Your agents are spreading across machines. How do you keep them one identity, not a mess?
The Apiary is clean on one laptop. The moment you add a second machine, a VPS, or throwaway workers, you need to know which agents are alive and who is allowed to join, without handing your memory to the cloud. Queen coordinates all of that and never reads your memory content. Coming soon.
Do I have to open two laptops to add a device?
No. Approve the new device in the cloud and an existing trusted machine finishes the cryptographic handoff next time it is online. A headless VPS joins with a short-lived token whose only power is to let it in, it cannot read or decrypt anything.
Can I see all my agents in one place?
Yes. A read-only fleet view shows every agent with a derived health state, so an idle-but-fine daemon and a crashed one stop looking identical. It is scoped to your own fleet, nothing more.
Does the cloud hold my credentials or memory?
No. Your orchestrator holds the Deeplake credential; the cloud coordinates identity and presence and stores only encrypted blobs it cannot open. No prompts, no session text, no plaintext keys.
What if I lose a device?
Revoke it and rotate your credential, two clear steps, and it is cut off. Lose every trusted device and the answer is a written re-link path, never a hidden backdoor.
When your AI memory stack spreads across machines and people, who is in control?
One machine is clean: four daemons behind one portal on loopback. Across a fleet the hard questions start, which daemons are alive on which boxes, who can enroll a new device, how an admin sees org-wide ROI, what gets cut off when a laptop is stolen. Queen answers exactly those, and never touches your memory content. Coming soon.
Does the cloud get to see our memory?
No. Queen coordinates identity, presence, and encrypted blobs it cannot decrypt, while your own long-lived orchestrator holds custody of the Deeplake credential. The control plane carries no memory, no prompts, and no plaintext credentials, by design.
How do we add and remove devices safely?
Every agent, even an ephemeral sub-agent, gets its own attributable, revocable identity, brokered by a signing authority against a pinned key. Revoking a device and rotating the credential are two honest, separate steps, written down before they hit a support ticket.
Can leadership see ROI across the whole org?
Yes. A hosted admin surface rolls ROI up per org, per team, and per user, with allocated-versus-measured cost on every line and per-user views gated behind verified identity, so no number is fabricated.
What happens when a machine is stolen?
You revoke that device in Queen and rotate the Deeplake credential, and its access is cut. Recovery, revocation, and escrow are explicit, reversible policy, not improvised in the middle of an incident.