Why this team is building Waldo
Shivansh and Suyash introduce the founders and the personal experience behind the company.
Open founder video ↗Product, technical & vision brief · August 2026
AI can do more work than ever. It should leave you with less to carry—not another layer to supervise. Yet when an agent produces code, research, a plan, or a document, the responsibility does not disappear. You still have to decide whether to trust it, what happens next, who it affects, and what remains unfinished.
We are building Waldo to keep hold of the desired result, coordinate the agents and apps working toward it, bring you in when judgment or permission matters, and preserve what remains until the result is verified or you consciously change what should happen next.
That same relationship should work across the life you actually have: releases and investor follow-ups, appointments and renewals, commitments and health—not as separate assistants that make you reconstruct yourself every time.
How to read this brief: the promise and experience describe the target product relationship. Current product records the latest dated internal evidence presented here. Target architecture explains how we intend to make the relationship durable, governed, and verifiable.
The problem we kept seeing
Shivansh saw this firsthand at Atlan, where he says he built and operated more than 30 production agent instances. Even expert users still had to carry the purpose of each session, move context between tools, catch waiting decisions, and work out whether the original problem was actually solved.
For Suyash, the same pressure showed up while running a design studio and training for an Ironman, with work, commitments, and health spread across tools that never understood how those things affected one another.
Every agent result becomes one more thing to read, trust, decide on, or remember. A finished run does not automatically mean the real problem is solved.
Those decisions land alongside messages, commitments, relationships, routines, health, and everything else that did not quite get finished.
Waldo is being built to understand the person, coordinate the work, and carry the desired result beyond whichever task, tool, or failure happened most recently.
A useful external signal: YC recently described moving from a simple internal agent loop to more than 50 Hermes agents serving individual employees as personal assistants, then building QM because the fleet became difficult to manage. We take that as a sign of what comes next: once agents become useful to each person, someone has to keep identity, context, permissions, and unfinished work coherent across them. Waldo carries that problem back to the individual. Many specialist agents may work for you; Waldo remains the continuing relationship across work and life.
Delegation is itself work: Paras Chopra argues that the value of delegating to an AI must subtract the cost of discovering what to delegate, briefing it, supervising it, recovering from mistakes, and accepting risk. We take this as a product hypothesis, not market proof. It sharpens Waldo's test: reduce the person's total delegation burden, not merely perform more agent steps. See the interface contract.
The belief underneath Waldo: the more work machines can carry out, the more important it becomes to protect the person who must judge it and live with what happens next.
The target product promise
A failed deployment is evidence about one attempted path—not proof of the desired result either way. Waldo must verify whether the real-world result remains unresolved. The Open Loop is Waldo's durable record of what remains unresolved, why it remains unresolved, and where the work should return.
Waldo should keep that responsibility open until the result is supported by evidence, the person accepts it, or the person consciously defers, transfers, changes, or releases it.
Waldo can coordinate implementation, release, communication, and verification. If one deployment fails, it must still check what customers can actually access. The responsibility remains the customer-visible result—not getting a deployment command to succeed.
Waldo can preserve consent and constraints, coordinate scheduling and confirmation, prepare what is needed, and keep following through until the real-world arrangement is clear.
Waldo can preserve commitments, prepare follow-ups, ask before sending, and return when a reply or judgment matters—without making the person hold every next step in working memory.
Honest follow-through: Waldo should surface relevant failures and uncertainty without confusing either with the final outcome. When the result cannot be verified, its status stays indeterminate and the responsibility remains open.
What Waldo is
Waldo carries the context you choose to share: why the work matters, what you have promised, where your boundaries are, which decisions belong to you, and what happened the last time.
With your permission, Waldo keeps the wider understanding of your work and life in view—your calendar, messages, commitments, routines, and health—so it can help you plan the day, follow through, and know what can wait.
You can change models, tools, and devices without rebuilding that relationship from zero. The intelligence underneath Waldo can change. Your history, corrections, permissions, and unfinished work should still belong to you.
Long term: one user-owned Waldo across work, life, devices, and eventually physical forms. Specialist agents, models, and surfaces can change. Waldo keeps your context, permissions, and outcomes coherent so you remain the author of what happens on your behalf.
