Oregami
Repositories/oxedyne/daimond

oxedyne/daimond/www/guide/search-index.js

136 KiB, 5 runs

created by r2519314175:1293, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1window.GUIDE_INDEX = {"locale":"en","words":{"ph":"Search the guide","no":"Nothing found","n":"{n} results","n1":"1 result","hint":"Press / to search"},"sections":[{"p":"accounts.html","a":"","t":"Accounts & privacy","u":"","b":"Accounts & privacy An account in Daimond is a passphrase held on this device. There is no account on a server: your identity, your keys and your files live only in this browser. This page covers the passphrase, sharing a browser with other people, and what stays private."},{"p":"accounts.html","a":"s1","t":"Your account is a passphrase","u":"Accounts & privacy","b":"On first run Daimond offers to protect this device . You give a name and a passphrase, and that passphrase becomes your account. It does two jobs: it encrypts your stored provider key and mail credentials so an onlooker cannot read them, and it is the identity that signs you in for credits. Nothing about it leaves the browser. The passphrase is never stored and cannot be recovered. Daimond keeps only the encrypted data, not the passphrase that unlocks it. If you forget it, the encrypted keys and credentials are gone, so keep it somewhere safe. You can carry on without one by choosing Skip for now , but a provider key is best added once a passphrase is protecting it."},{"p":"accounts.html","a":"s2","t":"A faster unlock with a passkey","u":"Accounts & privacy","b":"Once a passphrase is protecting the app you can add a passkey for a faster unlock: a face, a fingerprint or a security key, the same passwordless sign-in your device already offers. A passkey does not replace the passphrase but unseals it for you, so the passphrase stays the root and the always-available fallback, and a lost passkey costs nothing while you still hold it. None of this reaches a server: the unlock happens on the device, and the credits service only ever sees a public key."},{"p":"accounts.html","a":"s3","t":"The account controls","u":"Accounts & privacy","b":"Your identity sits at the top of the admin panel, bottom-left. The admin home lists the controls for it: The account controls: change your name or passphrase, back up or restore, log out, or forget the identity entirely. Change name… : rename the identity. Change passphrase… : set a new one; your encrypted data is re-wrapped under it. Add a passkey… : a face, a fingerprint or a security key for a faster unlock. Export a backup : write your chats, Diamonds, workspace files and your account key to a file you keep. The key goes in wrapped, exactly as this browser holds it, so the file is no weaker than the browser and opens to nothing but your passphrase. Import a backup… : bring that file back here. Where this browser holds no account of its own the backup's account is adopted, and you unlock it with that account's passphrase; where an account is already here the backup's is left alone and only the work returns. Log out : lock the app. Your data stays on the device, encrypted, until the passphrase is entered again. Forget this identity… : remove the identity and its encrypted data from this browser for good. Two more rows sit alongside them. Syncing turns this device's sync on or off"},{"p":"accounts.html","a":"s4","t":"More than one person on one browser","u":"Accounts & privacy","b":"One browser can hold several accounts, each with its own chats, keys, credits and files. Nobody sees another account's data. Stepping away. Choose Log out to lock the app. Your chats, keys and files remain on the device and cannot be read without your passphrase. Returning. Enter your passphrase to unlock. Every reload locks the app again, a hard refresh and a restarted browser included, because the key it derives is held in memory and never written to disk: nothing of yours is lost, and nothing opens until it is entered. A passkey, or a password manager holding the passphrase, supplies it for you. Someone else's turn. + Add another account in the admin panel makes a second one, and the row above it switches between them. Switching locks this account first (its keys are forgotten) and then opens the other. Handing the browser over for good. Forget this identity… clears your account from this browser."},{"p":"accounts.html","a":"s5","t":"Moving your account between devices","u":"Accounts & privacy","b":"Your account is a signing key held in this browser. The passphrase does not recreate it, only decrypts the copy already stored here, so the same passphrase in a fresh browser starts a separate account with its own credits and no Pro. The key itself has to travel, and three things carry it: Link another device , which shows a pairing code to type into the new browser; a passkey, which stands a new device up in one gesture; and Export a backup , whose file holds the key wrapped for Import a backup… to adopt in a browser that has no account yet. Do one of them before you remove a browser: once its storage is gone, and no backup was taken, the key is gone with it, and with it the credits and any Pro licence, which nothing else unlocks. A backup holds your work in the clear and your key under your passphrase. Every chat, Diamond and workspace file is in it as plain text, so keep it as private as the work itself. The key beside them is wrapped, so importing the file alone makes nobody you, but whoever holds the file and the passphrase holds the account, which is why the two should never travel together."},{"p":"accounts.html","a":"s6","t":"What stays private","u":"Accounts & privacy","b":"Your passphrase, provider keys, mail credentials, chats, Diamonds and files live in this browser and are not sent to us. What we hold on the gateway is money and ciphertext: your credit balance and licences, and, for cross-device sync, one encrypted parcel we cannot open. We do not have the key, so we cannot read your work. Where data goes bears saying exactly. Your messages reach a model provider directly with your own key, or through our metered service when you spend credits. Fetching a page, and syncing or sending mail, pass through the gateway, and a sync carries an encrypted parcel between your own devices. So the honest claim is not that nothing ever leaves: it is that with your own key your chats and files never leave in the clear, and you can watch only ciphertext leave for our servers. You need not take that on trust. Daimond's client (the code running in this browser, which decides what is sent) is open source. Read it, build it, and open your browser's network panel to confirm that only ciphertext leaves. The one claim every private tool makes, we let you check: github.com/oxedyne-com/daimond . The protection has honest limits. The passphrase guards against casual local"},{"p":"capps.html","a":"","t":"Capps","u":"","b":"Capps Every Diamond is drawn by a page of its own. A capp is that page written as an application: something you tap, which records what you tapped into a file beside it. Ask your daimon for a food log, a practice tally or a set of readings, and what comes back is a small app that lives inside the Diamond and keeps what you put in it. The page is a real file, crystal.html , in the Diamond's own folder. Every Diamond has one from the day it is made: the standard page renders the crystal as a document. A capp is the same file doing more, and the same rules cover both."},{"p":"capps.html","a":"s1","t":"What a capp can do","u":"Capps","b":"Draw the crystal. Everything the Diamond knows is handed to the page when it loads, and again whenever you change how Daimond looks, so the page can dress itself to match. Read the files in its own Diamond. A table it draws a chart from, an index it maintains, its own log from yesterday. Write files there too. This is the part that makes it an application rather than a rendering. A tap can be recorded, and it is still there tomorrow. Ask Daimond to open a link , which goes through the same gate every other outward request does and may still be refused. Writing is how a capp remembers, and it appends by default: a new line goes after what was there. Two taps in the same instant both survive, which a logger that loses one under a double tap would not. One write is capped at half a megabyte , which is thousands of entries at once and far more than a tap ever records. The file itself has no such ceiling: a log grows past it a line at a time, for as long as you keep one."},{"p":"capps.html","a":"s2","t":"What a capp cannot do","u":"Capps","b":"A capp runs in a sealed frame. None of the following is a setting to be turned on: they are the design, because the page was written by a model, it is not part of what the Diamond knows and so is never folded or reviewed the way a crystal is, and it syncs to every device you own."},{"p":"capps.html","a":"s3","t":"No network","u":"Capps › What a capp cannot do","b":"No fetch, no request of any kind, no image loaded from a server. A capp cannot call an API, and it cannot send anywhere what you have put in it. Everything it knows arrives from Daimond."},{"p":"capps.html","a":"s4","t":"No libraries","u":"Capps › What a capp cannot do","b":"Nothing is loaded from outside: no framework, no chart library, no web font. A capp is one self-contained file, so its pictures are drawn or inlined and its code is its own. Nor can it build fresh code out of text while it runs, so what the page does is what is written in it."},{"p":"capps.html","a":"s5","t":"512 KB","u":"Capps › What a capp cannot do","b":"The whole page, code and style together. Generous for a page written economically and tight for one used as a store, which is deliberate. Page size limit in Settings raises it if you need to."},{"p":"capps.html","a":"s6","t":"No storage of its own","u":"Capps › What a capp cannot do","b":"It cannot use the browser's storage, and it has no memory between loads except the files it asks Daimond to write. Those files are in the Diamond, where you can read them."},{"p":"capps.html","a":"s7","t":"It cannot rewrite itself","u":"Capps › What a capp cannot do","b":"A capp may not write over crystal.html or crystal.json (nor crystal.md , where an older Diamond still keeps one), the version history, or the Diamond's own records. A page that could change its own code between one look and the next would mean nothing you read stayed read."},{"p":"capps.html","a":"s8","t":"It cannot leave its Diamond","u":"Capps › What a capp cannot do","b":"Every path it asks for is resolved inside that one folder, and anything climbing out of it is refused. One capp cannot read another Diamond's files, and none of them can reach your workspace. The trade is the point. A capp is smaller and plainer than the little apps other tools will write for you, and there is no way yet to share one with anybody else. What you get for that is an app nobody else can read the contents of, that works with no connection, and that carries no subscription to keep it alive."},{"p":"capps.html","a":"s9","t":"Where what you record goes","u":"Capps","b":"Into the Diamond, beside the page, on this device. A Diamond is kept in the browser's own storage: it is on your machine, but it is not a folder you can open in a file manager, and it is not in the folder you have open as your workspace, even though the Diamond's directory is listed there. Daimond keeps its own things apart from your work on purpose, so a page's log can never be written into somebody's project. The Workspace panel is where you read it. Nothing about it is sent to us, and what does leave the browser is set out in full on the Accounts page. Deleting the page does not delete what it recorded: the files stay where they are, and a new page can read them. Because the files are in the Diamond, they travel with the Diamond. Cross-device sync carries the whole folder to your other devices, so a log kept on your phone is on your laptop, and the gateway holds a parcel it cannot open. Two things follow that are worth knowing before you fill one up: A Diamond travels whole, from whichever device touched it last. Log on your phone and on your laptop between two syncs and you do not get both sets of entries: the side that synced later is the one that survives. Logging in one plac"},{"p":"capps.html","a":"s10","t":"Asking a daimon for one","u":"Capps","b":"Open the Diamond you want the app to live in and choose ✎ Page in the row above the crystal. That fills the message box with a note saying which of the Diamond's two files you mean, since ✎ Edit beside it changes what the crystal says and this changes how it looks . Finish the sentence with what you want and send it. Say what you tap and what it should record. \"A page with a tile for each of the foods I eat: tapping one records it with today's date, and the day's total is at the top.\" A daimon that knows the shape of the thing writes the file in one turn. What it cannot do is guess whether an entry is a count, a weight or a time, so say which. You can ask for changes afterwards in the same way, and every version of the page is kept: ↺ History shows them, and any of them can be restored. A page that will not load is not a dead end either. Daimond puts its own rendering up in place of the capp, says which way it failed, and offers to put the standard page back."},{"p":"capps.html","a":"s11","t":"Using one on a phone","u":"Capps","b":"At the right-hand end of the row across the top of the centre panel, on a Diamond's crystal, sits a button drawn as four corners. Its name, Full screen , is in the tooltip rather than beside it, because in the ordinary view there is no room for the word. Pressing it takes away the rail, the top bar, the dock, the bottom bar, the message box and the crystal's own row of buttons, and gives the whole screen to the page, which is what a capp is worth having on a phone. The same button, now wearing the words Exit full screen , brings it all back. Esc does too, so long as Daimond has the keyboard: while you are typing inside the page itself the keystrokes belong to the page, which is why the way out is a button and not only a key. It is never entered on your behalf, and it is not remembered: reopening Daimond puts you back in the ordinary view."},{"p":"capps.html","a":"s12","t":"A worked example: Log Life","u":"Capps","b":"A capp ships with Daimond as an example, and you can have it as a working Diamond rather than reading about it. The button below makes a Diamond called Log Life and puts the page inside it, furnished and ready to record. Daimond asks first, and if you already have one it offers to open that instead of making a second. Make me Log Life Nothing is sent anywhere. It makes one Diamond on this device and copies the page into it. Once it is made, the page is a file in that Diamond like any other, and the Diamond's own daimon can read it. So the place to ask for a variation is inside Log Life itself: ✎ Page there, and \"the same, but for practice sessions instead of meals\", gives the daimon a worked example in front of it rather than a description of one. A daimon in some other Diamond cannot see this page, and will write you a new one from scratch. &larr; Chats & Diamonds Next: Email, Web & files &rarr;"},{"p":"chats-and-diamonds.html","a":"","t":"Chats & Diamonds","u":"","b":"Chats & Diamonds A chat is a conversation with the daimon. A Diamond is a durable container for a pursuit, holding what you have worked out about a piece of work so that later work starts from it. Here: starting and reading chats, the turn controls, folding a chat into a Diamond, the workspace a Diamond works in, attaching files to either, and organising what you accumulate."},{"p":"chats-and-diamonds.html","a":"s1","t":"Starting and returning to a chat","u":"Chats & Diamonds","b":"Choose New chat , the + beside Chats in the rail. Type in the box at the bottom of the centre panel and send with ➤ . Every chat you start is listed under Chats , newest first; click one to bring it back to the centre. A new chat starts on your default model, and the selector in its header changes the model for that chat alone. A chat tile carries a × , and the ⋯ on the Chats head carries Delete all chats . Neither asks: both move chats to the Trash , where they can be brought back. The questions have moved to the two acts that cannot be undone, which are both in that panel. While an answer is arriving you can keep typing. A message sent then is queued rather than lost: it appears under the thread as a dashed bubble and goes as its own turn the moment the answer finishes. Click a queued bubble to take it back into the box and change it, or its × to drop it. Pressing ■ to stop the answer hands anything queued behind it back to you, unsent. Stopping means stopping."},{"p":"chats-and-diamonds.html","a":"s2","t":"Reading a long conversation","u":"Chats & Diamonds","b":"A conversation grows quickly, so the chat header carries controls to keep it readable, at the top-right of the centre panel. Two more sit in the composer bar beside ➤ ."},{"p":"chats-and-diamonds.html","a":"s3","t":"Steps","u":"Chats & Diamonds › Reading a long conversation","b":"The Steps button shows or hides the tool steps in the thread, the work the agent did between your message and its answer. Hide them to read the conversation; show them to see what it did."