Kingsparrow

ensembly

Approve/deny gates and live status under the bots you already run.

A thin control and memory layer on the operator machine. Harnesses keep their own chat memory; ensembly adds a persisted ledger, sync files, and pulse. Grok Bot and Build are the first quality bet; more ecosystems can follow.

Product direction

What the layer is for — not a shipped demo. Proving it needs costly real workflow evals.

Ledger

Track done, pending, and denied. Aim: inspect past status from the ledger, not chat scrollback.

Memory

Sync files the operator owns. Aim: reconcile facts across sources without silent overwrite when calendars, mail, and tools disagree.

Pulse

Aim: live status the operator and bots can read between sessions — less repeated re-briefing.

One writer. On the operator machine, a single kernel holds the ops database and writes live status, gates, and irreversible acts. Grok Bot and other clients read and propose; they do not each hold canonical truth.

Gates

Agents and platforms capture context and draft output. Irreversible acts wait on approve/deny gates: send, pay, merge, submit. Plain gates — no insider command dumps.

ensembly holds live status and pending gates between sessions. Complement the bot loop; do not compete with it.

Hard problems

Three problems chat-scale products rarely productize — and that the pillars above must earn through evals:

Frontier vs daily tools

Frontier models earn their keep: higher intelligence, steeper learning curve, real dollars and tokens. Use them where the work demands it.

Free tools and open-weight models handle daily assist. A frontier can hand work down when the pattern is clear.

Humans scatter tools, data, and effort across ecosystems. No harness controls what lives outside its boundary. CRDT-style sync everywhere is not the realistic story.

Sync

CRDT — Conflict-free Replicated Data Type: offline copies merge without a central lock. The paper assumes controlled replicas and a clean update stream.

Real scatter — chat threads, files, agent wire protocols and cloud sync, skewed clocks — can merge conflict-free on paper and still be wrong for gates, approve, and deny.

Multi-master CRDT is not solved for operator truth. The honest path: ledger, careful sync, one kernel writer on the operator machine when live status matters.

Hard gap

The remaining work needs real workflow evals — costly, which means capital. A frontier lab may buy ensembly later. This is product truth, not a loud pitch deck.

Evals on verified artifacts: correct, effective, efficient. Generational gain is harness and evals — not daily kernel churn.

Palantir vs ensembly

Palantir Foundry, AIP, and Ontology cover governed enterprise data, HITL actions, and agents that stage proposals. ensembly's wedge is different: coherent state under personal multi-harness scatter — chat never owns the ledger. Cousins in HITL thinking; different customer and tenancy.

Related: Sovereign AI, Hybrid Routing, Token Optimizzing (Jul 2026) — hybrid routing, token discipline, Palantir Ontology for governed enterprise context.

Enterprise SoT

Palantir

Heavy. Ontology = nouns + actions; lineage, RBAC, writeback

ensembly

Per-human / operator SoT — one writer on your machine

HITL gates

Palantir

Heavy. Agents stage proposals; humans approve

ensembly

Same pattern, thin local kernel — not an enterprise platform

Agent + decision

Palantir

Heavy. AIP Logic, Workshop, Automate

ensembly

Complements Grok Bot / harnesses; not a second chat OS

Hybrid / sovereign routing

Palantir

Partial–strong via on-prem / partner stacks

ensembly

Routing thesis lives with the operator; ensembly holds gates and pulse across scatter — it is not the model router

Process tools

Palantir

Palantir is the process/ops app layer (Workshop)

ensembly

Process tools stay flavors (UI/UX); ensembly refuses to be another process UI

Personal multi-harness scatter

Palantir

Weak. Built for org tenancy

ensembly

Core wedge — coherent state under tool scatter

Local-first durability

Palantir

Not the product story

ensembly

Explicit — status survives laptop sleep and bot context resets

Buyer

Palantir

Enterprise, long lock-in

ensembly

Operators / seed; a frontier lab may buy ensembly later

Aligned incentives

One writer on the operator machine holds the ledger, live status, and pending gates. Bots read and propose; they do not each hold canonical truth. Less re-briefing, fewer stalls when state was wrong or missing — that is the job.

Frontier labs earn when outcomes match intelligence: operators stay in flow instead of stuck on bad state. Stalls burn tokens without outcomes; flow spends tokens on finished work. Cheaper frontier pricing may help affordance — hope, not a promise or partner deal.

Free and open-weight tools handle daily and delegable work — cost-free or cheap enough to run locally. A frontier hands down when the pattern is clear; the kernel keeps status either way.

Operators get both: frontier depth where it matters, cheap daily cover elsewhere — one coherent, correct pulse across data, process, and place. The usual path is hundreds of process tools, a poorly adopted AI stack, failed applied AI, and everyone partly unhappy.

Without buy-in

Same as any product: competitors ship similar coordinators. That is fine. The choke — scattered tools, chat memory as truth, failed applied AI — still gets addressed by ensembly-like products. Category formation, not monopoly.

Process tools

Process-tool makers either talk to ensembly, or the harness bridges them. Tools read and propose; one writer on the operator machine holds the ledger, live status, and gates. Coherent state stays on the kernel — not in each app's private map.

Then process tools become flavors — visualization and UI flows across markets and geography, like people buy different cars and phones. Taste, not source of truth.

Kernel law: HITL / HOOTL

Automate the digital. Surface the physical. Wait only for permission. Make the truth playable.

HITL — human in the loop: deliberate verification and steering. HOOTL — human out of the loop: swarm clears digital thrash; physical pickups and irreversible gates wait for permission. Auth and physical gates never self-approve.

Use cases

Morning status

Operator and bots aim to read one live status instead of re-briefing from scratch.

Irreversible act

Send, pay, merge, submit — pending gate. Human approves or denies.

Conflict

Calendar, mail, and finance disagree. Kernel should record the contradiction and apply a winner rule — explicit data, not an implicit merge.

Past status

Inspect ledger state at a past moment — done, pending, denied — without scrolling chat or reconstructing the day in tokens.

Ask

Collaborators

Kernel engineering, typed IR, local-first sync, HITL protocol design, ledger design, usage-driven evolution.

Investors

Seed conversation. No invented traction.