AI twins of your real team, on your own machine. Each twin is trained on one real person's own work, the twins debate your hard questions in a Team Meeting, and nothing they change in the outside world happens without your approval.
Install · Why it's different · A Team Meeting in 30 seconds · How it works · Vs. alternatives · Security model
![]() |
![]() |
![]() |
![]() |
npx employee001 setup # interactive first-run wizard
npx employee001 start # opens http://localhost:3000Note
Requires Node.js 22+ and either an Anthropic API key, customer-cloud credentials for Bedrock, Vertex AI, or Azure AI Foundry, or a local Anthropic-compatible endpoint. A Composio API key is needed when you invite a real employee for training — marketplace agents work without it. Press Ctrl+C to stop the server.
Important
Your data stays on your machine. Profiles, memory, audit log, and org knowledge live in ./data/ on your hardware. Twins send prompts (with the profile context they need) to Anthropic, your own cloud's Claude endpoint, or your configured local endpoint. Tool calls go to the services you connect. See exactly which hosts with npx employee001 doctor --egress. No telemetry, no analytics.
- Twins of real people, not role templates. Each employee connects their own tools (Slack, Gmail, Linear, GitHub ...) and a training agent writes their twin from their actual history: expertise, decisions, tone.
- Team Meeting. Ask one question and the right twins argue it out, challenge each other and land on a verdict you can act on.
- Nothing runs unapproved by default. Every external action (an email, a Slack post, a ticket) stops at an approval gate, and every tool call is written to an audit log. Each employee authorizes their own twin's tools with their own OAuth.
- Local-first. Your profiles, memory, audit log and org knowledge live in
./data/on your hardware. Prefer a server? Run your own single-tenant cloud instance. - Speaks Hebrew. Twins converse, write and remember in natural Hebrew, with right-to-left rendering, no extra service needed.
| 🧠 | Your organizational brain. Scattered expertise, past decisions, and work patterns become one living layer your company can query, trust, and grow. |
| 👤 | A twin for every employee. Always-on AI agents that understand a specific person's role, context, tone, and prior work — not generic role templates. |
| 💬 | Team Meeting (council). Ask one question and the right twins debate, challenge each other, and converge on a shared answer. |
| 🔌 | Connected to how people actually work. Email, calendar, docs, Slack, Linear, GitHub, CRM — through Composio MCP, the same tools your people already use. |
| ⚡ | Knowledge → execution. Twins draft Slack messages, file Linear tickets, send emails, follow up — each action gated by your approval. |
| 🏠 | Local-first by default. Runs on your Mac mini (or any Node 22 machine). Bound to 127.0.0.1. Data stays local; model prompts and connected-tool calls can leave. See where. |
You: What should we do before launching the new customer onboarding flow?
| Twin | Tools | Says |
|---|---|---|
| 🟠 Dana · Product | Linear, Slack | Risks first — the new flow touches activation. Let's pull last quarter's drop-off points. |
| 🔵 Arie · Engineering | GitHub, Linear | DB migration ships Thursday. Day-1 launch blocks if rollback isn't tested. |
| 🟣 Noa · Sales | Slack, Monday | Two enterprise demos this week. Defer = revenue at risk. Stage launch? |
| 🟢 Tamar · Support | ClickUp, Slack | Need help docs + macros ready, or the queue floods. 2 days of work. |
Tip
Verdict. Stage launch to 10% next Tuesday after migration rollback test. Sales keeps demos; Support ships docs + macros by Monday.
Each speaker is grounded in their own profile files (EXPERTISE.md, DECISIONS.md, CONTEXT.md, ...) and can call real tools to back up claims. Full transcript exports as markdown.
