#105·aos-ce

feat: build a governed mobile companion for PC activities

Author: joshuajbouwCreated Aug 28, 2026Updated Aug 28, 2026
Labelscampaign/adaptive-workspacefeatneeds-design

Outcome

Deliver an AOS mobile companion that lets a person converse with their agent, inspect PC activity, issue governed commands, handle approvals and notifications, and hand work between phone and computer without pretending the phone is a scaled desktop shell.

Product boundary

The computer remains the execution and rich-pane rendering target. The phone is a controller and continuity surface:

  • conversation and command entry;
  • target device, principal, activity, and session status;
  • Go intents adapted to mobile;
  • notifications, approvals, denials, receipts, and failures;
  • launch, focus, split, switch, close, pause, resume, and handoff intents;
  • compact spatial/activity overview where useful;
  • reconnect and stale-session handling.

It does not reproduce the desktop pane renderer, shrink desktop applications into phone cards, promise mobile parity, or treat presentation as authority.

Ownership and dependencies

AOS owns the mobile product experience, command composition, continuity UX, and accessible presentation. Astrid owns principal/device identity, pairing, authenticated transport, capability enforcement, target binding, revocation, audit, reconnect semantics, and authoritative receipts.

The exact mobile backend and any private substrate contract remain design work. This issue does not authorize a public Astrid WIT, post-delivery filtering, copied live handles, ambient network authority, or a second identity model.

Dependencies include the durable activity/recipe model, the Go command vocabulary, governed live actions, and an accepted Astrid device/session command boundary.

Exit gate

From a paired phone, a normal user can identify the target computer and activity, converse with the agent, issue one bounded PC command, review or approve a governed request, observe an authenticated result/receipt, survive disconnect/reconnect without acting on stale state, and hand the activity back to the computer. Denial, offline, revoked, and wrong-device cases fail closed and remain understandable.

Claim boundary

This does not prove remote desktop, application streaming, desktop renderer parity, arbitrary device control, public availability, or general mobile platform support. No live-home installation, release, publication, or public Astrid contract is implied.

Verification

Novice usability; explicit target-device and activity identity; authenticated pairing; command and approval receipts; stale-session and replay falsifiers; revocation; offline/reconnect behavior; accessibility; notification privacy; no desktop layout leakage into the mobile acceptance gate.