Pricing
$150 a seat a month. One price.
The company buys the seat. The employee switches it on, or it does not run. There is no ladder, no annual discount and no enterprise call; a team starts at ten seats, and the list of what is unfinished is printed above the number rather than after it.
What is wrong with it, before what it costs.
An application you can install
not yetThere is no installer, no menu bar and no notarized build, and buying a seat today does not hand anybody an app. There IS a local page: node apps/desktop/src/cli.ts serves the observing state, the stream, the day's record and all five hands on one screen, reading a directory on your own machine. It prints a URL and opens nothing. Underneath it are a Swift probe, a redaction library, a skill registry, a hand runner and a recall CLI, with 267 test files green on 12 September 2026.
A notarized Developer ID build
not yetReading the accessibility tree cannot be sandboxed, so the Mac App Store is closed to it and Developer ID with notarization is the only route onto an employee’s Mac. That needs a paid Apple Developer account. It is not an engineering problem and it is not solved.
The hands still waiting for a signature
1 of 5 signedA person read desk.collect on 13 September 2026, typed its id back and signed it, so it runs: it is the safest of them, reversible, asks nothing, and sends nothing off this Mac. The other 4 have not been read by anybody, so the registry refuses to load them and they print the field they refused on. That is the gate working in both directions rather than only in the one that flatters us — and the remaining 4 are a reading job nobody has been staffed for, not a feature nobody has built.
A model that reasons about the day
none runsNo model is in any of these paths. Classification is a heuristic scoring 25 right and 3 wrong on a 28-row labelled fixture, and where it is not sure the task type reads unclassified at confidence zero on purpose. That is deliberate — a frontier model got 118 of 270 rows wrong on the sibling project’s labelled set where the heuristic got 13 — but it means the reasoning tier is specified, priced and unbuilt.
An administrator’s console
not yetThere is no fleet deployment, no MDM profile, no seat assignment screen and no billing portal, so the honest description of a sale is still a spreadsheet. Two of the promises underneath it did stop being contracts: an administrator cannot put somebody on a seat — enrolment turns on who is asking, and the database refuses an enrolled seat whose invitation was never spent — and an administrator can neither grant nor cancel the confirmation an employee gives before anything acts. Those are mechanisms. The console is not.
A measurement that the hours are there
never runThe case for it is 1.7 hours a month of somebody's time, and nobody has measured whether a thing that watches all day finds them. Not on one person, not for one month. The number has never been observed. Nobody should count on those hours before somebody has run it for a month.
An independent privacy review
not yetNobody outside the project has read the probe, the redactor or the serializer. Everything in the trust section is a mechanism you can make us run in front of you, not a review somebody else has signed.
Live payments
not connectedCheckout is not connected on this deployment — no Stripe key is set, so the deposit button opens no payment page and asks for no card. Taking real money needs an account this project does not have yet. The switch is one environment variable and it has not been thrown.
It reads text, and there is no path for a picture
true todayThe probe walks the accessibility tree and prints counts, roles and timings. In its report modes it never prints the text it read, which is why you can run it in front of somebody; --emit and --watch are the two modes that do put captured text on stdout, and --watch is the one the product runs. There is no screenshot code anywhere in the tree, and no field for a picture in the eight the serializer will accept.
Your account name is removed by exact match
true todayThe machine knows the account name, the home directory and the device name at runtime, so they are removed by exact match at full precision with nothing to tune — and that pass runs first, before any pattern. It was found the honest way rather than designed: a Terminal window title carried the developer’s own account name straight through a live run, and every one of the pattern passes had no opinion about it. A name is only a name if you already know it, which is exactly the thing the machine does know.
A password field is never asked for its value
true todayThe subtree is not entered, the secure check runs before any text attribute is requested, and a node that will not answer a subrole query is treated as secure rather than as ordinary. 9 gates in the probe are pinned structurally by an audit rather than by a test, because deleting one would break no test, fail no audit, and produce output that looks better — more nodes, more text, richer sketches. A regression that improves every number you are watching is the kind nobody catches.
One outbound serializer, with a key whitelist
true todayExactly one file may build the payload that carries your day off this Mac. It assembles from a dedicated struct and re-checks against an allowed-keys set that throws on an extra key and on a missing one; three of the eight are members of a closed vocabulary, three more are numbers, one is an HMAC of a key that never leaves the Mac, and the eighth is the sentence, so the only field that can hold screen text is the one the redactor produced; and a leak guard refuses any field sharing a twelve-character run with the text before redaction, any field still containing something the redactor removed, and any field that still holds a URL, an email address or a key. The eight keys printed on this site are that constant.
