Locus gives you persistent, named AI teammates that work on a real computer of their own: a container with a browser, a filesystem and a terminal. Your own API key, your own hardware, no account and no central service. They can also run on a schedule, without you watching.
That last part is where the interesting design problem is.
Every tool call an Operative makes passes a classifier before it executes. Deletes, exfiltration, publishing, remote access and permission changes stop at high danger. Installs and system writes stop at medium. Reads and GET fetches go straight through.
That last line is a deliberate design decision and it is the one people argue with. It would be easy to ask about everything, and it would be worse. A prompt that fires constantly trains the person to dismiss prompts without reading them, and once that habit exists the layer is decorative. Letting reads through is what buys the right to interrupt on a delete.
Two smaller choices in the same spirit:
Routines run the same Operative, with the same tools, at 3am, with nobody there. So what happens when a scheduled run hits an approval?
The tempting answers are all wrong. Auto-approve, and the safety layer only exists when it is not needed. Auto-approve just the medium ones, and you have invented a second, laxer policy that nobody reads. Queue it and wait, and you have an agent holding a half-finished action open for eight hours.
Silence is refusal, not consent. A routine that needs approval and gets no answer within five minutes stops, records needed_approval, and reports. It does not act.
The reason a routine cannot quietly behave differently from a person asking is that there is no second implementation for it to drift from. A human message, a scheduled run and a handoff from another Operative all drive the same turn code. Approval, tool dispatch, memory writes, error handling: one path.
This sounds like tidiness and it is actually the safety property. Any system where "unattended mode" is a separate code path will eventually have an unattended mode with weaker rules, because that is the path nobody is looking at.
The test for this is not that the refusal was logged. Logs are what you check after something has already happened.
The test fires a routine that wants to delete something, lets the approval go unanswered, and then asserts that the command never reached the computer at all. Not that it was blocked downstream, not that it was recorded — that the container never saw it.
Operatives can hand work to each other, which introduces loops. I shipped two guards, not one: refuse a handoff to anyone already on the current chain, and cap the chain depth.
Either on its own leaves a hole. Cycle detection alone permits an unbounded chain of distinct Operatives. A depth cap alone permits a tight two-agent loop to burn the whole budget before it trips. You need both, and the second one is the one people skip.
Locus is Apache-2.0 and the repository opens at launch. Written by Maaz Kazi: https://maazkazi.com