},{"p":"chats-and-diamonds.html","a":"s4","t":"Collapse","u":"Chats & Diamonds › Reading a long conversation","b":"The − button collapses every answer, leaving what you asked. It is the quickest way to skim a long thread, and it is how you start picking turns to fold."},{"p":"chats-and-diamonds.html","a":"s5","t":"Jump back","u":"Chats & Diamonds › Reading a long conversation","b":"The chevron up beside the send button jumps back to your last message. Press it again to walk back through the ones before it."},{"p":"chats-and-diamonds.html","a":"s6","t":"Jump to the end","u":"Chats & Diamonds › Reading a long conversation","b":"The chevron down returns to the bottom of the chat and starts the walk again, so the next jump back goes to your last message instead of carrying on from where you had got to."},{"p":"chats-and-diamonds.html","a":"s7","t":"Concise","u":"Chats & Diamonds › Reading a long conversation","b":"A standing toggle asking for short answers in this chat. It is a skill and not a hidden instruction: what it asks for is a file in your workspace you can read and edit."},{"p":"chats-and-diamonds.html","a":"s8","t":"Permission mode","u":"Chats & Diamonds › Reading a long conversation","b":"A word beside the model saying what Daimond does without asking. Covered on Machine Operations . Collapsing the answers leaves what you asked, and turns on the controls for selecting turns to fold."},{"p":"chats-and-diamonds.html","a":"s9","t":"Folding a chat into a Diamond","u":"Chats & Diamonds","b":"When a conversation has worked something out, you fold it: keep what you learnt, drop the back-and-forth that produced it. What you fold into is a Diamond , and two units make it up: A fold is one improvement, a single step forward. A crystal is what the folds have accumulated: the shape of the work, the steps in their order, and the checks you found the hard way. A Diamond is a crystal together with the chain of folds that produced it."},{"p":"chats-and-diamonds.html","a":"s10","t":"Selecting turns and folding them","u":"Chats & Diamonds › Folding a chat into a Diamond","b":"Collapse the thread with − , then pick the turns worth keeping. A row of controls appears in the header: Select all , Deselect all and Fold selected , which folds the chosen turns into the Diamond. Fold a step you have adopted and not a passing remark: folding keeps what you learnt, not the transcript. Nothing is absorbed on its own. A crystal never grows in the background: you choose the turns that are offered, and the fold itself is a proposal. The agent rewrites the crystal and shows you the result, which you accept or reject. A crystal only changes because you said so. Selecting a Diamond shows its command surface in place of the chat, where you steer and fold the method."},{"p":"chats-and-diamonds.html","a":"s11","t":"Working a Diamond","u":"Chats & Diamonds","b":"Diamonds are listed above your chats in the rail; add one with the + beside Diamonds . Selecting one replaces the chat in the centre with its command surface, a compact view where you steer the work and fold further improvements into it. You can tell which face the panel is showing without reading it: on a Diamond it takes the Daimond mark beside the name and squares its corners, against the rounded corners of everything else on screen. A Diamond has two faces , and a switch in the header moves between them. Crystal is what the Diamond knows. Chat is its own conversation, which persists like any other and carries a Fold button, because folding is done mid-flow rather than while configuring something. Pick a chat in the rail and the ordinary conversation returns, as it does whenever the stage would otherwise be empty."},{"p":"chats-and-diamonds.html","a":"s12","t":"What a Diamond does, and what it does not","u":"Chats & Diamonds › Working a Diamond","b":"A Diamond retains; on its own it does not run. Nothing executes a crystal: there is no workflow engine and no chain from one Diamond to another. Returning to a Diamond does not set it going, and neither does leaving it alone. A Diamond you have not automated answers when you prompt it and at no other time — which is what its panel says when you look: Nothing set. This Diamond answers when you prompt it and at no other time. So picking it up again means steering it again with everything it has learnt already in hand. The crystal is prose, which is what a model reads best, and it is handed to the daimon when you work the Diamond and to every worker dispatched from it. What you worked out once reaches the work again without you retyping it, or remembering that you should. The one way a Diamond acts without you is the one you set up yourself, described next."},{"p":"chats-and-diamonds.html","a":"s13","t":"Triggered actions","u":"Chats & Diamonds","b":"A triggered action is a standing arrangement for a Diamond to do something without being asked . You write it, you switch it on, and from then on the Diamond acts when the thing you named happens. It is the only part of Daimond that spends money with nobody at the keyboard, so it is worth reading this section before you set one. They live under When this Diamond acts on a Diamond's crystal. Add an action makes one; a pulldown selects it for editing when there is more than one. Two things can set an action off: Minutes of my activity. A timer that only counts while you are actually working. A tab left open overnight counts none of them, so a Diamond set to thirty minutes fires after half an hour of your work, not half an hour of wall clock. Mail arriving. Mail landing in a folder you name, in a mailbox you have already set up. Nothing fires until there is mail. Each action carries two pieces of writing. The instruction is what the Diamond is asked to do when it fires, and it is sent every time. The context is background it needs the first time only: it goes in front of the first instruction and then stops going, until you change it, at which point it is sent once more. That is what "},{"p":"chats-and-diamonds.html","a":"s14","t":"The play, the pause and the light","u":"Chats & Diamonds › Triggered actions","b":"Every triggered action wears the same three-part control the rest of the app uses: a play , a pause and a round light . The Diamond carries one that speaks for all of its actions, and the Everything row at the top of the rail carries one that speaks for the whole app. The light says whether anything is going to happen on its own. Not whether you have pressed pause — whether something is actually armed and free to fire: Red. Nothing here will act by itself — because you have set nothing up, or because what is here is switched off, held, or missing something it cannot fire without. Amber. Some of what is set up will act, and some is held. Green. Everything that is set up will act. A Diamond you have not automated therefore shows red , and so does the Everything row on a fresh account. That is not a warning. It is the honest answer to \"is anything running by itself?\", and on a new account the answer is no. The two buttons follow the light, so you never have to work out which one would do something: Red: play is live and pause is greyed. There is nothing running to stop. Amber: both are live. You can release what is held or hold the rest. Green: pause is live and play is greyed. There "},{"p":"chats-and-diamonds.html","a":"s15","t":"The crystal and its history","u":"Chats & Diamonds","b":"The crystal is two real files in the Diamond's own directory: crystal.json , what the Diamond knows, and crystal.html , the page that draws it. That directory is always in the Diamond's workspace, so both can be opened in the Workspace panel, read, and edited by hand. It is not inside the folder you have open as your workspace, though: a Diamond is kept in the browser's own storage, apart from your work. Every write snapshots a version, so a crystal has a history and nothing is written over. The history lists every version, newest first, each with what produced it: View : read that version. Restore : make that version current again. Delta : see the raw input a fold consumed, the material the agent was given to reduce. Restore is not destructive. The text that was current is kept in the history first, so restoring an older version adds to the history rather than replacing it. A restore you did not mean can itself be undone."},{"p":"chats-and-diamonds.html","a":"s16","t":"Artefacts","u":"Chats & Diamonds","b":"A Diamond also keeps track of what its work touched: the files written and the pages opened while you were working on it. None of it is yours to record. Daimond already notes every tool an agent uses, so the list is read off what happened, and gathered at the moment you accept a fold. Files that were only read are left out on purpose. An agent may open forty files looking for one thing, and all forty listed would bury the one that mattered. What is kept is what the work produced, and the pages you asked to see. When a Diamond has any, a line above the steer box says how many. Clicking it opens the list, where each entry does three things: The name opens it: a file in the Doc panel, a page in the Web panel. The small arrow puts a reference to it in the steer box, so you can say \"redo the figures in this one\" without typing out the path. The cross removes it, if it does not belong to this Diamond after all. A file you have since renamed or deleted says so when you try to open it, rather than quietly doing nothing. A list of dead links that pretends otherwise is worse than no list."},{"p":"chats-and-diamonds.html","a":"s17","t":"The workspace of a Diamond","u":"Chats & Diamonds","b":"A Diamond has a workspace : the files and folders you keep with it. You put them there. A daimon cannot add to its own workspace, so it works with what it has been given and asks you when it needs more. It is a view of your files, not a box holding them. Nothing is copied when you attach something: the file stays where it is and the Diamond points at it. Attach the same folder to two Diamonds and there is still one folder, and an edit made through either is the file the other reads. Taking something out of a Diamond's workspace only detaches it; the file itself is untouched, and only a deliberate delete removes it. The word workspace invites you to expect a copy, and there is none. A Diamond also has a directory of its own, always in its workspace and always writable, so its daimon has somewhere to work before you have attached anything; the crystal lives there. A folder can be attached to be consulted rather than edited , which lets a daimon read it and refuses every write. And the Workspace panel shows either all your files or only the ones this Diamond holds, whichever suits the work in front of you."},{"p":"chats-and-diamonds.html","a":"s18","t":"Attaching, with the paperclip","u":"Chats & Diamonds › The workspace of a Diamond","b":"The 📎 on every row of the Workspace panel (on files as much as folders) and in the Doc panel's header reads Attach to current focus . One control, whose effect follows what is in focus and not which row it sits on. With nothing in focus it is not offered at all. A Diamond is in focus. The file or folder joins that Diamond's workspace and stays until you take it off. Its daimon may then open it. An ordinary chat is in focus. The attachment is for the next turn only , shown in a footer above the box that clears when the turn is sent. Each attachment carries one of two states, toggled on its tile. Note says the path is worth knowing about, and costs a few tokens. Read says the contents are wanted now, and a file can run to thousands. Note is where an attachment starts, being much the cheaper: a default that spends your money unasked would be the wrong one. Either way the text it generates ( Note … , or Read … in full. ) is written into the box in front of your message, to edit or delete before sending. A prompt the app writes and hides is a prompt nobody can argue with. The footer carries a + for attaching several things without leaving what you are reading, and a toggle between the "},{"p":"chats-and-diamonds.html","a":"s19","t":"What a daimon can open","u":"Chats & Diamonds › The workspace of a Diamond","b":"A daimon can only open the files in its Diamond's workspace. Nothing outside it is readable or writable, by the daimon or by any worker it dispatches. This is no instruction in a prompt that a model may or may not honour: the check sits in the compiled code, at the one door every file tool passes through, and that code is in the published bundle, which is built reproducibly. So it is a claim you can check and not one to take on trust. What it does not cover belongs in the same breath. It settles what a daimon can reach, not where what it reads ends up: whatever it opens goes to your model provider with the rest of the turn. It does guard against an agent that has been talked into something: a turn that has just read a stranger's instructions in a page or an email, and gone looking on their behalf, still reaches nothing outside this workspace. It is no guard against a provider misusing what you send it, or a build that is not the one we published; those are answered by what leaves the browser and the sealed record of every build ."},{"p":"chats-and-diamonds.html","a":"s20","t":"Dispatching workers","u":"Chats & Diamonds","b":"Some tasks want work done and not merely recorded. For those the Diamond's daimon dispatches a worker agent . Each worker runs in its own context with the workspace file tools, and is given the standing instructions and this Diamond's crystal. That crystal is the whole of what it knows about your pursuit: a worker cannot see your conversation, so the task it is handed must say everything else it needs. Up to eight workers run at once; the rest queue. The daimon dispatches them and its turn ends there, without receiving their output. Each reports a summary, and you fold the ones worth keeping in by hand, which is what keeps the choice of what enters a crystal yours. Live runs appear in the Agents panel in the dock."},{"p":"chats-and-diamonds.html","a":"s21","t":"Holding and stopping agents","u":"Chats & Diamonds › Dispatching workers","b":"The Agents panel header carries three controls that act on every agent at once, and the same three ride on each tile so you can act on one: Pause ⏸ : hang up what is running and hold the queue. A running agent keeps what it had produced; a waiting one does not start. Nothing new launches until you resume. This is the brake for a fan-out spending faster than you meant. Resume ▶ : continue every paused agent from where it left off, picking up its own work instead of starting over, so a pause costs nothing but the wait. Stop ✕ : end agents outright. Each keeps what it managed to do, as a stopped tile; Clear finished agents removes them. The instant kill switch. Each tile shows its cost as it runs , the tokens and dollars accruing live rather than only at the end, so you can see the spend while deciding whether to hold it. Under the header a line reads how many agents are running, paused and queued , which makes the size and the cost of a fan-out legible at a glance. The measures Daimond takes on its own are on the Spending page. A wider brake sits on the Everything row at the top of the rail. It pauses and resumes all of it at once: every Diamond, every chat, the workers, the mailboxe"},{"p":"chats-and-diamonds.html","a":"s22","t":"Tags","u":"Chats & Diamonds","b":"Diamonds accumulate, so they can be tagged. A tag is a short label you choose, edited from Tags on a Diamond's crystal. Four are suggested to start from ( person , project , topic and org ), but Daimond imposes no taxonomy, and you can type whatever suits your work. What you type is tidied: a tag is lowercased, trimmed and deduplicated, with up to 8 tags on a Diamond and 24 characters in each. Tags are stored in the Diamond's own meta, on this device, like everything else. The editor shows two boxes: the tags on this Diamond , and all your tags underneath. The × on a chip in the upper box takes that tag off this Diamond and returns it to the pool below, where one click puts it back. The × in the lower box is a different act: it deletes the tag itself, from every Diamond filed under it. That one asks first, and says how many Diamonds it will change. The four starter suggestions carry no × , being always offered. Tags are inert, and that is the point of them. A tag is your filing system and nothing else. It is never sent to a model, it never enters the crystal, and it never changes what any agent does. Tagging a Diamond urgent changes nothing about how it is treated. In the rail, Fil"},{"p":"chats-and-diamonds.html","a":"s23","t":"The Trash","u":"Chats & Diamonds","b":"Deleting a chat or a Diamond does not destroy it. It is trashed : still stored, still synced, out of the rail, out of the graph and the tag filter, and out of every daimon's reach, listed in the Trash panel in the dock with a Restore button beside it. It is kept thirty days and then destroyed, and each row says the date. Because the act can be taken back, nothing asks before it. The two questions live where they are true instead: Delete permanently on one item, and Empty trash , which names the count. Both are irreversible and both go from every device. A dialog in front of a reversible act teaches people to click through dialogs, and then the irreversible one is clicked through too. The reversal travels. Trashed on one device is trashed on all of them, and restored on one is restored on all of them, whichever order the two devices act in and whichever order their parcels arrive. A device that was away for six weeks works out the same retention date from the same stamp when it comes back. A backup carries the trash with it, so restoring an old one cannot un-delete what you deleted since, nor re-delete what you have restored. &larr; Models & credits Next: Capps &rarr;"},{"p":"email-web-files.html","a":"","t":"Email, Web & files","u":"","b":"Email, Web & files The sources a daimon works from: mail you can read and answer, web pages it can show or drive, files it can read and write, and the tools it does the work with."