Product, technical & vision brief · August 2026

AI can generate infinite work. Judgment decides what should become real.

Waldo is being built as the user-owned personal agent that remains on your side—carrying context, commitments, and consequences so you do not have to supervise everything yourself. Its first urgent job is protecting human judgment as AI output multiplies: coordinating models, tools, workflows, people, and eventually machines; asking for consequential judgment and authority at the right moment; preserving attributable evidence; carrying each Outcome until the person accepts it; and keeping any remaining Open Loops visible until the person resolves, defers, transfers, or consciously releases them. Kennel is the current Mac wedge and working foundation.

Judgment → accepted outcomes One agent · many presences General units of work Exact authority · durable evidence Attention and capacity protected

Three shifts · one product

Generation is abundant. Attention, judgment, and accountable control are scarce.

Waldo is being built between human intent and increasingly autonomous actors. The product goal is to reduce what a person must review, preserve what they should not have to remember, and keep authority legible as action moves from software into the physical world.

Launch wedge

The judgment layer

Agents create more drafts, plans, research, code, and alternatives than people can responsibly review. Waldo is designed to turn output into evidence-backed decisions and accepted outcomes instead of another queue.

Product responsibility

The burnout economy

Always-on software should not make people permanently available. Waldo should protect attention, batch judgment, respect capacity, preserve re-entry, and treat “enough,” deferral, and conscious release as valid outcomes.

Expansion frontier

The physical world

The same governed Work Unit can eventually coordinate a person, connected device, trade professional, machine, or robot—provided identity, safety, authority, telemetry, abort, evidence, and acceptance remain explicit.

Why this team believes it: Shivansh reports building more than 30 production agent instances at Atlan and watching expert users carry purpose, context, blockers, and outcome judgment themselves. Suyash experienced the collision of a design studio, Ironman training, and fragmented work and health tools. Waldo began with health, learned that insight without action becomes another dashboard, and now treats health as protected capacity context inside a broader outcome system.

Watch and read

Meet the founders, see Kennel, then open the company story.

These are the short companion artifacts for reviewers who want the people, product, and company narrative before going deeper into the system.

Founder video

Why this team is building Waldo

Shivansh and Suyash introduce the founders and the personal experience behind the company.

Open founder video ↗
Product video

Waldo through Kennel

See the Mac surface for understanding agent activity, evidence, consequential judgments, accepted outcomes, and what remains open across sessions.

Open product video ↗
Pitch deck

Waldo company overview

The product wedge, founder story, market, business model, and long-term physical-AI direction.

Target Outcome loop

Waldo is designed to carry work from intent to evidence, judgment, acceptance, and re-entry.

This is the target cross-surface experience, not a claim of current end-to-end integration. A coding session may be one Work Unit. So may research, a document workflow, a human review, a message, a booking, or a physical inspection. None of them is the Outcome by itself.

1 · IntentName the OutcomeState what should become true, the constraints, acceptance checks, and who may judge them.
2 · PlanCompose Work UnitsWaldo assigns bounded contributions to the right agent, person, tool, or deterministic workflow.
3 · ActGrant exact authorityEach consequential effect receives a current, purpose-bound permission with a visible destination and blast radius.
4 · ProveArtifact, receipt, evidenceProvider completion can produce attributable evidence. A separate verifier or acceptance check determines whether the intended result is satisfied.
5 · JudgeNeeds You, only when neededWaldo presents the recommendation, alternatives, uncertainty, reversibility, and exact decision.
6 · ContinueAccept, defer, reopen, releaseThe Outcome and remaining Open Loops survive devices, sessions, restarts, and the next day.

The point: Waldo should reduce supervision, not merely move it. The person sees a compact decision packet—not every draft—with the recommendation, material alternatives, evidence, contradiction, uncertainty, reversibility, and consequence of acting or waiting.

One agent · many presences

There is one Waldo for the person. Every surface is a different way to reach the same agent.

Models, interfaces, and devices will change. The person's identity, continuity, permission policy, corrections, and right to judge closure should remain durable.

