Vision
Where Project Orchestrator is going
Everyone keeps their own PO. The organization shares what it chooses to share.
Think of a company. Each person has their own PO, with their own notes and plans. Later, the organization will add a common knowledge, teams and access rights. Each PO will then use what it is allowed to use. Today, the base runs. The organization layer is planned.
- Available
- In progress
- Planned
In the middle, the knowledge the organization shares. Around it, one PO for each person.
Illustration of the planned model, with invented people. Select a person to see which shared resources their PO can reach.
Reachable, out of 6 resources 4
- Supplier decisionsWriteDecisions
- Spring launch planWriteProject
- Budget 2026No accessProject
- Customer FAQReadNotes
- Bank accessNo accessVault
- Welcome notesWriteNotes
From one PO to a company
Four steps, each with its real status
Follow a project from one machine to a whole organization. Each step says if it runs, if it is partial, or if it is only planned.
Separate instances 3
- Ana, MacBook ProOwn identitydid:key:z6MkhaXg…q8Wd
- Ben, workstationOwn identitydid:key:z6MknP2c…4tRe
- Chloé, MacBook AirOwn identitydid:key:z6MkvT9a…Lm3b
Step 1
One PO for each person
Available
Each PO keeps its own memory, plans and notes. It signs what it sends with its own identity (did:key). By default, PO shares nothing with other PO.
Runs today.
InstancesSeparate instances 3
- Ana, MacBook ProOwn identitydid:key:z6MkhaXg…q8Wd
- Ben, workstationOwn identitydid:key:z6MknP2c…4tRe
- Chloé, MacBook AirOwn identitydid:key:z6MkvT9a…Lm3b
Step 2
Share a project, with consent
In progress
A project stays private until its sharing policy allows sharing. In manual mode, PO waits for your approval before each action. A copy received by another PO expires after a set time. The owner can take it back.
In progress: the consent step, the expiry and the signed revocation exist. The exchange between instances is not complete.
SharingProject
- Spring launch planShared with MarketingCopy expires in 90 days, revocableMarketing team
Step 3
A company shape: teams and people
Planned
The organization holds a common knowledge. Teams and people sit below it. What the organization shares with a team reaches its members.
Planned: the product has no organization or team yet.
AcmeShared knowledgeMarketingFinanceSupportSelect a person to see what they inherit from the levels above.
Step 4
Access that follows the person
Planned
Each shared resource has a level for each person or team: read, write or admin. A new person reads the welcome notes. Only the Support team can edit the customer FAQ.
Planned: sign-in exists. Roles and rights per resource do not.
Ben, MarketingReachable, out of 6 resources 4
- Supplier decisionsWriteDecisions
- Spring launch planWriteProject
- Budget 2026No accessProject
- Customer FAQReadNotes
- Bank accessNo accessVault
- Welcome notesWriteNotes
What exists
Available, in progress, planned
Each line names the part of the backend that carries it, so you can check.
Available
Runs in the product today.
Capabilities 8
- An identity for each POEach PO has its own signed identity (Ed25519, did:key). Messages between PO are checked with PASETO v4 tokens.src/identity
- Sign-inSign in with Google, another OpenID Connect provider, or a password. Once sign-in is set up, the API is protected. Without it, access stays open (single-user mode).src/auth
- WorkspacesGroup several projects with a shared context and shared objectives. A workspace lives on one PO.workspaces
- VaultSecrets are encrypted on your machine. Assistants get access for a limited scope and a limited time.src/vault
- Share skillsExport, publish and import skills between projects and between PO instances.src/skills
- Event busAn optional NATS bus keeps events in sync between the PO server, the MCP server and the desktop app.NATS_URL
- External tool serversPO can connect to outside tool servers that assistants call. A policy decides what they may do, and it is enforced.src/mcp_federation
- Remote access from Claude.aiOptional. Claude.ai can reach your PO through a standard sign-in flow (OAuth 2.1).src/auth/oauth_server.rs
In progress
Partial: an MVP exists, the whole is not finished.
Capabilities 2
- Sharing between PO instancesMVP: each project has a sharing policy (manual, suggest, auto). Each note can have its own consent.src/sharing
- Time-limited copies and revocationMVP: a copy received by another PO expires. The delay goes from 7 days to never. The owner takes it back with a signed revocation.src/sharing
Planned
The vision. Nothing here is shipped.
Capabilities 3
- Common knowledge of the organizationOne shared knowledge that the whole organization reads and writes. Not built yet.roadmap
- Teams and hierarchyOrganization, teams, people. Knowledge flows down the tree. The code has no organization or team today.roadmap
- Roles and access rightsRead, write or admin, for each resource and each person or team. Sign-in exists. Roles do not.roadmap
Try it today
Start with one PO
The base of the network is what you install first: your own PO, your own memory, your own identity.