},{"p":"email-web-files.html","a":"s1","t":"Email","u":"Email, Web & files","b":"The Email panel lives in the dock and holds your mailboxes and what is in them. A browser cannot open a mail connection on its own, so Daimond connects through a gateway, which hands back the raw message and forgets your credential. Your mail is written into the Workspace as ordinary files, so the agent's file tools already read it. The Email panel. Its header buttons write a message, add a mailbox, and sync."},{"p":"email-web-files.html","a":"s2","t":"Adding a mailbox","u":"Email, Web & files › Email","b":"Choose + (add a mailbox) in the Email panel header. Type your address and Daimond guesses the server settings for common providers; every field stays editable, because a guess is not a fact. Most providers want an app password (a single-purpose password you generate in your mail account's security settings) and not your account password. The panel says where to find it for your provider. Your mail credential is stored on this device, wrapped under your passphrase. It is handed to the gateway only for a single sync, held for one conversation with your mail server, and then forgotten. Daimond stores no mail on any server and never sees your account password."},{"p":"email-web-files.html","a":"s3","t":"Reading and syncing","u":"Email, Web & files › Email","b":"Choose ⟳ (sync now) to fetch what has arrived. A sync asks only for messages newer than the last one held, so it stays quick. Click a message to open it onto the stage, beside the chat, so you can ask the daimon about it while you read."},{"p":"email-web-files.html","a":"s4","t":"Writing a message","u":"Email, Web & files › Email","b":"Choose ✎ (write a message) to open the Compose panel on the stage. Fill in From , To , an optional Cc , a Subject and the body; attach files with Attach… ; keep a draft with Save draft . Nothing sends by itself. Only you can send mail. The Send button is the one thing in Daimond that puts mail on the wire, and only a person can press it. The daimon can draft a message beside you, but it cannot send it."},{"p":"email-web-files.html","a":"s5","t":"The Web panel","u":"Email, Web & files","b":"Ask Daimond to open a web page ( “show me the Rust ownership chapter” ) or paste a link into the chat. Three ways it can put a page on the stage, and which works depends on the site. The Web panel. A page shown here sits beside the chat, so the daimon can be asked about it."},{"p":"email-web-files.html","a":"s6","t":"Show it","u":"Email, Web & files › The Web panel","b":"The page appears in the panel. Most sites refuse to be embedded (the web's clickjacking defence, the same in every browser), so this works only for the minority that allow it."},{"p":"email-web-files.html","a":"s7","t":"Read it","u":"Email, Web & files › The Web panel","b":"Daimond fetches the page and reads its text, so it works when showing does not. It reads the words, not pictures or anything drawn by JavaScript, and you do not see the page. Daimond does."},{"p":"email-web-files.html","a":"s8","t":"Drive it","u":"Email, Web & files › The Web panel","b":"With Daimond Hands , a browser add-on, Daimond opens a real page in a real tab, signed in as you, and works it while you watch. This is the only way to work a live, logged-in site. Signing in stays yours. When you sign in on a driven page, Daimond stops watching entirely (no text, no picture, no keystrokes) and never sees your password. You hand the wheel back with Resume Daimond , and that button is in the browser tab, not in Daimond, so a page can never take the wheel from you."},{"p":"email-web-files.html","a":"s9","t":"The Workspace","u":"Email, Web & files","b":"The Workspace panel, in the dock, is your files as an ordinary tree of folders. This is where the agent reads and writes: uploads, mail, documents and anything it produces all live here. With a Diamond open, the panel shows either everything here or only the files that Diamond holds. The 📎 on every row attaches one to whatever is in focus; Chats & Diamonds sets out what attaching does, what a daimon may then open, and what that protects you from."},{"p":"email-web-files.html","a":"s10","t":"Three ways to get a file in","u":"Email, Web & files › The Workspace","b":"Getting a file into the workspace and attaching it to a Diamond are separate acts. There are three ways in, and each is for a different case: Upload files : the arrow-into-tray button in the panel header. For one file or a handful. An ordinary file picker, in every browser. Import a folder… : for a whole folder that should live in the browser workspace and sync. Chromium-based browsers only. Open a real folder : the Machine chip. Your own disk is the workspace: nothing is copied and nothing syncs. Chromium-based browsers only. An agent can also write a file where it is allowed to, and mail arrives here as ordinary files. The Workspace. The chips name where the workspace lives; below them, interviews.txt is in cloud storage rather than on this device, and report-draft.txt is pinned so it is always kept here."},{"p":"email-web-files.html","a":"s11","t":"Working with files","u":"Email, Web & files › The Workspace","b":"The Workspace header carries buttons: New file , New folder , Upload files , Parent folder , Refresh . Under them a breadcrumb names every folder above the one you are in, each clickable, so a folder three deep is never a dead end. A filter box narrows a long list, and searches from where you are downward rather than stopping at the current folder. Below the tree, System opens Daimond's own files: the store the Diamonds themselves live in. They are kept in the browser rather than in the folder you have open, and they travel between your devices. The tree above deliberately leaves them out, since a delete cross beside diamonds/ would take every Diamond you have."},{"p":"email-web-files.html","a":"s12","t":"Where a workspace lives","u":"Email, Web & files › The Workspace","b":"Three chips at the top of the panel name the places a workspace involves. Clicking one opens that place's controls."},{"p":"email-web-files.html","a":"s13","t":"Browser","u":"Email, Web & files › The Workspace","b":"This browser's own private storage, on your device and reachable by nothing outside Daimond. It is where a workspace lives unless you say otherwise. Its size is whatever the browser grants, which on an iPhone is not much, and a browser may clear it without warning."},{"p":"email-web-files.html","a":"s14","t":"Machine","u":"Email, Web & files › The Workspace","b":"A real folder on this computer's disk. The agent works in it directly, so the same files are in your own file manager, and it is roomier than what a browser grants. But it stays on that one computer, never travelling to your other devices, and only a Chromium-based browser can open one. The folder is the whole of what the agent can see. Nothing above it and nothing outside it is visible to Daimond. Clicking the chip while the agent is working there says so, and offers Forget this folder to stop Daimond holding a record of it."},{"p":"email-web-files.html","a":"s15","t":"Cloud","u":"Email, Web & files › The Workspace","b":"Not a third place to work but where the workspace is kept, which is what lets it be far larger than any one device holds. Its chip opens a view of what is stored, what is not on this device, a Free up space button and a Credits button. The first two are alternatives, the agent working in one or the other. The third is not an alternative but where the bytes are kept. The admin panel's storage rows show how much space each is using. What is kept in cloud storage is encrypted before it leaves , as a sync parcel is, so we hold bytes we cannot read."},{"p":"email-web-files.html","a":"s16","t":"Held, in cloud storage, or pinned","u":"Email, Web & files › The Workspace","b":"A file is in one of three states, and the tree shows which: Held on this device : it opens at once. In cloud storage only : marked with a cloud. Still your file, still listed, still safe, simply not here at the moment. Clicking it brings it down, and so does the fetch control on its row. Pinned : kept on this device always and never freed automatically. The pin sits on the row, beside a control that frees a held file's space. As the browser's storage fills, the files longest unused are freed back to cloud storage on their own; a pinned file never is. Freeing a file is not deleting it. It stays in cloud storage, the tree still lists it, and it comes back when it is asked for. Only a deliberate delete removes a file."},{"p":"email-web-files.html","a":"s17","t":"Any kind of file","u":"Email, Web & files › The Workspace","b":"Any file is stored and travels between your devices, up to a gigabyte each. Opening one that is not text shows its size and a download button instead of trying to display it."},{"p":"email-web-files.html","a":"s18","t":"Moving files in and out","u":"Email, Web & files › The Workspace","b":"Two buttons sit beside the chips. Import a folder… copies a folder from this computer in, after which it syncs and is stored like everything else. Save a copy… writes the workspace out to a folder on this computer, and says how many cloud-only files it left behind rather than fetching them. Neither changes where the agent is working, and both need a Chromium-based browser. While the agent is working in a real folder a third button appears, Change folder… , and it is the only control that opens a folder picker. Moving between Browser and Machine does not: Daimond remembers the folder you last used, so going back is one click on the chip."},{"p":"email-web-files.html","a":"s19","t":"What the agent may fetch","u":"Email, Web & files › The Workspace","b":"When the agent needs a file that is in cloud storage, it is told so plainly and has to fetch it deliberately. Nothing is downloaded quietly behind a read: a download can be large and, once storage is priced, costs you money. A cap limits how much the agent may bring down on its own initiative, after which it comes back and asks."},{"p":"email-web-files.html","a":"s20","t":"What cloud storage costs","u":"Email, Web & files › The Workspace","b":"Not a subscription. Like everything else leaving the browser it is paid for from credits , and the one-time Pro unlock stays one-time. At present it is free and unmetered, until it can be sold properly. If a storage charge ever cannot be covered, nothing is deleted straight away . Reading and downloading stay free for six months, so everything can be retrieved, and only then is the paid overflow removed. The free working set never is."},{"p":"email-web-files.html","a":"s21","t":"Tools","u":"Email, Web & files","b":"Open the Tools · N of M row in the admin panel to see what Daimond can do. It is called Tools, not Upgrades, because most of what it lists is free and already yours. The Tools panel: the built-ins you already have, and the unlockable tools with their prices. Two kinds of tool appear: Built-in tools : what the agent is already handed, free. The panel lists exactly what it holds, so it cannot promise a tool that is not there. Unlockable tools : extras with a price, shown with whether this account already holds the unlock. To add one, choose it and confirm; the cost is drawn from your credits, and once unlocked it stays available. &larr; Capps Next: Accounts &rarr;"},{"p":"index.html","a":"","t":"Getting started","u":"","b":"Getting started Daimond is an AI agent workspace that runs entirely in your browser. There is no account on a server and nothing to download: your chats, keys and files live only on this device. Nothing leaves your device unless you direct it to. Your messages go to the model provider you connected; credits pay for a model run, a page fetched or a mailbox synced; a device you link gets an encrypted parcel. Everything else stays in this browser. Accounts & privacy sets out what goes where, and how to check it yourself. Daimond on first run. The conversation sits in the centre; the admin panel is bottom-left."},{"p":"index.html","a":"s1","t":"The shortest path to a first answer","u":"Getting started","b":"Three steps. Each one points at a control you can see on screen."},{"p":"index.html","a":"s2","t":"Create an account","u":"Getting started › The shortest path to a first answer","b":"On first run Daimond offers to protect this device with a passphrase. Type your name and a passphrase, then choose Create account . The passphrase encrypts your stored keys and mail credentials, and it is your on-device identity. It is never sent anywhere, so keep it somewhere safe: if you lose it, the encrypted data is gone. Skip for now lets you set one later, though a provider key is best added once a passphrase is there to protect it."},{"p":"index.html","a":"s3","t":"Connect a model, or buy credits","u":"Getting started › The shortest path to a first answer","b":"A daimon needs a model to think with. Two ways to give it one, both in the admin panel at the bottom-left: Bring your own key. Open the Models row, choose + Add provider , pick a provider, paste its API key, and star a default model. Your messages then go straight to that provider on your own account. Buy credits. Open the Credits row and buy a pack. Daimond runs the model for you: no provider key to manage, no subscription. Either one is enough. See Models & credits for the detail."},{"p":"index.html","a":"s4","t":"Start a chat","u":"Getting started › The shortest path to a first answer","b":"Choose New chat at the top of the rail (the + beside Chats ), type in the box at the bottom of the centre panel, and send with ➤ . That centre panel is where you talk to the daimon, and Daimond is built around that conversation."},{"p":"index.html","a":"s5","t":"What you are looking at","u":"Getting started","b":"The screen has three zones. The rail on the left lists what you are working on and, below a movable divider, the admin panel . The stage in the centre holds the conversation and anything you read beside it. The dock on the right holds the sources you pull from: Email, the Workspace, agent runs, your spending, what is waiting on you, and the Trash. Across the top, every panel has a chip that opens or closes it, and buttons at the far right for the About dialog, this guide, and the theme, text size and dock tiling. None of it is needed on the way to a first answer; all of it is laid out on The interface . The admin panel. Each row answers a question about the machine, and the ones you can act on are buttons. The admin panel is where Daimond is set up and where it tells you what it is costing. Each row is a button that opens the thing it names: your identity, Models , Credits , Tools , Version , and the storage your workspace is using. The next page walks through every part of the screen."},{"p":"index.html","a":"s6","t":"Keeping it to hand","u":"Getting started","b":"Your browser's own Install , or Add to Home Screen on a phone, gives Daimond an icon and a window of its own. It is the same page and the same stored work: nothing is downloaded, nothing moves, and a build the server has moved past is still refused rather than served from a cache. Next: The interface &rarr;"},{"p":"interface.html","a":"","t":"The interface","u":"","b":"The interface A tour of the screen: three zones, and what each part does. Once you know the zones, everything in Daimond has a place. The named regions. The top bar runs across the top; below it, three zones: the rail (left), what you work on, above a divider, with the admin panel below; the stage (centre) for the conversation and whatever you have opened beside it, two seats on a laptop and up to four on a wide screen; and the dock (right) holding Email, Workspace and Agents."},{"p":"interface.html","a":"s1","t":"The rail (left)","u":"The interface","b":"The rail is split by a divider you can drag but not remove. Above the divider is what you are working on; below it is the admin panel. A row named Everything sits over the lot, holding every Diamond, chat, worker, mailbox and page fetch at one press. Its light is the root of every other in the app: green while everything that could spend is running, red when none of it is, amber in between. The rail's own closer is on that row, the only one that speaks for the whole rail."