The ntndOS roadmap

From useful agents
to a working company.

The first alpha gives people and agents a place to work together. What comes next should be shaped by the businesses and people who use it: the jobs they need done, the limits they need respected, and what they tell us is missing.

The priority now

Build with the people who will use it.

We are listening to our community before fixing the shape of beta v1. In your alpha request, tell us what you would try with ntndOS, where it could help, and what would need to change before you could rely on it.

Feedback can change the order, scope and contents of this roadmap.

Release path

From alpha
to beta v1.

First alpha

macOS

Invite people into the initial app, learn from real work and improve the first-run experience.

Following alpha

Linux

Bring the tested experience to Linux, with packaging and platform-specific checks.

Following alpha

Windows

Bring the tested experience to Windows, with its own installation and release checks.

Room to change before beta

What would help you most? Ideas on this roadmap include clearer work and approvals, reusable methods and agents working across companies. Tell us what is missing.

The destination

Beta v1

Work toward a more dependable human–AI workspace. Its exact scope will be decided through testing and feedback, not assumed today.

Alpha priorities and later explorations

A clearer workspace
for the whole job.

Alpha · usability proposal

Make human work
easier to handle.

Give people a clear view of their questions, tasks and reviews, with the context and next action beside each one. Keep rules and permissions in Govern.

  • Show what needs a person, why it needs them and what happens after they respond.
  • Make it easy to answer, request changes or hand a task back to an agent without hunting through Chat.
  • Keep a readable, resizable workflow inspector and explore a dedicated Approvals view inside Work.
  • Preserve the original Brain, Files views, spatial workflow graphs and Calendar.
What must the redesign preserve?

People can still reach the current controls and links. Workflow edits save, the inspector works with a keyboard and on smaller screens, and an approval keeps the same decision record if its screen moves.

Alpha · core work cycle

Carry a job from
intent to accepted result.

Follow one job from its brief through agent work, human decisions and external actions to a result someone accepts.

  • Human tasks, questions and reviews with an owner, a reason and a response route.
  • Exact decisions, bounded runs, meaningful pause and stop behavior, and recoverable progress.
  • Evidence of what happened, followed by a separate check that the result meets the brief.
  • Calendar proposals that become commitments only when accepted; deadlines are not automatic bookings.
An illustrative job

Prepare a course launch → ask a teacher to review → confirm the offer → review an invitation → send through the agreed integration → verify the result. A fictional studio is the test scenario, not a limitation on the product.

How will we know the work cycle holds up?

Test a complete job in the production app, including pauses, denied requests, changed inputs and revoked access. At each point, the person supervising it should be able to see what is waiting, what is allowed and what actually happened.

Alpha · first-party Library

Start with a method
you can inspect.

Install an NTND-authored skill, workflow or starter role, see what access it asks for and create a separate copy for your company.

  • See the purpose, publisher, compatible version, connections and requested permissions.
  • Preview an example, try sample data and create an independent company instance.
  • Review version updates and any expanded access before applying them.
What stays private when you reuse a method?

A template never brings another company’s credentials, private memory or standing permissions with it. The first milestone is an install and update path for one skill, one workflow and one starter role—not an open third-party marketplace.

Alpha · integrations proposal

Bring more tools
into the workflow graph.

Expand useful actions for existing connections and explore new ones, including Buffer, so a workflow can carry more of a real job.

  • Show each node’s required access, inputs, outputs and approval point before a run.
  • Extend existing connections only where their permissions and failure handling are clear.
  • Explore Buffer for reviewed social drafts; scheduling or posting would need its own tested permissions and human controls.
Is Buffer connected today?

No. It is a candidate for future workflow integration, not a current ntndOS capability or an announced partnership.

Reading slot · openWorkflow integrationsA future article or paper about the connections, permissions and design behind this work.
Alpha · funding-dependent proposal

Fund independent
security audits.

