Local control plane for coding agents

Put your coding agents to work, without giving up control.

Nodal supervises Claude Code and Codex across isolated worktrees and human-gated integration. Your agents work in parallel, and their work comes back as a branch you review before anything merges.

Request a beta invite
What you get

Three things a supervisor has to guarantee.

Guaranteed

01 · IsolationWork in parallel without collisions

Agents never edit your working tree. Session agents work in Nodal-owned git worktrees, pipeline agents in a staged clone outside the repo, and their work reaches you as a branch and a pull request.

02 · DurabilityRuns survive interruption

Transcripts, approvals, run records, staged transfers, and committed work are durable across reconnects, worker restarts, crashes, and project reopens. A crash ends the live agent process, and Nodal tells you exactly what stopped rather than pretending otherwise.

03 · The gateNothing permanent happens by implication

Merging is a human action that no autonomy setting can grant. Context sharing, spend and destructive calls pass through explicit gates, and approval is bound to the exact action and material you reviewed.

How it works

Four steps, and you are in the loop for the last two.

Nodal drives your logged-in Claude Code and Codex sessions, so runs bill the subscription you already pay for. It does not resell inference.

Agent territory
Roundtable

Stop copy-pasting one model's answer into another.

Put Claude Code and Codex in the same room. Nodal runs structured positions, critiques, revisions, and comparison, then shows accepted points, unresolved disagreements, and evidence linked to the exact frozen context each model received.

Multiple models review the work. You make the call.

Roundtable · auth/session-refresh
Claudeposition

Refresh the token on every request where expiry < 60s. Simple, and it never serves a stale session.

Codexcritique

That fires a refresh per in-flight request. Under concurrency you get a token stampede and the last write wins. Refresh once behind a lock.

Your ruling Take the lock. Ship it.
Surfaces

Six places you actually work.

01 — 06
01

Sessions

Resume managed work or start from a goal.

02

Operator

Delegate an autonomous run with visible limits and controls.

03

Roundtable

Structured cross-model critique with frozen context.

04

Map

See agents, branches, dependencies, locks, and contention.

05

Requests

Rule on every gated action from one audit surface.

06

Cost

Track spend per project and per run against a monthly budget.

Trust machinery

Safety claims should survive contact with the implementation.

Pipeline agents run under a macOS seatbelt write fence confined to their staged run folder. Session agents run in Nodal-owned git worktrees rather than under the OS fence, because confining them would mean admitting the shared .git directory and everything in it. Reads stay broad and the model CLIs reach the network. Nodal keeps its state on your machine and records activity in a hash-chained event log whose head is stamped into the git commits it writes, so the history can be checked by something other than Nodal.

01

Write-fenced pipeline runs

02

Tamper-evident audit chain

03

Enforced operator ceilings

04

Unarmable merge gate

What we do not claim Stated plainly

Session agents are not OS-fenced. Reads are broad and the model CLIs reach the network, so a run can read anything your user account can. The monthly budget tracks spend and warns, it does not block it; the enforced ceilings are the operator's. Old audit entries age out under a retention window. And if you turn on API-key mode for the operator, your Anthropic key is stored on your machine, encrypted by the macOS keychain, and goes nowhere except Anthropic.

Category

Nodal is not another coding agent.

Claude Code and Codex produce work. Nodal coordinates, isolates, supervises, reviews, recovers, and integrates that work.

Performs a task Coordinates agents and tasks
Operates in a session Preserves durable run state
Produces changes Isolates and gates integration
Reports its own output Enables cross-model critique
Uses provider access Supervises access you already own
The beta

Small, on purpose.

Beta 1 is free, invite-only, and built for macOS on Apple silicon. It currently supports Claude Code and Codex through their existing CLI sessions. The first cohort is limited to 20 to 50 developers.

Request a beta invite
Cohort 120 — 50 seats
Filled seats shown solid