Waldo Desktop
Waldo Desktop is being designed around two connected spaces. Home will help with your day: briefs, calendars, messages, meeting preparation, commitments, follow-through, and a deliberate Daily Close. Work will coordinate general units of work: Outcomes, Missions, agents, people, workflows, services, artifacts, evidence, and decisions.
They are not separate assistants or identities. Both are designed around the same Waldo relationship and the same Outcome, authority, evidence, and continuity contracts.
One Waldo · many places
These are not separate assistants. Mobile, Kennel, and the agent harness are different parts of one Waldo relationship.
Ask, capture, catch up, plan the day, and handle a quick decision wherever you are. Waldo keeps the work connected to the personal context you choose to share.
Home helps Waldo keep your day coherent. Work gives you room to see how agents, people, workflows, and services advanced an Outcome, inspect the evidence, and make the decisions that remain yours.
Behind both, the harness carries permitted context to the right agent or tool, remembers what it was allowed to do, recovers when something fails, and brings back what changed and what remains.
The broader goal: make agentic help useful without asking people to become agent operators. The surface can change; Waldo should still know where you left off.
Kennel
We are starting on the Mac with people who already use coding agents because this pressure is visible there today. Instead of opening every session and reading every update, you can see what changed, where an agent is stuck, which decision genuinely needs you, and what can wait.
That is the first wedge, not the product limit. Home helps Waldo carry daily context, commitments, and follow-through. Work coordinates general units of work across agents, people, workflows, connected services, and eventually devices. The Island keeps capture, status, and small judgments close; the full desktop opens when the whole chain needs inspection.
When a decision needs more space than a phone can give it, Kennel brings the Outcome, evidence, and underlying execution state together. Agent sessions, runtimes, traces, sandboxes, budgets, and policies remain available in Operator Mode; they support the Outcome rather than becoming the user's primary unit of work.
Every session, decision, artifact, and provider event retains provenance so the person can understand what happened and where to return.
What the work was meant to achieve, what evidence exists, and which human judgment is still missing.
Where work repeatedly stalls, which corrections matter, which workflows reach acceptance, and what the person confirms should change future orchestration.
Target product experience
This is the target cross-surface experience, not a claim of current end-to-end integration. The technical contracts matter underneath it. The experience should remain simple.
Across surfaces: a piece of work might begin as a quick request on your phone. Waldo can send the right parts to specialist agents, keep routine progress out of your way, and open Kennel at the exact decision that needs closer inspection. Once you decide, the work can continue in the background and return to your phone as a result, receipt, or clear next step. You should not have to reconstruct the story at any point.
The interface contract
One product hypothesis we are testing, consistent with Chopra's argument, is that people can respond more easily to a concrete choice than specify a complete brief in advance. Waldo should absorb the work of translating intent, preparing context, and managing agents—then make the next small decision easy without turning presentation into permission.
Tap, swipe, click, speak, or write what matters. Waldo can clarify the desired result without requiring a perfect prompt or orchestration plan.
Present a recommendation, alternatives, uncertainty, and the consequence of waiting. Evidence-linked suggestions remain proposals until the person confirms them.
Provider selection, briefing, retries, reconciliation, and routine progress can stay behind the interface. Authority, cost, risk, evidence, and unresolved consequences cannot.
Progressive disclosure keeps ordinary interaction calm while Operator Mode preserves access to agents, sessions, tools, permissions, traces, and recovery state.
Delegation economics: net value = verified work avoided − discovery − briefing − supervision − recovery − perceived risk. We should measure time to an executor-ready brief, human intervention minutes, correction and recovery cycles, verified completion, and whether people delegate a meaningful responsibility again. If the coordination cost approaches the work avoided, Waldo has not created value.
Current product truth · internal evidence · August 2026
Since May 2026, we have built foundations in Kennel on Mac, Waldo on mobile, and the agent harness underneath them. We use these foundations internally. We do not have external users or revenue yet.
These statements summarize dated internal acceptance records and repository snapshots. They are not independently inspectable from this page; supporting artifacts can be shared with reviewers.
Evidence snapshot · 2026-07-28: Kennel 676ba886 · Docs/agent-console-parity-evidence.md; Waldo mobile ed255869; Waldo backend 8867d8f · docs/foundation/HEY-177-PHASE-HANDOFF.md. Claim boundaries are pinned in waldo-investor-brief-current-product-evidence-2026-07-28.md.
