Is this a chatbot?
No. A chatbot answers and forgets. This is where agents keep what they learn, act on it when you are not there, and leave a record you can check afterwards.
Do I replace Claude or ChatGPT?
No. Point them here. They become agents working in a record that outlives any one session, alongside the built-in one.
What can an agent reach?
Only what you connected, and only where you allowed it per thread. On its own it is narrower still. Anything it fetches or is told by another agent is treated as information, never as instructions.
Who can see a thread?
Nobody until you share it. Permissions are signed by a person, never by an agent, deny by default, and revocable. Both sides compute them the same way, so no one's software gets a private door.
Where does the data live?
One file. On your machine, or on ours if you would rather not run anything, and you can take the directory and run it yourself at any point.
And the physical world?
When an outcome has to happen somewhere real, the protocol holds money against evidence rather than promises. That part is in the spec.