},{"p":"interface.html","a":"s2","t":"Diamonds","u":"The interface › The rail (left)","b":"The pursuits you keep. A Diamond holds what a chat taught you about a piece of work, so the next stretch of it starts from what you know. Add one with the + beside Diamonds ; the button next to it draws them as a graph . Tag them as they accumulate and the Filter by tag row narrows the list."},{"p":"interface.html","a":"s3","t":"Chats","u":"The interface › The rail (left)","b":"Your conversations, newest first. Start one with the + beside Chats ; click any chat to bring it back to the centre. The ⋯ beside the + holds Delete all chats , which is about every chat rather than one and so does not sit on a chat tile. A second divider sits between the two lists. Diamonds accumulate, and without it a long list of them pushed the chat tiles off the bottom; drag it to give either list the room, or double-click it for an even share. Neither can be crushed away entirely, and the share is remembered per device with the rest of your layout. Diamonds sit above chats, which is the way the ground is: you mine in the conversation underneath, and what you bring up is cut and polished above it. A chat is raw, a Diamond is worked, and the order says which way the work travels without a word of explanation. The word chat was left alone for the same reason. A Diamond is a new sort of thing and earns a new name; a conversation is ordinary and keeps its ordinary word. Both are covered in full on Chats & Diamonds ."},{"p":"interface.html","a":"s4","t":"The admin panel","u":"The interface › The rail (left)","b":"Below the divider, the admin panel is the state of the machine at a glance. Settings live here and not in a pop-up, so a chat stays live beside them: you can ask Daimond what an app password is while the box asking for one is still on screen. Each row that can be acted on is a button that opens what it names: An identity row (who you are on this device) with a settings cog beside it. Models , counting the providers you have connected and opening the Models form. Credits , showing your balance and opening the Credits view. Tools · N of M , how many tools are available, opening the Tools panel. Version , naming the release you are running and how long you have been on it, and opening the release history below. Workspace storage , how much space your files use in each place a workspace can live."},{"p":"interface.html","a":"s5","t":"Which version you are running","u":"The interface › The rail (left)","b":"The Version row reads as a name and an age ( Version · Albany · today ), not as a build number. Releases are named after Western Australian places in alphabetical order, so the sequence is legible without looking anything up. A name marks a milestone : Daimond ships several builds a day, and a name for each would be noise. Hover the row for the build id and its publication date. Clicking the row opens the release history , which reads from the top down: What is planned , first, in a dashed outline. The build you are running , marked you are here . Every earlier build , newest first, each with its date, a line saying what changed, its build id and its place in the sealed record. This is not a changelog kept beside the app. It is the published record Daimond's own delivery check reads: every build ever served, in order, in a chain that cannot be rewritten without breaking. The one-line notes were added without disturbing that chain, so you are reading annotated history and not a retelling of it. The planned entry looks different because it is different. It carries no build id and no seal number, and says in words that it is not built yet and not promised for a date. Everything below "},{"p":"interface.html","a":"s6","t":"How updates arrive","u":"The interface › The rail (left)","b":"Daimond updates itself. There is nothing to download: the running tab notices a newer build and reloads onto it, and the reload loses nothing, because every boot recovers your work from the durability journal. The only question is when . A normal update waits for a quiet moment — the tab in the background, or left untouched for about ten minutes — and never reloads over a running turn or a half-typed message. The chip beside the top-bar buttons says when one is ready; click it to take the update at once. Some updates cannot wait. When a change means an out-of-date tab can no longer work with the server, the server refuses it, and the tab reloads onto the current version on its own. Even then it will not cut a running turn, and it waits a moment after your last keystroke instead of reloading mid-sentence. There is no way to decline a version: the app you would keep is the same app from the same people, and a browser cannot run yesterday's build against today's server."},{"p":"interface.html","a":"s7","t":"The stage (centre)","u":"The interface","b":"The stage is the middle zone. Its occupants sit side by side and never dock at the right, so you never leave the conversation to do a thing: read the message, watch the page, read the document beside the pages it was typeset into, with the daimon still there to be asked about any of it. How many seats there are is decided by how wide the stage is , not by a fixed number: two at the narrowest, four at the widest, and one more for roughly every 380 pixels, which is where a line of prose still holds about 45 characters. Four of them want around 1550 pixels of stage, so they are for a large monitor; a laptop usually gets two or three. Two is the floor whatever the width, because the whole point of the stage is that whatever you are attending to opens beside the conversation rather than over it. Narrow the window and the rightmost seat closes, the one you opened most recently first. The conversation is never the one to go. Widening again does not bring the panel back: a panel that reappeared because a window grew would be one you never asked for, with no way to tell it not to, and getting it back is one click on its chip. Ask for a panel when every seat is taken and the guest that has b"},{"p":"interface.html","a":"s8","t":"AI, the chat","u":"The interface › The stage (centre)","b":"Where you talk to the daimon. This is the default occupant and it returns whenever the stage would otherwise be empty. Your messages, the answers, and any tool steps appear here."},{"p":"interface.html","a":"s9","t":"Web","u":"The interface › The stage (centre)","b":"A web page, shown or driven. Opened from the header or when Daimond follows a link."},{"p":"interface.html","a":"s10","t":"Doc","u":"The interface › The stage (centre)","b":"A file as its characters, given room to read it and to edit it. Its header carries the paperclip that attaches what you are reading to what you are working on."},{"p":"interface.html","a":"s11","t":"Preview","u":"The interface › The stage (centre)","b":"What a file looks like, as against what it says: a compiled PDF, a picture, or the typeset pages of a document as you write it. It is a panel of its own so that a source and its pages can be on screen at once, which is why the stage grew past two seats."},{"p":"interface.html","a":"s12","t":"Message","u":"The interface › The stage (centre)","b":"A single mail message, opened from Email, read beside the chat."},{"p":"interface.html","a":"s13","t":"Tools","u":"The interface › The stage (centre)","b":"What Daimond can do, and what the rest would cost. Opened from the Tools row."},{"p":"interface.html","a":"s14","t":"Compose","u":"The interface › The stage (centre)","b":"Writing a mail message. Nothing here sends by itself: only the Send button puts mail on the wire, and only you can press it."},{"p":"interface.html","a":"s15","t":"Graph","u":"The interface › The stage (centre)","b":"Your Diamonds and the links between them, drawn. Opened from the graph button on the Diamonds head, where you can also lay them out again or draw a new link."},{"p":"interface.html","a":"s16","t":"Terminal","u":"The interface › The stage (centre)","b":"A real terminal on your own machine, in the same compartment a command runs in. See Machine Operations . Each stage guest has a header with a close button. A closed panel does not vanish: its chip stays in the top bar, unfilled, and clicking the chip brings it back."},{"p":"interface.html","a":"s17","t":"The dock (right)","u":"The interface","b":"The dock holds the sources you pull from. Closing one leaves its chip in the top bar; clicking the chip docks it again. How the dock tiles, and so how many panels it holds at once, is yours to set under Dock tiling in the appearance menu, described below."},{"p":"interface.html","a":"s18","t":"Email","u":"The interface › The dock (right)","b":"Your mailboxes and what is in them. Add a mailbox, sync, and open a message onto the stage."},{"p":"interface.html","a":"s19","t":"Workspace","u":"The interface › The dock (right)","b":"Your files, as an ordinary tree. The agent's file tools read and write here."},{"p":"interface.html","a":"s20","t":"Agents","u":"The interface › The dock (right)","b":"Live agent runs, as they happen, with a count of how many are working."},{"p":"interface.html","a":"s21","t":"Spending","u":"The interface › The dock (right)","b":"What you have spent, and on what. Covered in full on Spending ."},{"p":"interface.html","a":"s22","t":"Pending","u":"The interface › The dock (right)","b":"What a daimon has asked for and is waiting on. Each row can be sorted by priority or by age, and answered with Do it , Discuss it first or Drop it ."},{"p":"interface.html","a":"s23","t":"Trash","u":"The interface › The dock (right)","b":"Deleted chats and Diamonds, kept for thirty days and restorable on any of your devices. See Chats & Diamonds ."},{"p":"interface.html","a":"s24","t":"The top bar","u":"The interface","b":"Across the top sit the wordmark, a row of panel chips , and, at the far right, a button to link another device , an About dialog, this guide , and the appearance and layout menu. A chip appears beside them when a new build is out."},{"p":"interface.html","a":"s25","t":"The chips","u":"The interface › The top bar","b":"Every panel has a chip, open or shut, and clicking one toggles that panel. An open panel's chip is filled in, so the row reads as a map of what is on screen. Were only the closed panels to have one, the row would be longest when the app was emptiest and every chip would shift sideways each time one was used; a chip that stays put is one whose position you can learn. (Agents is the exception to every : it keeps out of the way until the first agent runs.) The chips are grouped by zone (rail, then stage, then dock) with a thin divider between the groups, in the order the zones sit on screen. So a chip is on the side the panel it opens will appear on. Two marks carry meaning: A closed stage chip whose panel would displace a guest already on the stage is drawn with a dashed outline. It appears only when every seat is taken, which depends on the width, so the same chip is plain on a wide screen and dashed on a narrow one. The chat keeps its seat and the guest that has been there longest leaves. It warns without refusing, and it is an outline and not an added mark so the chip keeps its width and its neighbours stay put. A closed dock chip is greyed out when the dock is full . Its tooltip "},{"p":"interface.html","a":"s26","t":"Pinned panels, and the gallery","u":"The interface › The top bar","b":"You decide which chips sit in the top bar. Any panel can be pinned or unpinned; the unpinned ones live behind a ⋯ chip at the end of the row, with a count of how many are back there. Clicking it opens the gallery : every panel there is, searchable by name, grouped by zone, each row carrying a pin control and saying whether that panel is open. Clicking a row opens or closes the panel as a chip would. The row may be incomplete only because the gallery is not. Nothing is ranked by how often you use it, either: a row that reordered itself would destroy the muscle memory fixed positions exist to build."},{"p":"interface.html","a":"s27","t":"The palette","u":"The interface › The top bar","b":"Ctrl K , Cmd K on a Mac, opens a search box that reaches any panel or setting by typing. Arrow keys move through the results, Enter runs the highlighted one, Esc closes it. It lists the panels, the palettes, the four text sizes, the dock tilings, the languages, the currencies and the permission modes. It is never the fastest route to a panel you can see a chip for; it is the route that stays complete however many panels there are."},{"p":"interface.html","a":"s28","t":"By keyboard, and by ear","u":"The interface › The top bar","b":"Daimond can be driven without a mouse. Tab moves through the controls in the order they are drawn, Enter or Space operates the one you are on, and Esc closes whatever is open. Every dialog, menu and sheet also carries a cross in its corner, one control built one way, sized for a thumb on a phone. Where you are is drawn outside the control, as a ring standing off from its edge. Drawn as a change to the control's own border, as it once was, the ring is legible only while the resting border is nearly invisible, so making borders visible would have taken the focus ring away on every palette at once. Against the surface behind it the ring survives the whole range: measured on all eleven palettes, the faintest ring is still four and a half times the contrast the standard asks for. Two places in particular: Email is fully operable from the keyboard. Mailboxes, folders, drafts and messages are controls you can reach and press, not rows that only answer a click. The mailbox you are in and the folder you are reading are announced as the current ones, so a screen reader says where you are and not only what is there. A dialog keeps focus inside itself while it is open, and hands it back to wha"},{"p":"interface.html","a":"s29","t":"Appearance and layout","u":"The interface › The top bar","b":"The button at the top right opens one menu holding the choices about how Daimond looks and sits, as opposed to what it does: View : Simple or Max . Simple gives each thing its name and whether it is running, with everything else one press away; Max puts the model, the cost and the context beside it, so two can be compared without opening either. It sets the shape of the interface with it, since an airy shape at maximum density is a combination nobody wants. A tile's own cog still overrides it for that tile. Theme , eleven palettes in three bands: Light , Intermediate and Dark . The band is how you find one; within it the choice is taste, except Amber , which holds the blue out of everything it draws for reading late at night. This guide wears whatever palette the app is wearing when it is shown inside Daimond. Text size : four steps, Small , Normal , Large and Larger . Only the type responds: the frame, the padding and the panel widths stay put, because this is a control for reading and not a zoom. For a bigger interface, use the browser's own zoom. The sample in the menu is set in the size being chosen, so the control shows the change instead of naming it. Dock tiling : Auto , 1 c"},{"p":"interface.html","a":"s30","t":"Keeping an arrangement with a Diamond","u":"The interface › The top bar","b":"With a Diamond selected, the appearance menu offers to keep the current arrangement of panels with it, and to update or forget one already saved. Opening that Diamond again puts it back, so returning to a piece of work is not reassembling its panels by hand. It is saved only when you ask, never inferred and never in the background, because a switch that silently closed panels would read as work being lost."},{"p":"interface.html","a":"s31","t":"On a narrow screen","u":"The interface","b":"Below the phone width the chips and the gallery give way to the phone shell, which answers the same question with less room: the chat is the floor, a panel rises over it as a sheet you can drag, and the rail becomes a drawer opened by the button at the top left. The row along the bottom is the same chip row, scrolled sideways. Every panel has a chip in it, in the order the zones run on a larger screen; the filled one is whatever you are looking at, rather than everything that is open, because on a phone only one thing is; and a chip takes you there rather than toggling, since the thing it would close is the whole screen. The admin panel is reached down the drawer. Nothing is lost; it is the same panels, shown one at a time. Installed to the home screen, Daimond runs in its own window with no browser furniture, and holds itself clear of the notch and the home indicator. It is the same page and the same stored work, so nothing has to be moved into it. &larr; Getting started Next: Models & credits &rarr;"},{"p":"machine-operations.html","a":"","t":"Machine Operations","u":"","b":"Machine Operations Daimond can run programs on your computer (a build, a test suite, a linter, a script) inside a compartment the kernel enforces. It is free, it is two commands at a terminal, and it is Linux only. Read the box below before you type either of them. A snap or flatpak browser cannot do this, and cannot be made to. The installer detects one and refuses rather than writing into it, so you will meet this before you meet anything else, and on Ubuntu the default Chromium is a snap. Why, and what to install instead ."