Agent chats

An agent chat is a conversation in the browser whose work — reading files, writing files, running commands — happens on a machine running the LLeMbas CLI. Nothing ever runs on the server itself.

What it takes

Three things on the server, all off by default on purpose:

  1. Admin → Agents switched on;
  2. the Run commands permission for the people who should use it;
  3. at least one model marked for agent execution under Admin → Models.

And on the machine where the work is, the LLeMbas CLI, logged in and running as a service:

shell
lembas login https://your-server
lembas service install
loginctl enable-linger $USER      # keep it running while nobody is logged in

The machine decides what it allows, in the remote: block of its global config.yaml:

yaml
remote:
  enabled: true
  roots: [~/code, /srv/work]    # the only directories a remote session may use
  max_mode: edit                # the most a remote session may run in
  approval_timeout: 600         # seconds before an unanswered approval is a denial
  require_trust: true           # only directories trusted on this machine
  terminal: false               # true: allow the browser's terminal panel here

Choose the machine with care. The containment is that machine. A throwaway container built for the job is a very different thing from your own workstation, and LLeMbas cannot tell them apart. Choose roots and max_mode accordingly.

Start a chat

  1. Switch the sidebar to Agents. Each linked device has its own section; offline ones are dimmed.
  2. Press the device’s +, choose a directory — the dialog shows the device’s roots and trusted directories — and a mode.
  3. Write your message. The directory and device are fixed once the chat exists; the mode and model can change at any time.

Modes

ModeReadsWrites filesRuns commands
Manualasksasksasks
Editfreefreeasks
Autofreefreefree
Planfreeasksasks

The mode is enforced at every step, not written into the prompt — anything a model reads may try to argue with a rule that lives only in text. The device may lower a mode to its own max_mode, never raise it. Plan finishes by proposing steps, with a button that carries them out in Edit (or Manual).

Approvals, questions and plans

When the agent needs you, a card appears in the chat: an approval for a command or a file change, a question with options (the recommended one marked, plus Something else), or a plan to approve, send back or dismiss. If the session is also open in a terminal, the same card is there — the first answer counts and the other goes away. An approval nobody answers becomes a denial after the device’s timeout.

Files, commands and attachments

  • @ lists the device’s own files, ranked the way its terminal ranks them. The device reads the file when the message arrives — nothing is copied to the server.
  • / offers the device’s commands after the server’s own, marked On the device: custom commands, skills and built-ins such as /compact, /undo, /review and /init.
  • Attachments reach the device: pictures as images, documents as text, anything else as a file — up to 10 MB a file and 25 MB a message.

One session, two places

A session runs in exactly one place — the device — and both the browser and the terminal are windows onto it.

  • With the service running, a session you open in a terminal (in a directory the remote: limits allow) appears as a chat, with its earlier turns, and every turn typed in the terminal shows up as it happens.
  • /remote in the terminal shares the current session by name, outside those limits, for as long as the terminal is open.
  • A message typed while the agent works goes in at its next step, from either side.
  • Switching model or effort on the device follows into the chat. A model that exists only on the device shows as on the device: ….
  • Renaming, compacting or deleting the chat reaches the device. A delete made while the device is offline is delivered when it is back.
  • A reply that was running when the server restarted is picked up again, never sent twice.

The terminal panel

An agent chat has a Terminal button that opens a real shell on the device, in the chat’s directory, beside the conversation. It needs the Open a terminal permission on the server and remote.terminal: true on the device.

  • The modes do not apply: what you type is yours, as in any terminal. The model cannot see the panel.
  • Copy takes the last command and its output; Send puts it into the message box; Auto collects every command you run into your next message. Nothing is sent on its own.
  • With the device’s shell integration (bash, zsh, fish), the header follows the shell’s directory, each command gets a green or red mark for its exit status, and Ctrl+Shift+↑/↓ jump between commands.
  • Closing the panel does not end the shell; a build keeps running and you reattach with the scrollback.

Tokens and credits

A device using the server’s models does so through the server’s API, which counts and charges them once. A model of the device’s own costs the server nothing.