Skip to content

Vision

Where Project Orchestrator is going

Everyone keeps their own PO. The organization shares what it chooses to share.

Think of a company. Each person has their own PO, with their own notes and plans. Later, the organization will add a common knowledge, teams and access rights. Each PO will then use what it is allowed to use. Today, the base runs. The organization layer is planned.

  • Available
  • In progress
  • Planned
Shared knowledgeOrganization

In the middle, the knowledge the organization shares. Around it, one PO for each person.

Illustration of the planned model, with invented people. Select a person to see which shared resources their PO can reach.

Ben, Marketing

Reachable, out of 6 resources 4

  • Supplier decisions
    Write
    Decisions
  • Spring launch plan
    Write
    Project
  • Budget 2026
    No access
    Project
  • Customer FAQ
    Read
    Notes
  • Bank access
    No access
    Vault
  • Welcome notes
    Write
    Notes

From one PO to a company

Four steps, each with its real status

Follow a project from one machine to a whole organization. Each step says if it runs, if it is partial, or if it is only planned.

  1. Step 1

    One PO for each person

    Available

    Each PO keeps its own memory, plans and notes. It signs what it sends with its own identity (did:key). By default, PO shares nothing with other PO.

    Runs today.

    Instances

    Separate instances 3

    • Ana, MacBook Pro
      Own identity
      did:key:z6MkhaXg…q8Wd
    • Ben, workstation
      Own identity
      did:key:z6MknP2c…4tRe
    • Chloé, MacBook Air
      Own identity
      did:key:z6MkvT9a…Lm3b
  2. Step 2

    Share a project, with consent

    In progress

    A project stays private until its sharing policy allows sharing. In manual mode, PO waits for your approval before each action. A copy received by another PO expires after a set time. The owner can take it back.

    In progress: the consent step, the expiry and the signed revocation exist. The exchange between instances is not complete.

    Sharing

    Project

    • Spring launch plan
      Shared with Marketing
      Copy expires in 90 days, revocableMarketing team
  3. Step 3

    A company shape: teams and people

    Planned

    The organization holds a common knowledge. Teams and people sit below it. What the organization shares with a team reaches its members.

    Planned: the product has no organization or team yet.

    AcmeShared knowledge
    Marketing
    Finance
    Support

    Select a person to see what they inherit from the levels above.

  4. Step 4

    Access that follows the person

    Planned

    Each shared resource has a level for each person or team: read, write or admin. A new person reads the welcome notes. Only the Support team can edit the customer FAQ.

    Planned: sign-in exists. Roles and rights per resource do not.

    Ben, Marketing

    Reachable, out of 6 resources 4

    • Supplier decisions
      Write
      Decisions
    • Spring launch plan
      Write
      Project
    • Budget 2026
      No access
      Project
    • Customer FAQ
      Read
      Notes
    • Bank access
      No access
      Vault
    • Welcome notes
      Write
      Notes

What exists

Available, in progress, planned

Each line names the part of the backend that carries it, so you can check.

Available

Runs in the product today.

Capabilities 8

  • An identity for each PO
    Each PO has its own signed identity (Ed25519, did:key). Messages between PO are checked with PASETO v4 tokens.
    src/identity
  • Sign-in
    Sign in with Google, another OpenID Connect provider, or a password. Once sign-in is set up, the API is protected. Without it, access stays open (single-user mode).
    src/auth
  • Workspaces
    Group several projects with a shared context and shared objectives. A workspace lives on one PO.
    workspaces
  • Vault
    Secrets are encrypted on your machine. Assistants get access for a limited scope and a limited time.
    src/vault
  • Share skills
    Export, publish and import skills between projects and between PO instances.
    src/skills
  • Event bus
    An optional NATS bus keeps events in sync between the PO server, the MCP server and the desktop app.
    NATS_URL
  • External tool servers
    PO can connect to outside tool servers that assistants call. A policy decides what they may do, and it is enforced.
    src/mcp_federation
  • Remote access from Claude.ai
    Optional. Claude.ai can reach your PO through a standard sign-in flow (OAuth 2.1).
    src/auth/oauth_server.rs

In progress

Partial: an MVP exists, the whole is not finished.

Capabilities 2

  • Sharing between PO instances
    MVP: each project has a sharing policy (manual, suggest, auto). Each note can have its own consent.
    src/sharing
  • Time-limited copies and revocation
    MVP: a copy received by another PO expires. The delay goes from 7 days to never. The owner takes it back with a signed revocation.
    src/sharing

Planned

The vision. Nothing here is shipped.

Capabilities 3

  • Common knowledge of the organization
    One shared knowledge that the whole organization reads and writes. Not built yet.
    roadmap
  • Teams and hierarchy
    Organization, teams, people. Knowledge flows down the tree. The code has no organization or team today.
    roadmap
  • Roles and access rights
    Read, write or admin, for each resource and each person or team. Sign-in exists. Roles do not.
    roadmap

Try it today

Start with one PO

The base of the network is what you install first: your own PO, your own memory, your own identity.