Skip to main content

Lex, the personal agent

Lex is a Labs feature. It is built into nightly builds and switched off until you turn it on in Settings → Labs.

Everything else in Celeris starts when you ask. Lex starts when you do not.

Lex looks over the work you already have in flight, such as the review waiting on you, the check that went red, or the thing you said you would do on Tuesday, and hands you one brief. Out of the box it proposes and does not act. There is one switch that changes that, and it is off until you turn it on.

Lex is deliberately narrow. It does a few things well, the morning brief first, and it is not an answer to everything you do in a day. On a phone, Lex runs on a computer you have connected and paired; the phone shows the brief and the computer does the work.

What it actually does​

On a schedule, Lex collects signals from the sources you have connected, ranks them for whether they are worth interrupting you over, and writes a short brief. The brief lists what changed, what it thinks matters, and what it would suggest doing next.

Each suggestion is an offer. Taking one starts an ordinary Celeris session with that as the prompt, with the same tools, approvals and history as if you had typed it. Ignoring one costs nothing. Nothing is queued up behind it waiting to run.

That boundary is the default, and for most people it is where Lex should stay.

How loudly things reach you​

Most of what Lex finds waits for the next brief. A few things are worth breaking in for, and those arrive as an interrupt: a bell item, titled with Lex's name and the thing that happened, and a one-line reason in plain words for why it reached you now. Every interrupt says which of the reasons below applies, so you are never left guessing why the bell rang — or why something you expected to ring only turned up in the digest.

  • A fresh install holds its fire. Until Lex has either seen you engage with something it surfaced, or you have stated a rule telling it to always tell you about a kind of event, it will not interrupt you at all; anything it would have interrupted for waits for the digest instead, and says so. This is the cold-start ceiling, and one stated "always" rule or one engagement lifts it.
  • Your rules can say "always tell me." A rule you state in the setup conversation — "always interrupt me when a background job fails", say — is the clearest signal that something should reach you loudly, and Lex honours it even outside your working hours. The digest names the rule in your own words; it never shows you a pattern or an internal id.
  • There is an hourly ceiling on interrupts. Lex will interrupt you at most four times an hour. This limit applies to everything, including a stated "always" rule: an always-interrupt rule is not exempt from the hourly ceiling. When the ceiling is reached, the next matching event is held for the digest rather than dropped, and its digest line says exactly that — that you have already had four interrupts this hour, and that your rule still applies once the hour rolls over. We keep stated rules subject to the budget on purpose: a single noisy source should not be able to turn a busy hour into an unbounded stream of interruptions, and holding the overflow in the digest loses nothing, because the digest still shows it and names the rule.
  • A burst is eased off. If the same kind of event keeps firing, Lex quietens it to the digest for a while rather than interrupting on each one, and the digest line says it is easing off a burst of similar alerts.

Letting Lex act​

Let Lex run the work it prepares is a separate switch on the same page. With it on, Lex may carry out work between briefs instead of only offering it. The rules it works under are worth reading first.

  • It never asks. Nothing is watching, so there is no approval dialog to answer. Work Lex is not already allowed to do is put aside rather than attempted, and turns up in your next brief as an ordinary suggestion with the exact command or change attached, for you to accept or ignore.
  • It cannot grant itself anything. Anything that leaves your machine or changes something someone else sees, such as pushing a branch, commenting on a pull request or sending a message, runs only where you had already allowed it. This switch widens no permission. It only lets Lex use the ones you gave.
  • It works only where you said. Lex's working folders is the list of folders, one absolute path per line. Commands run in the folder you named. Name exactly one and Lex works there. Name none, or several, and there is nothing saying which you meant, so the work is put aside and offered instead. The list starts empty, which means nowhere. Lex ignores a folder that doesn't exist, that you don't own, that other accounts can change, or that is your home folder itself, a hidden folder in your home (such as .ssh or .config, and anything inside one), Library or AppData in your home, the folder where Celeris keeps its data, a temporary folder or a system folder. Name the project folder instead.
  • Its commands run in a sandbox. Every command Lex runs on its own is confined by the operating system: it can read your files, but it can change only the working folder. Even the temporary folder is read-only to it. It has no internet access. On Linux it can still reach services on your computer that listen on a local socket, such as Docker or your SSH agent. Commands that need the internet, such as gh, are offered to you instead of run. This applies whether or not you turned on the command sandbox for your own conversations. Where Celeris can't sandbox a command, for example on Windows, Lex runs nothing and offers the commands to you instead.
  • It won't run a command that could start something else. Lex refuses forms that delete, write a file or run another program, such as find -delete or fd -x, even where you allowed the command itself. It runs git with the git settings it knows can start another program switched off. Where a repository's settings name a program that can't be switched off, such as a merge driver, Lex doesn't run git in that repository. It lists tags and branches without creating any, and ignores your global git settings, such as your global ignore file.
  • It does not edit your files. This version writes no file changes at all. When the work is a change to a file, Lex drafts the exact diff and puts it in front of you, in the brief and in Lex's own window, for you to apply. The folder list above is what a later version would apply one inside. Today it is what keeps a drafted change tied to a project you named.
  • It has a daily budget. Daily execution budget is a token allowance per day. When it runs out, remaining work is put aside rather than half-finished. Set it to 0 and Lex goes back to proposing.
  • It shows you what it did. Each brief opens with what Lex ran while you were away, what it cost, and a place to say whether it was any good. Work Lex finished is ticked off your list; work it only drafted stays on it.
  • Changes to your code stay suggestions. Lex will write you a diff. It will not apply one.