A hand cannot widen its own permissions
true todayThe runner refuses a write to the directory that decides whether hands may run, so a skill cannot write its own approval, and it refuses a resource that looks remote to any skill declaring outboundReach: none. Both refusals are structural: they are checked before the step runs, and the reason is printed. Read outboundReach narrowly, though: it is about the resources a hand claims, not about the words it read. Whether those leave is a second field every manifest has to declare, and the two hands that do declare it — reply.draft and mail.send — say so in their own row above.
Eight open items, named by us, on the site where we ask a company for money.
What closes them
The application, the notarized build and the administrator’s console are the same item wearing three coats: somebody has to be paid to build the product around the pieces that work. The approved skill closes the day a person is given the job of reading manifests and signing them — it is a staffing decision, and pretending otherwise is how a review gate becomes a rubber stamp. Classification closes when a reasoner is wired behind the gate, which is the expensive half and is why the cost table above is the watching figure and not the bill. The independent review is booked before the first paid seat, not before this page. Live payments close when there is an account holder who can sign for them. When an item closes it moves to “true today” and the date above changes.
This table will get shorter. It will not get quieter.
The offer
One thing to buy, because there is one thing that works.
A seat is continuous observation of the focused window, read as text, and the hands that act on it. It is bought per employee, per month, and it is billed to the company.
Seat
An office worker whose day is spread across a dozen applications, and the company that pays for those applications.
- Continuous observation of the focused window, read as text from the accessibility tree
- One picture of the work, kept up to date across every application
- Hands that act: declared side effects, preconditions, confirmation and cancellation
- Redaction before anything leaves the machine, and a record of what left
- No screenshots, no video, no pixels — there is no field for them
- No admin console, no fleet deployment, no export of another person's day
The arithmetic, in one line: $150 ÷ $60 an hour = 2.5 hours a month that have to come back to the person for the seat to have paid for itself. Substitute your own number; $60 is an illustration, not a measurement, and the division is the whole of the claim.
Nobody has measured whether it finds 2.5 hours. That is an open item above, it is above this price on purpose, and it is the reason billing does not start until the agent is running unattended on your own Mac — and the reason the founding cohort is 200 seats rather than as many as will fit.
Nothing is charged when you commit; the first invoice is for the month it runs unattended on your own Mac. And that month is refunded in full, with the subscription ended, if it has not taken over at least four recurring jobs end to end — noticed, offered, run, and you kept the result.
There are no tiers, and the reason is not restraint.
A ladder prices capability: the cheap rung gets less of something and the expensive rung gets more of it. The thing a ladder would ration here is the hands, and the number of them a person may run today is one of the five written. They all have working code behind them now; what they do not have is a signature, and the registry refuses to load a manifest nobody has read.
So a three-tier table would be part drawing: four of the five hands it would ration cannot be run by anybody, at any price. We would be charging more for capability nobody may use and less for capability nobody may use, and the shape of the table would be doing the arguing. One price for one thing is the only version of this page that is not a diagram of a product.
Who has to say yes
The company buys the seat. The employee turns it on.
Two keys, and the lock needs both. An administrator cannot enable it on somebody’s behalf, and cannot export another person’s day. Below, which half is built and which half is still a sentence in a contract.
The company
Buys the seat
Can
- Buy a seat for an employee, at $150 a seat a month
- Stop paying for it, which removes the seat
- See how many seats are paid for and how many were switched on
Cannot
- Turn it on for somebody. There is no path, and adding one would be the end of the product
- Read one person’s day, or any part of it
- Export another person’s record, in aggregate or otherwise
- Set an exclusion list on an employee’s behalf, or remove one they set
on paper Policy on paper. There is no admin console, no MDM profile and no fleet deployment, so today this key is an invoice and a sentence in a contract.
The employee
Switches it on
Can
- Switch it on, and it does not run until they do
- Exclude an application, after which nothing sourced from it is read or raised
- Pause it, and have that mean the tree is not walked at all
- Switch it off, individually, without asking anybody
Cannot
- Be overridden. A seat that is paid for and not switched on does nothing, and that is the expected state until they choose otherwise
built Built. touch ~/.opus-paused pauses the read and rm resumes it; both transitions are announced on the stream, because a stream that just goes quiet is indistinguishable from a crashed probe.
This is Microsoft Recall’s structure, taken deliberately: on a managed device it is removed by default, an administrator can never enable it on a user’s behalf, and an administrator cannot export another user’s data. It is the only shape in which a capture product has ever been sold into a company, and the reason is not politeness — a seat somebody did not choose is a seat nobody uses.
Why that is not a concession
A seat somebody did not choose is a seat nobody opens.