flowchart LR
CEO(["👤 CEO<br/>(browser)"])
subgraph local ["🏠 Your machine"]
Server["⚡ employee001 server<br/>Next.js + Node"]
Data[("💾 data/<br/>profiles · audit · org brain")]
Server <--> Data
end
Anthropic["🧠 Anthropic API<br/>(Claude)"]
Composio["🔌 Composio MCP<br/>(300+ tools)"]
CEO -->|invite link| Server
CEO -->|ask| Server
Server -.->|prompts + profile context| Anthropic
Anthropic -.->|twin response| Server
Server -->|tool call| Composio
Composio -->|Slack · Linear · email · code| Server
Server -->|answer + approval gate| CEO
classDef local fill:#0d2818,stroke:#2ea44f,color:#fff
classDef external fill:#1e1e2e,stroke:#888,color:#fff
class Server,Data local
class Anthropic,Composio external
sequenceDiagram
actor CEO
participant Server as employee001 server
participant Employee
participant Composio
participant Claude as Anthropic
Note over CEO,Composio: 1. Invite
CEO->>Server: create invite (lookback 30–360 days)
Server-->>CEO: shareable link
CEO->>Employee: sends link
Note over Employee,Composio: 2. Train (autonomous)
Employee->>Server: opens invite, OAuth their tools
Server->>Claude: spawn training agent (120-turn budget)
Claude->>Composio: read Slack/Gmail/Linear/GitHub history
Composio-->>Claude: real work signal
Claude->>Server: writes 9 profile .md files
Server-->>Employee: ✅ twin ready
Note over CEO,Composio: 3. Ask, propose, approve, audit
CEO->>Server: question (single twin or Team Meeting)
Server->>Claude: prompt + profile files + Org Brain
Claude->>Server: proposes Composio tool call
Server-->>CEO: 🛑 approval queue
CEO->>Server: ✅ Approve
Server->>Composio: execute (send email, file ticket, ...)
Composio-->>Server: result
Server-->>CEO: answer
Server->>Server: append to audit.jsonl
As of October 2026:
| ChatGPT Teams / Copilot | Cabinet1 | Paperclip2 | ZooWork3 | Employee001 | |
|---|---|---|---|---|---|
| Who the agent represents | A generic assistant | Agent teams | Configurable AI "employees" | Agents that engineers build and deliver | A twin of a real, named person, trained on their own work |
| Where it runs | OpenAI / Microsoft cloud | Self-hosted, markdown on disk (cloud on a waitlist) | Self-hosted or managed | Managed cloud | Your machine, or your own single-tenant cloud. What leaves it |
| External actions | Depends on the connector | Human approval queue | Its own approvals; Claude/Codex runs default to full auto since v2026.1001.0 | Approval gates | Approval gate on every external action, on by default |
| Several agents on one question | — | Agent teams | Task routing between agents | Agent workflows | Team Meeting: twins debate and converge on a verdict |
| Shared knowledge | Conversation history | Knowledge base | Company skills learned from finished tasks | Packaged agent skills | Org Brain: what one twin learns, the others can use |
Spotted something out of date? Open an issue and we'll fix the table.
📧 Email · 📅 Calendar · 📄 Documents · 💬 Chat · ✅ Tasks
💻 Code repositories · 🛍️ CRM · 📚 Knowledge bases · 🔧 Internal tools
Connected through Composio MCP — 300+ toolkits, OAuth per employee (the employee authorizes their own twin, not the CEO on their behalf), token refresh handled automatically. Add a custom MCP server with Bearer auth or full OAuth from /settings — Apify, Stripe, Firecrawl, Higgsfield, anything that speaks MCP.
Twins run on the Claude Agent SDK. Permissions are deliberate and identical for every twin in every workspace.
stateDiagram-v2
[*] --> Proposed: twin wants to call<br/>an external tool
Proposed --> ApprovalQueue: SDK pauses
ApprovalQueue --> Approved: CEO clicks ✅
ApprovalQueue --> Denied: CEO clicks ❌
ApprovalQueue --> Expired: 10 min timeout
Approved --> Executed: tool runs
Denied --> Audited: twin notified, no retry
Expired --> Audited
Executed --> Audited
Audited --> [*]: append to<br/>data/audit.jsonl
note right of ApprovalQueue
Read-only tool calls
skip this gate entirely
(listing channels, fetching
messages, reading PRs)
end note
Bash · NotebookEdit · EnterWorktree · ExitWorktree
No twin runs shell commands on your machine. Enforced in two places at once (the SDK's disallowedTools plus a defensive PreToolUse hook).
📋 Detailed permissions per run type (click to expand)
| Run type | Built-in tools | External tools |
|---|---|---|
| Twin chat | Read, Glob, Grep, Write¹, WebSearch, WebFetch, Task², TodoWrite, AskUserQuestion |
Composio³ |
| Twin training | Read, Write¹, Glob, Grep, TodoWrite |
Composio³ (read-only signal — Slack/Gmail/Linear/GitHub history) |
| Scheduled routines | TodoWrite |
Composio³ |
| Org-brain summarisation | — none — | — none — |
¹ Write is sandboxed to data/scratch/<employee-id>/. A twin can jot a memo or draft — it cannot overwrite its own profile, the org brain, audit logs, or any other file under data/. Path traversal is rejected.