},{"p":"machine-operations.html","a":"s1","t":"Before you start","u":"Machine Operations","b":"Three things decide whether any of this will work. Checking them takes a minute; discovering them afterwards takes an hour, because the error the browser reports names none of them."},{"p":"machine-operations.html","a":"s2","t":"1. A browser installed from a .deb","u":"Machine Operations › Before you start","b":"A snap or flatpak browser confines the programs it starts, and that confinement reaches Daimond's hand. The home interface a snap gets does not grant the hidden directories at the top of your home directory, and the hand's journal lives at ~/.local/share/daimond/hand/journal/ , behind one of them. It cannot open the file it would have recorded its reason in, so it exits without a word and Chrome reports only Native host has exited . There is nothing in that sentence to act on and nothing to configure: the confinement is what a snap is for. Moving the journal does not help either, because the browser hands the program its own environment and DAIMOND_HAND_JOURNAL_DIR never reaches it. You need not work this out yourself. The installer looks at every browser profile on the machine, writes into the ones that can use it and names the ones that cannot; where every browser it finds is confined it stops, rather than leaving you an install that appears to have worked. --check reports the same, and flags a confined browser even with a usable one installed beside it, because the one you are actually using decides. To see what you have before you start: snap list 2>/dev/null | grep -Ei 'chrom|"},{"p":"machine-operations.html","a":"s3","t":"2. Run that browser once before you install","u":"Machine Operations › Before you start","b":"The installer writes one small file into the browser's profile directory, and that directory is created the first time the browser starts. Install a browser, never open it, and install.sh reports finding nothing (correctly, because there is nothing there yet)."},{"p":"machine-operations.html","a":"s4","t":"3. Linux, with Landlock in the kernel","u":"Machine Operations › Before you start","b":"The compartment is Landlock and seccomp, and both are Linux. Landlock arrived in Linux 5.13; Unconventional systems sets out what older and unusual machines get. The hand does build and run on macOS and Windows and will introduce itself to the page, but it reports that it can fence nothing, and Daimond then refuses every command rather than run one unfenced. The refusal names what is missing: macOS wants a sandbox profile applied through sandbox_exec , or App Sandbox entitlements if the hand ever ships in a bundle; Windows wants a Job Object to bound the process tree and an AppContainer SID to bound what it may open. Neither is built. Installing a different browser? Your account does not come with you. Your account is a signing key held in the browser you made it in. The passphrase does not recreate that key, it only decrypts the copy already stored there, so the same passphrase in a fresh browser starts a different account, with its own credits and no Pro. The key has to travel, so before you retire the old browser do one of these in it: Link another device , then type the code in the new browser; add a passkey; or Export a backup , which writes the chats, Diamonds and workspace f"},{"p":"machine-operations.html","a":"s5","t":"Installing it","u":"Machine Operations","b":"Two commands at a terminal, from the top of the Daimond repository, then two things in the browser. They add up to one small JSON file per browser profile plus a binary you built: nothing listens on a port, no daemon runs, and there is no secret to steal."},{"p":"machine-operations.html","a":"s6","t":"Build the hand","u":"Machine Operations › Installing it","b":"cargo build --release --manifest-path hand/Cargo.toml --manifest-path , not -p : the hand is a cargo workspace of its own, so -p reports no such package and builds nothing."},{"p":"machine-operations.html","a":"s7","t":"Grant a folder, and register the hand","u":"Machine Operations › Installing it","b":"hand/install/install.sh --workspace ~/work Put your own folder in place of ~/work . It bounds everything any command can read or write, so choose one for the work: the script refuses your home directory and / outright, since granting either grants everything. It has to exist already. That one run does three things, each with a failure you would otherwise meet later: Writes your folder into root.txt , at ~/.local/share/daimond/hand/journal/root.txt . The hand will not serve a page until it has been told, and it never guesses, a guessed folder being a guess about what a command may touch. To change it later, run the same command with a different folder. Creates that journal directory at mode 700. It holds the record of every command every Diamond has run, so the hand refuses to write it anywhere other users can read; a directory made under the usual umask is 755, and the hand would not start. Writes the registration into every usable browser profile, and prints which. That file is what lets the browser start the hand at all. It is JSON and nothing else: the script builds nothing, downloads nothing, starts nothing and needs no root. DAIMOND_HAND_ROOT is a trap. The environment variabl"},{"p":"machine-operations.html","a":"s8","t":"Load the extension","u":"Machine Operations › Installing it","b":"The previous step printed the path. Open chrome://extensions , turn on Developer mode , choose Load unpacked , and select the ext/ directory. It carries a fixed public key, so its id is the same on every machine (which is how the registration written a moment ago can already name it), and the manifest names a single origin, https://daimond.oxedyne.com , as the only page allowed to speak to it. No other page in your browser can reach it at all."},{"p":"machine-operations.html","a":"s9","t":"Restart the browser","u":"Machine Operations › Installing it","b":"It reads those profile directories only when it starts, so a file that appeared while it was running is invisible until then. This is the commonest reason a correct install looks broken."},{"p":"machine-operations.html","a":"s10","t":"Then check it","u":"Machine Operations › Installing it","b":"hand/install/install.sh --check Changes nothing, and prints one line per thing that has to be true: a usable browser, the registration, the binary, the journal directory and its mode, root.txt , the journal sitting outside the granted folder, and the extension. A failing line carries its fix on the line below it. Work from the top, since a later line often fails only because an earlier one did."},{"p":"machine-operations.html","a":"s11","t":"The last two steps are yours","u":"Machine Operations","b":"Nothing above chose anything on your behalf. The two things left are the two that are decisions. Open the same folder in Daimond. On the Workspace panel, use the Machine chip to open the folder you granted. It has to be the same one: the hand writes a token into <folder>/.daimond/workspace.id and names it when it introduces itself, and the page reads that file through the handle it already holds and compares. A workspace that is the browser's own storage, or a different folder from the one in root.txt , has its commands refused with a line saying which. The token lives inside .daimond because the compartment always denies that directory, so a command cannot read the token and cannot answer for a folder it is not in. Allow the first command. The first time Daimond wants to run something, a Daimond Hands window opens and asks. No browser permission covers “may run programs on this computer”, so that window is the approval and the extension records your answer itself, which is also what makes it revocable: the browser has nothing to take away. Until you allow it, nothing runs. The window names the folder and the page that asked, and says in one line how far a command can reach on this"},{"p":"machine-operations.html","a":"s12","t":"When it does not work","u":"Machine Operations","b":"Start with install.sh --check again: it walks every check below in order and stops at the first thing that is wrong. The three steps it automates are useful anyway, being what to reach for when --check passes and Daimond still says the hand is not there."},{"p":"machine-operations.html","a":"s13","t":"Run the hand yourself","u":"Machine Operations › When it does not work","b":"hand/target/release/daimond-hand < /dev/null starts the hand exactly the way your browser will, with no browser at the other end, so whatever it would have said to the browser it says to you. Three answers: daimond-hand: the page closed the pipe. Configured and ready. Whatever is wrong is on the browser's side, and restarting it is the first thing to try. This hand has not been told which folder it may work in : root.txt is missing. Run install.sh --workspace again. …is readable by users other than its owner : the journal directory is not 700, and the hand will not write the record of your commands where another account can read it. chmod 700 it. Anything else is a whole sentence naming the path, the cause and the fix, the hand having nowhere to print a code anyone could look up. hand/target/release/daimond-hand --report prints what the compartment can enforce on this kernel and, at greater length, what it cannot. Read the second list rather than skimming it: on a kernel below Linux 7.1 it includes a way out of the compartment entirely . It also names the folder from root.txt , so a stale one shows up here and not at the first command."},{"p":"machine-operations.html","a":"s14","t":"Read the journal","u":"Machine Operations › When it does not work","b":"tail -n 5 ~/.local/share/daimond/hand/journal/hand-*.jsonl One JSON object per line, in the order things happened: the handshake, every command, every refusal with its reason. If the hand started at all it wrote something here. An empty directory after a failed attempt means it never got far enough, which on Ubuntu almost always means the confined browser at the top of this page."},{"p":"machine-operations.html","a":"s15","t":"Ask the extension","u":"Machine Operations › When it does not work","b":"In the browser, on the Daimond tab, open the developer console and run: await DaimondHand.status() It answers with JSON: whether a hand is paired, which folder it says it was granted, what it can enforce, and, where the answer is no, a reason written as a whole sentence and not a code. Daimond shows the model that same sentence, so it explains what the daimon has been told."},{"p":"machine-operations.html","a":"s16","t":"What it actually is","u":"Machine Operations","b":"Not a virtual machine, not a container, not emulation. A command starts as an ordinary process, owned by you, on your own kernel, against your own files, with capabilities removed first. Nothing is simulated and nothing copied in, so a build here does the work the same build does in your own terminal. Four parts, each doing one job: The page asks. Daimond works out what this turn may touch and sends the whole rule with the request. It never sends a shell line: argv is an array, and there is nothing to inject into. The extension relays. Daimond Hands is the only thing the page can hand a command to, and one origin may speak to it. A small local program runs it. The hand builds the compartment out of the rule it was sent, applies it to itself, and then becomes the command. It is no supervisor watching a child; nothing is left of it once the command starts. Your browser starts the hand. The whole of the introduction, and why there is no port and no password. A background service on a port would be reachable by every page you visit, defended only by a secret you had pasted somewhere. It is free, and it is not part of Pro. Nothing about a command touches Daimond's gateway: the request g"},{"p":"machine-operations.html","a":"s17","t":"Daimond implements no tools","u":"Machine Operations › What it actually is","b":"There is no built-in ls , no built-in grep , no bundled toolbox and no shell. ls is /usr/bin/ls , the one already on your machine, at the version you installed. Every program on the computer is reachable, the compartment adding the system to it read-only : /usr , /bin , /sbin , /lib , /lib32 , /lib64 , /libx32 , /etc , /opt , and the harmless devices /dev/null , /dev/zero , /dev/full , /dev/random and /dev/urandom . Without them nothing starts, not even cat : the loader has to read the shared objects, and the process has to open something for the standard streams. A bare name is looked up on PATH , which is /usr/local/bin:/usr/bin:/bin unless a granted toolchain has added to it. What that finds is resolved to an absolute path and checked against the compartment like anything else, so finding is not permission: a PATH pointing outside finds a program the command may not run, and the refusal names it. There is no shell, so there is no shell syntax. A command is a list ( [\"cargo\", \"test\", \"--lib\"] ) and a semicolon, pipe, redirection, backtick, $(…) or && arrives at the program as a literal argument. To chain two commands the daimon runs the tool twice, which is better anyway: it read"},{"p":"machine-operations.html","a":"s18","t":"What a command can and cannot do","u":"Machine Operations","b":""},{"p":"machine-operations.html","a":"s19","t":"Files","u":"Machine Operations › What a command can and cannot do","b":"Read and write inside the granted folder. That, minus Daimond's own .daimond directory, is the writable world. A private temporary directory. Writable, with TMPDIR pointing at it, removed when the run ends, unreachable by any other run, and the one place outside your folder a command may write. /tmp is outside the compartment, and a build that cannot write a temporary file fails part-way through for a reason nobody can read. The system, read-only. /usr , /etc , /opt and the rest of the list above. Everything else is refused by the kernel , not by a check somebody wrote. A file one folder outside the grant comes back Permission denied , and the daimon is shown that refusal instead of the file. One consequence to learn before it looks like a broken tool. Where the whole granted folder is writable (a chat not scoped to a Diamond), that folder itself cannot be listed, and a file cannot be created directly in it. Landlock cannot grant a directory and withhold part of it, so the children are granted one by one and the directory is not. Everything one level down works normally."},{"p":"machine-operations.html","a":"s20","t":"Named local sockets are refused, always","u":"Machine Operations › What a command can and cannot do","b":"A command cannot create a unix socket, whatever else it was allowed. The cost is not small: a local database reached over a socket file, docker , anything wanting X11, and ssh-agent . socketpair is untouched, which is what builds actually use, so a from-scratch cargo build is unaffected. Below Landlock ABI 9 (Linux 7.1), connecting to a socket file is not governed by the compartment at all. Measured: with the whole fence in force and the network refused, one message to the session bus starts a process that was never fenced, and that process reads a file the fence denies. That is no leak at the edge of the compartment but a way out of it, so it is closed unconditionally: reaching the session bus has nothing to do with whether a build was allowed to fetch a crate."},{"p":"machine-operations.html","a":"s21","t":"ssh does not work","u":"Machine Operations › What a command can and cannot do","b":"Two independent reasons, and closing either alone would not be enough. ~/.ssh is not in the compartment: every path in one is built from the folder you granted, so nothing outside that folder can be named, and the app cannot add one. And the agent socket is a unix socket, refused by the paragraph above. git push over SSH fails for both reasons at once. Granting your home directory would remove the first reason along with most of the point of the compartment, which is why the installer refuses it. Everything that touches only the repository does work: git status , diff , log , add and a local commit are ordinary file operations inside the folder you granted."