Kennel

The judgment presence

The reviewed direction is a native Mac working home for Outcomes, Needs You, evidence, authority, acceptance, re-entry, and an Operator Mode for the underlying sessions and workflows.

Waldo mobile

The everywhere presence

The mobile role is conversation, capture, briefings, meetings, notifications, lightweight judgment and Outcome continuity, and protected device context when the person is away from the Mac.

Waldo Core

The durable nervous system

The Backend role is shared Outcome state, Work Unit orchestration, memory, schedules, connectors, policy, delivery, recovery, evidence, verification, and cross-surface continuity.

One personal identity across changing surfaces

mindmap
  root((Waldo<br/>one agent for one person))
    Context
      Priorities and commitments
      Boundaries and corrections
      Capacity and health
      Relationships and routines
    Software presences
      Kennel on Mac
      Waldo on mobile
      Browser and messaging
    Intelligence fabric
      Coding agents
      General and specialist models
      Tools and skills
    Durable core
      Memory and provenance
      Permission policy
      Outcomes and Work Units
      Evidence and acceptance
      Open Loop continuity
    Physical actors
      People and trades
      Devices and machines
      Robots under one policy
          

Capability boundary · internal evidence · August 2026

Foundation, next proof, and expansion are different claims.

Research gives Waldo a capability library and architecture direction. It does not make an integration live. The build statements below summarize dated internal acceptance records and repository snapshots that are not independently inspectable from this public page; supporting artifacts can be shared with reviewers. We track useful capability from missing to foundation, partial, live, verified, and finally coherent across the product.

Working foundations

Three real pieces, not yet one complete loop

Internal acceptance records—not independently available from this page—cover bounded live Codex session discovery, conversation history, real-time processing state, same-task continuation, first-message handling, and archive cleanup in Kennel. Internal repository snapshots show durable run, typed-tool, permission, scheduling, delivery, recovery, and audit foundations in the harness, plus native personal and health-context foundations in the earlier mobile app.

Next product proof

One accepted cross-surface Outcome

One shared Outcome and Work Unit contract across Backend, Kennel, and mobile; approved source retrieval; a versioned artifact; an exact Judgment Request and authority grant; real delivery and receipt; independent verification; authorized acceptance plus explicit disposition of any remaining Open Loops; and next-day re-entry.

Sequenced expansion

Parity → coherence → compounding advantage

Deep Google Workspace integration, messaging, schedules, browser and computer action, documents and artifacts, Skills, specialist actors, CRM and social work, voice and calls, physical actors, and enterprise controls—added behind the same Outcome, authority, evidence, and continuity contracts.

The first acceptance gate: the same Outcome identifier must survive intent, heterogeneous Work Units, artifact creation, exact approval, external effect, provider receipt, independent verification, human acceptance, unresolved-loop disposition, restart recovery, and cross-surface re-entry. Until then, broad integration remains direction rather than shipped coherence.

Kennel

The Mac working home for what matters, what needs judgment, and what became true.

Kennel begins with coding agents because the coordination problem is already painful and observable there. The product model makes the durable object a general Outcome, so the same surface can govern research, documents, communication, human work, workflows, and future physical effects.

1. What matters nowOutcomes ordered by consequence, timing, dependency, and the person's explicit priorities—not engagement.
2. Needs YouConsequential judgments packaged with recommendation, alternatives, evidence, uncertainty, reversibility, and exact authority.
3. What became trueArtifacts, external effects, receipts, verification, acceptance, and consequences shown without equating provider completion with success.
4. What remainsWaiting, blocked, deferred, transferred, reopened, or consciously released Open Loops with an exact re-entry point.
5. Operator ModeProgressive access to the sessions, actors, tools, workflows, traces, costs, permissions, and recovery state underneath each Work Unit.
Supervision

Truthful state

Every session, decision, artifact, and provider event retains provenance so the person can understand what happened and where to return.

Judgment

Reviewable outcomes

What the work was meant to achieve, what evidence exists, and which human judgment is still missing.

Insight

Correctable continuity

Where work repeatedly stalls, which corrections matter, which workflows reach acceptance, and what the person confirms should change future orchestration.

