SABLE

You're signed out

Your work keeps running — tasks continue in the cloud and will be waiting when you return.

Go to ashleystewart.com →
SABLE
G Ashley · authorized users only

Waiting for your email…
Tap the link in the email — this screen signs in by itself — or type the 6-digit code:

Use a different email · check spam for "Sable sign-in" the first time

✨ Sable has been updated. Reload when you are ready — your place and anything typed to Iris are kept; other unsaved boxes are not.
SABLE
📱 Add your mobile device so Sable can reach you with the app closed: open on your phone, signed in, and allow notifications.

My Workspace

My requests

Everything you've asked — Teams, portal, email, SMS — in one place, with its tracking id and status.
Loading…

Waiting on you

Loading…
Hand this over — a block to paste into another session

        
      
Remind me about something
#TaskRepoRouteStatusPR

New Task

A report or an analysis starts from this one message. Coding work needs a repository — I will pick one from what you said and tell you why.

Proposed plan

This is a proposal. Nothing is queued until you choose. There is no timer — it waits.

Set it up in detail instead

Coding task — a repository, a branch, a pull request. Reports and analysis are built in Reports → Report builder.

Coding tasks use PR-only writes — Sable never pushes to main (SBL-015)

Tasks

Your coding and orchestrator work — open, completed, archived — on this project, not on My Workspace.

#TaskRepoStatusPR

Sessions

Work done in Claude Code or Cowork on your own machine, brought here so it is visible alongside everything else. These did not run on Sable's runner.

Where do these come from?
Claude Code writes every session to a .jsonl transcript on your own machine, under ~/.claude/projects/. Sable cannot reach that folder — your browser has no access to it — so a session gets here one of two ways.

One session, by hand: press Import a session above and pick the .jsonl file. Importing the same file again UPDATES that session rather than making a second copy, so it is safe to re-import as work continues.
All of them, from the machine: run the courier, which reads the folder directly:
node scripts/import-session.js --all
It needs SABLE_URL and SABLE_SESSION set in your environment; it imports as you, into your account.

Only the conversation is carried over — the messages, and counts of the tool calls. Sable does not receive your files, your keys, or the repository itself.

Orchestrate this task

A split is disjoint by file. Each part owns the files listed under it. Nothing starts until you press Launch — you can adjust the parts first.

Sessions
Imported Claude Code / Cowork threads filed under this task. The same list as Sessions, scoped here.
Oracle needs confirmation

Two answers to the same point

Changes


    
The full transcript stays saved. Mute shows only the outcome or required action.
+

My Profile

Build: checking…

My own department

Projects you keep here are yours: they are in none of the estate's departments or rollups, nobody is added to them automatically, and they are left out of the conflict scan. Leave the name empty to call it Personal.

Talk to Iris

Ask Iris a question out loud while you are working in Sable. She is told nothing about your Projects and looks up every answer as you — so she can tell you exactly what you could read yourself, and nothing else. Off unless both you and an admin turn it on, because it bills by the minute.

Project master code

A session uses this to create a Project as you. Five characters, no 0 O 1 I. Give the session this code and any mailbox on Me (primary or linked). Refreshing it does not break existing page links — only new creates need the current code.

—————

What Sable does

Everything your account can reach, and what to ask for.

What I am responsible for

Report workflows and agents you hold a role on. Roles are granted by an admin.
Loading…

Text messages

Read the full policy

Reaching me on my phone

My Knowledge

Facts, decisions and preferences Oracle should carry into every conversation. Company records apply to everyone and win if they conflict with yours.

My email addresses

Any of these signs you in to this account, and a report sent to any of them appears in your Reports. One report is listed once, however many of your addresses it went to.

My usage

Loading…

What Iris remembers about you

Set up how Iris works for you

A preference is how you like answers — “give the number before the explanation”. A skill is something to always do — “open the workbook before answering an R1 question”. Both are yours alone, and a company rule always outranks them.

      

My fallback chain (SBL-011)

OrderCredentialKindEnv refHealth

Personal accounts power only your tasks. Values are never shown — only the env-var name that holds them.

My Codex subscription

Connection not checked.

Enter this code on the OpenAI sign-in page:

Open OpenAI sign-in

After signing in, choose Check connection. Keep this code private.

Link a personal account

Help

What your account can reach, and what the company has written down.

Show me around

The short walkthrough. Same one as the first day.

1 / 1

Features

What your account can reach, in chapters. The same list Iris reads — it cannot describe a Sable that is no longer here. Features that landed in the last two weeks are marked NEW; older screens have no date, so they do not wear one.

Loading…

← Help

Handbook

What the company has written down, as it is — every row says where it came from and how old it is.

Loading…

← Help

Loading…

← Back

Terminal

A shell in the runner container — node, npm, git, python3, pandoc, LibreOffice, Chromium. Work inside it is free. Anything that leaves it — a push, a deploy, publishing — is held for approval, exactly as it is for Oracle.

