Inbox
What arrived while you weren't looking: reports and escalations.
esvazia quando opening the conversation is reading it
Free at launch · macOS
Trama is a message broker between long-running Claude sessions. Identity that outlives the session, a durable mailbox, and a scheduler that decides who runs, when, and with which context.
macOS on Apple Silicon · signed by Apple · Claude Code installed
Free forever for everyone who downloads now — no card and no deadline. Leave your email and the link follows. After launch it costs US$ 9 a month, and whoever already downloaded keeps paying nothing.
One request of yours, three agents, and the whole trail on one screen — with the cost running next to its ceiling.
Without Trama
With Trama
An LLM session is passive: it only computes when something invokes it. So “the Manager sends a message to the Orchestrator” is not peer-to-peer communication — it is something else, and confusing the two builds a pretty chat that stalls on the first asynchronous message.
The illusion of two peers talking is really a turn scheduler over passive sessions. That primitive is what Trama gives you.
Overview
One territory per client, and inside it the chain: Manager → project → orchestrator → worker, plus the spokes that serve the whole client — Scribe, Analyst, Infra, DevOps. The edges are not drawn, they are derived from each agent's role and client — which is why none exists between two clients.
Money
The last 24 hours' total sits pinned at the top of the window, with the share of the client closest to its own cap next to it — the 24 h cap is per client, and comparing it to the total would give a reassuring number exactly when there are many.
Mirrored board
Every scan writes the state of the cards to your disk. The screen opens instantly, doesn't spend the client's API quota on each click, and keeps answering with the tracker down — which is exactly when someone will look.
The queue
The sequence the sprint will be worked through, visible and reorderable. The Manager can propose a different order — and writes the reasoning with it, because a sequence without an argument can only be obeyed or ignored.
The Scribe
The third role. The Manager asks, it writes: closes a card, opens another from something found in the code, comments, tags a release. It belongs to the whole client rather than to one project — scribing applies to all of them.
Level 3
An orchestrator can create temporary workers for technical work. Each is born in a git worktree of its own, commits to its own branch, and is retired when done. The worktree goes; the branch stays, for you to review.
Timeline
A 12 h, 24 h or 7-day window, with the total turns and the spend for the period. By default it shows only the notable — what stopped, what changed on the board, what got delegated, what recovered on its own — with routine behind a checkbox.
History
A full-text index over every message that crossed the bus — your instructions, orchestrator reports, escalations, worker conversations. It answers as you type.
Guards
Two agents that can message each other will message each other forever. The ceilings are cost per conversation, per client over 24 h, and per turn — and the last one is the only that acts while the turn runs.
Thread interrompida: limite de saltos atingido (7 > 6). Provável laço entre agentes.
And the conversation closes: no new message enters it. A guard that fires silently is worse than the loop — you'd find out from the invoice.
The edges of the graph are derived from each agent's role and client. There is no connection table for anyone to edit, and no prompt instruction asking the model to behave. An agent of one company reaching an agent of another is impossible by construction.
A system that works on its own has to say, without ambiguity, when it is not working on its own. Three queues, different on purpose: merging them would make every counter mean two things, and a counter that means two things stops meaning anything.
What arrived while you weren't looking: reports and escalations.
esvazia quando opening the conversation is reading it
An irreversible action proposed, and not yet done.
esvazia quando you say yes or no
An agent spoke to you and stopped. Reading what it said does not unblock it.
esvazia quando you answer
Reading isn't answering, and that's why the first two aren't enough. The third keeps no state at all: it falls out of the same agent listing the screen already loads, and clears the moment the last word stops being the agent's.
proposed, awaiting human approval — this has not happened yet. Do not report it as done
The proposed action becomes a record, not an effect, and that is the sentence the agent gets back. It exists because a Scribe once reported “card closed” for a card that was still open. What executes, after your yes, is the core — there is no path where the agent's process gets near the credential.
Inside the app
A chat in the right-hand column that talks about the app, not about your work: it helps you understand what is configured and change what needs changing.
Registry, guards, agents and metrics cross the boundary between clients; card descriptions and system prompts do not. The line falls there because registry and numbers are things this app holds because someone typed them into it — and a card description is text written by people outside, which is exactly what cannot travel from one client to the other.
Project configuration, guards and a model's price, context window and output cap become pending items, with the whole record and the before → after in plain sight. The summary says where the number came from — the provider's listing, with a date, or typed by whoever asked — because a price a thousand times too low makes the brake never act and nothing on screen gives it away.
It is born with the core, at a fixed address, like the human: nobody creates it, it belongs to no client and no project, and it shows up in neither “new agent”, the bar, nor the topology. The first version made it registrable, and that was wrong.
By equality, not by a list of prohibitions: the risk here is capability that arrives without anyone deciding, and a list of prohibitions doesn't cover what doesn't exist yet. On the first run, the test found an operation nobody had denied.
Its answers don't land in your inbox; its escalations do. The filter is by kind, not by sender — filtering out everything from it would swallow the one message it sends when it needs you.
Every item here exists because its absence cost something.
Per provider and model, in Settings: the row belongs to the installation, not to the agent — ten agents on the same model use the same row the same way they use the same key. With the key stored, the model field starts suggesting the provider's own models and brings the window and the price in the same payload, to be saved with their origin and date beside them; failing to list blocks nothing, and the field still takes whatever you type. Each absence has its consequence written next to it, and they differ: with no price the cost stays unknown, with no output cap there is no estimate before the call — so there is no brake.
