Skip to content
Agent Ops

The Local Agent Operator Station

Use Quorum as the local control room for your agent CLI, IDE work, sessions, and decisions: observe first, steer deliberately, and keep irreversible actions human-approved.

Published Aug 20, 2026 · 9 min read

The rule

An agent station is not a remote-control toy. Quorum stays on your own machine, shows the work already happening there, and gives you a clear place to inspect a session, resume a controlled conversation, and record a decision. Visibility and accountability come before speed.

What is connected

Quorum watches local Claude Code and Codex session activity, running processes, project rooms, health signals, background services, and recent task state. The Studio and Deck views organize that activity by project; Radar exposes the session and system detail; Roundtable turns a difficult choice into a recorded, cost-aware argument. Your IDE and agent SDK remain the tools that write and run code—Quorum is the operator surface that makes their current work legible, including which project room the work belongs to, which runtime is ready, and what the last visible action claimed.

The safe first launch

1. Start Quorum only on the machine that owns the work. It binds to localhost; do not expose it to a public network. 2. Install or verify the client-approved IDE, the required agent CLI, and any Agent SDK runtime the project actually uses. The setup card should report readiness and paths, not token values. 3. Define the allowed project roots and workspaces before inviting an operator to steer anything. A visible room is a permission boundary, not just a label. 4. Take the guided tour, then open Studio or Deck and match the visible project room to the session you expect. 5. Click a session before steering it. Read the live transcript, current working directory, task context, and health signal. If those do not agree, stop and resolve the mismatch instead of sending a command into an unknown session. 6. Use the session conversation only to continue work that is already in scope. A resumed terminal is an interaction with a live local process, not permission to publish, spend, delete, or change accounts.

How to watch without losing the thread

1. Keep the project room, session detail, and live transcript together while an agent works. 2. Watch the activity summary for state changes: waiting on input, running a check, a background task, a failed process, or a completed result. 3. Use the project catalog and task view to separate independent work instead of treating every terminal as one anonymous stream. 4. Keep the IDE open to the same project root when reviewing code. The IDE proves files and diffs; Quorum proves which agent/session claimed to touch them. 5. When a decision is expensive or contentious, convene a Roundtable. Review its pre-spend estimate, choose only the necessary participants, observe the opening, clash, and convergence phases, then export the markdown decision record. 6. Treat a transcript as evidence, not a success signal. Verify the claimed change with the product's tests, browser or host check, and release gate.

Where humans stay in the loop

Agents can inspect, draft, run documented checks, and prepare changes within their assigned scope. A human still approves privileged installation, production deployment, money movement, account connection, destructive operations, client publication, and any action that spends outside the stated budget. Quorum's roundtable cancellation and local-only boundary are safety features, not friction to bypass.

The client-machine handoff

For a client setup, install the required local CLI, IDE, Agent SDK runtime, and Quorum on the client-controlled machine, verify the localhost dashboard, define the project catalog and allowed workspaces, and teach the operator to read a session before opening a terminal. Give the client the guide, a project-specific runbook, and a recovery path—not your credentials. If the guide is later gated in Trident Playbook, Google sign-in can protect the guide library, but it does not replace Quorum's local machine boundary or product-specific session auth.

Where it breaks

A dashboard becomes dangerous when it looks authoritative but cannot prove what it is observing. Stale sessions, a missing CLI, a disconnected service, or an unexpected working directory are stop signals. So is any request to turn local observation into silent remote control. Fix the connection or obtain explicit approval; never hide the gap with a fake green status.

Get the next play first

One email when a new playbook ships. Zero noise — that would violate the playbook.

← All playbooks