What Waldo owns

Waldo rents model intelligence, but owns the relationship between a person and the actors working for them.

The bet is not that one model, tool, interface, or machine wins forever. The durable layer is where changing capabilities become useful for one specific person without taking ownership away from them.

Own

Context

Priorities, commitments, boundaries, health and capacity, relationships, routines, corrections, and current Open Loops.

Own

Outcomes and continuity

Outcome intent, Work Units, briefs, conversations, handoffs, judgment, evidence, delivery, acceptance, re-entry, and Open Loop disposition.

Own

Trust

Explain, preview, approve, edit, undo where possible, audit, correct memory, export, revoke, and delete.

Rent and route

Models

Frontier, open, specialist, local, and future models enter through adapters and compete for the work they are best suited to perform.

The product triangle

Product, consumer trust, and technical depth have to compound together.

Product

Brief, Chat, Handoff, Patrol

Simple surfaces for understanding the day, asking for help, handing off work, supervising exceptions, and returning to what remains open.

Consumer

Taste, habit, emotion, safety

The agent must feel calm and specific enough that a person can let it closer to work, health, relationships, and consequential choices.

Technical

Runtime, router, memory, evals

The harness makes every suggestion scoped, attributable, permissioned, recoverable, model-routed, measured, private, and economically viable.

Brief

What matters now

A calm synthesis of capacity, commitments, consequences, and the decisions that deserve attention.

Chat

Think with Waldo

A conversation grounded in the person's current life and work context, not a blank thread.

Handoff

Delegate with control

A reviewable plan that states the goal, context, tools, limits, evidence contract, and permission required.

Patrol

Supervise exceptions

Continuous awareness of agent work that stays quiet until a decision, risk, or unresolved consequence needs the person.

Why all three matter: product without harness depth becomes another dashboard. Harness depth without consumer trust becomes another developer tool. A warm character without useful decisions becomes theatre.

The learning loop

Waldo should learn from steering and verified outcomes, not from activity volume.

Token counts, session duration, commits, and tool calls can describe activity. They cannot tell us whether the work mattered or whether the person is finished.

Observed

Evidence

Provider events, artifacts, changed files, decisions requested, plans, corrections, and user responses.

Inferred

Candidate pattern

A possible habit, recurring blocker, preferred steering move, or unfinished commitment. It remains an inference.

Confirmed

User-owned truth

The person accepts, edits, rejects, defers, or releases the candidate. Correction is part of the product.

Applied

Better future work

Waldo briefs the next agent, protects a boundary, proposes a follow-up, or chooses a better workflow.

The agent that cares for you: Waldo is not trying to maximize session completion. It carries the person's commitments, capacity, boundaries, and consequences long enough to help the real outcome move.

Behavioral evidence without scoring

Agent traces can reveal useful patterns, but the product must belong to the person being interpreted.

Studying adjacent behavioral-evidence systems strengthened our belief that plans, corrections, tool choices, and outcomes can teach a personal agent how someone works. It also clarified what Waldo should not become.

What we carry forward

Evidence-linked, longitudinal help

Patterns should point back to their evidence, accumulate across time, express uncertainty, and help the person re-enter work without reconstructing everything.

What we reject

Opaque scoring or external judgment

Waldo does not turn agent activity into a builder score, productivity grade, admissions signal, or irreversible personality claim. The user can inspect, correct, reject, or release every important interpretation.

The design consequence: behavioral evidence should help the person understand and steer their own agents. It should never become an opaque score produced for someone else. The useful unit is an evidence-linked pattern the user can inspect, correct, and apply.

Target architecture and authority

A hybrid system keeps each truth with one authority while sharing the Outcome across every presence.

The target system is one product, not one giant database. Cross-surface Outcome state belongs to the governed Backend; local Mac and mobile effects retain local authority; provider activity enters as attributable evidence, never automatic authority over memory, acceptance, or future action.

Shared contracts

Outcome, Work Unit, Actor, Artifact, Evidence, Verification, Judgment Request, Authority Grant, Acceptance, Open Loop, Schedule, Presence, and Context Claim will use versioned identifiers and conformance fixtures across TypeScript and Swift.