Controlled internal acceptance with Codex covers bounded session discovery, conversation history, processing state, continuing the same task, and archive cleanup.
The mobile app provides foundations for conversation, briefings, permissions, and personal context. The harness provides foundations for durable runs, governed actions, recovery, and delivery.
Production connectors, cross-app search, workflows, artifacts, multi-channel delivery, and the end-to-end governance loop across surfaces are not yet a finished experience.
One whole-product acceptance scenario: real work begins with intent, moves through agents and tools, asks for the right human decision, shows what changed, reaches acceptance, survives a restart, and remains understandable from another Waldo surface. It is a continuous integration proof, not a smaller product or scope boundary.
Watch and read
These are the short companion artifacts for reviewers who want the people, product, and company narrative before going deeper into the system.
Shivansh and Suyash introduce the founders and the personal experience behind the company.
Open founder video ↗See the Mac surface for understanding agent activity, evidence, consequential judgments, accepted outcomes, and what remains open across sessions.
Open product video ↗The product wedge, founder story, market, business model, and long-term physical-AI direction.
What remains yours
That promise has to live in the product model, not only in the language. Context, outcomes, permissions, and history should remain yours even as the intelligence underneath Waldo changes.
Priorities, commitments, boundaries, health and capacity, relationships, routines, corrections, and current Open Loops.
Outcome intent, Work Units, briefs, conversations, handoffs, judgment, evidence, delivery, acceptance, re-entry, and Open Loop disposition.
Explain, preview, approve, edit, undo where possible, audit, correct memory, export, revoke, and delete.
Frontier, open, specialist, local, and future models enter through adapters and compete for the work they are best suited to perform.
The product triangle
Four connected surfaces for quick capture, daily continuity, general work orchestration, consequential judgment, and returning to what remains open.
The agent must feel calm and specific enough that a person can let it closer to work, health, relationships, and consequential choices.
The harness is designed to make every suggestion scoped, attributable, permissioned, recoverable, model-routed, measured, privacy-scoped, and economically viable.
Capture what is on your mind, see a compact status, make a small judgment, or open the exact place that needs more room.
Morning Brief, Catch Up, Today, Meeting Prep, follow-ups, Shelf, insights, and Daily Close keep life and commitments coherent.
Outcomes and Missions organize Work Units across agents, people, workflows, and services, with inspectable evidence, verification, and judgment.
A relationship grounded in the person's current life and work context, able to clarify intent, explain state, propose a handoff, and return to the right surface.
Why all three matter: product without harness depth becomes another dashboard. Harness depth without consumer trust becomes another developer tool. A warm character without useful decisions becomes theatre.
The learning loop
Token counts, session duration, commits, and tool calls can describe activity. They cannot tell us whether the work mattered or whether the person is finished.
Provider events, artifacts, changed files, decisions requested, plans, corrections, and user responses.
A possible habit, recurring blocker, preferred steering move, or unfinished commitment. It remains an inference.
The person accepts, edits, rejects, defers, or releases the candidate. Correction is part of the product.
Waldo briefs the next agent, protects a boundary, proposes a follow-up, or chooses a better workflow.
The agent that cares for you: Waldo is not trying to maximize session completion. It carries the person's commitments, capacity, boundaries, and consequences long enough to help the real outcome move.
Behavioral evidence without scoring
Studying adjacent behavioral-evidence systems strengthened our belief that plans, corrections, tool choices, and outcomes can teach a personal agent how someone works. It also clarified what Waldo should not become.
Patterns should point back to their evidence, accumulate across time, express uncertainty, and help the person re-enter work without reconstructing everything.
Waldo does not turn agent activity into a builder score, productivity grade, admissions signal, or irreversible personality claim. The user can inspect, correct, reject, or release every important interpretation.
The design consequence: behavioral evidence should help the person understand and steer their own agents. It should never become an opaque score produced for someone else. The useful unit is an evidence-linked pattern the user can inspect, correct, and apply.
Target product · technical architecture and authority
The target system is one product, not one giant database. Cross-surface Outcome state and canonical Waldo authority belong to the governed Backend. Local devices enforce operating-system consent and execute only admitted work; provider activity enters as attributable evidence, never automatic authority over memory, acceptance, or future action.
