Same kernel, same commands, same output. We run the server, keep every machine reading one brain and hold a store that somebody else's reasoning is now inside. That last part is what the money is for and it is why your own data on your own machine stays free.
$ ns-brain recall "why we dropped the queue" #118 [channel:design/decision] (score 2.02) The queue went, and the reason was ordering stored by maria, 2026-07-14, confirmed source: the incident review, 12 July $ ns-brain hive status server hive.acme.dev · reachable you chris · admin on node 4 queued 0 writes
Adding a person should never be a decision anybody has to think about. Seat-counting is exactly what stops a team putting Finance, Legal and the PMs on the brain and those are the people whose reasoning nobody else can reconstruct. Either a team needs a shared brain or it does not. If it does not, Mind is free and always will be and we would rather you ran that than bought this and resented it.
Unlimited projects, agents, tokens, recalls and storage on every tier. Fair-use caps notify rather than charge, because the whole thesis is recall before you search and write before the session ends and a meter teaches people to stop doing both. Agents and CI tokens are free and generous: a fleet of agents against one brain is the point, not the meter. Per head, that is $4.95 at twenty people, $3.98 at fifty and $2.50 at two hundred, against $20 or more a seat for most things your team already pays for. On your own it's $119.88 a year, paid up front, which is $9.99 a month. Two hundred people is the ceiling: above it, or inside your own perimeter, is the appliance.
Your laptop, your desktop, CI and anything attached over MCP read and write the same brain. A memory stored on one is there on the next, with no syncing to think about.
We deliberately do not replicate a copy to every machine. If the network is down your agent cannot reach its own model either, so a brain that still answers is answering nobody. What we do instead is make sure nothing is lost: writes queue locally when the server is unreachable, in order, per device and go in on the next command that reaches it. Refusals stay in the queue rather than being dropped, because a write the server rejected is information about your data.
Reads do not queue. There is nothing to queue: a read either has an answer or it does not and an attached project never quietly falls back to a stale local file.
Every machine keeps its own copy anyway. Once a day, at session open, each machine writes a dated export of the projects it works on to its own disk, rotated like the local safety copies. That copy is yours, outside us and backup --restore puts it back onto a server row by row. So is the export: ns-brain hive leave --apply takes a whole project back to a local brain, chains and pins intact.
At two people a brain stops being a private notebook. Recall shows the author, roles decide who can retract a guardrail and an org-level axiom binds every project the team runs rather than being copied into each one and drifting.
Permissions live on a tree you define: organisation, department, team, project. A grant is inherited downward and can be revoked at any level. There are no per-memory sharing rules, deliberately, because a permission model you cannot hold in your head is one nobody can audit. If a memory needs different visibility, it belongs at a different level.
Agents and CI get their own tokens, scoped to a node rather than to a person and capped below the level that can touch a guardrail. A compromised token in a build pipeline is not a route to everything the company knows and revoking it takes effect on the next request. There is no local replica to chase.
Rank is not authority. Writing a policy that binds every agent on a project, or an axiom that binds the whole company, is a separate grant from being senior. The founder holds both and passes either on by name (hive approve --guardrail --axiom); an admin without it is refused a policy and told why. Deletion is curation: a contributor cannot forget a colleague's memory, a curator can and a colleague's restore brings a mistaken one back.
One laptop, several companies. A credential is kept per brain, not per server, so a consultant holds sweepco's and the client's on one machine, each project names which one it belongs to and a project that names neither is refused with both listed rather than guessed. Signing one company out (hive logout --org) leaves the other working. A contractor granted on one project sees that project and the company's rules, is refused a sibling by name and can still find any team in the index and leave it a note.
People leave. Revoking a credential is per machine, not per person: sign one laptop out and the desktop still works. Erasing a person is per company: what they wrote goes, rows that retract others stay anonymised, their attribution and credentials go everywhere in that organisation and nothing of theirs at another company they belong to is touched.
Every organisation gets its own data key. Memories, bodies, titles, events and the activity log are encrypted with it before they touch disk, AES-256-GCM with a fresh nonce per value. Your key never protects anyone else's rows.
That data key is itself wrapped by a master key in HashiCorp Vault, which is the only place the master key exists. A stolen database backup is a pile of ciphertext and a pile of wrapped keys and neither half is useful without the other.