Turning the switch back off stops the work immediately and keeps your budget, your rules and what Lex had learned.

Turning it on​

Settings → Proactive has the switch, and everything below it.

  • Event sources. Which services Lex reads for signals. It starts empty, which means it reads nothing. A source you have not switched on is left alone entirely: Lex runs no command against it, so a scan with the list empty never touches an outside account and never lists, for instance, your GitHub pull requests. Add the sources you want it watching.
  • Setup conversation. A short set of questions Lex asks once. Your answers become plain rules about what should reach you loudly and what should not, and you can edit or delete them afterwards like any other setting.
  • Status. When it last scanned, when the next scan is due, and what happened to recent signals. There is a Scan now button for when you do not want to wait, and a pause that stops delivery for a while without touching your rules.
  • Execution. Whether Lex may run the work it prepares, how many tokens a day it may spend doing it, and which folders it may change files in. All three start off or empty; see Letting Lex act above.
  • Pronouns. How Celeris refers to Lex. "It" is the neutral default; the other choices make it read as more of a character. This is taste, and it changes nothing about behaviour.

What Lex remembers about how you work​

Separately from the rules about what reaches you, Lex keeps a short list of plain sentences about how work goes for you. It reads them before it plans anything.

Some of them are yours. The rest it writes for itself: when you tell it a piece of work was right or needed work, it counts that feedback up overnight and, if the same thing keeps coming back, writes one line quoting what you actually said. It never invents a line, because it can only repeat feedback you gave, and it writes at most a couple a night.

You can see the whole list in Settings → Proactive, under the Lex inspection panel. Every line can be deleted. A line Lex wrote for itself can be confirmed if you agree with it, which is the only way one of its own lines is ever promoted to something you stand behind; that is your click, never its own.

The list is kept with everything else Lex holds. Turning Lex, or execution, off does not touch it.

Why it is affordable​

The scan runs when nobody asked for it, so it has to be cheap or it is not worth having. The scanning pass uses a small, fast, deliberately limited turn: it can read a list of signals and rank them, and that is all it can do. It is offered no tools, so it cannot fetch anything, act on anything or wander off.

Unless you have turned execution on, anything that acts is a normal session you started, under the normal approval rules. Either way, "the personal agent asked for it" is not a reason for something to run that would otherwise have stopped for approval. With execution on, work like that is put aside for you rather than run.

Personal archive​

You can export a private, versioned copy of everything Lex holds, and later preview and restore it. Export writes only where you point it. A restore starts as a dry run that reports every addition, update, conflict, revocation and unsupported record before it writes anything, and it applies only to an empty profile: if state files or SQLite memory are already present it is refused, so a restore can never overwrite a profile in use. Both live in Settings → Proactive, under the Personal archive panel.

The same page carries the read-only Lex inspection panel: its rules, decisions, metrics and delivery traces, the same local views the command line shows. Nothing in it scans or delivers; it only reads back what Lex has already recorded.

Turning it off​

Turn off the personal agent and the scanning stops immediately. Nothing is deleted: your rules, your setup answers and your past briefs stay exactly where they were, and turning it back on resumes with all of them intact.

Next​