Agent chats
An agent chat is a conversation in the browser whose work — reading files, writing files, running commands — happens on a machine running the LLeMbas CLI. Nothing ever runs on the server itself.
What it takes
Three things on the server, all off by default on purpose:
- Admin → Agents switched on;
- the Run commands permission for the people who should use it;
- at least one model marked for agent execution under Admin → Models.
And on the machine where the work is, the LLeMbas CLI, logged in and running as a service:
lembas login https://your-server
lembas service install
loginctl enable-linger $USER # keep it running while nobody is logged inThe machine decides what it allows, in the remote: block of its global config.yaml:
remote:
enabled: true
roots: [~/code, /srv/work] # the only directories a remote session may use
max_mode: edit # the most a remote session may run in
approval_timeout: 600 # seconds before an unanswered approval is a denial
require_trust: true # only directories trusted on this machine
terminal: false # true: allow the browser's terminal panel hereChoose the machine with care. The containment is that machine. A throwaway container built for the job is a very different thing from your own workstation, and LLeMbas cannot tell them apart. Choose roots and max_mode accordingly.
Start a chat
- Switch the sidebar to Agents. Each linked device has its own section; offline ones are dimmed.
- Press the device’s +, choose a directory — the dialog shows the device’s roots and trusted directories — and a mode.
- Write your message. The directory and device are fixed once the chat exists; the mode and model can change at any time.
Modes
| Mode | Reads | Writes files | Runs commands |
|---|---|---|---|
| Manual | asks | asks | asks |
| Edit | free | free | asks |
| Auto | free | free | free |
| Plan | free | asks | asks |
The mode is enforced at every step, not written into the prompt — anything a model reads may try to argue with a rule that lives only in text. The device may lower a mode to its own max_mode, never raise it. Plan finishes by proposing steps, with a button that carries them out in Edit (or Manual).
Approvals, questions and plans
When the agent needs you, a card appears in the chat: an approval for a command or a file change, a question with options (the recommended one marked, plus Something else), or a plan to approve, send back or dismiss. If the session is also open in a terminal, the same card is there — the first answer counts and the other goes away. An approval nobody answers becomes a denial after the device’s timeout.
Files, commands and attachments
@lists the device’s own files, ranked the way its terminal ranks them. The device reads the file when the message arrives — nothing is copied to the server./offers the device’s commands after the server’s own, marked On the device: custom commands, skills and built-ins such as/compact,/undo,/reviewand/init.- Attachments reach the device: pictures as images, documents as text, anything else as a file — up to 10 MB a file and 25 MB a message.
One session, two places
A session runs in exactly one place — the device — and both the browser and the terminal are windows onto it.
- With the service running, a session you open in a terminal (in a directory the
remote:limits allow) appears as a chat, with its earlier turns, and every turn typed in the terminal shows up as it happens. /remotein the terminal shares the current session by name, outside those limits, for as long as the terminal is open.- A message typed while the agent works goes in at its next step, from either side.
- Switching model or effort on the device follows into the chat. A model that exists only on the device shows as on the device: ….
- Renaming, compacting or deleting the chat reaches the device. A delete made while the device is offline is delivered when it is back.
- A reply that was running when the server restarted is picked up again, never sent twice.
The terminal panel
An agent chat has a Terminal button that opens a real shell on the device, in the chat’s directory, beside the conversation. It needs the Open a terminal permission on the server and remote.terminal: true on the device.
- The modes do not apply: what you type is yours, as in any terminal. The model cannot see the panel.
- Copy takes the last command and its output; Send puts it into the message box; Auto collects every command you run into your next message. Nothing is sent on its own.
- With the device’s shell integration (bash, zsh, fish), the header follows the shell’s directory, each command gets a green or red mark for its exit status, and Ctrl+Shift+↑/↓ jump between commands.
- Closing the panel does not end the shell; a build keeps running and you reattach with the scrollback.
Tokens and credits
A device using the server’s models does so through the server’s API, which counts and charges them once. A model of the device’s own costs the server nothing.