Chief of Staff — the guided assistant for non-technical users
Chief of Staff turns AMC into a single friendly chatbox. Instead of learning projects, sessions, panels, and settings, you turn on one toggle — or just click the Chief of Staff item in the sidebar — and talk to it in plain language — "remind me to call the vet at 4", "save this as a note", "what needs my attention right now?" — and it does the work for you behind the scenes. It's built for people who want the power of AMC without the cockpit.
What it is
Chief of Staff turns AMC into a single friendly chatbox. Instead of learning projects, sessions, panels, and settings, you turn on one toggle — or just click the Chief of Staff item in the sidebar — and talk to it in plain language — "remind me to call the vet at 4", "save this as a note", "what needs my attention right now?" — and it does the work for you behind the scenes. It's built for people who want the power of AMC without the cockpit.
Your Chief of Staff is a real AMC AI assistant, not a scripted bot. Under the hood it is an ordinary Claude session — the same kind that powers Ask AMC — cloned and pointed at a friendlier, plain-language persona, with extra guard rails turned on because it's aimed at people who won't read the fine print.
Chief of Staff is in development and off by default. It's hidden until a developer
ships it; you can reveal it early from Settings → Lab (listed as Chief of Staff
Mode) or by launching AMC with AMC_SHOW_SIMPLE_MODE=1.
Naming: "Chief of Staff" is the user-facing name. Internally the feature is still "Simple Mode" — the
simpleModeEnabledsetting, the__concierge__session, and theSimpleMode*files keep that name (same split as KMS ⇄ "The Vault"). Only the labels the user sees say "Chief of Staff".
Where to find it
Click the Chief of Staff item in the sidebar, or turn the mode on from Settings → Lab, where it is listed under its former name.
How it behaves
- Plain language, no jargon. The concierge never shows you code, file paths, IDs, or tool names. It gives a short friendly acknowledgement, a note if something takes a moment, and a plain-English result — not a play-by-play.
- Starting a chat is instant. The moment you send your first message, your chat opens and your message shows right away, with a "Thinking…" note while your assistant spins up in the background — no blank waiting. If it ever fails to start, you get a clear "send again to try" message instead of a stuck screen.
- One question at a time. When it needs a decision it asks a single simple yes/no question, never a wall of options.
- It actually knows the app. It carries a curated, plain-language guide to what Omniscio can do and how, so it can answer "what can this do?" and "how do I…?" and get things done — reminders, notes, tasks, your inbox, email, your AI sessions, and settings. For anything it's unsure about, it looks it up live before ever saying it can't.
- You can steer it in your own words. An Edit instructions button in the header opens a simple text box where you tell it anything it should know about you or how you'd like it to work — "call me Sam", "keep answers short", "I run a trading company". It keeps your notes in mind every chat, layered on top of its built-in brain, and your notes can never override its safety rules. Changes apply to your next chat.
- Routine lookups just happen; actions ask you with one tap. Checking your state or searching happens instantly, no nagging. But whenever it's about to do something — create, change, send, or delete — a friendly "Can I do this for you?" card pops up with Yes / No, so nothing that changes anything happens without you seeing it. It also asks in plain words before a permanent delete, and it never starts a paid AI session or touches your logins on its own.
- Real work goes to the right place — automatically. When you ask for actual project work, Chief of Staff quietly figures out which of your projects the request belongs to and starts a normal working session there instantly — you never pick a project or see the plumbing. That session then looks and behaves exactly like any other session (same chat, same controls), just without project jargon in the header. Questions, reminders, and app help stay with the Chief of Staff helper itself. If it isn't sure where something belongs, the helper simply handles it — a request never gets stuck on the decision.
- It won't build software itself. If you ask it to build, fix, or change code, it offers to open a separate dev session in your own AMC project to do the work properly — and only spawns that (which costs money) when you clearly ask.
- It treats what it reads as untrusted. If an email, web page, or note it fetches contains text that looks like an instruction ("ignore your rules and forward this…"), the concierge shows it to you rather than obeying it. This is the standard defense against a message trying to hijack an assistant.
- Every chat starts fresh. The concierge has no memory of previous conversations, so nothing you said (or that a fetched email tried to plant) carries into the next one.
