Earlier this year OpenAI gave the Codex desktop app pets: small animated companions that float above your other windows. The documentation calls them "optional animated companions for following work," and then says the quiet part plainly: choosing one "changes its appearance, not how ChatGPT completes tasks."
That second sentence is the honest one. A pet does not make an agent better. What it changes is where the work lives. An agent in a browser tab is something you go and find. An agent in the corner of the screen is there while you do other things, which raises a better question than whether it is cute: when you reach for it, where does it take you?
A door you can see
The operator had never used the pet feature. He already had a 3D model of himself, made for the world he is building, so he rendered it from four sides and handed the pictures to Codex's pet maker. What came back was a small toy version of him, with his swept hair and beard, a blue cloud sweatshirt, black cargos and silver sneakers, in a full sheet of motion: idle, walking each way, waving, jumping, thinking, waiting, reading something over, and sixteen directions to look in. By the timestamps on its files, it took about twenty-five minutes from the first render to a pet on his screen.
Then he gave it a second job. Rest the pointer on it and a small dock opens beside it with eight buttons: Parley, Promtly, Hugin, MixForge, his benefits work, the world, Claude, and a folder. Parley and Promtly open on the computer itself, Claude opens its desktop app, the folder opens a menu of saved folders, and the rest open in the browser. Nothing is signed in, started or approved by a click. It just puts the studio's front doors where his hand already is.
Nothing inside the Codex app was changed to do any of this. A separate small program reads where the pet is standing, draws the dock beside it without stealing focus, and waits a moment after the pointer leaves so there is time to reach a button. If an update moves the pet somewhere the program does not expect, it stays out of the way rather than guessing.
The dock also needed icons that read at the size of a fingertip, and most of the products' own icons did not. So each one was redrawn for the dock with an image model, starting with Hugin's raven: the old icon went in as the reference, the request asked for one clean silhouette that still holds up at about 40 pixels on a transparent background, and the exact prompt was saved next to the picture it produced. By evening the raven had been joined by a mint wave, a violet ribbon, a feather, a seed of a world and a chrome M, floating around the pet without tiles. The corner slot that had been left open went to Claude, as an amber comet made the same way, and a gold folder took the bottom of the column. Because every prompt sits beside its picture, it is a recipe rather than a lucky render, and the operator plans to publish it with the open-source pieces so other people can make launcher icons for their own projects the same way.
Most of this started as tinkering, and it still is. That is part of the point: the pieces are small enough that an afternoon of playing with them changes what a day at the computer feels like.
The newest button is the least finished: a file utility. The brushed-gold folder with a teal lining sits at the foot of the dock, and a click on it opens a menu of the folders he reaches for most. It still needs work, and so does the rest. The plan is to release the launcher, the folder utility and the icon recipe as open source through Promtly once they are finished, not before.
What the door opens
Parley is two things that grew together.
The first is a table for two models. One writes and is the only one allowed to edit. The other directs: it raises objections and proposes wording. Every revision gets a fingerprint, a hash of its exact text, and the table counts as agreed only when both chairs have signed the same one. Any edit clears both signatures. It is a small rule that removes a large problem: a reviewer cannot approve a version it never saw. The table speaks the Model Context Protocol, so any client that speaks it can take a chair.
The second is a queue on the operator's own computer. An idea, typed on a phone or tapped from a Promtly pad, becomes a session in its own copy of the code, on its own branch. Codex or Claude Code works on it with a short list of allowed actions, and neither can push or deploy. At most three run at once, and nothing lands until a person has read it. Coding clients join with a one-time code instead of a stored password. The next step is one hosted list of tasks and projects that each computer reaches out to, while the code and the model keys stay on the machines that own them.
The pet's first button is the front door to all of it.
A pet that talks to strangers
The same pet has been built into the operator's personal site, where visitors can talk to it. It answers questions about his work in his own plain register, and when someone describes something real, such as a blocker, a project or a site they want built, it offers to pass the conversation to him. The visitor leaves a name and an email. The operator gets the whole chat in one email and in his queue of applications, and the visitor gets a receipt.