Waldo Backend and harness

The governed cloud plane is designed to own shared Outcome state, durable runs, Work Unit orchestration, schedules, cloud connectors, policy, delivery, recovery, artifact versions, evidence events, and cross-surface presence.

Kennel on Mac

The desktop plane is designed to be authoritative for local provider observation, local action grants, and its durable local projection. It will mediate and record the person's Needs You judgments, acceptance, re-entry, and Operator Mode inspection while syncing minimized events and receipts rather than indiscriminate local transcripts.

Waldo mobile

The mobile plane is designed to be authoritative for device consent, capture, protected local context, notifications, and offline actions. It will mediate and record lightweight user judgment without becoming the judgment authority. The target privacy invariant is that raw health and other sensitive device data must remain local by default; only purpose-bound claims or snapshots may leave the device.

Provider and actor adapters

Models, agents, people, deterministic workflows, connected services, and future machines will advertise typed capabilities, authority requirements, evidence contracts, cost, latency, cancellation, and recovery behavior.

Truth and privacy boundaries

Agent Session, Outcome, Evidence, Verification, Acceptance, Open Loop, and Context Claim must remain separate. The target system must prohibit blanket home-directory crawls, ambient screenshots, global input capture, raw cross-device sync, and authority inferred from memory.

The agent platform

Every serious personal agent must solve eight problems beyond calling a model.

These are the platform responsibilities Waldo keeps first-party even when providers, transports, tools, and interfaces change.

Context

What enters intelligence

Layered, purpose-bound compilation with just-in-time tools, selected personal context, evidence, and progressive compaction—never the person's whole life in every prompt.

Action

What can change the world

Typed tools, reviewable skills, explicit blast radius, per-purpose permissions, previews, approvals, and recoverable failure.

Memory

What survives

Typed, provenance-bearing, inspectable, correctable memory written through a gate so a model cannot silently rewrite personal truth.

Initiation

What wakes the agent

KAIROS lets user intent, schedules, events, unresolved consequences, and changing context wake Waldo. Its tick-and-decide gate keeps the agent quiet when nothing deserves attention.

Outcome + judgment

What counts as done

Versioned artifacts, receipts, independent verification, exact Judgment Requests, authorized acceptance, and explicit Open Loop disposition challenge every actor's completion claim. Generation never grades itself.

Life intelligence

What makes help realistic

Capacity, health, calendar, commitments, relationships, routines, and boundaries shape what a good plan means for this person now.

Delivery

How help reaches the person

Channel-native cards, conversation, desktop presence, and selective notification ordered by consequence and timing—not engagement.

Continuity

How responsibility survives

Shared Outcome identifiers, exact re-entry points, cross-surface presence, durable dispositions, and continuity that survives dates, model changes, handoffs, restarts, and deliberate rest.

Tools, skills, and transports are different: a tool is a typed capability; a skill is a reviewable way of using capabilities; MCP and provider APIs transport them. None of these grants authority. Waldo keeps context, permission, memory, evidence, and outcome policy first-party.

Technical depth

The harness is the contract between a probabilistic model and the real world.

Runtime, routing, evaluation, memory, privacy, permissions, and cost are product decisions. They determine whether an always-present agent can be useful without becoming careless, expensive, or impossible to trust.

Principle 01

Deterministic seams

Models can propose. Code owns authentication, validation, permissions, idempotency, state transitions, and audit. A prompt is never a security boundary.

Principle 02

One writer per truth

Provider activity, outcome evidence, personal memory, and human closure have explicit owners. A projection or cache cannot silently become authority.

Principle 03

Memory never authorizes

A remembered approval is information about the past. Every new action still needs a current, purpose-bound grant.

Principle 04

Contract-first adapters

Models, providers, tools, and surfaces enter through typed capabilities. The surrounding personal-agent contract stays stable when any one of them changes.

Principle 05

Durability before autonomy

Long work needs journals, replay, idempotency, bounded retries, and explicit failure states before it earns broader authority.

Principle 06

Required context, not maximal context

Compile only what the declared outcome requires. Personal context remains permissioned, purpose-bound, correctable, and removable.

