NAOMS Devlog

Building a sovereign, local-first memory & identity system โ€” in the open, honestly.

Four tabs for things that need you

A new device asking to join your identity, an app asking to install, an AI plan waiting to run, a group vote where it is your turn, an invitation, a question from an agent. In NAOMS all of these land in one window, Approvals, split into four tabs: Approvals, Governance, Memberships and Agents. Two of the tabs say, in opposite ways, what happens if you stay silent.

Product Architect free September 17, 2026ยท6 min readยทgovernance
TL;DR Many things in NAOMS that wait on your say-so share one home: the Approvals window. It has four tabs, one for permission requests, one for group votes, one for invitations and memberships, and one for questions agents have asked you. This is a tour of what you can approve there, as it stood on 17 September.

Plenty of things in NAOMS pause and wait for a person. A second laptop wants to join your identity. An app you are installing asks for permission. An AI assistant has drawn up a plan and will not start until you say yes. Your group is voting and it is your turn. Someone invites you into a group, or asks to join one you look after. An agent working on your behalf reaches a fork and asks you which way to go.

These come from very different parts of the system. In NAOMS each of them shows up in the same place: the Approvals window. Its heading reads Decisions: things your group is deciding together, and it has four tabs.

flowchart LR
  W[Approvals window] --> A[Approvals
permission requests
that time out] W --> G[Governance
group votes
where you count] W --> M[Memberships
invitations, join requests,
offered credentials] W --> Q[Agents
questions an agent asked you
that wait for you]

Finding it

Approvals lives in your person menu, with a red count beside it when something is waiting. There is also a Pending approvals icon in the header. The count adds up two things: requests you have set aside, and group votes where it is your turn.

The tab names are the owner's. The first version used internal language, and his feedback was blunt: "the approval text itself looks very technical and is unreadable change the titles to: Approvals, Governance, Memberships, Agents." That is what they have been called since late August.

Approvals: things asking for permission

The first tab holds requests from software that wants to do something on your behalf and needs a yes first. Each card says what kind of request it is:

  • Device approvals. A new device of your own asking to join your identity, a device joining a group, or a friend's hardware being offered for work. The card shows what the machine is: its architecture, memory and graphics.
  • App approvals. An app asking to be installed or registered, named with its version.
  • Plan approvals. An AI plan waiting to run. Approving one writes a signed receipt, and the card confirms it: Approved โ€” receipt signed.
  • AI model approvals. A request to use a particular model for a particular purpose.
  • AI chat approvals. An AI assistant asking to take part in a conversation.
  • Session approvals. A grant for a working session.
  • Action approvals. The catch-all for specific, consequential acts.

Behind these cards is one shared approval mechanism, and it defines 29 kinds of request so far. The "action" family covers a wide spread: joining a group, handing a capability to another party, granting access for account recovery, an agent using a tool, releasing a shared signing ceremony, overriding a missing prerequisite, configuring a cloud AI provider or letting a prompt leave for one, sharing with a friend, defining a token, parsing a chat message for detected content, transcribing a voice note, looking up the weather, and three checkpoints in a game the project uses to recognise contributions. Approving or denying both send a signed receipt of your answer, and the tab notes that biometric confirmation is used when available.

Two properties matter more than the list:

  • These requests time out. Each kind has its own lifespan, from five minutes for an app's sign-in to a day for a standing permission. The tab says so in words: if a request expires before you answer, it can no longer be approved and the app has to ask again.
  • The stakes set how loudly it asks. Depending on how much is at stake, a request can pop up wherever you are in the app, raise a banner that asks for a deliberate review, or both. Installing an app, for example, is set up to raise the banner, because a single stray click should not be enough to let new code onto your machine.

Governance: votes where you count

The second tab gathers the open decisions from every group you belong to, with a filter to show one group at a time when you are in several. Each card says in one sentence what it takes to pass, for example "Once 2 of the 3 stewards approve, this takes effect right away", and lists who has decided so far: Approved, Rejected, Hasn't decided yet, or, on your own row, Your turn. You vote Approve or Reject from the card, through the same governance engine the rest of the system uses.

Stewards are the people who hold a governing role in a group. The 2 September piece explains where that role comes from.

Memberships: who belongs where

The third tab is about belonging. It shows:

  • Group invitations. NAOMS calls a group a hive, so the card reads Hive invitation โ€” open to join. It takes you to the group's join card, where you see what joining means before you accept.
  • Requests to join groups you look after. Wants to join, with the person's name. Approving does not drop them straight in. It sends them an invitation, and the card changes to Invited โ€” awaiting their accept. Both sides say yes.
  • Credentials offered to you. A group can offer you a role credential; the card reads Offers you followed by the role, and after you accept, held on your chain: kept in your own signed record.
  • Friend requests. On 17 September these pointed you to Contacts to accept.

Agents: questions that wait

The fourth tab holds questions an agent asked you before carrying on. You can pick one of the options it offers or type your own answer, and when the question was asked in a channel, you can open that channel. The answer is the same whether you give it here, in the terminal, or in the channel.

When you pick an offered option, the app sends only which option you chose, not any text. The recorded answer is taken from that option's own label, so the screen cannot put words in your mouth, and the record always shows whether you chose an option or wrote something yourself.

The tab is also careful about what it cannot see. Answering releases the agent if it is still running, and in the tab's own words, "this tab cannot tell you whether it is."

What your silence means

The design choice we like best here is small and written in plain sight. The first tab and the fourth handle silence in opposite ways:

  • On Approvals, silence ends in no. The request expires and has to be made again.
  • On Agents, silence means still waiting. In the tab's own words: "Nothing here times out: a question waits until it is answered."

Someone who learns one rule and carries it to the other tab would be wrong both ways round: assuming an old permission request is still waiting for them, or assuming an agent's question has quietly lapsed. So each of these two tabs states its own rule at the top, in one sentence, where you will read it before you act.

Status

This describes the window as it stood on 17 September. The four tabs were not new that day. They took shape in late August, when a fourth tab for agents' questions was added and all four were renamed to the owner's wording.

One change came three days later. From 20 September the Memberships tab also lists direct connection requests from people who want to become your contact. Accepting one opens a Choose what to share popup, where you pick which of your relationship cards to share with them, instead of sending you to another screen.

Related: The permission you granted is the one that gets checked ยท The ceremony that turns a stranger into a contact

Written by AI agents from real project logs; owned and edited by Mujo.


Written by AI agents from real project logs; owned and edited by Mujo.

โ† more in Product   home โœฆ   all โ†’