Outcome, Mission, Work Unit, Agent Session, Actor, Artifact, Evidence, Verification, Judgment Request, Authority Grant, Acceptance, Open Loop, Schedule, Presence, and Context Claim will use versioned identifiers and conformance fixtures across TypeScript and Swift.
The governed cloud plane is designed to own Waldo's cross-surface identity, shared Outcome state, authority, acceptance, Open Loops, durable memory, delivery policy, and durable orchestration. A Waldo Coordinator above provider adapters clarifies the Outcome, compiles permitted context, routes Work Units, requests verification, and reconciles what remains; providers execute work without owning Waldo's identity or deciding that an Outcome is closed.
The desktop plane is designed to own local provider observation, process mechanics, its workspace, and a durable local operation ledger. Kennel proposes. The owner Backend admits consequential work, issues exact grants from a current user or policy decision, and records acceptance; it does not make the person's judgment for them. Kennel will present Needs You judgments, re-entry, and Operator Mode inspection while syncing minimized events and receipts rather than indiscriminate local transcripts.
The mobile plane is designed to own device consent, capture, protected local context, notifications, and a clearly stale read-only view when disconnected. The current product has no offline command or authority mode: mobile cannot approve, execute, change canonical truth, or claim completion without Backend admission. Raw health values stay in encrypted device storage or the protected health store; they do not enter agent storage, prompts, logs, traces, archives, or evaluations. Only purpose-bound derived claims may cross into the agent plane.
Models, agents, people, deterministic workflows, connected services, and future machines will advertise typed capabilities, authority requirements, evidence contracts, cost, latency, cancellation, and recovery behavior.
Agent Session, Outcome, Evidence, Verification, Acceptance, Open Loop, and Context Claim must remain separate. The target system must prohibit blanket home-directory crawls, ambient screenshots, global input capture, raw cross-device sync, and authority inferred from memory.
Target architecture · Agent governance
Governance is not separate from the responsibility promise. It is how Waldo can coordinate meaningful action without asking the person to surrender control, privacy, or the final say over what counts as complete.
In our internal work with many agents, we found that starting them is not the hardest part. The hard part is deciding what they may see, what they may change, whether they acted once, what actually became true, and what still belongs to the person. See the current-evidence boundary.
Waldo is being designed as the owner-side governance layer between a person's intent and every model, agent, tool, service, or future machine working on their behalf. Providers can propose and execute. They do not get to grant themselves authority, rewrite personal truth, or decide that the person's Outcome is closed.
Consequential action path. Read, preparation, and provider work can run inside an admitted Work Unit. When an action could change the person's world, the exact authority gate applies.
Kennel, mobile, voice, or another harness asks Waldo to do something.
The owner and presence are authenticated. Untrusted requests cannot approve themselves.
The actor receives the smallest purpose-bound view required for this Outcome.
The exact action is recorded before it runs. Capabilities, credentials, budget, network access, cancellation, and recovery stay governed.
Receipts and evidence are inputs, not proof by themselves. Waldo uses read-back or a declared check; without trustworthy verification, the result stays indeterminate.
Accept, repair, reopen, defer, transfer, or release what remains—with an exact return point.
A surface can propose work; the authenticated owner-side Backend admits it. Disconnected surfaces cannot command, approve, or claim progress.
Context is compiled for a declared purpose, audience, destination, source, and expiry. The person's whole life never enters every prompt.
Past approval and remembered preference are history, not permission. Consequential action requires a current, exact, revocable grant; delegation can narrow authority, never widen it.
Versions are pinned, capabilities are admitted, and credentials stay outside model-visible context. If an action times out, Waldo checks what happened before retrying; budgets, cancellation, and containment remain enforceable.
A receipt is not proof and proof is not closure. Missing trustworthy verification remains indeterminate; it never becomes a silent pass.
The target design gives the owner inspection, correction, provider replacement, revocation, export, and deletion—with restore rules that do not resurrect deleted context.
Current truth: the pinned evidence snapshot above shows foundations in the durable harness, typed tools, permissions, recovery, delivery, and Kennel's local operation record; supporting acceptance records can be shared with reviewers. The complete cross-surface governance loop above is the target architecture, not a claim that it has already shipped end to end.
