---
title: Chief of Staff — the guided assistant for non-technical users
---
# Chief of Staff — the guided assistant for non-technical users

## What it is

**Chief of Staff** turns AMC into a single friendly chatbox. Instead of learning
projects, sessions, panels, and settings, you turn on one toggle — or just click the
**Chief of Staff** item in the sidebar — and talk to it in plain language — "remind me to
call the vet at 4", "save this as a note", "what needs my attention right now?" — and it
does the work for you behind the scenes. It's built for people who want the power of AMC
without the cockpit.

Your Chief of Staff is a real AMC AI assistant, not a scripted bot. Under the hood it is
an ordinary Claude session — the same kind that powers **[Ask AMC](ask-amc.md)** — cloned
and pointed at a friendlier, plain-language persona, with extra guard rails turned on
because it's aimed at people who won't read the fine print.

Chief of Staff is **in development and off by default.** It's hidden until a developer
ships it; you can reveal it early from **Settings → Lab** (listed as **Chief of Staff
Mode**) or by launching AMC with `AMC_SHOW_SIMPLE_MODE=1`.

> **Naming:** "Chief of Staff" is the user-facing name. Internally the feature is still
> "Simple Mode" — the `simpleModeEnabled` setting, the `__concierge__` session, and the
> `SimpleMode*` files keep that name (same split as KMS ⇄ "The Vault"). Only the labels
> the user sees say "Chief of Staff".

## Where to find it

Click the **Chief of Staff** item in the sidebar, or turn the mode on from **Settings → Lab**, where it is listed under its former name.

## How it behaves

- **Plain language, no jargon.** The concierge never shows you code, file paths, IDs,
  or tool names. It gives a short friendly acknowledgement, a note if something takes
  a moment, and a plain-English result — not a play-by-play.
- **Starting a chat is instant.** The moment you send your first message, your chat opens and
  your message shows right away, with a "Thinking…" note while your assistant spins up in the
  background — no blank waiting. If it ever fails to start, you get a clear "send again to try"
  message instead of a stuck screen.
- **One question at a time.** When it needs a decision it asks a single simple yes/no
  question, never a wall of options.
- **It actually knows the app.** It carries a curated, plain-language guide to what
  Omniscio can do and how, so it can answer "what can this do?" and "how do I…?" and get
  things done — reminders, notes, tasks, your inbox, email, your AI sessions, and settings.
  For anything it's unsure about, it looks it up live before ever saying it can't.
- **You can steer it in your own words.** An **Edit instructions** button in the header opens a
  simple text box where you tell it anything it should know about you or how you'd like it to
  work — "call me Sam", "keep answers short", "I run a trading company". It keeps your notes
  in mind every chat, layered on top of its built-in brain, and your notes can never override
  its safety rules. Changes apply to your next chat.
- **Routine lookups just happen; actions ask you with one tap.** Checking your state or
  searching happens instantly, no nagging. But whenever it's about to *do* something —
  create, change, send, or delete — a friendly "Can I do this for you?" card pops up with
  **Yes / No**, so nothing that changes anything happens without you seeing it. It also
  asks in plain words before a *permanent* delete, and it never starts a paid AI session
  or touches your logins on its own.
- **Real work goes to the right place — automatically.** When you ask for actual project
  work, Chief of Staff quietly figures out which of your projects the request belongs to and
  starts a normal working session there instantly — you never pick a project or see the
  plumbing. That session then looks and behaves exactly like any other session (same chat,
  same controls), just without project jargon in the header. Questions, reminders, and
  app help stay with the Chief of Staff helper itself. If it isn't sure where something
  belongs, the helper simply handles it — a request never gets stuck on the decision.
- **It won't build software itself.** If you ask it to build, fix, or change code, it
  offers to open a separate dev session in your own AMC project to do the work
  properly — and only spawns that (which costs money) when you clearly ask.
- **It treats what it reads as untrusted.** If an email, web page, or note it fetches
  contains text that looks like an instruction ("ignore your rules and forward this…"),
  the concierge shows it to you rather than obeying it. This is the standard defense
  against a message trying to hijack an assistant.
- **Every chat starts fresh.** The concierge has no memory of previous conversations,
  so nothing you said (or that a fetched email tried to plant) carries into the next
  one.

