout, but it does not enforce the company budget, validate a recipient or amount, or unlock the local signing wallet while the owner machine is offline. Keep provider-side caps, wallet limits, ad-account limits, and payment confirmations enabled. Unattended hosted spending requires a separately connected, narrowly scoped provider or a reviewed hosted smart-wallet or custody rail; deploying a Bot does not enable one.

Hosted Routines

The Routines tab creates two kinds of always-on work:

  • Schedule: a five-field cron expression evaluated in the selected IANA timezone.
  • Event: a named event such as company.lead.created, published with a stable event id so retries are deduplicated.

Every routine has a bounded prompt, runtime limit, stale-event window, pause control, manual Run now action, and recent run receipts. The routine prompt is stored so the schedule can run while your devices are offline; do not paste credential values into it. Only event keys, a payload hash, timestamps, status, and a generic output preview are stored in the routine ledger; raw event payloads and model responses are not kept there. A failed routine appears in the Bot panel and creates a deduplicated in-app Alert.

Routines tell the Bot to respect its computer policy, pending approvals, human takeover, provider limits, and secret handoffs. Test a routine manually before scheduling it, make external writes idempotent, and use stable event ids when a sender retries.

What Persists

The agent’s workspace and runtime state live on persistent managed storage. Stopping the agent removes active compute but keeps that workspace, its stable service identity, and the connections you explicitly retained.

  • Stop lowers ongoing compute use while preserving the workspace.
  • Start creates fresh compute around the same retained workspace.
  • Delete permanently removes the compute and persistent workspace. Review and export anything important first; deletion cannot be undone.

Running out of managed credit stops compute rather than allowing an unbounded balance. Check current usage and funding in the Hivemind Bots view.

Run A Zero Human Company With A Bot

Create or edit a company and choose Hivemind Bot · first-party as its autonomy engine, then select one managed Bot. The binding contains only the managed Bot id; portable company templates never include that account-specific binding.

Launching the company sends a bounded operating brief containing the company shape, apex goal, directives, product catalog, budgets, approval policies, and saved autonomy cadence. It does not add personal profile fields, setup-key values, or recognized credential values. HivemindOS waits for the first managed response and records an observed Company Run, company memory entry, and governance receipt. It also creates one company-bound hosted routine in a paused state, records that server-created binding, and only then enables the saved cadence. Existing and manually configured companies default to 30 minutes; governed watcher templates may start at 60 minutes. Later hosted receipts remain on the Bot. Stop autonomy, Freeze, changing engines, and company deletion disable future hosted cycles before claiming the local state changed; a cycle already in flight is allowed to finish.

The first-party Bot path is different from Grok Bot · external handoff. HivemindOS can create, control, inspect, and record Hivemind Bot work. It can only produce a privacy-reviewed template and runbook for Grok Bot until xAI provides a documented Bot-control API.

Staff A Company Crew With Bots

A Bot can also hold one role inside a normal HivemindOS crew company instead of running a whole company by itself. Add the Bot to the company’s crew like any other agent and give it a role. From then on it is routed Work Board tasks by the same router, claims and reports them the same way, and passes work to the next role through the same task dependencies — so a several-role company can keep running with no personal machine online.

Use the crew path when the work is a pipeline whose handoffs you want to see and review on the Work Board. Use Hivemind Bot · first-party as the company engine when one Bot should own the whole company on a hosted routine instead.

A stopped Bot stays on the crew but is not given work, in the same way an agent on an offline machine is skipped; start it again to resume. Bots do not claim a specialty, so when a specialist agent on one of your machines is online for a task that names one, the specialist is picked first and the Bot remains a fallback. Every Bot turn is metered against your managed-agent credit, so a Bot-staffed crew keeps consuming credit for as long as it is working.

Pricing And Funding

Cloud-agent availability and pricing can change. HivemindOS loads the authoritative plans, rates, balances, and entitlements from the managed service at the time you review or fund an agent. Treat the values shown in the confirmation as current; do not rely on an old documentation table or a locally edited app setting.

When wallet funding is available, HivemindOS shows the exact network, asset, amount, recipient, expiry, and expected credit before asking the selected wallet to sign. Normal wallet controls still apply:

  • spending must be enabled;
  • per-payment, daily, and monthly limits must allow the amount;
  • company budgets and freeze controls apply to company-funded work;
  • an approval threshold can pause the payment;
  • the same onchain payment cannot be credited twice.

The managed service—not the desktop app—enforces official balances, settlement, pricing, resource ownership, quotas, and cloud entitlements.

Use Hive Superbrain From The Cloud

Cloud agents do not receive your brain automatically. You can explicitly pair a managed workspace with an approved Hive Superbrain sync peer. The cloud copy can then support work while personal machines are off and reconcile again when another authorized peer reconnects.

Review what the shared vault contains before pairing it with a managed machine. Plaintext secrets should remain outside the vault. Provider and integration credentials added to the managed agent are separate trust decisions and are stored by the managed service rather than copied silently from your laptop.

Know Which Integrations Stay Available

An integration works only while the machine or service that owns it is running.

Capability When personal machines are off
Managed model access and files in the cloud workspace Available while the cloud agent is running.
A remote HTTPS tool explicitly connected to the cloud agent Available according to that connection’s permissions.
Hive Superbrain copied into the managed workspace Available from the approved cloud copy.
An app on another always-on trusted machine Available while that machine and its private connection remain online.
A filesystem, browser session, or local tool on an offline computer Unavailable.

Connecting a cloud agent to your private machine network does not make an offline computer’s files, browser, or local apps keep running. HivemindOS should never pretend otherwise.

App Projects

A running Managed Cloud Agent can host app projects in its retained workspace. This is useful when the agent must continue building or operating away from your computer. Local and fleet agents use the same App Builder project model, so choose the host based on where the source should live and whether it must remain available continuously.

The Bot panel includes an App Projects section with a project host picker. Choose “Your computers” to see projects that live on your own machines (those are created and operated from Chat), or choose a Bot to manage the projects it hosts. On a running Bot you can create a project from the reviewed Next.js starter, start or stop its development runtime, and delete a project. Start runs the project in an isolated, resource-limited container on the Bot’s machine; starting, stopping, and deleting each ask for explicit confirmation, and deleting permanently removes that project’s workspace files from the Bot.

Two honest limits apply today. First, the dashboard does not yet show a live preview of a managed project’s running app; publish through Hosting when you want a viewable site. Second, a Bot deployed before app runtime controls existed must be reconfigured once before Start, Stop, and Delete can manage its projects; the panel tells you when that is needed.

Cloud-hosted app projects are still rolling out: today they can be created, listed, and inspected through the platform interfaces, while start, stop, and delete controls for cloud-hosted projects arrive in a later release. The App Builder view in the dashboard currently builds on local and fleet machines.

Publishing is a separate decision from choosing a cloud build machine. Review the App Builder and hosting guide before creating a public preview or site.

Smaller Screens And Remote Access

The Bot panel collapses to one column on narrow screens, including the computer, approval, routine, and policy controls. It uses the same authenticated HivemindOS API rather than exposing the browser sidecar directly. Remote access still depends on the supported HivemindOS dashboard and network setup; do not publish the local dashboard or managed runtime endpoints to the open internet.

Before You Delete One

Export or hand off important project files and deliverables, stop schedules that point to the agent, reassign company work, and check whether it is the only online copy of any explicitly paired data. Deleting a cloud agent does not delete your local Hive Superbrain, but it permanently removes that agent’s managed workspace.

Expanded image Scroll to pan · Esc to close
100%