How to use this
1. Start a session. Press Open a terminal. To work on a repository, put owner/name in the box first and it is cloned for you; leave it blank for an empty scratch container.
2. Type a command and press Enterls, npm test, git status, python3 script.py. cd is remembered between commands, so you stay where you moved to.
3. Three kinds of command. Most run immediately. A few ask first — anything that rewrites history or deletes in bulk. A few are refused outright and become an approval request instead: pushing, deploying, or sending anything outside the container.
4. The container is temporary. It is yours until the session ends. Commit and push (which asks for approval) if the work needs to outlive it — files left in the container are gone when it stops.
Long output is trimmed from the MIDDLE, so the command you ran and its final result are both always visible.

Change Sable itself

Describe the change and Claude does it in a session on this repository — a branch and a draft pull request, never a push to main. You review the PR as you would anybody's.

      

Report Builder

Build a standard report from your files. It stays a draft until Samarth locks it — nothing you do here reaches anybody.

Projects

A Project is a numbered folder of published pages — a BRD, a plan, a guide — that its collaborators read, comment on and refresh, and that a session can be pointed at by link. How Projects work.

← All Projects

Spaces

A Space holds files and the conversations about them. Anything you ask Iris inside a Space already has its files — you never attach them twice. Your uploads stay yours: they are not read by the fleet or by any report.

Bug reports

Things handed to Oracle to investigate. Oracle decides whether each one is a fault it can fix, or a change that needs approval first — you are never asked to make that call.

Report a bug

Running now

Your coding runs and the ones you collaborate on — what is working, what is queued, and what has stopped to wait for you. Oldest first, because the thing that has been going on longest is the reason anybody opens this.

Your runs

Loading…

Reports

Upload a report

Send history (admin) — from the mailer ledger

Sent (ET)ReportFileModeRecip.

Create a report route (admin) — no code

Setting recipients emails those people — this is a live distribution change (audited).

Live mailer library (reports.gashley.com) — reference

NameStreamModified

Read-only view of the existing reports dashboard. These stay served there too — nothing is disabled.

Fleet — AS Agents

Loading fleet status…
📄 Roster as text

Purpose and department come from the fleet roster; status comes from the fleet's own /status. An agent in the roster that is not reporting is shown as such rather than hidden. The reconcile never wires an agent up by itself — it tells you one appeared, and a person decides what it is for.

Sable bot

Leave an instruction for a bot; it does the work and posts back here. Never put a password, key or token in an errand — the text is readable by every bot on the seat and cannot be recalled. Name where the value lives instead.

ET
How it has been doing
Loading…
Loading the desk…

The desk asks each bot what became of its run every minute. For the Sable bot a run cannot be reached once it has started — nothing here can call into that machine — so an errand whose run ended without sending anything back is shown as exactly that, rather than as done. The Claude bot does not have that gap: its transcript outlives the run, so the desk can still read the answer out of a session nobody was watching.

Settings

Running now

Loading…

Store health

Loading…

Which code is running

Loading…

Access

Who may read, write or own a report workflow, a Space, or an agent. A role never widens somebody's departments — if the data is not theirs to see, a grant here gives them nothing until an admin allows the department too.
Loading…

Groups

A group is a set of registered people. Adding somebody to it gives them everything the group holds — which is the point, and the reason a group has only two roles of its own: user and admin (of the membership).

Repositories

Who may start coding work on which repository. Sable keeps this list; GitHub stays the authority over what the token can push. Coding is not open to other users yet, so GitHub has never heard of them — assigning here is what makes a repository appear in their New Task picker.
Loading…

What needs you

NetSuite write access

Who may create or update records in NetSuite. Reads are never restricted. A grant is scoped to exact record types and either expires the same working day (break-glass) or stands until revoked, reviewed every 30 days.

Item register

    Iris replies

    Recorded judgement, not a computed flag. ok or fix — empty returns the cell to unreviewed. Identities are already removed. The status workbook stays at four tabs.

    Loading…

    NetSuite replica

    The general-ledger copy the fleet keeps in the vault (MR-0224). Loaded one closed period at a time by the 02:00 backfill; verified against NetSuite's own totals before a period counts as done. This reads the vault directly, so it works even while the fleet is deploying.
    Loading…

    Email subject controls — Superadmin

    Stop Sable emails whose subject contains any phrase below (case-insensitive). One phrase per line. Removing a phrase allows future sends again. Suppression does not approve actions or mark emails sent.

    Loading…

    Code review

    Loading…
    Loading…

    Review policy — estate default

    Who reviews a pull request, how many rounds, and what each covers. The estate default here (superadmin); the superadmin may also set a different policy on one Project from its Settings, where a Project admin reads it but cannot change it. Sessions read the effective policy from the Project brief and invent no rounds.

    Models: usage and spend

    What the models Sable uses cost — not the reviewers, which is Performance next door. Metered inside llm.chat, so every path that calls a model is counted, including the worker's and Iris's. Costs are estimates: tokens priced from a rate table, never a provider invoice.