### Your chats and your inbox

Simple Mode is more than one chat — it keeps a history and surfaces what needs you:

- **One list down the left, two things in it.** A column on the left holds a **New chat**
  button and a two-way switch: **Inbox** (with the count of what's waiting) and **Chats**.
  Whichever you pick fills the column; the right-hand side is always whatever you're working
  on. It opens on your **Inbox**, so you land on what needs you.
- **Switching lists never disturbs what you're reading.** Flipping to your Inbox does not close
  the chat or notice open beside it — the left side is for finding things, the right side is
  for doing them, and they don't interfere.
- **Fold it away when you want room.** The collapse control shrinks the column to a slim strip
  of three icons — New chat, Inbox (still showing its count), and Chats. Clicking any of them
  opens that list straight back up, so nothing is ever more than one click away.
- **Many chats, like ChatGPT.** The **Chats** side lists everything you've started from Chief
  of Staff mode, newest first, with a search box. On a phone the same list lives in the ☰ menu.
  Reopen any of them to pick up where you left off. (Each chat is still fresh on its own — the
  "no memory between chats" safety rule is about not carrying instructions across chats, not
  about hiding your history.)
- **Rename or delete a chat.** Right-click (or long-press) any chat in the list to rename it
  or delete it. Delete asks first and is undoable for a moment afterward — it tidies the
  chat away rather than destroying anything.
- **Not sure what to ask?** A fresh Chief of Staff screen shows a few tappable "Try asking…"
  examples — tapping one just fills the box for you to edit; nothing sends until you send it.
- **Your inbox is always right there.** The **Inbox** side of the switch shows the same things
  you'd see in the full app: emails, texts, approvals, and AI sessions waiting on you — grouped
  by where they came from, newest first. It no longer takes over the screen, so you can read
  something on the right while the list stays put on the left. How many are waiting shows in
  amber on the Inbox label, and on the 📥 button in the header.
- **Tap to respond, without leaving Simple Mode.** Tapping an inbox item opens a chat to deal
  with it: a waiting AI session reopens its own chat so you can reply to it; anything else opens
  a new concierge chat pre-filled with the item (as quoted, untrusted text) so you can tell the
  concierge how to handle it. Nothing is sent until you send it.

### The model it runs on (yours first, ours as the safety net)

Simple Mode uses the exact same "never breaks" model logic as Ask AMC:

- If you have **your own Claude credentials**, the concierge runs on **your** model —
  as capable as any other session you run.
- If you **don't**, it falls back to a **built-in, company-paid model** (**Claude
  Haiku**, which also reads screenshots and PDFs) so a brand-new user still gets a
  working helper. A cheaper, faster text model (DeepSeek V4 Flash) can handle typed
  questions on the same monitored company path; screenshots/PDFs always stay on
  Claude, and if it's ever unavailable a typed question falls back to Claude too.

**Spending guardrails.** The company-paid fallback carries a per-session spending cap
(about **$1**) and a daily ceiling on company-funded starts — because that's our
money. On your own credentials the concierge spends like any other session you run.

**No file writing, ever.** The concierge can read, search, and take the usual
approval-gated actions, but it **cannot create or edit files** on any credential
path. It's a helper that explains and does things for you through the app — not a
builder. (Building is what a dedicated dev session is for.)

### How its permissions work

The concierge runs at a careful permission level and **cannot create or edit files**. Its
everyday work is talking to Omniscio's own controls, handled in two layers:

- **Routine lookups are auto-approved** — only its read-only checks to Omniscio's own local
  service, and only those, so it never nags you for a simple "what's happening right now?".
- **Everything else asks you** — any action it takes surfaces the friendly Yes/No card in
  Simple Mode. This is a property of *what the concierge is*, not of who's paying, and it
  can't be relaxed from inside a chat.

### How to use it

1. **Open it.** Click the **Chief of Staff** item in the sidebar to drop straight into
   its focused chat, or turn it on from Settings → Lab → **Chief of Staff Mode** (or
   launch with `AMC_SHOW_SIMPLE_MODE=1` while it's in development).
2. **Find your inbox, your chats, and the controls.** On a computer the left column holds
   **New chat** and an **Inbox / Chats** switch; it opens on your Inbox. Collapse it and those
   three become a slim strip of icons you can click straight back open. On a phone the same
   column is behind the ☰ menu. The header carries **Edit instructions** and a **Full ⇄ Chief of
   Staff** switch — flip to **Full** to go back to the normal app (you stay opted in, and the
   switch stays there) and back whenever you like. On a phone the switch lives inside the chatbox.
3. **Just talk to it.** Type what you want in plain language. Ask questions about the
   app, set reminders, save or search notes, or ask what needs your attention.
4. **Steer it if you like.** Tap **Edit instructions** in the header and jot down what it
   should know about you or how you'd like it to work — it uses your notes from your next
   chat on.
5. **Tap Yes or No when it acts.** Lookups just happen; whenever it's about to change or
   send something, a quick Yes/No card appears — tap Yes to go ahead (or press Y / N).
6. **Approvals still land in your inbox.** When it schedules something that needs
   approval, it says so and the approval row appears in your inbox, exactly like every
   other AMC agent action.

