Continuity belongs to the project, not to any single agent.
A local-first human–agent collaboration space where the project is the enduring subject.
English documentation · 中文 · Project positioning · Architecture · Contributing · Security · Apache 2.0
Important
Carryforth is under active development. The repository is currently intended only for local source builds, functional evaluation, and study. No stable installer has been released, and the project does not yet promise production deployment, formal support, or a stable upgrade path for existing data.
Carryforth is an independent project developed and evolved from the
block/buzz source code released by Block, Inc. under the
Apache License 2.0. It is not a from-scratch rewrite. Buzz's Desktop, local Nostr Relay,
agent runtime, and collaboration foundations provided Carryforth with a strong engineering
starting point.
We thank Block, Inc. and all Buzz contributors for their work in open source. We also recommend the original Buzz project to readers interested in local-first collaboration, Nostr, and agent workspaces.
On that foundation, Carryforth continues to explore what it means for the project—not an
agent—to be the enduring subject. It adds and reshapes Project View, Role Continuity, Project
Documents, Project Context, structured Meetings, the local single-Relay boundary, and the
agent-first cf CLI.
Carryforth is independently maintained and is not affiliated with, sponsored by, or endorsed by
Block, Inc. Its public source baseline is a reviewed, squashed import based on
block/buzz@ab3af828;
the Carryforth repository does not reproduce Buzz's commit ancestry. It retains the applicable
upstream license and copyright notices, while Carryforth's own NOTICE records that
attribution. See LICENSE and UPSTREAM.md for details. Existing buzz-*
names, BUZZ_* environment variables, and some database, protocol, and bundle coordinates are
wire/storage/data-continuity compatibility contracts. They do not represent the current product
identity.
Today's agents are good at completing a task, but they do not naturally carry a long-running project forward. Context often remains inside a conversation, a Leader, or one agent's memory. When the session ends, the model changes, the team dissolves, or a member leaves, the project often has to explain itself again from the beginning.
Carryforth reverses that relationship: the project persists, while humans and agents join it as members with roles and responsibilities. Members may enter, leave, recover, or be replaced, but the project's understanding, work state, documents, context, recorded choices, and commitments remain.
The fundamental unit is not a conversation, a code repository, or a temporary agent team. It is the project. An agent is a member with an independent lifecycle. Even a Leader neither owns all project context nor serves as a prerequisite for the project to continue.
Carryforth is not a super-agent that “remembers every chat.” It provides a shared project space where humans and agents collaborate through the same identities, permissions, and project state, and continuously write back the information that will affect future work.
Project View brings together project direction, plans and stages, roles, attention items, and resources so that humans and agents can continue from the same verified project state.
Project Context organizes explicitly preserved relationships among project objects, Documents, and Meetings into a browsable context graph. Layout is only for navigation; it does not imply ranking or causality.
This local-development capture shows Meeting action-recording recovery protection: the shared Board and existing outcome record remain visible while action materialization awaits recovery. It is a recovery-state example, not an idealized completed Meeting.
Project / Community
│
├── Project View
│ ├── Project Profile
│ ├── Goal
│ ├── Role
│ ├── Plan
│ ├── Stage
│ ├── Requirement
│ ├── Issue
│ ├── Work
│ └── Resource
│
├── Project Documents
├── Project Context
├── Meetings
└── Human / Agent Members
Project View preserves first-order current state. Documents preserve evolving project content. Project Context explains why objects are related. Meetings carry formal collaboration. Roles, Assignments, Checkpoints, and Handoffs allow responsibility to continue when an agent runtime changes.
See the core model for the identities, relationships, and boundaries of each model.
A Role is a stable responsibility held by the Project; an Assignment is one tenure in which a Human or Agent Member bears that Role. Work Responsibility persists across tenures, while a Commitment is attributed to a specific Assignment and Member. Continuously appended Checkpoints, optional Handoffs, and a derived Role Brief let a successor resume from Project state without waiting for the predecessor to return or provide an exit summary.
See Core design: Role Continuity.
An Agent can use its current Role and relevant Work, Issue, Meeting purpose, or other verified task
facts to progressively retrieve Project Context. It normally starts from a Coordinate already
identified by current work; when no reliable start exists, semantic Coordinate discovery proposes
candidates for the Agent to inspect. The Agent then alternates Coordinate → Edge → Coordinate,
using semantic ranking to narrow each local choice, lightweight canonical observations to reject
misleading matches, relation Documents to preserve why a hop is valid, and complete canonical reads
only when the task actually needs them.
This is how the same question can lead Agents in different context environments to different but related, traceable context paths. All Agents still read one Project-owned Context Graph—there is no private graph per Role or Agent. Semantic ranking does not select a path by itself, traversal follows only real undirected Hyperedges, and retrieval never creates or rewrites Project relationships.
The semantic parts are not fully local. Indexing may send source type, current visible title/name,
and an optional summary to the user-configured Provider; the current foundation does not send
Document bodies or chunks. Natural-language start and one-hop searches send their query text to the
same Provider. The supported local start.sh path treats startup as authorization for that Provider
egress and idempotently prepares the exact loopback Community's semantic gates and active
generation. Raw Relay and production startup retain their fail-closed defaults.