The durable personal-agent loop

flowchart TB
  subgraph UNDERSTAND["1 · Understand"]
    direction LR
    T["Trigger or user intent"] --> O["Outcome<br/>intent + constraints + acceptance policy"]
    O --> W["Work Unit plan<br/>agents + people + workflows"]
    W --> C["Context compiler<br/>purpose + permitted context"]
  end
  subgraph ACT["2 · Act safely"]
    direction LR
    M["Selected actor or provider"] --> D["Typed capability dispatcher"]
    D --> G{"Permission + policy gates"}
    G -->|allowed| E["Artifact, effect, receipt<br/>+ durable evidence"]
    G -->|needs judgment| H["Needs You<br/>exact Judgment Request"]
    H -->|approved grant| E
  end
  subgraph LEARN["3 · Learn with the user"]
    direction LR
    V["Independent Verification"] --> A["Authorized Acceptance"]
    A --> L["Open Loop disposition<br/>close, defer, reopen, release"]
    L --> R["Correctable memory + exact re-entry"]
  end
  C --> M
  E --> V
  R -. "next useful action" .-> C
          
The compiled prompt — REASONS anatomy

Context is compiled from typed layers, not written as one giant prompt. REASONS is the anatomy: a provider-shaped working brief assembled for the intended outcome using only the personal context, tools, evidence, and safeguards that purpose requires.

RRequirementsThe trigger, intended outcome, constraints, and definition of done.
EEntitiesThe people, artifacts, commitments, and permitted personal context involved.
AApproachThe selected workflow or skill and why it fits this task.
SStructureAvailable tools, channel, evidence contract, and output shape.
OOperationsThe ordered steps, prior evidence, and explicit handoffs.
NNormsVoice, user preferences, correction history, and interaction boundaries.
SSafeguardsPermission, privacy, safety, and failure rules enforced outside the prompt.

Why compile instead of append: a personal agent may know a great deal, but useful context is not maximal context. Compilation controls relevance, privacy, latency, cost, and the chance that old information distorts the current job.

Five-layer memory — user-owned continuity

The five-layer design separates short-lived task context from durable personal truth. The important idea is not a particular database: every layer has a purpose, provenance, lifecycle, correction path, and authority limit.

Memory tiers · from working context to user-owned archive

flowchart TB
  T0["Layer 0 · Working context<br/>volatile, task-bounded, rebuilt"]
  T1["Layer 1 · Typed personal memory<br/>facts, events, discoveries, preferences, advice"]
  T2["Layer 2 · Episodes and evidence<br/>attributable sessions, corrections, outcomes"]
  T3["Layer 3 · Skills and procedures<br/>reviewable ways of working"]
  T4["Layer 4 · Archive and export<br/>history, deletion, recovery, portability"]
  T4 --> T3 --> T2 --> T1 --> T0
  T0 -. "new evidence, never direct truth" .-> T2
  T2 -. "candidate claim" .-> T1
  T1 -. "user correction or release" .-> T2
              
Scribe

Staged, evidence-linked memory

Observations enter a memory inbox. A governed write path promotes them only with provenance, scope, confidence, correction, reversibility, expiry, and deletion.

Reflection

Patterns without silent truth

Background reflection can connect episodes, surface recurring patterns, decay stale confidence, and propose memory changes. The person keeps the right to inspect, correct, release, export, or delete them.

Time and retrieval

History without rewriting it

Memory records when something was true and when Waldo learned it. Retrieval fuses relevance, recency, confidence, and the current purpose instead of treating every old fact equally.

Security — authority is enforced at every seam

Security is a sequence of independent refusals. Seeing evidence, inferring a habit, remembering a preference, or receiving provider completion never grants permission to act.

Defense in depth · enduring contract

flowchart LR
  I["Verified identity"] --> P["Fresh purpose-bound permission"]
  P --> A["Capability allowlist"]
  A --> T["Untrusted-input and taint checks"]
  T --> Z["Schema validation + sanitization"]
  Z --> X["Human approval for consequential action"]
  X --> V["Evidence and output verification"]
  V --> J["Attributable journal + audit"]
  J --> R["Revocation, correction, deletion"]
              
Memory

“The user approved this before.”