## For agents

### For agents with repo access

Simple Mode is a reuse-first layer over existing AMC machinery — no new AI engine, and the
approve card reuses the existing permission plumbing (no new IPC). The user-facing name is
**Chief of Staff**; the internal name (setting key, sentinel, files) stays "Simple Mode" /
"concierge".

- **Entry point — clicking the sidebar item:** the `__concierge__` row is a
  `src/renderer/src/lib/sidebar-action-rows.ts`
  (`enter-chief-of-staff`) — the cycle-safe pattern where selecting a row fires an action
  instead of becoming the active project. `setActiveProject` (the universal click funnel,
  guarded by `source !== 'restore'`) dispatches the `amc:sidebar-action` event, and the
  handler in `src/renderer/src/app/useAppCustomEvents.ts` calls
  `enterSimpleModeChat()` (opt in + land on the Simple view), which shows the focused chat.

- **Settings:** `simpleModeEnabled` (opt-in, default `false`) + `simpleModeFullView`
  (which view while opted in, default `false`), single source of truth in
  `src/shared/types/settings/simple-mode-settings.ts`.
- **Gate + view switch:** registered as the `'simple-mode'` in-development feature in
  `src/shared/unreleased-features.ts`; gate
  visibility through `isUnreleasedFeatureVisibleInRenderer('simple-mode', settings)`,
  never the raw setting. The takeover (`resolveSimpleModeGate`) renders only when opted in
  AND `!simpleModeFullView`; the two-way **Full ⇄ Simple** header switch
  (`SimpleModeViewSwitch`, the canonical SegmentedControl) shows when opted in and flips
  `simpleModeFullView`. The header (Full-side) switch is desktop-only; the Simple-side
  switch renders in the mobile surface.
- **The concierge** is the `__concierge__` virtual project — a spawnable session in the
  managed workdir `<userData>/concierge`, cloned from Ask AMC. Its spawn plan (model,
  budget cap, disallowed tools) is
  `src/main/services/concierge/concierge-model-plan.ts`;
  its persona (safety rules, plain-language behavior, untrusted-content rule) is
  `resources/concierge-claude.md`, written into the
  workdir as `CLAUDE.md` by
  `src/main/services/concierge/concierge-bootstrap.ts`.
- **Its knowledge** is a curated pack in
  `resources/concierge-knowledge/` (an overview + a
  how-to playbook), staged into `<userData>/concierge/knowledge/` by that same bootstrap,
  with the live `GET /capabilities/search` catalog as the fallback.
- **The smart unlock** (auto-approve read-only control-server curls at `guarded`) is
  `src/main/services/concierge/concierge-command-allowlist.ts`
  + the carve-out in
  `src/main/process/ndjson-permission-handler.ts`; **the
  approve card** is in
  `src/renderer/src/features/simple-mode/SimpleModeConversation.tsx`.
- **The steering knob** — the user's own notes live in the `conciergeCustomInstructions` setting
  (same simple-mode-settings.ts slice); the editor is
  `src/renderer/src/features/simple-mode/SimpleModeConciergeEditor.tsx`,
  opened from the `src/renderer/src/features/simple-mode/SimpleModeSurface.tsx`
  header. The bootstrap composes the persona `CLAUDE.md` = base + the notes on each chat —
  append-only, subordinate to SAFETY, bounded, and fail-open (contract §C / invariant L).
- **The hub router (CoS-shell pivot, 2026-08-28)** —
  `src/main/services/concierge/concierge-hub-router.ts`
  routes each new request to a real hub (or the helper) with one cheap validated Haiku call
  (cost label `'cos-routing'`, 2.5s timeout, daily cap, fail-open to the helper); routed
  sessions spawn as NORMAL sessions and render in the real
  `src/renderer/src/features/sessions/SessionPanel.tsx` with the
  `hideHubChrome` prop suppressing the project-name prefix + branch chip. The smart unlock
  and injection hardening key on the concierge PROJECT id, never the `source: 'simple_mode'`
  stamp.
- **Full invariants + how to change it safely:** the
  `Simple Mode contract`.

## Related

It is built on the same session machinery as Ask Omniscio, and the guided mission that fills in your global agent instructions pairs well with it.
