CATO
channel live · 6 sessions · 1 awaiting approval
Auditory command center for agentic architecture

See when needed.
Speak by default.
Keep moving.

CATO attaches to the agent sessions you already run — Claude Code, Codex, OpenClaw, tmux, remote servers — and gives you one continuous voice conversation to brief, steer, approve, and govern all of them. It puts a screen in front of you only when your judgment actually needs one.

$ cato connect
Attach, don't replace Bring your own agent entitlement Outbound-only
scroll
Attach, don't replace

Built to attach to the stack you already run — no migration, no lock-in.

Claude CodeCodexOpenClawrailtracksMCPtmuxiTerm2WezTermSSHDockerPodmanKubernetes
The supervision gap

Autonomous work now scales faster than any human can watch through terminals, dashboards, and chat windows. The industry's answer is more screens.

Every new session is another window to watch, another approval to catch, another context to hold in your head. CATO's answer is the opposite: many concurrent agent systems collapsed into one continuous voice-and-visual command channel — so a single operator can direct more work than a room of monitors could ever show.

The operating loop

Seven moves, one conversation

A project starts read-only and earns capability as you trust it — from observing to steering to approving production. The channel never breaks between steps.

01

Connect

The local Bridge discovers your projects, runtimes, terminals, and live sessions. No migration, no Docker required.

02

Observe

One command center shows every session, its runtime and adapter, agent lineage, changed files, artifacts, and pending approvals.

03

Brief

Say the wake word and get a prioritized executive summary — what shipped, what's blocked, what's waiting on you, what's high-risk.

“CATO — where do things stand?”
04

Steer

Route a spoken instruction to the exact organization → project → runtime → session → agent. No window-hunting.

“Tell the frontend session to cut motion 30% and verify mobile Safari.”
05

Preview

When visual context materially improves your judgment, CATO opens a secure, signed, short-lived localhost preview over an outbound tunnel.

06

Walk away

Leave the screen. The same authenticated session continues through your headphones, interrupting only at thresholds you set.

07

Govern

Approve staging, deny production. Elevated actions demand explicit authorization, and every command and result is timestamped and attributable.

Progressive by design

Each capability is opt-in. CATO only ever offers controls the connected runtime can actually perform.

Why it works

The interface splits by what a human is actually for

Voice and vision share the same authenticated session — same state, same active-agent graph, same approvals and transcripts. You never re-establish context switching between them.

default medium

Speak by default

Voice is the persistent control channel. Briefing, steering, interrupting, approving, governing — all of it runs while you walk, commute, or think, with your hands and eyes free for anything else.

continuous · hands-free · low-friction
on demand

See when needed

Visual previews appear automatically — and only — when something spatial, graphical, or high-risk genuinely needs your eyes. The screen is an exception you earn, not a tax you pay all day.

signed · short-lived · port-scoped
Non-negotiables

Built for people who take production seriously

CATO is not another agent, not a sandbox, not a remote desktop, not a credential proxy, and never an unrestricted remote shell. The trust model is the product.

Attach, don't replace

Your tools stay yours

Keep your repos, terminals, servers, subscriptions, and workflows. CATO connects to them where they already live.

BYO agent entitlement

Never a credential proxy

Provider auth stays inside your first-party clients. CATO never stores your Claude or OpenAI passwords or subscription credentials.

Local policy authority

The Bridge has the final say

The cloud may request an action; your local Bridge independently enforces permissions and can deny any command.

Outbound-only

No inbound attack surface

The Bridge initiates encrypted outbound connections. No inbound ports, no public shell, no listening service on your machine.

Auditable control

Everything is on the record

Every instruction, approval, denial, preview, and handoff is timestamped and attributable. Nothing happens off the log.

Runtime-agnostic

Docker is one adapter

Native processes, containers, remote servers, multiplexers, and an optional CATO sandbox are all first-class citizens.

The architecture

One outbound link between your machine and your judgment

  • 01CATO Bridge — a local, loopback-only daemon that discovers runtimes, hosts adapters, enforces policy, redacts secrets, and supervises processes.
  • 02CATO Link — a persistent, outbound-only, mutually-authenticated encrypted transport with reconnect, backpressure, and command signing.
  • 03CATO Control Plane — identity, session and lineage registries, voice orchestration, the command router, approvals, the preview broker, and the audit log.
local
CATO Bridge
discovery · adapters · policy · redaction
↕ outbound · mTLS · signed
cloud
CATO Control Plane
voice · routing · approvals · audit
Early access

Command more autonomous work than you can watch.

CATO is in early access for operators running multiple concurrent agent sessions. Tell us what you run today and we'll get you a Bridge.