Two planes, one operator.
The command plane controls live sessions. The context plane keeps what happened. Both run on hardware you control.
Six layers. Drover is the middle three.
Hover or tap a layer to see its contents and status.
Interaction
ShippedWhere you make the next decision: the phone, a chat or a terminal.
- Drover iOS app (source build, beta)Shipped
- Drover web cockpitShipped
- Chat through an orchestratorYou bring it
- Terminal, also from the appShipped
Orchestration
You bring itAgents that plan work and delegate it. They use Drover through MCP and the HTTP API.
- OpenClawYou bring it
- HermesYou bring it
- Any other agent, script or CI jobYou bring it
Continuity
In progressKeeps work alive across restarts, hosts and harnesses. Partly shipped. This is the direction of the project.
- Session identity across restarts and hostsShipped
- Handoff between harnessesShipped
- Wake-ups and status back to the orchestratorIn progress
- Goal-level progressRoadmap
Context
ShippedThe durable record of each session, and the tools that return it to the next session.
- Event historyShipped
- Recall and searchShipped
- Session summaries (opt-in)Shipped
- Handoff and project briefsShipped
- Portable profile with privacy tiersShipped
Execution
ShippedThe hub routes each operation. A daemon on each host owns the sessions, processes and files.
- Hub routing to direct and relay hostsShipped
- Sessions and worktrees on the host daemonShipped
- Approvals (Claude Code today) and interruptsShipped
- A structured adapter for each harness, and a terminalShipped
Harnesses and compute
You bring itEach native harness keeps its own models, sign-in, tools and sandbox. It runs on a machine you own.
- Claude CodeYou bring it
- CodexYou bring it
- AntigravityYou bring it
- DeepSeek HarnessYou bring it
- More as adapters are addedRoadmap
Capacity and governance
In progressThe limits and rules across the stack: remaining quota, cost, credentials and data location.
- Provider quota windowsShipped
- Measured cost vs subscription usageShipped
- Credentials and scopesShipped
- Privacy and data residencyShipped
- AuditRoadmap
Command plane above, context plane below.
On a small screen, scroll the diagram sideways.
Follow one turn.
- 1
You send a turn
The hub finds the session and forwards the turn to its host.
- 2
The host does the work
The host daemon passes the turn to the agent through a harness adapter.
- 3
The hub writes each event once
One transaction records the event, its payload, a preview and an outbox entry.
- 4
An exporter publishes facts
With DuckLake selected, one fenced exporter publishes batches with a receipt.
- 5
Workers derive memory
With a model backend, workers write summaries, briefs and embeddings.
- 6
Reads verify or refuse
A query child checks the serving proof. It returns a verified result or "unavailable".
What each component owns.
| Component | Runs on | Owns |
|---|---|---|
| iOS, web and CLI clients | Your devices | Presentation and authenticated requests |
| drover-server (hub) | One central machine | Fleet API, pairing, relay, ingest, exporter, MCP |
| drover-harnessd (host daemon) | Each host | Agent processes, adapters, terminals, a local spool |
| drover-collect and hooks | Source hosts | Parsing of agent logs |
| PostgreSQL control store | Central storage | Fleet state, payloads, outbox, derived memory, profile |
| DuckLake catalog and Parquet files | Analytical storage | Event facts, export receipts, snapshot history |
| Query child | Central machine | One bounded, verified analytical read |
Listeners
| Interface | Default port | Protocol | Authentication |
|---|---|---|---|
| Fleet API and web cockpit | 7080 | HTTP and WebSocket | Bearer credential or session cookie |
| Host daemon | 7081 | HTTP and WebSocket | Bearer credential |
| MCP | 7077 | Streamable HTTP at /mcp | Bearer credential. Loopback only. |
| OTLP (optional, off by default) | 4317 | gRPC | Loopback by default |
Each central listener binds to localhost by default.
Two stores, two jobs.
PostgreSQL control store
The authority for operational state: hosts, sessions, credentials, events, the outbox, summaries and the profile.
Use your own PostgreSQL, or let the installer manage a local PostgreSQL 17 container.
DuckLake lake
Append-only facts for analytics. A lake is a PostgreSQL catalog and Parquet data files.
You select DuckLake explicitly. A failed read does not fall back to older history.
DuckDB
Each host keeps a local DuckDB spool. DuckDB is also a compatibility control store for existing single-machine installs.
Backups
A complete backup is the control store, the DuckLake catalog and each data file the catalog references. Roadmap Automated off-site backup is not shipped.
Your data stays on your machines.
Self-hosted
There is no Drover cloud and no Drover account.
Private networks
Use localhost, a private LAN or a private Tailscale network. Do not expose Drover to the internet.
One trust domain
Drover has no user accounts or roles. It does not sandbox what an agent runs.
Read Security and privacy. For full detail, see docs/architecture.md and the threat model.