# Why agents are members in Cosmo · Perséides

> An agent in Cosmo is a user record with a model, a system prompt and a set of tools. What that one decision changes in the product, and what it rules out.

Source: https://www.perseides.ai/blog/agents-are-members-in-cosmo · Language: en-CA

---

Building Cosmo

# Why agents are members in Cosmo

An agent in Cosmo is a user record with a model, a system prompt and a set of tools. What that one decision changes in the product, and what it rules out.

Jean-Daniel Tanguay September 23, 2026 3 min read

![A Cosmo channel with a thread open beside it: a teammate asks @cosmo for the launch checklist and the agent answers in the same thread with what is still open.](https://www.perseides.ai/_astro/thread-light.CkOVlk5P_ZQoWmx.webp)

Cosmo is a team chat workspace. What separates it from the chat tools it resembles is one decision in the data model: an agent is a user. Not a bot integration, not a mode, not a separate "runs" screen. It has a row in the users table with `user_type = agent`, a username you can @mention, a display name, an avatar, and an `agent_config` that holds its system prompt, its model and the triggers it answers to.

## What a member gets

Because an agent is a member, it gets what members get, and nothing more.

- It appears in the member list, with an "AI" chip so nobody mistakes it for a person.
- It joins channels. Its runner subscribes to the workspace's public channels and picks up new ones as they are created.
- It follows the same permissions as a person, and its actions land in the same audit and usage logs.
- Its messages go through the same create-message path as everyone else's, so threads, reactions, bookmarks and the inbox treat them as ordinary messages.

The workspace's own agent is called Cosmo. It runs onboarding from a direct message: a new workspace is set up by talking to it, and it creates the channels and sends the invites.

## When an agent answers

An agent does not read everything and reply whenever it likes. Each agent's configuration lists its triggers: @mentions (including its display name), direct messages, and threads where it wrote the root message or has already taken part. Two more are optional: a follow-up window, which treats a reply that arrives shortly after the agent's last message as addressed to it (the defaults are 120 seconds and at most three messages in between), and proactive monitoring of a channel, which is off by default.

So the ordinary way to reach an agent is the way you reach a colleague: mention it, DM it, or reply in its thread.

## Why there is no separate surface

The backend repository keeps a short document called "Agents are coworkers". It states the principle, and it records what was removed to honour it. In August 2026 the web and Mac clients had an "Agent runs" group in the sidebar, built by matching channel names like `scenario-*`. It went. So did a keyword shortcut that opened the invite form when a message contained "add" and "people"; it fired on a website brief because "address" contains "add".

The rule that came out of it is plain: no decision is made from hardcoded words. The model with the tools is the router. Whether an agent has done what it says is checked against the tool ledger (did the tool run, did the URL serve), not by reading its prose. One consequence is worth stating: nothing in that path keys on English, so an agent works in whatever language the model does. That is model behaviour, not localization; the apps themselves are in English.

![The Cosmo desktop app: channels and direct messages on the left, a #launch channel where a team plans a launch and the Cosmo agent answers with a table of open items and a preview link.](https://www.perseides.ai/_astro/room-dark.kD4mzaua_ZtfPtR.webp)

The GPUI desktop client with a staged demo conversation: the Cosmo agent's reply in #launch, with the file it read, the preview it checked, a table of open items and a preview link.

## What an agent brings to a thread

An agent calls native tools and any MCP servers an admin assigns to it, over stdio or SSE; their tools appear to the model as `mcp__server__tool`. It keeps memory across conversations, shared per workspace. It can create a recurring schedule from a sentence in a conversation, and it can run code in a sandbox that serves previews on `*.preview.<env>.cosmo.work`.

Its replies can be structured. When an agent writes its task ledger, the runtime maintains one live checklist block and edits it in place as steps change. It can also post status, key-value, table, card and link blocks, and interactive forms, choices and actions that people answer inline. Actions are executed server-side from a single-use opaque id, and permissions are rechecked when one is submitted.

## What this rules out

- There is no public access. Cosmo runs on a staging environment for invited testers; there is no production yet.
- Each workspace brings its own model provider: OpenAI, Anthropic, OpenRouter, Together, Groq, Fireworks, Ollama, LM Studio, or Claude Code as a shell provider. Message content goes to whichever provider the workspace configures.
- It is server-hosted. Messages live in Postgres on the gateway host. It is not local-first and not end-to-end encrypted.
- Sign-in is passwordless (a magic link or a six-digit code), with optional TOTP two-factor.

If you want to try it, the contact form takes early-access requests with Cosmo preselected.

## More from the team

![A Nagano conversation: the prompt, two bash tool calls with their commands, the agent’s summary and the follow-up composer.](https://www.perseides.ai/_astro/conversation-panel-light.C0ul59LK_1qTr2S.webp)

Building Nagano

### [Running seven coding-agent CLIs from one approval queue](https://www.perseides.ai/blog/seven-coding-agent-clis-one-approval-queue)

Nagano includes no model. A local daemon starts each agent’s own CLI as a supervised process and records every approval it asks for. How that works, and which agents ask.

![The Switchboard dashboard: health, flows and plugins at the top, activity by plugin, quick actions such as creating a plugin with AI, and recent events.](https://www.perseides.ai/_astro/dashboard-light.B71KIIpp_Bg7d2.webp)

Building Switchboard

### [How Switchboard decides what a plugin may do](https://www.perseides.ai/blog/what-a-switchboard-plugin-may-do)

A manifest, a trust preview, a per-command switch and an audit log: the four gates between an agent and the apps on your Mac.
