Orcyx is a native desktop app, not a web page in a wrapper. The knowledge graph your agents read is plain markdown on your disk. Your login tokens sit in the operating system's secure storage, never in the browser layer. The only network calls are the ones you set up.
Agents touch only the paths you grant - nothing outside the workspace.
Prompt-injection screening on inbound content before an agent acts on it.
Environment variables pass an explicit allowlist - secrets stay out of agent reach.
CPU, memory, and spend caps per seat - a runaway agent hits a wall, not your machine.
Every command audited with redacted args - a reviewable trail of everything agents did.
The Vault ships with its own built-in MCP server - every tool behind a per-tool ACL. External MCP servers you connect are managed the same way: health-checked, rate-limited, and audited with redaction so credentials never land in a log.
Eight shell presets - WSL, Git Bash, PowerShell, pwsh, cmd, bash, zsh, fish - each a first-class pane on a ConPTY-backed terminal, so a Claude Code seat in WSL and a Codex seat in pwsh sit side by side with the same cost counters. Windows is not the port; it is the platform the terminal work was done on.
Schema tree, query editor, result grid, and an Orcyx-managed database sidecar, so a scratch database is one click rather than a container file to write. Not enabled in the current build - the panel opens and saves connections, but querying is switched off until the driver ships.
SSH sessions open as ordinary panes - same splits, same cost counters, same agents able to work over the wire. Not enabled in the current build - connecting reports that plainly rather than hanging.
Spin a container per project and attach panes to it - agents inherit the container's toolchain and the sandbox's limits.
Orcyx watches the things you'd otherwise learn the expensive way - cost about to be paid, a step about to do damage, knowledge about to go stale - and surfaces them before they happen.
An idle agent pane warns you when your next message will pay to re-read the whole conversation - before you send it. And when a provider misbehaves, the Doctor starts from the cheapest check and names the first broken link - credential, endpoint, or model - instead of a wall of red. Every run lands in a per-workspace spend ledger.
Autonomous runs weigh every step's blast radius before it executes. Anything destructive pauses and waits for a human - and the approval reaches your phone, so a run doesn't stall because you stepped away. Steps the run can't classify are deny-only, by design.
Every dispatched agent arrives already briefed with the workspace knowledge that matters - automatically. Outdated notes sink instead of misleading, superseded facts point at their replacement, and workers hand back structured results instead of prose to re-parse. Long conversations stay sharp instead of drowning in their own history.
Atomic writes, rolling snapshots, restore wizard for corrupted state.
Shared workspaces with live presence - see who's driving which pane.
Silent updates when signing ships; a loud demo badge so fake data is never mistaken for real.
Extend surfaces and wire external services - licensing and billing handled in-app.
Live recreations of two screens: every agent's change before it lands, and spend against the cap you set. Hover over them.