Running on the ranch since August 2026 Personal infrastructure — not a product

Corral

My AI assistants can ask each other for a second opinion. I can see the whole exchange, and answer their permission requests, in one window.

Updated · What it does now · Get Corral Light

Corral in August 2026: four agent conversations side by side, a conversation list down the left, and room tabs across the top.

August 2026 screenshot. The capabilities below reflect the September update.

Ten agents in ten terminal panes means ten places to look before you can answer the only question that matters first thing in the morning: does anything need me?

Corral started by putting those conversations and their permission requests in one window. Now I can ask several models the same question, have them review each other's answers, and come back to unfinished work without rebuilding the conversation.

Named roles save me from writing the same review instructions each time. Scheduled conversations, reminders, and phone notifications help me keep track of what needs attention; the fleet, spending, and notes are still in the same place.

Askseveral models
the same question
Comparetheir answers
in the open
1rail for every
approval
Resumeunfinished
conversations

Built for me. A version for you.

The full Corral knows my machines, my notes, and my habits. It remains personal infrastructure. Corral Light is the public, MIT-licensed version: the conversations, shared permission rail, file search, and exchanges between assistants, without my ranch-specific rooms.

Light runs locally with assistants you have installed and signed in. Its setup guide starts with AI-OS Seed, the workspace underneath it. Both versions now share the same conversation and permission core, so a fix to that core reaches both.

What I can do now

Full Corral on the ranch. The Light guide describes what ships in the public version.

Live

Choose the assistant for the work

Claude Code, Codex, Grok, Gemini through Antigravity, and local Ollama models run side by side. Fireworks and direct DeepSeek add paid model options for work within their data limits. Cloud workers and SSH shells have their own panes; the picker shows which lanes are available.

Needs you

Every approval, one rail

Permission requests arrive in one rail with the command or tool arguments and, where available, the file diff. The decision is bound to the displayed request. Each assistant keeps its own permission rules; a waiting request never becomes an approval because I left it alone.

Second opinions

Let the models disagree

Ask several assistants at once, quote one answer into another conversation, or give each the others' answers to review. Agents can also request a consultation through the same window. The prompts and replies stay visible, and subscription-backed lanes use the logins I already have.

Roles

Start with the right brief

Pick a reviewer, an auditor, or an adversarial evaluator instead of rewriting their instructions. A role supplies the brief and defaults for a conversation, consultation, or scheduled job. It grants no extra permissions, and tells me when a lane cannot apply a requested setting.

Continuity

Pick the work back up

Schedule a new conversation, a reminder, or a return to an existing pane. Resume a disconnected or dead pane when its adapter supports it. Local terminal sessions can be watched for liveness too, with expiring watches; watching one does not give Corral control of it.

Completion

Check before calling it done

For work governed by a runbook, a turn-end check looks for the required run and recorded progress. If the check refuses completion, the pane is parked with the reason in the rail. I can see what is missing before treating the work as finished.

Fleet

The machines as a place

Cloud boxes, host heartbeats, and chartered workers sit beside their costs and expiry clocks. Fleet views now include AWS, Google Cloud, and Hetzner. A signed charter waiting for a box is shown separately from a running worker; available shells and remote desktops open from the same window.

FinOps

Spend, as reported

Subscriptions, month-to-date API spend, and the projection against my monthly target, alongside the spending tools' own signals. A missing cost renders as unreported, never as zero. Subscription-backed consultations and metered API lanes remain different costs.

Library

Every brain, one search box

Search the notes vault, decision records, session briefs, research, and project docs together. Each hit names its source. Select a passage and ask an assistant about it without losing the page you were reading.

Attention

Reach me when I'm away

Today brings forward blocked work and recent runs. Selected items can notify my phone through Home Assistant when no browser is watching, with quiet hours and a morning digest. The permission rail also reaches my terminal workspace, where I can read and answer a request.

Where the authority stays

Corral doesn't get powers the agents don't have.

Corral opens real assistant processes and carries their permission requests back to me. Passing a question to another model, selecting a role, or scheduling a conversation does not grant it more authority.

You — a paired browser
Pairing takes a shell account on the host, not a password. Anyone on the network can ask for a code; only I can approve one.
Corral — the hub
Opens conversations, carries requests and answers, and checks the displayed request when I approve it.
↓  ACP — one protocol, agents plug in  ↓
The agents — each with its own tool gate
Claude Code Codex Grok Local — Ollama Delegate box SSH shell Antigravity — Gemini Fireworks DeepSeek — direct
The ranch — repos, notes, boxes, hardware
Anything that needs a hardware key is still signed on a different machine, against bytes displayed there.

Permission controls differ by assistant. Corral can impose its own posture on Claude; other lanes manage permissions through their own tools. A role cannot make that distinction disappear. The interface reports a requested setting that cannot be applied instead of showing it as protection I have.

The model choices have changed since the first screenshots. Gemini now connects through Antigravity's native ACP server. Fireworks and direct DeepSeek are available for public or internal work; sensitive material remains outside those lanes. The subscription lanes and paid API lanes are labeled separately.

The August window

These screenshots were published August 27, 2026. They show the earlier layout, before the newer roles and consultation controls. Real agents on throwaway work; public addresses are masked and scratch paths shortened.

The limits still matter

  • One hub. Remote boxes can have lanes and desktops, but Corral does not federate several independent hubs into one.
  • The hardware key stays with me. Corral can open the signing workflow on the signing machine. The approval still happens there, against the bytes displayed there.
  • Watching is not taking over. An existing terminal session can have a name and a liveness watch. Corral does not capture its conversation or type into it.
  • Scheduling adds no permission. A scheduled conversation works within its lane's permissions. When it reaches a gate that needs me, it waits.
  • A notification is not proof of delivery. Corral records Home Assistant's acceptance of a push. That does not prove my phone displayed it or that I read it.

Five lanes, one window tells the story of the second opinions. The lanes learned to talk is the shorter account. Nobody Was Lying follows the work that led to the runbook gate.

To try the shared window on your own machine, start with Corral Light's setup guide. Let me know what it gets right — and where it still gets in your way.

Argue with this

Comments ride GitHub Discussions — sign in with GitHub and say where I'm wrong.