LockFlare

Themis (the activity)

Authorization. Two lists, Authorized and Awaiting authorization, one verb each. Authorizing a server creates one folder, /var/lib/lens, where her reports, the baseline and the run ledger live — no agent, no daemon, nothing listening, no AI call and no cost; removing the folder removes every trace. Authorize All runs in the background, 5–10 in parallel, over shells already open (Lens will not open a connection on its own to change a machine).

Fleets. A named SELECTION of servers drawn from anywhere on the map — two boxes from one group, one from another, three from a third — with the words Themis is given before she reads them. The picker is the map with checkboxes; drag works too. A fleet is never a parallel list of groups.

Ask across servers. One conversation over many sessions: the fleet on screen, or whatever is ticked for a one-off question with nothing saved. Servers without a shell are opened first in one batch behind a lightbox that counts them in; the question is not sent until every one is up or has given up. Proposals arrive one at a time with Run / Show me / No, each saying in words what is authorized; a transcript is kept per fleet and one for the chair.

Themis in LockFlare Lens proposing a change with Run, Show me and No
A proposal, not a command to paste: Run, Show me the exact script, or No.

The model she thinks with. Set per drive under Setup: the provider (Anthropic, OpenAI, xAI), the model, whose account pays (the API key sealed in the credstore, never in the map document), and how much she may write (the model's own ceiling). The model catalog is a document Go holds — the one the build shipped with, or a newer one downloaded only from a button; Lens never calls home on its own.