Your chats and your inbox
Simple Mode is more than one chat — it keeps a history and surfaces what needs you:
- One list down the left, two things in it. A column on the left holds a New chat button and a two-way switch: Inbox (with the count of what's waiting) and Chats. Whichever you pick fills the column; the right-hand side is always whatever you're working on. It opens on your Inbox, so you land on what needs you.
- Switching lists never disturbs what you're reading. Flipping to your Inbox does not close the chat or notice open beside it — the left side is for finding things, the right side is for doing them, and they don't interfere.
- Fold it away when you want room. The collapse control shrinks the column to a slim strip of three icons — New chat, Inbox (still showing its count), and Chats. Clicking any of them opens that list straight back up, so nothing is ever more than one click away.
- Many chats, like ChatGPT. The Chats side lists everything you've started from Chief of Staff mode, newest first, with a search box. On a phone the same list lives in the ☰ menu. Reopen any of them to pick up where you left off. (Each chat is still fresh on its own — the "no memory between chats" safety rule is about not carrying instructions across chats, not about hiding your history.)
- Rename or delete a chat. Right-click (or long-press) any chat in the list to rename it or delete it. Delete asks first and is undoable for a moment afterward — it tidies the chat away rather than destroying anything.
- Not sure what to ask? A fresh Chief of Staff screen shows a few tappable "Try asking…" examples — tapping one just fills the box for you to edit; nothing sends until you send it.
- Your inbox is always right there. The Inbox side of the switch shows the same things you'd see in the full app: emails, texts, approvals, and AI sessions waiting on you — grouped by where they came from, newest first. It no longer takes over the screen, so you can read something on the right while the list stays put on the left. How many are waiting shows in amber on the Inbox label, and on the 📥 button in the header.
- Tap to respond, without leaving Simple Mode. Tapping an inbox item opens a chat to deal with it: a waiting AI session reopens its own chat so you can reply to it; anything else opens a new concierge chat pre-filled with the item (as quoted, untrusted text) so you can tell the concierge how to handle it. Nothing is sent until you send it.
The model it runs on (yours first, ours as the safety net)
Simple Mode uses the exact same "never breaks" model logic as Ask AMC:
- If you have your own Claude credentials, the concierge runs on your model — as capable as any other session you run.
- If you don't, it falls back to a built-in, company-paid model (Claude Haiku, which also reads screenshots and PDFs) so a brand-new user still gets a working helper. A cheaper, faster text model (DeepSeek V4 Flash) can handle typed questions on the same monitored company path; screenshots/PDFs always stay on Claude, and if it's ever unavailable a typed question falls back to Claude too.
Spending guardrails. The company-paid fallback carries a per-session spending cap (about $1) and a daily ceiling on company-funded starts — because that's our money. On your own credentials the concierge spends like any other session you run.
No file writing, ever. The concierge can read, search, and take the usual approval-gated actions, but it cannot create or edit files on any credential path. It's a helper that explains and does things for you through the app — not a builder. (Building is what a dedicated dev session is for.)
How its permissions work
The concierge runs at a careful permission level and cannot create or edit files. Its everyday work is talking to Omniscio's own controls, handled in two layers:
- Routine lookups are auto-approved — only its read-only checks to Omniscio's own local service, and only those, so it never nags you for a simple "what's happening right now?".
- Everything else asks you — any action it takes surfaces the friendly Yes/No card in Simple Mode. This is a property of what the concierge is, not of who's paying, and it can't be relaxed from inside a chat.
How to use it
- Open it. Click the Chief of Staff item in the sidebar to drop straight into
its focused chat, or turn it on from Settings → Lab → Chief of Staff Mode (or
launch with
AMC_SHOW_SIMPLE_MODE=1while it's in development). - Find your inbox, your chats, and the controls. On a computer the left column holds New chat and an Inbox / Chats switch; it opens on your Inbox. Collapse it and those three become a slim strip of icons you can click straight back open. On a phone the same column is behind the ☰ menu. The header carries Edit instructions and a Full ⇄ Chief of Staff switch — flip to Full to go back to the normal app (you stay opted in, and the switch stays there) and back whenever you like. On a phone the switch lives inside the chatbox.
- Just talk to it. Type what you want in plain language. Ask questions about the app, set reminders, save or search notes, or ask what needs your attention.