² Task spawns one of two restricted sub-agents: a web-researcher (only WebSearch + WebFetch) or a brain-explorer (only Read + Glob + Grep). Sub-agents inherit the same hard-disallow list.
³ Composio MCP tools are external-effect tools — posting to Slack, sending Gmail, opening GitHub PRs. Every call hits the approval gate above. Auto-execution is off by default. Read-only Composio calls run without prompting.
Audit trail. Every tool call — built-in or Composio — is appended to data/audit.jsonl with the run id, the employee id, the tool name, the input, and the verdict (executed / ceo_approved / ceo_denied / hard_blocked). Browseable from /audit.
Web citations. After any WebSearch or WebFetch, a PostToolUse hook injects an instruction telling the model to cite the URL and the fetch date. Twins can look things up online, but they can't pretend they "just knew" something.
Models. claude-sonnet-5-5 (Claude Sonnet 5.5) by default, with claude-sonnet-5 as the fallback. Override to Opus for a single message from the chat UI. Source of truth: src/lib/sdk-defaults.ts.
employee001 setup can route every twin Agent SDK run through your AWS Bedrock, Google Vertex AI, Azure AI Foundry account, or a local Anthropic-compatible endpoint. For a local endpoint, it requires ANTHROPIC_BASE_URL and all three explicit model pins; ANTHROPIC_AUTH_TOKEN is optional. Ollama >= 0.14 is one compatible example. Open-weights models are much weaker than Claude: tool use may fail and Hebrew quality may be poor, so use this preset for evaluation and air-gapped pilots only.
This boundary mode does not by itself make every optional integration local: direct Anthropic API features (memory rerank, follow-up suggestions, knowledge proposals, and live Relay) are disabled unless EMPLOYEE001_ALLOW_DIRECT_ANTHROPIC=1 is explicitly set. Inspect the effective routes with employee001 doctor --egress.
./
├── .env # your API keys (chmod 600)
└── data/
├── employees/<id>/ # 9 markdown profile files per twin
├── org/ # Org Brain (shared knowledge graph)
├── audit.jsonl # every tool call, every approval
├── routines.json # scheduled work
├── hired-agents.json # marketplace hires
├── memory/<id>/ # per-twin memory — episodic recall + distilled facts
└── shifts/<runId>/ # autonomous-shift archives (events · outputs)
Tip
npx employee001 export ~/Desktop/e001-backup.tar.gz snapshots everything except secrets. npx employee001 import <archive> restores on a fresh install.
By default the server binds to 127.0.0.1 — only this machine can reach it, OS access control is the boundary.
For a LAN-shared install (e.g. Mac mini in the office serving the whole team):
EMPLOYEE001_BIND=0.0.0.0 npx employee001 startWhen bound to anything other than loopback, every request must carry a shared-secret token. setup generates one (EMPLOYEE001_TOKEN in .env); start prints the access URL on boot. Visit it once from each device — the token becomes a 30-day e001_token httpOnly cookie. API calls without a matching cookie return 401.
Invite tokens are carve-outs — they bypass the LAN gate for /join, /onboarding, and /api/invites/<token> only, so employees can onboard without holding the workspace secret.
Warning
Use a firewall or Tailscale. The token gates HTTP access, but the app is not hardened for the public internet. Don't put this on a port-forwarded box.
Need remote employees to reach their twins when they're off the office network? Deploy a single-tenant instance to an always-on host — your infrastructure, your data. Not a multi-tenant SaaS.
- Isolation by deployment — one org = one container + one persistent volume + its own secrets + its own subdomain. The storage model doesn't change:
data/just lives on a mounted volume, so there's no database to migrate to. - Recommended stack: Fly.io — a single always-on Machine + persistent volume + per-app secrets + free TLS. Not Vercel or any serverless host: the filesystem is ephemeral there, so SQLite and the
data/tree won't survive. - Zero-loss migration from a local install using the same
export/importyour backups already use.
Warning
The app isn't hardened for the open internet yet. For a first deploy, keep it private (Fly private networking / Tailscale) or put real auth in front — don't expose a public route until the access gate is hardened.
Full runbook — Dockerfile, fly.toml, migration steps, and a per-org security checklist: docs/DEPLOY-CLOUD.md.