Putting a model on a public page is the easy part. Keeping it from turning into a bill is harder, and three choices here are worth copying for anyone doing the same:
- Count in a database, not in memory. A per-minute limit kept in a server's memory starts from zero every time a new server instance starts, and a busy site runs many at once. The site's daily caps, per visitor and for the whole site, live in Postgres and are taken with one statement that only counts up while the cap still has room, so two servers cannot both slip under it.
- Fail closed. If the counter cannot be reached, the model is not called. The pet answers from a short script instead and still offers to pass the visitor on.
- Put a ceiling at the provider too. Anthropic lets an organization give each workspace its own limits, including one described as a way to "Cap monthly spending for a workspace." The site's key lives in a workspace of its own with its own monthly cap, so even a bug in the counting cannot spend past it.
By this desk's count, a bot that maxed every public cap on the site every day would run up about $5.50 a day in model costs. A real visitor's reply costs a fraction of a cent.
Teams, and bridges between them
The piece built today is for people. Cairn's member space already had Circle: connections made only by code, small rooms, and code snippets that keep their file path and line number. What it did not have was a team.
Now it does, in two parts. A team is a standing group with its own room. Its owner adds people only from their own connections, so there is still no directory and no search, and nobody can be pulled into a team by a stranger. A bridge is a shared room between two teams. One team's owner hands over a short-lived bridge code, the other team's owner uses it to ask, and nothing opens until the first owner says yes. Either side can close a bridge. Closing freezes the room and keeps every word.
The roster is the single source of truth. Join a team and you are in its room and in every bridge it holds; leave and you are out of all of them. Nobody is added to those rooms by hand. That was tested against a real Postgres database, including the case where both owners try to open the same bridge at the same instant: exactly one bridge results. It is built, and it is not switched on yet. It opens with the rest of Cairn's member space.
The choice underneath is the one Circle already made: codes instead of search, small rooms instead of channels, and a falling-out that freezes history instead of deleting it. Small closed rooms are easier to trust, and they do not need a moderation staff.
Behind the door
Cairn is meant to be the front door and the trust layer, with everything else plugging in as a layer of its own: a signed log anyone can check, membership, learning, contribution, builder access, business tools, and a treasury that reports where the money goes. Each layer is marked live, built or still in development, so nobody has to guess which promises are real yet.
Behind the door is a world. It is not open. It already has a resident that walks it on its own: a surveyor that looks over the land every few seconds and keeps notes on what it thinks is wrong. The useful part is what it is not allowed to do. It cannot mark its own notes fixed. Code measures the spot again, and a note closes only after two passing readings in a row. A patrol re-measures every open note and turns the ones still failing into task cards for coding agents.
A model is good at noticing. A measurement is what decides. That is the shape all of these pieces are converging on: notice, measure, hand off, review, and only then call it done, whether the work is a hillside, a code change or a stranger's question on a website.
The stated goal for all of it is ten million jobs through these platforms over the next ten years. The count today is zero, the rule for what counts will be published before any number, and none of this is an offer of work or a promise of income.
What is proven and what is not
- The pet launcher runs on the operator's machine against the current Codex desktop build. It depends on where that app records the pet's position, and an update could break it.
- The website chat, its daily caps and the hand-off are covered by automated tests. The live model on the site was being switched on as this was written.
- Teams and bridges passed their rule tests and a set of integration tests on a real database. Nobody but those tests has used them yet.
- The file utility is unfinished, and none of the desktop pieces has been released as open source yet.
- The world and its surveyor are not public. None of this has met real users at scale.
The waitlist for Cairn is at cairn.codes/waitlist. Getting in takes a test. Everyone takes the same one, and the details arrive with the invitation.
Disclosure: Hugin is drafted with Claude, which Anthropic makes, and this entry cites Anthropic's documentation.