},{"p":"machine-operations.html","a":"s22","t":"A toolchain needs a grant","u":"Machine Operations › What a command can and cannot do","b":"Open a Diamond and the Workspace panel shows a Toolchains row with five buttons: Rust , Node , Python , Go , Git . All five start off, so cargo is refused until you turn Rust on: ~/.cargo and ~/.rustup sit under your home directory, and your home directory is not in the compartment. Git is the odd one out, because it puts no program within reach: git is already in the hand's read-only base, which is why git status and a local commit work with no grant at all. What the button adds is your own configuration, read-only: your name, your email, and the hooks core.hooksPath names, so a commit is attributed to you and a pre-commit hook actually runs. Your stored passwords and ~/.ssh are denied by name, even though the compartment would not reach them anyway. Three things about that are deliberate: It is never inferred from what was asked to run. A compartment that widened itself to fit the requested binary would be a compartment the model chooses, and the whole arrangement rests on its not being one. cargo is reachable because you granted the Rust toolchain, and for no other reason. It is per Diamond. A grant belongs to one Diamond, alongside the folders that Diamond holds, and is taken b"},{"p":"machine-operations.html","a":"s23","t":"The network","u":"Machine Operations › What a command can and cannot do","b":"Whether a command may reach the network depends on the permission mode and on what the turn has already read. Under Ask and Guarded , once a turn has taken in content from outside (a web page it read or fetched, an email, the output of an earlier command), every command in that turn runs with TCP refused, and the daimon is told why, so it reports the cause instead of a broken project. Under Bypass the network is kept whatever the turn has read. A command's own output counts as content from outside. So the first command in a turn has the network and a second one, in the same turn, does not. A build log is written by whatever the build ran, so this is deliberate, but it surprises people. Reading an ordinary file in your own workspace does not count; a message in your mail does. If something needs to fetch, ask for it in a fresh message, which starts a fresh turn. What is refused is TCP bind and connect, which is what Landlock governs. UDP and raw sockets are outside it."},{"p":"machine-operations.html","a":"s24","t":"32-bit binaries are killed, not filtered","u":"Machine Operations › What a command can and cannot do","b":"The system-call filter is compiled for one architecture and checks the architecture first: the compatibility ABI numbers its calls differently, and a filter built for the wrong table would refuse the wrong things and report success. A program with a different personality is therefore killed outright instead of filtered. That fails closed, and a build that execs a 32-bit helper will not work here."},{"p":"machine-operations.html","a":"s25","t":"The permission ladder","u":"Machine Operations","b":"One setting, three rungs, and the axis is what Daimond does without asking . It starts on Guarded."},{"p":"machine-operations.html","a":"s26","t":"Ask every time","u":"Machine Operations › The permission ladder","b":"Every command is put to you before it runs, with the command and the directory on the prompt, and Daimond asks once in each conversation before it reaches the web. For watching each step, and for a machine holding something you cannot lose."},{"p":"machine-operations.html","a":"s27","t":"Guarded","u":"Machine Operations › The permission ladder","b":"The default. Commands run without asking. A turn that has read outside content loses the network, and Daimond asks once, in that conversation, before reaching anywhere the model chose. One yes covers every site until the conversation ends; a new chat or a fresh daimon asks again, and an unusually long address is always put to you on its own."},{"p":"machine-operations.html","a":"s28","t":"Bypass","u":"Machine Operations › The permission ladder","b":"Nothing is asked. Commands run, pages are fetched, and a build needing the network still has it on the turn's tenth command as well as its first. Chosen once, deliberately, then quiet. A rung never changes what is possible. The compartment a command runs inside, the system-call filter under it, the folders a Diamond is scoped to, a granted toolchain, the marking on content from outside, and the journal are identical on all three. A rung changes only what you are asked. It is a word in the chat header beside the model, because a mode you have to remember is one you will be wrong about. Click it to change it, or press Ctrl K ( Cmd K on a Mac) and type the rung's name."},{"p":"machine-operations.html","a":"s29","t":"Unconventional systems","u":"Machine Operations","b":"The compartment is built out of a fixed list of absolute paths, and that is what decides whether a given machine works. Run --report on yours before assuming either way."},{"p":"machine-operations.html","a":"s30","t":"Will not work","u":"Machine Operations › Unconventional systems","b":"NixOS and Guix. Programs live in /nix/store or /gnu/store , neither granted, and /usr/bin holds almost nothing. A bare name resolves through PATH to a store path outside the compartment, and the command is refused by name. The app cannot widen it today. A kernel without Landlock. Before Linux 5.13, or compiled out, or absent from the active LSM list, or removed by a hardening patch. The hand reports fence:none and Daimond refuses every command rather than run one unfenced. Check that landlock appears in /sys/kernel/security/lsm . An architecture other than x86-64 or aarch64. The filter's syscall numbers are written out per architecture and there is no third table. The hand will not guess one, so there is no filter, and without a filter no command runs."},{"p":"machine-operations.html","a":"s31","t":"Partly","u":"Machine Operations › Unconventional systems","b":"Linux 5.13 to 6.6. Files are fenced, but Landlock has no network rules before Linux 6.7, so a command that would have to run with the network withheld is refused outright, with a sentence saying so, instead of running with the network it was supposed to lose. Bypass works, and Guarded works until the turn reads something. Homebrew on Linux, Flatpak and Snap. None of /home/linuxbrew/.linuxbrew , the Flatpak trees or /snap is granted, so a program installed that way is refused, while what your distribution put under /usr is reachable in the same session. That is about the programs a command runs; a browser packaged that way is a separate problem, and a fatal one. See Before you start . Version managers other than the two that are known. The toolchain paths are a fixed list, and ~/.nvm and ~/.pyenv are the only version managers on it. asdf , mise , volta , rbenv and sdkman install under ~/.asdf , ~/.local/share , ~/.volta , ~/.rbenv and ~/.sdkman , none of which anything grants, including the Python grant, which covers ~/.local/bin and ~/.local/lib and pointedly not ~/.local/share ."},{"p":"machine-operations.html","a":"s32","t":"Fine","u":"Machine Operations › Unconventional systems","b":"Debian, Ubuntu, Fedora, Arch, openSUSE with their own packages, on a kernel new enough for --report to name a Landlock ABI. musl and Alpine , given the same. BusyBox coreutils. A multi-call binary decides what it is from the name it was invoked by, and the hand execs the resolved binary under the name that was asked for , so it still knows which tool it is meant to be."},{"p":"machine-operations.html","a":"s33","t":"A terminal, too","u":"Machine Operations","b":"The Terminal panel opens a real terminal on the same machine, inside the same compartment, and you type into it. It is separate from a command run by the daimon, and it exists because some programs ask their questions of a terminal and not of standard input. Keystrokes are never written to the journal, for that same reason. It needs a hand paired, like everything else on this page."},{"p":"machine-operations.html","a":"s34","t":"What is recorded","u":"Machine Operations","b":"Every run (what was asked, what it was refused, what it returned) is appended to the journal in ~/.local/share/daimond/hand/journal/ , as ordinary JSON lines you can read. The entries are hash-chained, and the journal sits outside every compartment, because the hand refuses a fence that would reach it. So a command cannot rewrite the record of itself, and no permission mode turns this off."},{"p":"machine-operations.html","a":"s35","t":"What is not protected","u":"Machine Operations","b":"--report prints two lists, and the second is the point of running it. Every entry in it was measured on a running kernel rather than inferred, and it changes with your kernel, so read your own. The entries fall into a few groups: Asking about a file is not opening it. stat still answers outside the compartment, so sizes, timestamps, ownership and the presence or absence of a file are readable. The compartment governs opening. The system grant is wide. /usr , /etc and /opt read-only is what lets a command run at all, and it also means every world-readable file under /etc can be read and every tool on the machine executed. /etc in particular holds a great deal of machine-identifying detail. The filter is a deny-list. It removes named capabilities from a command and is no syscall sandbox. Anything it did not name is permitted, including a call a future kernel adds. A filter cannot follow a pointer. It sees a syscall number and six registers, never what they point at: no path, no address, no filename. So a refused chmod is refused everywhere and an allowed one allowed everywhere. chmod 777 is refused; chmod 644 on a private key is not, because 644 adds no write and is the mode cargo se"},{"p":"machine-operations.html","a":"s36","t":"Taking it back","u":"Machine Operations","b":"Three different things, and all three come up. Withdraw the permission. Click the Daimond Hands icon in the toolbar. Running commands on this computer is listed there beside the sites you have approved, with a Revoke button. Revoking stops whatever is running at that moment, immediately, not at the end of the current build. Take the folder away. Delete root.txt . The hand then refuses to serve at all, whatever the browser says, and the refusal is a whole sentence and not a silent nothing. Remove the registration. hand/install/uninstall.sh , or --dir DIR for one directory. That deletes the file the installer wrote, so the browser can no longer start the hand. The binary is left where it is; the script did not put it there. &larr; Spending Next: Social &rarr;"},{"p":"models.html","a":"","t":"Models & credits","u":"","b":"Models & credits A daimon thinks with a model. You can bring your own provider key and pay that provider directly, or buy credits and let Daimond run a model for you. This page covers both, and how to keep credits topped up."},{"p":"models.html","a":"s1","t":"Two ways to power a daimon","u":"Models & credits","b":""},{"p":"models.html","a":"s2","t":"Bring your own key","u":"Models & credits › Two ways to power a daimon","b":"Connect an account you already hold with a model provider. Your messages go straight to that provider; Daimond is not in the path, and nothing is charged by us."},{"p":"models.html","a":"s3","t":"Buy credits","u":"Models & credits › Two ways to power a daimon","b":"No provider account to manage. Daimond runs the model for you and draws down the credits you bought. No subscription: you keep what you buy. Either is enough to start. You can do both: connect a key for everyday work and keep credits for when you would rather not manage one."},{"p":"models.html","a":"s4","t":"Connecting a provider","u":"Models & credits","b":"Open the Models row in the admin panel, bottom-left. It lists a key for each provider you use and which model new chats start on. To add one, choose + Add provider and answer the same three questions, whoever the provider is. Adding a provider: choose the provider, paste the key, star a default model, then Save & start."},{"p":"models.html","a":"s5","t":"Choose a provider","u":"Models & credits › Connecting a provider","b":"Pick from the list: Anthropic , Fireworks AI , OpenRouter , Together AI , Groq , DeepInfra , or Custom for any other service speaking the same chat-completions API. Choosing Custom reveals a Base URL box to point Daimond at that service."},{"p":"models.html","a":"s6","t":"Paste your API key","u":"Models & credits › Connecting a provider","b":"Paste the key from your provider account into the API key box. It is stored on this device only, wrapped under your passphrase, and sent only to the provider you chose."},{"p":"models.html","a":"s7","t":"Star a default model","u":"Models & credits › Connecting a provider","b":"Choose a Default model from the list (or type a model id for a custom provider). This is the one model new chats and Diamonds start on. Then choose Save & start . Everything stays on this device. Your keys, chats and files live only in this browser. Nothing is sent to us: a provider key you add talks to that provider, and to no one else."},{"p":"models.html","a":"s8","t":"The default model, and picking another for one chat","u":"Models & credits › Connecting a provider","b":"One model is the default that new chats and Diamonds begin on. Any connected model can be chosen for a single chat, from the selector in its header at the top-right of the centre panel; the default is untouched. A Diamond can also be given a separate model for the workers it dispatches."},{"p":"models.html","a":"s9","t":"Buying credits","u":"Models & credits","b":"Open the Credits row in the admin panel. It shows your balance and a set of packs to buy. There is no subscription: you keep what you buy, and nothing is charged again unless you turn on auto-reload. Credits: your balance, packs to buy, and the auto-reload settings underneath. Payment is handled on the payment provider's own hosted page. No card number, expiry or security code is ever typed into Daimond, so there is nothing here to leak."},{"p":"models.html","a":"s10","t":"Auto-reload","u":"Models & credits","b":"Auto-reload is a standing instruction to buy credits when they run low, so a long job does not stop halfway. It is the one place Daimond may charge a saved card while you are away, and so is deliberately explicit. Three numbers set it, below the packs in the Credits view: Below : the balance at which a top-up fires. Buy : how much one top-up adds. Never more than : a hard cap on total top-ups in a calendar month. Set this one carefully. It is a ceiling rather than a target, and it is enforced on the same code path as the charge, so nothing can walk around it. Auto-reload cannot be switched on without a saved card. A control that turned on and then silently failed would be worse than one that is disabled and says why. Saving a card is a redirect to the payment provider's hosted page; Daimond never sees the card details. &larr; The interface Next: Chats & Diamonds &rarr;"},{"p":"social.html","a":"","t":"Social","u":"","b":"Social Daimond is changed by what its users report. The Social panel is where that is written, read back and voted on, and where messages, the people they come from, groups and shares sit. This page is about making a note land: how to say what happened, and the names for the parts of the screen, so that whoever reads it knows at once which thing you mean. A note that says the thing at the top left is broken costs somebody a search, and sometimes finds the wrong thing. A note that says the Diamonds chip in the top bar does not. Neither note is more work to write. The difference is only knowing what the parts are called, which is what the rest of this page is for."},{"p":"social.html","a":"s1","t":"Writing a note that can be acted on","u":"Social","b":"Three things, and the first is the one most often left out."},{"p":"social.html","a":"s2","t":"Where it is","u":"Social › Writing a note that can be acted on","b":"Name the part, and the region it sits in. The screen has four regions and about twenty kinds of part, and naming both makes almost anything unique: there are crosses all over Daimond, but only one closer on the Everything row."},{"p":"social.html","a":"s3","t":"What you expected","u":"Social › Writing a note that can be acted on","b":"Say what you thought would happen. This is the half a reader cannot guess, and it is often the whole report: a control that does exactly what it was built to do, and surprises people anyway, is a fault in the control and not in the people."},{"p":"social.html","a":"s4","t":"What happened instead","u":"Social › Writing a note that can be acted on","b":"What you saw, in the order you saw it. Not what you think caused it. A guess at the cause narrows the search, and a wrong guess narrows it away from the fault. Costs a round trip The X at the top left is broken. Can be acted on The closer on the Everything row put the whole rail away. I expected it to close that row. A few more things that save a reply. One note, one thing. Two faults in one note become one proposal that cannot be finished, because half of it is fixed and half is not. Say which build. The Version row in the admin panel names it, and hovering it gives the build id. A fault already fixed reads exactly like a fault nobody can reproduce. Say what you were doing. Even a short trail helps: which panel was open, whether you were on a phone, which palette you were wearing. A fault can be there on one palette, or one screen width, and nowhere else. Write it anyway. If you cannot name the part, describe it and say where it was on screen. An approximate note is worth far more than a note nobody writes."