See Core design: Agent-directed context-aware Project Context retrieval.
The repository currently connects the following capabilities inside one local project boundary:
- Carryforth Desktop: project navigation, Project View, Documents, Project Context, and Meetings;
- local Relay: Community permissions, signed events, canonical state, queries, and audit boundaries;
- ACP-managed agents: run as project members with a controlled Carryforth environment;
- the
cfCLI: agent-facing messages, project objects, documents, context, meetings, and media; - Channels and Messages: everyday collaboration over signed Nostr events;
- preview Git project collaboration and content-addressed media;
- optional, gated semantic discovery and Agent-directed progressive Project Context retrieval.
The Relay is the current canonical state boundary. The system validates and preserves structure, but it does not automatically understand the whole project or promote every chat, draft, or model inference into project fact.
Implemented does not always mean enabled by default in a new environment. The Project View interface is enabled by default in Desktop, while Meetings and Git Projects still have preview switches, Relay readiness checks, durable Community gates, or signed initialization requirements. The exact local greenfield Desktop path creates an owner-signed blank Project View and Relay-signed, revision-zero empty Document and Project Context catalogs; remote and manually governed Communities keep their operator workflow. The supported local source launcher also prepares semantic state by default, but structural Project Context remains usable when no semantic Provider is configured. See Current status for exact capability and activation boundaries.
The supported workflow today is local development and evaluation from source. Prepare Docker 24+
with Compose v2, Python 3, curl, and the native dependencies required by Tauri, then run:
git clone https://github.com/lgYanami/Carryforth.git
cd Carryforth
./start.shThe script only checks external system dependencies. It does not install Docker, Python, curl, or
operating-system packages. On first run, it creates a private local .env. Source startup defaults
the semantic Worker, complete-path Query, Coordinate discovery, and one-hop search process switches
to enabled, so it prompts for a Provider API Key, HTTPS Base URL, and Request Model when they are
missing—none has a default. It then idempotently prepares the exact local Community's index/query
gates and active generation. When the first Human identity claims that exact loopback Community
through Desktop, Desktop signs a minimal Project View containing an untitled profile, one blank
Goal, and one unassigned Leader Role; the Human remains the independent Community owner. Relay
validates the command and atomically enables the capability. It then signs and enables empty
Document and Project Context catalogs and publishes Community Meeting reads only after proving the
Meeting corpus is empty. No default Document, Context Edge, binding, or Meeting is created. Relay
never signs on the Owner's behalf, and every surface retains its normal canonical-state and
readiness fences. You can explicitly disable all four semantic switches before startup; setting
BUZZ_MEETING_COMMUNITY_READ_ENABLED=false opts out of the local structural Context bootstrap.
Existing Docker volumes and project data are preserved.
Warning
This is a trusted-machine development stack. The checked-in .env.example binds the Relay to
loopback, the raw Relay default is also loopback, and the checked-in Compose file publishes
dependency ports on loopback. All local services still use development credentials. Run it only
on a trusted machine; do not deliberately expose these ports to a LAN or the Internet without a
separate security design.
See Local development from source for the full lifecycle, instructions for disabling semantic configuration, rebuild commands, and stop commands.
- English documentation
cfCLI function reference: every current command group and executable subcommand, plus identity, output, conflict, and capability boundaries- Core model: Project View, Role Continuity, Documents, Context, Meetings, and Members
- Core design: Role Continuity: how responsibility, tenure, Work commitments, and externalized situation survive agents and runtimes
- Core design: Coordinates before context: coordinate context, relational context, and progressive discovery by agents
- Core design: Agent-directed context-aware Project Context retrieval: how Agents use Role and work context to choose different but related paths through one shared graph
- Core design: Meeting: how humans and agents aggregate distributed context, form a shared conclusion, and produce explicit outcomes
- System overview: components, data flow, identity, permissions, security, and local-first boundaries
- Local development: prerequisites, configuration, build, start, stop, and data protection
- Current status: preview capabilities, activation requirements, local scope, and deferred artifact boundaries
- Project positioning and the Project Space Constitution
Carryforth is an actively developed source project. Its current public scope is limited to local source builds, functional evaluation, and study. No binary, installer, container, or other packaged release is part of this scope, and the project does not promise production deployment, formal support, or a stable upgrade path for existing data.
The current local evaluation scope focuses on Linux Desktop, a local single Relay, ACP-managed
agents, the cf CLI, and Channels, Messages, Project View, Documents, Project Context, and
Meetings. The Web client is also a source-only surface. macOS, Windows, automatic updates,
production multi-instance deployment, and long-term upgrade support are not committed.
Read CONTRIBUTING.md before contributing code. Report vulnerabilities privately through SECURITY.md, not through a public issue.
Carryforth source is distributed under the Apache License 2.0, retains applicable upstream copyright notices, and provides independent attribution in NOTICE. Third-party dependencies and assets may carry their own licenses; the current source audit and the deferred future artifact boundary are documented in release/THIRD_PARTY_ASSETS.md.