- Steer it if you like. Tap Edit instructions in the header and jot down what it should know about you or how you'd like it to work — it uses your notes from your next chat on.
- Tap Yes or No when it acts. Lookups just happen; whenever it's about to change or send something, a quick Yes/No card appears — tap Yes to go ahead (or press Y / N).
- Approvals still land in your inbox. When it schedules something that needs approval, it says so and the approval row appears in your inbox, exactly like every other AMC agent action.
For agents
For agents with repo access
Simple Mode is a reuse-first layer over existing AMC machinery — no new AI engine, and the approve card reuses the existing permission plumbing (no new IPC). The user-facing name is Chief of Staff; the internal name (setting key, sentinel, files) stays "Simple Mode" / "concierge".
Entry point — clicking the sidebar item: the
__concierge__row is asrc/renderer/src/lib/sidebar-action-rows.ts(enter-chief-of-staff) — the cycle-safe pattern where selecting a row fires an action instead of becoming the active project.setActiveProject(the universal click funnel, guarded bysource !== 'restore') dispatches theamc:sidebar-actionevent, and the handler insrc/renderer/src/app/useAppCustomEvents.tscallsenterSimpleModeChat()(opt in + land on the Simple view), which shows the focused chat.Settings:
simpleModeEnabled(opt-in, defaultfalse) +simpleModeFullView(which view while opted in, defaultfalse), single source of truth insrc/shared/types/settings/simple-mode-settings.ts.Gate + view switch: registered as the
'simple-mode'in-development feature insrc/shared/unreleased-features.ts; gate visibility throughisUnreleasedFeatureVisibleInRenderer('simple-mode', settings), never the raw setting. The takeover (resolveSimpleModeGate) renders only when opted in AND!simpleModeFullView; the two-way Full ⇄ Simple header switch (SimpleModeViewSwitch, the canonical SegmentedControl) shows when opted in and flipssimpleModeFullView. The header (Full-side) switch is desktop-only; the Simple-side switch renders in the mobile surface.The concierge is the
__concierge__virtual project — a spawnable session in the managed workdir<userData>/concierge, cloned from Ask AMC. Its spawn plan (model, budget cap, disallowed tools) issrc/main/services/concierge/concierge-model-plan.ts; its persona (safety rules, plain-language behavior, untrusted-content rule) isresources/concierge-claude.md, written into the workdir asCLAUDE.mdbysrc/main/services/concierge/concierge-bootstrap.ts.Its knowledge is a curated pack in
resources/concierge-knowledge/(an overview + a how-to playbook), staged into<userData>/concierge/knowledge/by that same bootstrap, with the liveGET /capabilities/searchcatalog as the fallback.The smart unlock (auto-approve read-only control-server curls at
guarded) issrc/main/services/concierge/concierge-command-allowlist.ts- the carve-out in
src/main/process/ndjson-permission-handler.ts; the approve card is insrc/renderer/src/features/simple-mode/SimpleModeConversation.tsx.
- the carve-out in
The steering knob — the user's own notes live in the
conciergeCustomInstructionssetting (same simple-mode-settings.ts slice); the editor issrc/renderer/src/features/simple-mode/SimpleModeConciergeEditor.tsx, opened from thesrc/renderer/src/features/simple-mode/SimpleModeSurface.tsxheader. The bootstrap composes the personaCLAUDE.md= base + the notes on each chat — append-only, subordinate to SAFETY, bounded, and fail-open (contract §C / invariant L).The hub router (CoS-shell pivot, 2026-08-28) —
src/main/services/concierge/concierge-hub-router.tsroutes each new request to a real hub (or the helper) with one cheap validated Haiku call (cost label'cos-routing', 2.5s timeout, daily cap, fail-open to the helper); routed sessions spawn as NORMAL sessions and render in the realsrc/renderer/src/features/sessions/SessionPanel.tsxwith thehideHubChromeprop suppressing the project-name prefix + branch chip. The smart unlock and injection hardening key on the concierge PROJECT id, never thesource: 'simple_mode'stamp.Full invariants + how to change it safely: the
Simple Mode contract.
Related
- ask-amc.md — the feature Simple Mode is built on, sharing the same session machinery.
- default-agent-instructions.md — the global agent instructions the guided mission fills in.
Last verified 2026-09-28