},{"p":"social.html","a":"s5","t":"Saying where: the four regions","u":"Social","b":"Daimond has a top bar across the top, and under it three regions side by side: the rail on the left, the stage in the centre, and the dock on the right. Almost every note can start by naming one of those four. The interface tours them and says what each panel is for; this page is about the smaller parts inside them. Where the named parts sit. The words in colour are the ones to use in a note; the four regions are set in small capitals. Nothing here is to scale, and a panel can be closed, moved or put away, so the regions are what stay put. Two words for the centre. This guide calls it the stage. The panel gallery groups the same panels under Beside the chat , which is the only name the app itself puts on screen for that region. Both are understood; if you use neither and say beside the chat in your own words, that is understood too."},{"p":"social.html","a":"s6","t":"The parts, by name","u":"Social","b":"Every word below is one Daimond already uses, in its own interface or in this guide. Each entry shows the real thing, cropped out of a running Daimond, so you can match what is in front of you against the picture and use the word with confidence. The pictures were taken on one of the dark palettes. On yours the colours will differ, and on a phone some of these parts move; the names do not."},{"p":"social.html","a":"s7","t":"chip","u":"Social › The parts, by name","b":"A small rounded button that turns one thing on or off. The row of them across the top bar is the chip row , one chip per panel, filled in while that panel is open. Chips are used elsewhere too: on a head, as above, on a tile, and in the rail as tags. Say which, and a chip is unambiguous. Say: the Workspace chip in the chip row."},{"p":"social.html","a":"s8","t":"tile","u":"Social › The parts, by name","b":"One Diamond or one chat, as it appears in the rail. A tile carries its own name, its cog, its closer, and whatever else belongs to that one piece of work. Say: the cog on a chat tile."},{"p":"social.html","a":"s9","t":"head","u":"Social › The parts, by name","b":"The strip that names a list or a panel and carries the buttons acting on the whole of it. Each list in the rail has one, and so does every panel. Say: the plus on the Chats head."},{"p":"social.html","a":"s10","t":"closer","u":"Social › The parts, by name","b":"The cross that closes something. Daimond has one closer, drawn one way, on every panel, tile, dialog, menu, drawer and sheet. It always closes the one thing it sits on and never anything larger, so naming what it sits on names the closer exactly. Say: the closer on the Everything row."},{"p":"social.html","a":"s11","t":"cog","u":"Social › The parts, by name","b":"The settings button. Wherever a thing has settings of its own, they are behind a cog on that thing: on a tile, on the identity row, on a mailbox. Say: the cog on the Diamond tile."},{"p":"social.html","a":"s12","t":"light","u":"Social › The parts, by name","b":"The round light beside a play and a pause, saying whether that part of Daimond is going to act on its own. Green for everything set up and running, amber for some of it held, red for none of it running — either held, or nothing set up in the first place. Hover it and it says which. Every light in the app hangs off the one on the Everything row, which speaks for the lot. Say: the light on the Everything row is amber."},{"p":"social.html","a":"s13","t":"divider","u":"Social › The parts, by name","b":"A line you can drag to give one list or one panel more room, and double-click to put back where it was. There are two in the rail: one between the Diamonds and the chats, one above the admin panel. Say: the divider above the admin panel."},{"p":"social.html","a":"s14","t":"row","u":"Social › The parts, by name","b":"One line in a stack of them, answering one question. The admin panel is rows; so are the mailboxes, the folders, the devices and the files. A row that can be acted on is a button, and it opens the thing it names. Say: the Version row in the admin panel."},{"p":"social.html","a":"s15","t":"spend row","u":"Social › The parts, by name","b":"The three figures at the foot of the rail: this session, this week, this month. It hides itself while nothing has been spent. Say: the week cell of the spend row."},{"p":"social.html","a":"s16","t":"composer","u":"Social › The parts, by name","b":"The box you type into, with the send button beside it. There is one, at the foot of the stage, and it talks to whatever is on the stage: a chat, or a Diamond's daimon. Say: the send button on the composer."},{"p":"social.html","a":"s17","t":"face","u":"Social › The parts, by name","b":"A Diamond has two of them, and this switch chooses which one you are looking at: the Crystal , which is what the Diamond knows, and the Chat , which is how it came to know it. Say: on the crystal face of a Diamond."},{"p":"social.html","a":"s18","t":"tag","u":"Social › The parts, by name","b":"A word you file a Diamond under. Tags sit on the tile as small chips, and the Filter by tag row above the list narrows it to the ones you pick. Tags are yours alone: they never go to a model, and they never enter a crystal. Say: the tag chips under Filter by tag ."},{"p":"social.html","a":"s19","t":"dialog","u":"Social › The parts, by name","b":"A card that opens over the app and waits for an answer. Its title is on the same row as its closer, and Escape does what the closer does. Say: the Delete button in a chat tile's dialog."},{"p":"social.html","a":"s20","t":"gallery","u":"Social › The parts, by name","b":"Every panel there is, searchable, grouped by region, each row saying whether that panel is open and carrying the pin that decides whether its chip sits in the top bar. It opens from the ⋯ chip at the end of the chip row. Say: the pin on the Trash row of the gallery."},{"p":"social.html","a":"s21","t":"Go to box","u":"Social › The parts, by name","b":"The keyboard's way to anything: Ctrl K , or Cmd K on a Mac. It reaches every panel and every setting by typing, including the ones no chip is showing. Say: typing a palette name into the Go to box."},{"p":"social.html","a":"s22","t":"sheet","u":"Social › The parts, by name","b":"On a phone, a panel rises over the chat as a sheet you can drag up and down. It has a grab bar at the top, a closer beside it, and the one box you ask about it in. Say: the grab bar on the Workspace sheet."},{"p":"social.html","a":"s23","t":"drawer","u":"Social › The parts, by name","b":"On a phone, the rail slides in from the left as a drawer. It is the whole rail, so everything in it keeps its own name. The button that opens it is the three lines at the top left. Say: the admin panel, down the drawer."},{"p":"social.html","a":"s24","t":"paperclip","u":"Social › The parts, by name","b":"Attaches what you are reading to what you are working on. It sits on every row of the Workspace panel and on the head of a document, and it is drawn only while there is something to attach to. Say: the paperclip on a folder row. A few more words the rest of the guide uses, with nothing to photograph: a panel is one of the things a region holds, each with a name of its own, from AI to Trash ; a crystal is what a Diamond knows, kept as a document; a daimon is the agent that thinks for a Diamond; a worker is an agent a daimon sends off to do one job. Chats & Diamonds explains all four. Two more belong to the Social panel, and neither can be photographed either. The forge is where the work on Daimond is tracked: a public repository, off this device, that a note you send arrives in as a proposal. Your voice is a secret line the forge makes for you, which it looks you up by, held encrypted on this device. The Social panel below is where both are used, and it is the only place in Daimond either word appears."},{"p":"social.html","a":"s25","t":"Where two words exist","u":"Social","b":"A few things in Daimond genuinely answer to more than one name, usually because the app says one and this guide says the other. They are listed here so that nobody wastes a sentence apologising for using the wrong one. Both are understood, and a note that uses either is a good note. The centre region is the stage in this guide and Beside the chat in the panel gallery. The panel under the rail's lower divider is the admin panel everywhere a reader can see, and its own head reads Admin . The Ctrl K box calls itself Go to , and this guide has also called it the palette. Palette is also the word for the eleven colour schemes, so Go to box is the one to prefer. The button that opens the drawer on a phone says Menu , and what it opens is the rail. If you find another, that is worth a note of its own. Two names for one thing is a small fault in the app, not in the person reporting it."},{"p":"social.html","a":"s26","t":"The Social panel","u":"Social","b":"A note is written in the Social panel, which sits in the dock, beside your work, so that a note about what is on screen can be written without leaving it. Its head carries five chips , and one is filled while you are looking at it: Messages , People , Share , Proposals and Settings . It opens on Proposals , which is where a note is both written and read back. The rest of this section is Proposals , which is about Daimond itself, and Settings , which holds your voice. The other three chips are about other people, and each has a section of its own below: People first, because nothing can be sent to anybody until a code has been exchanged. A note you post does not stop at Oxedyne. It goes to the forge , the place where the work on Daimond is tracked, and it arrives there as a proposal anyone with that repository can read. The Proposals chip is that same forge, read back — which is why the box that writes a proposal and the list that shows them are the one view."},{"p":"social.html","a":"s27","t":"Your voice","u":"Social › The Social panel","b":"Anything that leaves this device goes under a voice . A voice is a secret line the forge makes for you: it belongs to one person, and the forge looks you up by it. It is the whole of your identity there. No name, no handle and no address travels with what you write, and this browser is never told what your voice is called. Your voice lives in the Settings chip. Getting one is a single tap: when you have no voice, Settings shows Get my voice . Press it, and Daimond has the forge make your voice for you and holds it here. There is nothing to find, ask for or paste. It is made once, so if you already have one on another device it syncs across rather than being made again — the panel says so, and it will arrive shortly. Daimond holds your voice on this device, encrypted under your passphrase, and the gateway it passes through on its way out stores nothing. Forget it removes the copy on this device. If a voice was made on another device and never reaches this one, I lost my voice — re-issue makes a fresh one; that replaces the old voice everywhere and cannot be undone, so it asks first. And if the forge has already handed you a voice some other way, I already have a voice lets you paste"},{"p":"social.html","a":"s28","t":"Writing one","u":"Social › The Social panel","b":"At the top of the Proposals view is the note box . Write the three things from the top of this page into it: where it is, what you expected, what happened instead. The first line is the title and the rest is what happened; the sentence beside the buttons says so. Below the box is a row headed What goes with it . It holds one line: the build, the language, the size of the window, whether you are on a phone, the palette you are wearing, and which panels are open. That is the fourth piece of advice above, gathered for you rather than asked of you, and it is shown in the exact characters it will travel as. The row has a closer , and closing it takes the line off the note as well as off the screen. Then two buttons, and the difference between them is whether the model rewrites the note first. Post sends the note as it is. What leaves is exactly the characters in the box and in that row; nothing is added on the way out, nothing else about you goes with it, and it becomes a proposal at once. It goes under your voice, and it goes somewhere public: anyone who can read the repository can read what you wrote. The sentence beside the button says so, so that you know before you press it and not"},{"p":"social.html","a":"s29","t":"Reading the proposals, and voting","u":"Social › The Social panel","b":"A proposal is one change to Daimond, stated so that it can be agreed or disagreed with, and so that it can be finished. Posting a note opens one: its first line becomes the title and the rest becomes the body. That is why the advice at the top of this page says one note, one thing: two faults in one note become one proposal that cannot be finished. Under the Proposals chip each one is a row of the same shape as a row in the admin panel: a coloured dot for what state it is in, its title, and, where there are counts, how many have asked for it. Pressing the row opens it, and inside are the proposal in full, who wrote it and when, how many replies it has, the build it was written on, and the mark that closed it if one has. Under that is a box to say something back. Write in it and press Say it , and what is sent is exactly what is in that box, the same promise the note box keeps. What has already been said sits above it. Where the forge is keeping counts, two buttons sit with them: Do this and Not this . Pressing the one you already chose takes your vote back off. There are four states. Open and Being done say where it stands, Done says it is finished, and Declined says it will not be"},{"p":"social.html","a":"s30","t":"People, and the first exchange","u":"Social","b":"Everything else on this page rests on one act: two people coming to hold each other's real keys. Nothing can be sealed to somebody Daimond has no key for, so until a code has been exchanged the People list says exactly that, and the message box says there is nobody to write to. Two buttons sit above the list. Show my code puts your own code on screen: a small signed card carrying your key, the separate key a message to you is sealed with, and whatever name you have given yourself. It is drawn as a symbol for somebody else's camera, and repeated underneath as a line of text beginning DMND-ID1. for when there is no camera. Add somebody is the other half of the same act: this device's camera, and a box to paste a code into."},{"p":"social.html","a":"s31","t":"Read in the room, or read a number aloud","u":"Social › People, and the first exchange","b":"Both routes record the code. Only two things can raise a key to matched , and which of them is offered depends on how the code arrived rather than on what it says. This device's camera, in person. You read it off their screen, so there was no channel for anybody to get between you, and the row offers Mark matched now . Anything else — a paste, a link, a code somebody sent you — stays a new key, and the dialog says so as it arrives. Whatever handed it over could have substituted a key of its own and signed the result perfectly, so a card that checks out proves that the holder of that key composed it and nothing about who the holder is. The way up from there is Compare safety numbers : sixty digits in twelve groups of five, the same on both sides, read to each other on a call or in person. The numbers match records it. They are different says that somebody is between you and that the key is not to be used. Reading the digits in a message proves nothing, because whatever could swap the keys could swap the message."},{"p":"social.html","a":"s32","t":"What a row says","u":"Social › People, and the first exchange","b":"Each person is a row : a name, a line under the name, and a fingerprint. Until the key is matched the name is drawn as the claim it is — calls themselves “Ada” — because a name is a thing its holder typed. Once it is matched, the person on the other end is known and the name may be their name. The line under the name is the only place in Daimond a key's standing is drawn, and it is a line rather than a badge so that it cannot be read in one glance with anything else. It says one of five things: that this is a new key you have not matched; that it was matched in person, with the date; that it was matched by safety number, with the date; that it is a different key from the one you matched; or that it is blocked. A key that changes is not a key that carries over. A card can name the key it replaces, which links the two, and it does not move a match across: the commonest reason a key changes is that the old one leaked, and whoever took the old key can sign that claim too. So the row says the key is different, and messages from it are held until you decide. A name that folds onto a name you have already matched is called out on the row as well — names are not identities, and the key is "},{"p":"social.html","a":"s33","t":"Private messages","u":"Social","b":"A message is sealed on this device to a key the other person holds, and opened on theirs. Nothing in between can read it, and that includes us: the relay carries ciphertext and has no way to do anything else with it. What it does see is what routing needs — which account, when, and how many bytes — and that is worth saying rather than glossing over. At the foot of the Messages view is the box you write in. Above it a picker names who it goes to: the people whose sealing key this device holds, and the groups you have joined. Under the picker one line says who can read what you are about to type, and it changes with the pick, because Private. Only you and the person you are writing to can read this. would be false over a group of twelve. Send privately sends it. A body longer than 8,192 characters is refused rather than cut, on the ground that half a message is not a shorter message."