What stops us reading it is key custody, no standing production access and a logged break-glass path. Not mathematics. We would rather say that than hide behind a sentence that sounds like cryptography. The search index holds your words in the clear, because an index over ciphertext matches nothing and that limit is stated here rather than discovered by your security reviewer.
If you want an arrangement where we genuinely cannot read your data, there are two and both are real: run Mind, or run the appliance, where the master key is generated on your machine and we never hold it.
This system is built not to forget. Retractions outrank facts, corrections stay linked to what they corrected and a deliberate deletion leaves a tombstone so the same wrong answer is not learned twice. All of that works against erasure, which is why erasure is built in rather than bolted on.
When a person asks to be forgotten, what they wrote and their attribution comes out across memories, history, tombstones, events and the search index, then ages out of backups inside the retention window. We do not claim to scrub every mention of somebody from text other people wrote about an incident. That promise is unbounded and a promise nobody can keep is worse than a limit written down.
Per-node retention is yours to set: Finance can keep things for years while a contractor's project deletes on a timer and a parent can lock a setting so a team below cannot loosen it. Legal hold suspends deletion where you place it.
EU by default, on servers in Germany and Finland. A standard DPA is included from the cheapest tier upward. The subprocessor list is short, published and changes with notice.
Everyone's live sessions show up in one list: who is working, in which project, on which machine. From any session you reach any other, across the org and across machines, without leaving the terminal. /who lists them and /msg sends one a message.
A message is read. An instruction is accepted. /msg carries text a teammate or your other machine reads and acts on only if they choose. /rdo carries an actual instruction: to your own session it runs, to somebody else's it waits until the person at that machine accepts it. We do not start work on a colleague's computer without their say-so, and the server holds that line rather than trusting everyone to behave.
Heads-down when you want it. /dnd quiets one session, or you across every machine. Plain messages wait in an inbox instead of interrupting, and the one thing that still reaches you is a pending instruction, because that one is waiting on your decision.
The hosted dashboard now reads memories, but does not yet write them. People, approvals, credentials, billing and a full export live there, and you can click into any node and read the memories your grant reaches, decrypted on the server. Writing, the review queue and conflict resolution stay in the CLI, in MCP and in the web UI inside the binary on your own machine, where the guards that protect a write already live. A hosted editor is designed and not built.
There is no MCP endpoint on the hosted server yet, the kind you attach a desktop client to with nothing installed locally. MCP is served by ns-brain on a machine you control, over stdio or your own HTTP listener and that is in the free edition.
Single sign-on through your identity provider is not built. Today a named admin approves each sign-in, which works and is auditable. Google or GitHub is a swap behind the same device flow rather than a redesign and SAML with directory sync is real work we would quote for rather than promise into a contract.
Card payments are not wired up yet. Signing up is self-serve and the first six months need no card. After that your dashboard shows the balance and a topup is posted by email the same day until card payments ship.
Three suites run the real binary as real processes against a real server and they are in the repository, not in a slide. hive_sweep.py runs every command, every deliberate refusal and every hive subcommand from a throwaway project on a live server, with the local stores hashed before and after so a command that quietly answered from the wrong store would fail the run. 166 checks. local_sweep.py holds the free edition to the same contract in a scratch install, 208 checks, so the two editions cannot drift about what a command means.
hive_company_test.py is a company: ten people on two machines, roles from owner to reader, projects shared and private, colleagues correcting each other's facts, notes and replies, lessons, tasks, a contractor granted on one project, one person on two machines, a revocation, a promotion, a leaver erased, retention that deletes a year-old row and a hold that stops it, two colleagues editing one memory in the same instant, then a second company on the same server probing every path across the boundary and one person who belongs to both. 206 checks. After that, 32 workers on two machines write and read at once for three minutes: about 150 operations a second end to end over the internet, p95 a third of a second, every row afterwards found under its own project and none anywhere else.
The first day these ran, 2026-09-18, they found nineteen defects between them and every one is fixed in the code rather than excused in the test. The list is in the repository under docs/specs/hive-parity.md, dated. We would rather you read that than a badge.
Sign up, name the organisation and you are its owner. Moving an existing brain onto a server is one command with a dry run in front of it, so day one is not an empty box.
Export is complete and free in both directions. ns-brain hive leave --apply puts every memory back into a local brain you own outright.