Open build · Agent plugin · Human approve

The trust runtime agents plug into.

Ghost is not another AI agent. Claude, Cursor, and Codex may propose and start work; Ghost stops for send/pay/submit, verifies outcomes, and seals a hash-chained audit log. Designed so a manager can trust the run — not just the demo.

Solo project by Muhammad Rafiq · working name may change · commercial intent, no fake logos

The loop

Capture → Review → Approve → Execute → Verify → Recover

Agents may propose. Deterministic code executes only approved plans. Sensitivity is decided by a classifier — not a model hoping for the best. Agents never approve.

  1. 1

    Capture

    Demonstrate the workflow once. Compile into editable, typed steps. (Recording is the next build phase.)

  2. 2

    Review

    Inspect every step before it can run. No silent send, pay, or overwrite.

  3. 3

    Approve

    Risky steps halt. A human decides. The engine cannot skip the gate.

  4. 4

    Execute

    Replay via browser automation today; APIs/connectors next — still through the same pipeline.

  5. 5

    Verify & audit

    Assertions + screenshots per step. Hash-chained audit events per organization.

Proof, not pitch

What works in the repo today.

Phase 1 of the cloud product is runnable end-to-end against a bundled fixture: navigate → fill → halt on Submit → approve → resume → verify → succeed. If it isn’t in this list, don’t assume it ships.

Engineering

Stack you can actually clone.

Self-contained Turborepo under cloud/. Legacy Rust/Tauri desktop remains in-tree for history — it is not the product being built.

Web

Next.js 15 · Auth.js · org-scoped API routes

Worker

BullMQ · Playwright · approval state machine

Core

Prisma · Postgres · Zod step schema · audit chain

Agent

HTTP /api/agent · MCP stdio · no self-approve

Ops

Redis queue · disk/S3 artifacts · Docker Compose local

Product sense

Who this is for — when it graduates.

The design target is operations-heavy SMBs (wholesale, bookkeeping, property admin, logistics) that re-key work between ugly systems and cannot accept unsupervised agents. That ICP guides the build even before the first paid pilot.

Cross-app grunt work

Reporting, reconciliation, document processing — repetitive and measurable.

Human on the sensitive step

Send, pay, delete, submit must stop. That constraint is the product, not a bug.

Proof afterward

Screenshots, verification, audit chain — something a manager can review.

Positioning

What this is not.

Not a chatbot wrapper Not a Zapier clone Not unsupervised “agentic” magic Not agent self-approval Not a fake customer page

Built in public. Aimed at a real business.

I’m building Ghost as a serious systems project — trust pipeline, tests, and a runnable cloud engine — with the long-term goal of selling implementation + seats to ops teams. Today: open source, early, no logos. If you hire for product engineering or want to follow the build, the repo is the résumé.

Working name: Ghost (likely to change before a real go-to-market). Direction will not: approval-gated execution with verification and audit.

Archive

Legacy desktop preview (not the résumé piece).

An earlier local-first Mac/Windows Organizer build (v2.0.3) is still downloadable for reference. The active work — and what to judge — is the cloud operator under cloud/ on GitHub.

Legacy · optional

Desktop preview downloads

v2.0.3 for macOS and Windows — superseded by the cloud build.

macOS 12+ · Apple Silicon & Intel · Windows 10/11 · v2.0.3 — macOS notarized; Windows unsigned (SmartScreen may warn). All releases → · SHA256SUMS