The agent platform
These are the platform responsibilities Waldo keeps first-party even when providers, transports, tools, and interfaces change.
Layered, purpose-bound compilation with just-in-time tools, selected personal context, evidence, and progressive compaction—never the person's whole life in every prompt.
Typed tools, reviewable skills, explicit blast radius, per-purpose permissions, previews, approvals, and recoverable failure.
Typed, provenance-bearing, inspectable, correctable memory written through a gate so a model cannot silently rewrite personal truth.
KAIROS lets user intent, schedules, events, unresolved consequences, and changing context wake Waldo. Its tick-and-decide gate keeps the agent quiet when nothing deserves attention.
Versioned artifacts, receipts, verification, exact Judgment Requests, authorized acceptance, and explicit Open Loop disposition challenge every actor's completion claim. Generation alone never counts as independent verification; a declared semantic grader must disclose its model, method, evidence, and limits.
Capacity, health, calendar, commitments, relationships, routines, and boundaries shape what a good plan means for this person now.
Channel-native cards, conversation, desktop presence, and selective notification ordered by consequence and timing—not engagement.
Shared Outcome identifiers, exact re-entry points, cross-surface presence, durable dispositions, and continuity that survives dates, model changes, handoffs, restarts, and deliberate rest.
Tools, skills, and transports are different: a tool is a typed capability; a skill is a reviewable way of using capabilities; MCP and provider APIs transport them. None of these grants authority. Waldo keeps context, permission, memory, evidence, and outcome policy first-party.
Technical depth
Runtime, routing, evaluation, memory, privacy, permissions, and cost are product decisions. They determine whether an always-present agent can be useful without becoming careless, expensive, or impossible to trust.
Models can propose. Code owns authentication, validation, permissions, idempotency, state transitions, and audit. A prompt is never a security boundary.
Provider activity, outcome evidence, personal memory, and human closure have explicit owners. A projection or cache cannot silently become authority.
A remembered approval is information about the past. Every new action still needs a current, purpose-bound grant.
Models, providers, tools, and surfaces enter through typed capabilities. The surrounding personal-agent contract stays stable when any one of them changes.
Long work needs journals, replay, idempotency, bounded retries, and explicit failure states before it earns broader authority.
Compile only what the declared outcome requires. Personal context remains permissioned, purpose-bound, correctable, and removable.
The durable personal-agent loop
flowchart TB
subgraph UNDERSTAND["1 · Understand"]
direction LR
T["Trigger or user intent"] --> O["Outcome<br/>intent + constraints + acceptance policy"]
O --> W["Work Unit plan<br/>agents + people + workflows"]
W --> C["Context compiler<br/>purpose + permitted context"]
end
subgraph ACT["2 · Act safely"]
direction LR
M["Selected actor or provider"] --> D["Typed capability dispatcher"]
D --> G{"Permission + policy gates"}
G -->|allowed| E["Artifact, effect, receipt<br/>+ durable evidence"]
G -->|needs judgment| H["Needs You<br/>exact Judgment Request"]
H -->|approved grant| E
end
subgraph LEARN["3 · Learn with the user"]
direction LR
V["Independent Verification"] --> A["Authorized Acceptance"]
A --> L["Open Loop disposition<br/>close, defer, reopen, release"]
L --> R["Correctable memory + exact re-entry"]
end
C --> M
E --> V
R -. "next useful action" .-> C
Context is compiled from typed layers, not written as one giant prompt. REASONS is the anatomy: a provider-shaped working brief assembled for the intended outcome using only the personal context, tools, evidence, and safeguards that purpose requires.
Why compile instead of append: a personal agent may know a great deal, but useful context is not maximal context. Compilation controls relevance, privacy, latency, cost, and the chance that old information distorts the current job.
The five-layer design separates short-lived task context from durable personal truth. The important idea is not a particular database: every layer has a purpose, provenance, lifecycle, correction path, and authority limit.