Bring in external reviewers to test the app, backend and access boundaries. This needs a dedicated budget; no audit is booked yet.

  • Review sign-in, permissions, data handling and cross-company access.
  • Fix findings and retest the changes before widening access.
  • Share the review scope and remediation progress without publishing exploitable details.
Alpha · community dashboard proposal

Show the community
how ntndOS is developing.

Explore a public dashboard with aggregate product use, reliability, feedback themes and release progress, alongside short reflection notes from the team.

  • Define consent and privacy thresholds before collecting product telemetry.
  • Show trends and changes, not individual activity trails.
  • Leave out small groups or details that could identify a person or company.
Later · platform integrations

Work with your company
in ChatGPT and Claude.

Explore ways to ask questions using company knowledge you are allowed to access, see the sources behind an answer, and send proposed work back to NTND for review.

  • Connect as yourself, with NTND checking your company access for each request.
  • See which company information is shared with ChatGPT or Claude and where an answer came from.
  • Inspect the proposed work before saving it as a draft in NTND. Approval and execution stay in the company workspace.
What would make this ready?

Prove a signed-in path in both hosts from a sourced question to a reviewed draft and its status. Test company and source boundaries, revoked access and repeat requests that must not create duplicate drafts. Public listings would follow each platform’s review. This is a proposed integration, not part of the current alpha.

Later · commercial pilots

Acquire capabilities.
Offer what you have built.

Explore a market where companies can install a reviewed role or hire a seller-operated AI service. Both models remain open; neither is selected for launch.

Install a role

Bring a versioned method into your company, then configure a fresh identity, model, connections and access.

Hire a service

Agree a deliverable, bounded inputs, price, deadline and acceptance criteria. The seller operates the service.

  • Support both buyers and sellers: trials, quotes, capacity, delivery, revisions and resolution.
  • Explore structured hiring and payment cards in Chat that open the same engagement record.
  • Prepare a separate commercial release from reviewed reusable knowledge, not raw company memory.
What remains undecided?

The first commercial model, primary hiring entry point, payment provider, seller terms and release-review process. Live commerce needs tested access boundaries, payment controls and failure handling. Open publishing, exclusive transfers and decentralized settlement are separate later choices.

Later · deployment-led expansion

Grow the responsibility
with the evidence.

Enterprise administration and carefully calibrated autonomy should answer real deployment needs—not make every small company operate like a large one.

  • Explore organizational identity, administrative roles, multi-stage review and evidence export.
  • Add retention, residency and incident operations when a deployment requires them.
  • Evaluate wider autonomy at a narrow task scope, with uncertainty, review and rollback rules.
What does “earned” mean here?

Observed accepted outcomes may support a reviewable policy change. A confidence or trust score must not override a private boundary or silently grant new authority. The measure is better work with proportionate supervision, not a longer unattended run.

Later · research direction

Let agents work
across companies.

Explore how an agent in one NTND company could request help from an agent in another, with a specific purpose and boundaries both owners can inspect.

  • Define each agent’s identity and the exact room, task, data and capability scope.
  • Require deliberate authorization on both sides; a human passport alone does not authorize an agent.
  • Prevent reply loops and unintended handoffs, and keep a reviewable record of what was exchanged and done.
What works now, and what does not?

In the closed-alpha design, a person on one NTND installation can be approved to use another company’s agent in a shared room. Agent-originated requests to another company’s agent are currently denied. Cross-company agent-to-agent communication is a future exploration, not an alpha capability or a committed release date.

See how Chatrooms handles passports and agent access ↗︎
The foundation today

Already built
into ntndOS.

A desktop workspace for people and AI agents, with company knowledge, conversations, workflows and human decisions in one place.

Bring a job worth doing.

Tell us what you want your company’s agents to help with. Keep confidential information out of your access request; a clear description of the work is enough.

Request alpha access Discuss the direction on Discord ↗︎
Nova / a working session
Expanded product screenshot