This is the DIY version of our Professional onboarding — we can deploy and manage it for your org.
| Command | What it does |
|---|---|
npx employee001 setup |
Interactive first-run wizard. Writes .env, creates data/. |
npx employee001 start |
Starts the local server. Opens browser. --no-open / --port <n> / --strict (no nonessential traffic) flags. |
npx employee001 doctor |
Health check — Node version, env, API keys, port, build. |
npx employee001 doctor --egress |
Lists every outside host your current config talks to, and what is sent. |
npx employee001 update |
Checks GitHub releases for a newer version. |
npx employee001 export <path> |
Snapshot data/ to a tar.gz (excludes secrets). |
npx employee001 import <path> |
Restore data/ from a tar.gz. --force overwrites. |
npx employee001 mcp |
Connect Claude Code, Cursor, or another MCP client to the running local Employee001 app. Use --url <url> to choose a different local app URL. |
npx employee001 help |
Show help. |
Ask your org's twins from the editor where you build. Employee001 exposes your local organizational brain as an MCP server: find who owns a decision, search profile knowledge, inspect pending approvals and active Team Meetings, or ask a ready twin a focused question.
Start Employee001 first:
npx employee001 startThen add it to Claude Code:
claude mcp add employee001 -- npx -y employee001 mcpThe default connection is your local app at http://127.0.0.1:3000/api/mcp. No cloud account or separate service is required. Read the complete setup, tool reference, limits, and security model in docs/mcp.md.
The product has shipped the core loop end-to-end. Tracking against the public roadmap:
- Twin chat with profile-file citations (
/flow) - Composio MCP integration (Slack, Gmail, GitHub, Linear, Calendar, Drive)
- Approval gate on every external tool call
- In-UI profile editing of the 9 markdown files
- Per-invite training window (30–360 days)
- Team Meeting: multi-twin debates (
/council) - Scheduled routines (
/routines) - Marketplace agents (pre-built SDR/DevOps/Writer/Analyst/CSM)
- Custom MCP servers with OAuth bridge (
/settings) - Backup / export / import
- Org-brain search across twin profiles
- Autonomous shifts — twins run scheduled work and take action behind a live approval gate, with per-run archives + observability (
/cockpit) - Voice playback for twin answers (ElevenLabs)
- Self-curating twin memory — salience-ranked recall, dedup-on-write, multilingual (Hebrew/English) fact extraction
- Hebrew — twins converse and extract memory in Hebrew (Anthropic-only, no extra key), with right-to-left rendering
- Memory relevance gate — twins only recall memories that fit the question, with an optional agentic rerank
- Claude Sonnet 5.5 by default
- PDF and Word uploads become readable knowledge (extracted to Markdown next to the original)
- One sidebar for both modes, an approvals badge, and Autonomy as a pure kill switch for unattended work
- Single-tenant cloud deploy runbook (Fly.io)
- Full UI internationalization (i18n)
- Multi-CEO / multi-tenant
- Mac DMG / Electron wrapper for non-technical CEOs
100% of the code in this repo is MIT-licensed and free. Everything you see in the product is available to you.
Premium = services, not features:
- Professional onboarding — we install it for you, set up MCP connections, train your team
- SLA support with a dedicated Slack channel
- Custom integrations
If that's interesting, open a discussion or email office@bulldog-adv.com.
☁️ Cloud edition (planned, separate)
This repository is the local-first OSS edition. A managed cloud edition is on the roadmap as a separate product — for teams that want long-running shifts, audit logs in a hosted console, private MCP networks, and don't want to run their own Mac mini.
The cloud edition will be a paid service, not a feature gate on this code. Everything you see in the repo today stays MIT and local-first.
- Next.js 16 (App Router, RSC, standalone output)
- Claude Agent SDK for reasoning + tool use
- Composio MCP for tool integrations (300+ toolkits)
- JSON-on-disk for state — no database
PRs welcome. See CONTRIBUTING.md for setup, the rules of the road (no telemetry, no paid feature gates, no cloud dependencies), and how to file a security issue.
Maintainers: see RELEASING.md for the tag-driven publish flow.
MIT © Dolev Hayut
⭐ If Employee001 sounds useful, star the repo — it helps others find it. ⭐
Footnotes
-
Public information about Cabinet (cabinetai/cabinet, runcabinet.com) as of 2026-10-04. ↩
-
Public information about Paperclip (paperclipai/paperclip, release notes for v2026.916.0 and v2026.1001.0) as of 2026-10-04. ↩
-
Public information about ZooWork, formerly ZooClaw (zoowork.ai), as of 2026-10-04. ↩