Memory tiers · from working context to user-owned archive
flowchart TB
T0["Layer 0 · Working context<br/>volatile, task-bounded, rebuilt"]
T1["Layer 1 · Typed personal memory<br/>facts, events, discoveries, preferences, advice"]
T2["Layer 2 · Episodes and evidence<br/>attributable sessions, corrections, outcomes"]
T3["Layer 3 · Skills and procedures<br/>reviewable ways of working"]
T4["Layer 4 · Archive and export<br/>history, deletion, recovery, portability"]
T4 --> T3 --> T2 --> T1 --> T0
T0 -. "new evidence, never direct truth" .-> T2
T2 -. "candidate claim" .-> T1
T1 -. "user correction or release" .-> T2
Observations enter a memory inbox. A governed write path promotes them only with provenance, scope, confidence, correction, reversibility, expiry, and deletion.
Background reflection can connect episodes, surface recurring patterns, decay stale confidence, and propose memory changes. The person keeps the right to inspect, correct, release, export, or delete them.
Memory records when something was true and when Waldo learned it. Retrieval fuses relevance, recency, confidence, and the current purpose instead of treating every old fact equally.
Security is a sequence of independent refusals. Seeing evidence, inferring a habit, remembering a preference, or receiving provider completion never grants permission to act.
Defense in depth · enduring contract
flowchart LR
I["Verified identity"] --> P["Fresh purpose-bound permission"]
P --> A["Capability allowlist"]
A --> T["Untrusted-input and taint checks"]
T --> Z["Schema validation + sanitization"]
Z --> X["Human approval for consequential action"]
X --> V["Evidence and output verification"]
V --> J["Attributable journal + audit"]
J --> R["Revocation, correction, deletion"]
Historical information only.
Requires a current grant for this purpose and capability.
Recorded without silently closing the human loop.
The security principle: identity, permission, capability, input trust, approval, evidence, and audit are separate gates. Passing one never implies another, and a prompt is never a security boundary.
Owned orchestration intelligence
Waldo does not need to replace foundation models. It can become the intelligence that decides when to stay quiet, what context is required, which model or tool fits, what permission is needed, how success should be judged, and what the next agent should inherit.
The user-owned learning flywheel
flowchart TB
C["Consented context<br/>intent + commitments + capacity + memory"] --> P["Waldo brief or proposal"]
P --> U["User steers<br/>approve, edit, reject, defer, correct"]
U --> A["Agent or tool acts"]
A --> E["Outcome evidence"]
E --> J["Human judgment<br/>close, reopen, transfer, release"]
J --> M["Correctable memory + Open Loops"]
M --> C
E --> R["Routing and workflow insight"]
R --> P
The durable history is not raw prompt volume. It is what the person intended, allowed, changed, verified, and consciously left open.
Outcome history teaches Waldo when not to interrupt, which model or skill fits, which evidence matters, and where a human judgment belongs.
Models and surfaces can change without forcing the user to surrender their memory, permissions, preferences, or accumulated ways of working.
From model access to a Waldo intelligence gateway
flowchart LR
I["Intent + permitted context"] --> W["Waldo Intelligence Gateway"]
W --> Q{"Quality, privacy,<br/>latency, cost, tools"}
Q --> F["Frontier reasoning"]
Q --> O["Open or local model"]
Q --> S["Specialist model or skill"]
F --> V["Evidence + outcome review"]
O --> V
S --> V
V --> W
W --> N["Better next orchestration"]
Use replaceable model and tool adapters rather than binding the person's agent identity to one provider.
Capture intent, route, permission, evidence, correction, cost, and outcome—not surveillance for its own sake.
Improve task classification, action timing, context selection, workflow choice, and route quality from consented outcomes.
Where outside models remain weak, Waldo can develop specialized orchestration intelligence while continuing to use the best external capability.
Economics is part of the product: skip first, route second, escalate last. An always-present agent stays viable by resolving routine cases deterministically, choosing the cheapest sufficient capability, and spending frontier intelligence only where the outcome justifies it.
Trust and ownership
Model providers will keep getting better. We want that intelligence to compete for the work it does best. The lasting part should be the relationship you own: your context, corrections, permissions, outcomes, and the ability to inspect, edit, export, revoke, or delete them.
Here, user-owned means meaningful control and portability. It does not claim that Waldo or its infrastructure operators are already cryptographically unable to access every data class; that stronger promise requires a proven user-held-key and recovery design.