Historical information only.

Authority

“This action is allowed now.”

Requires a current grant for this purpose and capability.

Evidence

“Here is what actually happened.”

Recorded without silently closing the human loop.

The security principle: identity, permission, capability, input trust, approval, evidence, and audit are separate gates. Passing one never implies another, and a prompt is never a security boundary.

Owned orchestration intelligence

Models get better for everyone. Waldo gets better at helping one person.

Waldo does not need to replace foundation models. It can become the intelligence that decides when to stay quiet, what context is required, which model or tool fits, what permission is needed, how success should be judged, and what the next agent should inherit.

The user-owned learning flywheel

flowchart TB
  C["Consented context<br/>intent + commitments + capacity + memory"] --> P["Waldo brief or proposal"]
  P --> U["User steers<br/>approve, edit, reject, defer, correct"]
  U --> A["Agent or tool acts"]
  A --> E["Outcome evidence"]
  E --> J["Human judgment<br/>close, reopen, transfer, release"]
  J --> M["Correctable memory + Open Loops"]
  M --> C
  E --> R["Routing and workflow insight"]
  R --> P
          
What compounds

Intended, permitted, corrected

The durable history is not raw prompt volume. It is what the person intended, allowed, changed, verified, and consciously left open.

What improves

Timing, routing, and workflow

Outcome history teaches Waldo when not to interrupt, which model or skill fits, which evidence matters, and where a human judgment belongs.

What stays owned

The person's continuity

Models and surfaces can change without forcing the user to surrender their memory, permissions, preferences, or accumulated ways of working.

From model access to a Waldo intelligence gateway

flowchart LR
  I["Intent + permitted context"] --> W["Waldo Intelligence Gateway"]
  W --> Q{"Quality, privacy,<br/>latency, cost, tools"}
  Q --> F["Frontier reasoning"]
  Q --> O["Open or local model"]
  Q --> S["Specialist model or skill"]
  F --> V["Evidence + outcome review"]
  O --> V
  S --> V
  V --> W
  W --> N["Better next orchestration"]
          
01

Route broadly

Use replaceable model and tool adapters rather than binding the person's agent identity to one provider.

02

Trace meaningfully

Capture intent, route, permission, evidence, correction, cost, and outcome—not surveillance for its own sake.

03

Learn policy

Improve task classification, action timing, context selection, workflow choice, and route quality from consented outcomes.

04

Specialize later

Where outside models remain weak, Waldo can develop specialized orchestration intelligence while continuing to use the best external capability.

Economics is part of the product: skip first, route second, escalate last. An always-present agent stays viable by resolving routine cases deterministically, choosing the cheapest sufficient capability, and spending frontier intelligence only where the outcome justifies it.

The trust ladder

Authority is earned per action, not granted globally.

Waldo expands from understanding to action through visible usefulness, task-specific permission, evidence, reversibility, and repeated user-confirmed success.

Stage 1

Observe

Read permitted context, explain what matters, show uncertainty, and do nothing by default.

Stage 2

Suggest

Offer a concrete next move, preparation brief, recovery adjustment, re-entry point, or agent workflow.

Stage 3

Approve

Preview the plan and blast radius, request a purpose-bound grant, and let the person edit, defer, or refuse.

Stage 4

Automate selectively

Only reversible, bounded behaviors graduate after repeated success, clear audit, revocation, and a reliable exception path.

Continuous does not mean noisy: Waldo can wake often and act rarely. It should preserve exact re-entry points, batch non-urgent judgment, respect quiet hours and attention budgets, and interrupt only when timing, consequence, and the need for human authority justify attention.

The attention contract

The assistant should reduce how much of life the person must keep mentally open.

The burnout economy is not solved by an AI manager that produces more recommendations, monitors more behavior, or keeps the user permanently available. Waldo should carry responsibility without taking agency away.

Judgment budget

Escalate consequence, not volume

Filter drafts, collapse duplicates, resolve reversible cases within policy, batch non-urgent choices, and reserve interruption for decisions whose consequence or authority belongs to the person.