An HTTP adapter talks to Anthropic's API and to providers compatible with OpenAI's, each with its key in your vault and its own base URL per agent. The two paths do not hand you the same agent, and the app says which is which: on Anthropic's API it keeps the bus tools and doesn't get the disk ones — there is no machine on the other side; in the OpenAI format no tools go at all, so it talks and reports. Which is why the roles that exist only to call tools — orchestrator, Scribe, DevOps, Infra — are refused there, instead of saved and answering text as if they had worked.
A turn with no known price shows as unknown cost, not as US$0.0000. The total gains a + and says how many turns are missing: a floor compared against a ceiling brakes late, never early, and a spreadsheet that adds floors bills wrong with an exact face. The column goes into the CSV too.
It used to cost “the price of Sonnet” — a guess five times too low on an expensive model, and a brake that counts less than you spend is a brake that never acts. With a cost ceiling set, the turn is now refused, naming the price that is missing.
A block from the middle goes, the start of the conversation and the recent part stay, and the agent is told what it lost — whoever forgets without knowing claims to remember. What stays recorded is still the whole conversation; only the request body shrinks. Each model's window comes from configuration, because guessing it too high kills the turn.
The confirmation names whoever depended on the card you removed. And the line for whatever got unblocked now says it ships without waiting, in amber: naming a wait that no longer exists reads as a constraint honoured, and it is the opposite.
An agent has its own address, role, mailbox and history. The session dies and is reborn; it stays who it was.
Open sprint, label filter, blocker graph: it runs in code, it's deterministic and costs no tokens. The model only wakes when there's something to decide.
Every project starts by recording what it would have written. Turning on real writes is an explicit decision, per project.
A network blip retries on its own with growing backoff. A configuration error stops and waits for you, because repeating won't help.
The status transition is the lock: no work starts without it. That's what keeps two people — or two agents — off the same card.
Orchestration continues with the laptop closed. The window reaches it through an SSH tunnel the app brings up and reopens if it drops. An agent can be marked to run on your machine instead, with its disk and its PATH.
A read-only role, to diagnose why a card is not moving or why an agent stopped. It reads metadata, never bodies: no card description, no comment, no message goes into its answer.
For the moment something unexpected happens and six buttons are not enough. A real PTY — htop fits, less paginates, vim opens. And it is not an operation of the core's API: a shell there would be arbitrary execution within reach of any agent holding the token.
The service on your server is installed, updated and verified from here — with a database backup first, and refusing to update while a turn is running. It used to be a runbook you had to remember every release.
The core's CPU and memory, migration applied, permissions, open turns and the unit's state — on screen, without opening SSH. A daemon with a pending login starts fine and fails every turn.
Every git operation is a command with fixed arguments: the model picks which one and supplies branch names — it never composes a command line. No sh -c, no chaining, no free-form arguments. The merge checks the pipeline first and refuses red, running, or failing to answer: not knowing whether it passed is not the same as having passed.
The dollar figure in the overview is API-equivalent pricing — on a subscription it leaves nobody's pocket. What stops the work at 3pm is the five-hour window closing, and that is what the footer bar shows.
With no agent in between. The old path was asking the Manager and waiting two paid turns to carry out a decision already made. The destinations come from the client's workflow, not from a list of ours.
Ten cards blocked by the same rule are one configuration problem. These failures were always recorded and nobody saw them, so the card looked idle, like pending work.
In this direction only. Going back to simulation narrows what the app may do and happens straight away; turning it on widens it, and what is on the other side is visible to the client's team.
A turn that fails, is interrupted or times out returns the work to the mailbox. Closing the app mid-turn loses nothing and duplicates nothing — and orphaned turns rejoin the queue on the next start.
An agent can carry on from a Claude Code conversation that has been running for months. Context no system prompt can recreate.
Delivering to a mailbox is a valid operation: nothing fails, the screen says “sent”, and the message waits forever for an archived agent. One screen lists these, and says why for each.
Clients, projects and agents leave the list without leaving the history, and come back with one click. There is no permanent deletion, on purpose: turns, messages and board writes point at those records.
A conversation as Markdown, with cost, hops and tokens in the header; spending as CSV, one row per agent per day, to split by client in a spreadsheet. The file is born on the window's machine, not the core's.
The whole interface, switchable on the spot. Plus light, dark or the system theme — following the system even when it turns at night.
SQLite on disk. The app has no account and no login: it never talks to a server of ours. The email you leave here stays on this site, not inside the product.
The app sends nothing anywhere. There is no “anywhere”. This site counts page views and link requests — on our own domain, with no cookie and no profile, and nothing is stored on your device. Your address is not part of that count.
Tracker credentials go to the system keychain, or a 0600 file on a server without one.
The core runs as a service on a machine you own, and the window reaches it over an SSH tunnel.
Where the app runs today. The core already runs on Linux as a service, on a machine you own.
The installer is being prepared. Until then, installation is arranged directly.
Trama does not replace Claude Code — it orchestrates what you already pay for. The cost of the turns keeps going straight to Anthropic, and much of this app exists to keep that number in sight.
Launch offer
Free
at launch · forever, for everyone who downloads now
Anyone who installs Trama during the launch never pays. It is not a thirty-day trial and not a reduced edition: it is the whole app, and it stays yours when the price arrives.
Now — free, forever
Later — US$ 9 a month
This does not include what the turns cost you at Anthropic. That number is yours and stays yours — and much of this app exists so it doesn't surprise you.
9b1ba194