feat: build a governed mobile companion for PC activities
Outcome
Deliver an AOS mobile companion that lets a person converse with their agent, inspect PC activity, issue governed commands, handle approvals and notifications, and hand work between phone and computer without pretending the phone is a scaled desktop shell.
Product boundary
The computer remains the execution and rich-pane rendering target. The phone is a controller and continuity surface:
- conversation and command entry;
- target device, principal, activity, and session status;
- Go intents adapted to mobile;
- notifications, approvals, denials, receipts, and failures;
- launch, focus, split, switch, close, pause, resume, and handoff intents;
- compact spatial/activity overview where useful;
- reconnect and stale-session handling.
It does not reproduce the desktop pane renderer, shrink desktop applications into phone cards, promise mobile parity, or treat presentation as authority.
Ownership and dependencies
AOS owns the mobile product experience, command composition, continuity UX, and accessible presentation. Astrid owns principal/device identity, pairing, authenticated transport, capability enforcement, target binding, revocation, audit, reconnect semantics, and authoritative receipts.
The exact mobile backend and any private substrate contract remain design work. This issue does not authorize a public Astrid WIT, post-delivery filtering, copied live handles, ambient network authority, or a second identity model.
Dependencies include the durable activity/recipe model, the Go command vocabulary, governed live actions, and an accepted Astrid device/session command boundary.
Exit gate
From a paired phone, a normal user can identify the target computer and activity, converse with the agent, issue one bounded PC command, review or approve a governed request, observe an authenticated result/receipt, survive disconnect/reconnect without acting on stale state, and hand the activity back to the computer. Denial, offline, revoked, and wrong-device cases fail closed and remain understandable.
Claim boundary
This does not prove remote desktop, application streaming, desktop renderer parity, arbitrary device control, public availability, or general mobile platform support. No live-home installation, release, publication, or public Astrid contract is implied.
Verification
Novice usability; explicit target-device and activity identity; authenticated pairing; command and approval receipts; stale-session and replay falsifiers; revocation; offline/reconnect behavior; accessibility; notification privacy; no desktop layout leakage into the mobile acceptance gate.
Source: unicity-aos/aos-ce