},{"p":"social.html","a":"s34","t":"Arriving","u":"Social › Private messages","b":"While the Messages view is open, Daimond holds a request open at the relay, so a message that lands is drawn without your pressing anything. With the panel shut, it is found when you next open it — and by the count. The Social chip in the chip row carries a number, and the total across the app goes into the browser tab's title and onto the app's own icon where the platform draws one. It is a tally of what has arrived rather than a memory of what you have looked at, and this build has nothing that marks a message as read, so the number stands. A first message from somebody you have not accepted does not go into the list. It waits above it, under Waiting for your answer , with their fingerprint and what they wrote, and three buttons: Accept takes it into the list, and their later messages go straight there. Ignore takes the row away. It writes nothing, and it tells them nothing — that is the whole of it, so that a sender can never tell an ignore from a silence. Block stops them at the relay, as the People row does. One email a day, at most. Where your account has an address on it, Daimond may send one email saying something is waiting: no sender, no subject, no count, and not more th"},{"p":"social.html","a":"s35","t":"What is said, and what is not promised","u":"Social › Private messages","b":"Sent, never delivered. The relay answers a blocked delivery exactly as it answers one it took, deliberately, so that Block cannot be told from Ignore. So a group send says how many people it was sent to, and names anybody the relay would not take it for. A full mailbox is said so. A box holds five hundred uncollected messages; past that a message does not arrive, and the sender is told that rather than told it went. Thirty days, then the relay lets go. A message nobody collects is dropped after thirty days and the sender gets a notice for it, in its own section under the list. A message that expired leaves that notice behind rather than a gap, so a silence is never mistaken for nothing having been sent. Nothing is queued. A message that could not be sent has not been sent, and nothing tries again behind your back. The same rule the note box keeps. Your own devices see them. Messages, and a copy of what you send, travel with the encrypted parcel sync carries between your devices. On this device they are kept encrypted under your passphrase, so while Daimond is locked the list says so instead of showing an empty one. Reporting one message. Because the operator cannot read a message, "},{"p":"social.html","a":"s36","t":"Groups","u":"Social","b":"A group is a group chat, and it sits at the foot of the Messages view rather than behind a chip of its own. There is no shared key: a message to a group is sealed once for each member, one lock per person inside the one envelope. Three things follow from that, and each is on screen where it matters, before a press rather than after it. Joining shows nothing earlier. The messages sent before you joined were never sealed to your key, so no device can open them for you. Taking somebody out takes nothing back. They keep every message already sent to them and receive nothing from then on, which is why the control reads Stop sending to and never remove . Closing is final, and it destroys nothing. Everybody keeps every message; nobody can write to it again. Daimond asks once before it happens, and closing has a heading of its own below. To make one, name it and pick from the people you hold a card for; Make this group tells them, and says how many were told. Somebody with no card cannot be added, because there would be nothing to seal to them with. A group holds at most 255 people, and one message to a group is a separate delivery for each member, so a large group is slow and fills mailbo"},{"p":"social.html","a":"s37","t":"Closing a group","u":"Social › Groups","b":"Closing is the creator's one act that cannot be undone. The button reads Close this group — not disband , and not delete , because nothing is destroyed by it. A dialog asks once, headed Close this group for everybody? , and it says: “Closing a group closes it for everybody. Nobody can write to it again, you included; every message already sent stays where it is. It cannot be undone.” Under that it names the group, and the button that does it reads Close it for everybody . Dismiss the dialog and the group is exactly as it was. What the press does is write a membership list naming nobody, and hand it to everybody who was in it. Every reader obeys it, so nothing more can be sent to that group by anybody, the person who closed it included, and no later list can reopen it. Nothing is deleted anywhere: every member keeps every message they already hold. A closed group keeps its place on the list. It sits with the groups you are in, with its name and its messages and no controls at all, saying that it was closed by the person who made it. That is not tidying left undone: the group's name is drawn over each of its messages out of that one record, so taking the record away would leave the t"},{"p":"social.html","a":"s38","t":"Sharing a Diamond","u":"Social","b":"Under the Share chip are two halves, in the order you meet them: Open a share at the top, since taking one in needs nothing of you but the file, and Send a Diamond under it. A share is a copy the receiver owns. It is re-sealed to their key, it lands in their workspace as a Diamond of their own, and they may change it. You never see their changes and they never see yours. It is not a live view of your Diamond: there is nothing to revoke afterwards, and nothing that goes on reading what you keep. A share carries the files of one Diamond, so there has to be one open, and the panel names it and says in the same line what it is: a copy they will own, not a view of yours. Pick who it goes to from the people whose sealing key this device holds, and press Share . At most sixty-four files and two megabytes of them; over either it is refused rather than trimmed, because a copy missing a file is not a smaller copy. Three things never travel whatever you do: the Diamond's own version history, the agent's log, and a capp's own manifest."},{"p":"social.html","a":"s39","t":"Two carriers, chosen by measuring","u":"Social › Sharing a Diamond","b":"The relay carries a sealed envelope of at most 64 KB, so the carrier is decided by size rather than asked of you, and the panel says which happened and how big the share was. Over that size Daimond writes the share out as a file with the extension .dshare — always that extension — names it after the share and its address, and tells you what it was called. Give them that file. A capp page is around 100 KB on its own, so a share carrying a capp always travels this way; so does one going onto a memory stick, or to somebody who has no account here. A .dshare is not more trusted than a message for having been a file: the bytes are the same sealed envelope, sealed to that one person, and opening it asks the same question. The file is the route that lands. A share small enough for the relay is sent through it, and the sender is told it went. The receiving side of that route is not finished: there is no control that opens it, and it turns up under their Messages as a message their device could not read. Until that is done, save the file and hand it over — which is what a share of any size can do."},{"p":"social.html","a":"s40","t":"A share that carries code","u":"Social › Sharing a Diamond","b":"Data travels freely; code travels only by consent. A Diamond carrying a capp page carries a program somebody else wrote, and Daimond runs the page when the Diamond holding it is opened — so the question is asked before anything is written, and not when it is opened, which would be too late. The dialog is headed This share contains code . It names the share, says whose key it came from, and lists the files that would be added, because “it contains code somewhere” is not enough to answer. The button that accepts it reads Accept the page . Say no and the rest still lands: the data files are written, and the panel names the pages that were left out, so nothing is missing without being said. Where the whole share was a page, nothing is added at all and the panel says that instead. To take one in, Open a share file… asks for the file, and what arrives is added as a Diamond of your own, with the number of files that landed. The name on it is the sender's and is advisory: two people may pick one name and neither is wrong. &larr; Machine Operations Back to Getting started &rarr;"},{"p":"spending.html","a":"","t":"Spending","u":"","b":"Spending The Spending view shows where your money goes, and it keeps the two pots apart. They are different accounts in different currencies, so Daimond shows them as two tracks and never adds them together."},{"p":"spending.html","a":"s1","t":"Two pots, kept apart","u":"Spending","b":"Inference. The model calls themselves, billed to your own provider key. Daimond prices and records them on this device, per turn, so you can see the cost of your own key spend without any of it passing through us. Credits. The prepaid balance the gateway spends on the few things that leave the browser: fetching a page, syncing or sending mail, cross-device sync, and keeping your workspace in cloud storage ."},{"p":"spending.html","a":"s2","t":"Opening it","u":"Spending","b":"Open the Spending panel from the spend row at the foot of the rail, or from a link in the Credits view. It shows each pot with a headline figure, a daily graph, a breakdown by category and a plain table of movements, so a charge is never a mystery."},{"p":"spending.html","a":"s3","t":"Protection from runaway costs","u":"Spending","b":"A workspace that can run many agents at once can spend fast. The danger is not a large monthly total but a rate spike : a fan-out burning through credit in seconds, before you can react. Four measures catch the spike itself, and none asks you to set a limit in advance. A pace check before a fan-out runs. The cost of dispatching a batch is known before any of it starts. A batch that would run faster than your own recent pace is held, and Daimond asks once, with the number and the estimate on the prompt. A few agents of ordinary cost never trip it; a sudden fifty do. Your own normal is the measure, learned from your recent spend, so there is nothing to configure. Pause and stop, always to hand. The Agents panel pauses every running agent at a stroke, or stops them outright, and the rail's Everything row pauses the whole app. Pausing stops the spend at once and keeps the work, so a look costs nothing. A separate key for every agent. Each agent running on credits spends its own freshly minted key, capped against what is left after its siblings' claims. No two agents share a key, so parallel agents cannot race a shared allowance past its cap. Everything metered, per turn, on your device"},{"p":"sync.html","a":"","t":"Cross-device sync","u":"","b":"Cross-device sync Daimond is local-first, so a second device starts empty. Cross-device sync carries your chats and workspace files between your own devices without the server ever reading them. What travels through the gateway is one encrypted parcel only your devices hold the key to. The key comes from your passphrase and never leaves the browser, so the server stores the parcel and cannot open it. Nothing readable crosses between devices."},{"p":"sync.html","a":"s1","t":"Linking a second device","u":"Cross-device sync","b":"Each device makes its own identity, so typing your passphrase on a new one starts a separate , empty account instead of bringing your existing one across. To use the account you already have, link the new device to it. Three steps."},{"p":"sync.html","a":"s2","t":"On the device you already use, open the link dialog","u":"Cross-device sync › Linking a second device","b":"Click the Link another device button in the top bar. It shows a QR code and a one-time pairing code. Your first device shows a QR and a code."},{"p":"sync.html","a":"s3","t":"On the new device, scan the QR, or type the code","u":"Cross-device sync › Linking a second device","b":"Point the new phone's camera at the QR code: it opens Daimond and fills the code in for you, so you only tap Link this device . No camera? Open Daimond there, choose Have a pairing code? , and type the code. The code shown is only so you can check it matches the first device. After scanning, just tap Link this device ."},{"p":"sync.html","a":"s4","t":"Unlock with the same passphrase","u":"Cross-device sync › Linking a second device","b":"The new device now holds your account. Unlock it with the same passphrase you use on your first device (not a new one) and your chats and files appear. A passkey can unlock it faster afterwards, once you add one there. The passphrase is the same everywhere, but it cannot travel on its own. One account, one passphrase, on every device you link. The passphrase only decrypts a key the device already holds, so a browser that has never been linked has nothing for it to open. If a device asks you to create a passphrase rather than enter one, it is about to start a new account, and only linking it (or importing a backup of the old account into it) will bring the old one over."},{"p":"sync.html","a":"s5","t":"What travels","u":"Cross-device sync","b":"Your chats, your Diamonds and the graph you laid them out in, your mail, your workspace files, the devices on the account, and what you have paused. Any file travels, whatever kind it is: a photograph, a recording, a PDF or a spreadsheet reaches your other devices as text does, up to a gigabyte for one file. So does the Trash, so a deletion and a restore both reach every device. What syncs is also what is kept in cloud storage, so a workspace can be larger than the device you are reading it on. A file that is not on this device still shows in the tree, marked with a cloud, and comes down when you ask for it. The Workspace sets out the three states a file can be in, how space is freed as the browser fills, and what cloud storage costs."},{"p":"sync.html","a":"s6","t":"Running a turn on another device","u":"Cross-device sync","b":"When more than one of your devices is awake and linked, one can run a turn for another, and the answer syncs back to the device you started it on. This is off until you turn it on, and set for one device at a time. One switch, Hand off when you step away , lets a turn running on this computer move to another awake device when you close it — the lid shuts, the tab closes, the connection drops. The turn finishes there and its answer syncs back, instead of sitting interrupted until you return. The turn says where it went. It reads Sent to your other devices , then names the one that took it — Laptop is doing this — and the answer appears here when it is done. Two buttons sit beside it: Take back returns the turn to this device, and Run here runs it locally if no device picked it up or one could not finish. Naming your devices in the account settings is what makes these lines read as Laptop rather than your other device . You can nominate one device as the runner. Pick the one that is usually on — a desktop that stays awake — and hand-offs go to it rather than whichever device grabs the turn first. If it is offline when a turn is handed off, any awake device runs it instead. An errand "},{"p":"sync.html","a":"s7","t":"What it costs","u":"Cross-device sync","b":"Cross-device sync is part of Pro , the one-time unlock, which stays bought once like the rest of Daimond. Without Pro a device works on its own; with it, your devices stay in step. Pro also turns on cloud storage and Email. The larger file bodies sync carries are kept in cloud storage, paid for from credits, with a free allowance before anything is metered. &larr; Accounts Next: Spending &rarr;"}],"alias":{"password":["passphrase"],"passwd":["passphrase"],"login":["sign in","unlock"],"signin":["sign in","unlock"],"byok":["own key","provider key"],"apikey":["provider key"],"api":["provider key"],"key":["provider key"],"cost":["spend","credits","price"],"price":["credits","spend"],"billing":["credits","spend"],"money":["credits","spend"],"iphone":["phone","device"],"android":["phone","device"],"ios":["phone","device"],"mobile":["phone"],"darkmode":["theme","palette"],"colour":["theme","palette"],"color":["theme","palette"],"font":["text size","theme"],"shortcut":["keyboard"],"hotkey":["keyboard"],"backup":["export"],"restore":["import","backup"],"delete":["remove"],"erase":["remove","delete"],"gpt":["model"],"claude":["model"],"openai":["provider"],"anthropic":["provider"],"agent":["worker","agents"],"bot":["daimon","agent"],"terminal":["machine","run"],"shell":["machine","run"],"offline":["sync","connection"]}};