The published conversion rates for two assistants sold into the same market in the same year. The variable that moves is not the model. It is who decided.
| Who chose it | Product | Paid seats that are used | What that is |
|---|---|---|---|
| The company chooses it | Microsoft Copilot | 35.8%of paid workplace subscribers are active users | Roughly one seat in three is used by the person it was bought for. |
| The person chooses it | ChatGPT | 83.1%of paid subscribers are active users | Roughly five in six. Same year, same category, different chooser. |
Those are the vendors’ published figures, not our measurements, and they move — check them before you rely on either. We are not claiming Octopus converts like the second row. We are claiming that a product an administrator can switch on for somebody gets the first row, and that buying the first row at $150 a head is how a company ends up paying for software nobody opened.
So the second key is the commercial argument, not the compliance section. The structure above this — each person opting in individually, nobody able to do it for them — is Recall’s, and we took it because it is the only one that has shipped into managed devices, not because it reads well on a trust page. The rows here are why it survives contact with a finance conversation: the version of this product an administrator could switch on for people is the version that gets bought once and used by a third of them.
What that costs us is written down too: a company can be sold a hundred seats and switch on twenty, and there is no lever anywhere in the product that would change that. Adding one would end the product, so the honest thing to sell you is the number of seats you think people will choose.
What the price is made of
Watching is nearly free. Thinking is the entire bill.
Redo it: readings a month, times the tokens in a sketch, times the rented rate. Four inputs and one multiplication, and every one of them is a constant in this repository.
| Reading | Sketch size | Per person, per month | What it buys |
|---|---|---|---|
| Every 10 seconds | a typical sketch | $1.11 | The default. Enough for a person moving between documents. |
| Every second | a typical sketch | $11.10 | Ten times the readings, ten times the bill, and still under a working lunch. |
| Every second | every sketch at the cap | $25.80 | The ceiling the 800-character cap permits, not the expectation. |
8 hours a day, 20 days a month, charged at the full rented rate for every single reading — $0.2 per million tokens in and $1.2 out, the cheap tier of the same table the business computes its margins from. Nothing here is estimated and nothing is discounted: a real implementation would send changes rather than a whole sketch every tick, so the true figure is lower.
The rates are rented, per token, from a vendor. Nothing in this repository binds a model to a machine, and that is why these are the watching figures and not the whole bill — deciding what to do about what it saw is the expensive half, which is what the gate is in front of.
Reading somebody’s focused window every 10 seconds for a whole working month costs about $1.11 per person. Reading it every second costs about $11.10. Against $150 that is a rounding error, and it is the fact the whole product is built on: continuous observation is affordable because the thing being sent is a sentence rather than a picture.
The expensive half is deciding what to do about what it saw. That is why the gate stands in front of the reasoner and nothing stands in front of the reader. A thing that can act continuously will act constantly — the cost of an unnecessary action is not the tokens, it is the interruption — so the budget, the value test and the timing test are all on the side of the ledger that thinks, and the side that watches is uncapped.
And the swing is large enough to decide the margin by itself: the frontier reasoner bills 50 times the cheap one for the same million input tokens, in the same rate table the business computes its margins from. Both are rented, per token, from a vendor. Neither of them runs here — nothing in this repository binds a model to a machine, and a page that implied otherwise would be selling a privacy guarantee we do not have.
What else does this
Nothing ships this, which is a weaker claim than it sounds.
We can find no product that reads the operating system’s accessibility tree as text, across every application, continuously. That is a statement about what we could not find — not a benchmark we won.
What does ship reads pixels. A single screenshot to Claude computer use is 1,000–1,800 input tokens by Anthropic’s documentation, and Gemini samples video at 1 frame a second by Google’s. Those are the vendors’ numbers for their own products, published by them. Nothing sampled at that rate runs all day for a price a company would pay, which is why the products built on it are asked a question and then shown a screen rather than left watching one.
An absence is the weakest evidence on this page. Somebody may ship this next quarter, or may have shipped it somewhere we did not look. So the argument is not that nobody else does it. It is the measurement underneath: one reading of the focused window was ~39 tokens in 22 ms on this Mac, you can run the probe yourself, and the price of watching follows from that whether or not anybody else arrives.
There is no comparison table here on purpose. The products this would have been benchmarked against — note-takers, timesheet fillers, meeting scribes — answer a different question for a different buyer, and standing next to them would flatter this one without informing you.
The founding cohort
Take a seat. Pay when it runs.
Committing charges nothing today, and there is no deposit to get back: the first invoice is for the month it runs unattended on your own Mac. The cohort is capped, and the cap is on the front page with the form — every founding seat gets a fourteen-day audit read by a person, and there is only so much of that.