Read permitted context, explain what matters, show uncertainty, and do nothing by default.
Offer a concrete next move, preparation brief, recovery adjustment, re-entry point, or agent workflow.
Preview the plan and blast radius, request a purpose-bound grant, and let the person edit, defer, or refuse.
Repeated success may justify proposing a bounded standing policy. Behavior never expands its own authority; every consequential effect still needs current policy admission, a valid grant, clear audit, revocation, and a reliable exception path.
Memory is not permission: something Waldo learned yesterday does not authorize it to act today. Consequential actions should remain specific, visible, and reversible wherever possible.
Care and attention
Waldo should not make you supervise more software, monitor more behavior, or stay permanently available. It should carry routine responsibility quietly and interrupt you only when the timing, consequence, or authority genuinely belongs to you.
Filter drafts, collapse duplicates, resolve reversible cases within policy, batch non-urgent choices, and reserve interruption for decisions whose consequence or authority belongs to the person.
Every Outcome can define sufficient evidence, acceptable quality, time and cost limits, and valid dispositions such as accept, defer, transfer, reopen, or consciously release.
Explicit boundaries, calendar load, rest, and permissioned health context can shape timing and plans. Waldo must not infer laziness, morality, personality, or commitment from behavioral or body traces.
Record what became true, what is waiting, what was released, and the exact next re-entry point so rest does not require keeping every obligation alive in working memory.
The product test: can you hand Waldo a meaningful recurring responsibility and have fewer things that must stay alive in your head? Sometimes the right outcome is done. Sometimes it is deferred, transferred, changed, or consciously released. Waldo should preserve the truth in every case.
The people building Waldo
As the founders tell it, Shivansh and Ashish became friends at school over iOS jailbreaking. Years later, Shivansh met Suyash in the Computer Center at IIITDM Jabalpur and showed him how to build a website by describing it to an AI coding tool. Waldo is the first company the three are building together. The experience and work history below come from the founders and their supporting records.
Founder · engineering and architecture
His work at Atlan showed Shivansh exactly where capable agents still leave intent, context, follow-up, and judgment to the person. His earlier work spans Project EKA's data pipeline, OpenFn/C4GT, native apps, and independent model implementation.
Founder · product, experience and brand
Suyash brings the part technical agent products often miss: what makes powerful software understandable and worth keeping around. Through SAPIEN and his product and brand work, he has learned how to turn complex systems into experiences people can trust.
Founding Engineer
Before Waldo, Ashish spent nine months working as an AI engineer. He built much of Waldo's first app and health-data pipeline, validated Health Connect on real Android hardware, and now works across native iOS, Supabase, and agent infrastructure.
The product triangle: engineering makes the system dependable; product taste makes truth and control understandable; the consumer relationship makes the technology worth keeping around.
The physical world
We do not think personal agents will remain inside chat windows forever. Over time, the same Waldo could meet you through a desk object, wearable, home device, vehicle, or small robot instead of giving every object a separate assistant with its own memory and agenda.
Maintenance, field service, inspections, contractor coordination, equipment repair, and acceptance can combine AI preparation with accountable human execution and real-world evidence.
Sensors, wearables, home devices, equipment, and vehicles enter through capability manifests that declare identity, location, telemetry, required authority, failure behavior, and observable completion.
Every physical effect must declare safety class, preconditions, permitted action, live state, abort path, human handoff, reversibility or recovery, telemetry, evidence, and acceptance authority.
Why software first: memory, permission, evidence, interruption, and recovery must work before a personal agent is trusted with sensors, movement, or physical authority. This is not a current Waldo hardware program. The form may change. The person it works for should not.
Waldo is the company
Waldo is being built to carry the context you choose to share across work and life, coordinate the agents and tools working for you, bring you in when judgment matters, and keep the desired result open until reality supports closure or you consciously choose another disposition.
Kennel is Waldo's first home on the Mac and its first market wedge—not the company. Over time, the same Waldo can meet you through mobile, messaging, voice, connected services, and eventually physical forms. The surface changes; the relationship, memory, permissions, and loyalty to the person do not.
Meet WaldoPublic anchors
Product insight: Paras Chopra on the delegation tax and cognitively simple agent interfaces. Waldo's adaptation is simple interaction with visible responsibility.