Enough

Stop conditions are a feature

Every Outcome can define sufficient evidence, acceptable quality, time and cost limits, and valid dispositions such as accept, defer, transfer, reopen, or consciously release.

Capacity

Context without judgment

Explicit boundaries, calendar load, rest, and permissioned health context can shape timing and plans. Waldo must not infer laziness, morality, personality, or commitment from behavioral or body traces.

Daily Close

Continuity without mental custody

Record what became true, what is waiting, what was released, and the exact next re-entry point so rest does not require keeping every obligation alive in working memory.

The product test: does Waldo leave fewer things requiring active mental custody? Accepted Outcomes, avoided interventions, useful judgment requests, conscious release, and reliable next-day re-entry matter more than tasks generated, tokens spent, or time kept inside the product.

The people building Waldo

Systems depth, consumer taste, and a long habit of making things.

The team met through building: Shivansh and Ashish became friends at school over iOS jailbreaking; years later Shivansh met Suyash in the university Computer Center and showed him how to build a website by describing it to an AI tool.

Shivansh Fulper

Founder · engineering and architecture

Shivansh reports building more than 30 production agent instances at Atlan and learning where capable agents still leave purpose, context, blockers, and outcome judgment to people. His earlier work spans OpenFn/C4GT, Project EKA data-curation infrastructure, native apps, and independent model implementation.

Suyash Pingale

Founder · product, experience and brand

Through SAPIEN, product work, and the lived collision of a design studio with Ironman training, he brings the consumer discipline agent infrastructure normally lacks: making permissions, uncertainty, attention, and control feel legible.

Ashish Tembhekar

Founding Engineer

Before Waldo, Ashish spent nine months working as an AI engineer. He built much of Waldo's first app and health-data pipeline, validated Health Connect on real Android hardware, and now works across native iOS, Supabase, and agent infrastructure.

The product triangle: engineering makes the system dependable; product taste makes truth and control understandable; the consumer relationship makes the technology worth keeping around.

Expansion frontier · physical work

The same governed Work Unit can coordinate software, people, tools, machines, and robots.

Our expansion thesis is that AI will move further into trades, field work, connected hardware, logistics, homes, vehicles, and robotics. Waldo's role is not to own every machine; it is to preserve the person's intent, authority, evidence, continuity, and right to stop as work crosses the digital–physical boundary.

People and trades

Human Work Units remain first-class

Maintenance, field service, inspections, contractor coordination, equipment repair, and acceptance can combine AI preparation with accountable human execution and real-world evidence.

Devices and hardware

Connected effects need receipts

Sensors, wearables, home devices, equipment, and vehicles enter through capability manifests that declare identity, location, telemetry, required authority, failure behavior, and observable completion.

Robots and physical bodies

Action requires a safety contract

Every physical effect must declare safety class, preconditions, permitted action, live state, abort path, human handoff, reversibility or recovery, telemetry, evidence, and acceptance authority.

Why software first: the Outcome, authority, evidence, interruption, recovery, and acceptance contracts must be trustworthy before Waldo is given movement or physical-world authority. Low-risk coordination and observation come before actuation. Consumer bodies such as a desk object, wearable, home device, or small robot remain part of the horizon—not a current Waldo hardware program.

Waldo is the company

Waldo is the personal agent that stays on your side and keeps what matters moving.

Waldo is designed to carry the context you choose to share—your priorities, commitments, boundaries, health context, relationships, permissions, corrections, and outcome history—across work and personal life. Its job is to help decide what matters, coordinate the right people and AI, follow work through to a real outcome, and protect your attention while keeping you in control.

Kennel is Waldo's first home on the Mac and its first market wedge—not the company. Over time, the same Waldo can meet you through mobile, messaging, voice, connected services, and eventually physical forms. The surface changes; the relationship, memory, permissions, and loyalty to the person do not.

Meet Waldo

Public anchors

Product and provider references

Waldo

Product

heywaldo.in

Codex

Provider contracts

Hooks · App Server

Cloudflare

Durable runtime substrate

Durable Objects