    By model

    By slot — which part of Sable spent it

    By day

    Performance

    Pulled from the pull requests every Project names, hourly; nothing here is typed. The rating is computed: unique critical + high per run, less half the share of findings that were repeats or lower, discounted by the median wait.

    Sequence — when one pull request saw more than one reviewer

    Learning — did the run use what it was given?

    Accepted lessons — the markdown to paste, by hand

    Browser tests

    The Sable bot as a user
    Loading…
    Runs the full suite on the shared CI runner - unit checks then the browser tests, in four shards. It takes a few minutes and one run at a time; a second is refused rather than queued behind the first.
    Loading recent runs…
    Team — who is using Sable, and how much
    MemberRoleTasksDoneFailed

    Settings

    0 = never send by itself — the mic types what you said into the box and you press Send. Above zero, Iris waits that many seconds after you stop speaking and then sends on its own.

    Default OFF. With it off, Iris drafts an email and you press Send — so a misheard voice command can never mail a colleague or customer. Turning it on removes that gate for every outbound action. Change is audit-logged.

    Default OFF. When a delivery has been handed over and the session filed no walkthrough video, Iris opens the delivered pages, scrolls through each one and files a silent recording on the Build page. Off, Iris films nothing — a session's own video is still accepted. Change is audit-logged.

    Default ON. Coding tasks (including orchestrator children) run on Cursor. Uncheck to force the Claude Agent SDK instead. Needs CURSOR_API_KEY — without it the runner falls back to Claude and says so on the task. Change is audit-logged.

    Default ON. The runner copies the message that started a task — private content, typed into a private tool — onto a comment on a PUBLIC pull request, so a reviewer can see what was asked for. Uncheck it and the review is code-only, and says on the pull request why. A value the code does not recognise is read as OFF: unknown falls to the side where being forgotten is safe. Change is audit-logged.

    DashScope US and intl are always allowed. Add another vendor's hostname here (comma or space separated). An admin then wires the credential — ENGINE_* / COMPAT_* / FUTURE_* variable, https URL on that host, model, order. Localhost and private addresses are refused. Railway COMPAT_ENDPOINT_HOSTS is the same list without a deploy. Change is audit-logged.

    A session link is a bearer credential handed to a program outside Sable; this is how long one reads the Project before it must be accepted again. The browser's own binding still ends after its idle hours or at the daily hour. Change is audit-logged.

    hours days days days

    Recent is hours of a human save; Today is Eastern calendar. Day cuts are increasing whole days; more-than is past the last cut. Opening a card is not activity. Iris and machine writes are not. Change is audit-logged.

    Project codes, comma or space separated. * releases the whole estate. Empty means nothing is swept — the sweep fails closed rather than falling back to all, and the worker says so in its log. The sweep moves a noisy entry off a Project’s business tab and onto its Log; nothing is deleted. Change is audit-logged.

    The sweep takes non-IT Projects first, on the owner’s order. Departments are renamed on this page (R39), so the names that count as IT are read from here rather than typed into the code. Left empty, a usual set of spellings is assumed.

    Rename a department in its row; archive one to take it out of every picker (what already holds it is unchanged); People… sets who is in it — a person may be in several. The super admin may add a department with its report letter; keys and letters are permanent.

    Iris voice connection

    Blank addresses use the built-in provider endpoints. Only approved HTTPS provider origins are accepted. This does not enable voice or change anyone's microphone permission.



    Meeting sources

    Only the mailboxes listed here are authorized for calendar and transcript reads. Accepting an invitation does not add its organizer. Blank fields use deployment settings. Microsoft access permissions still apply.




    Email addresses — what each one is for

    Card map

    Superadmin. Change a card’s parent. The id never changes. A card with no loader cannot be invented here. Family letters and card width are the estate’s — revision 7 — and apply on the next paint.

    px · original Settings size until you change it

    Loading…

    Personas — SABLE & IRIS (name, colour, mark — no deploy)

    SABLE is the platform (the app icon). IRIS is your assistant (the ✨ helper). A change applies the moment you save — no deploy.

    Credentials — org keys & per-user keys

    Press Browse to read the vault directly — files the fleet and custodian have stored.
    Press Show plan to derive the groups from the last 14 days of report sends.
    LabelAssigned toKindEnv var (IT sets value)Status
    Sable runs these same checks automatically at 4:00 am ET, and notifies you only if one changes state.

    Per-user keys serve only that user's tasks. Sable stores the variable NAME only — IT pastes the value into Railway under that exact name. A future Anthropic-compatible engine: pick that kind, name an ENGINE_* / COMPAT_* / FUTURE_* Railway variable, the base URL (DashScope, or a host a super-admin added under Settings), the model, and the order. Coding walks it after Teams and Max automatically — no deploy.

    Routing rules (SBL-012) — edit, no deploy

    OrdTask classMatch keywordsModelRunner

    Reports, IRIS and Oracle

    VM · Sonnet 5 first, Terra 5.6 as backup, OpenRouter · Sonnet 5 third. Coding and escalation are not this chain.

    Model routing — other routine calls


      The day's ceiling — what the whole estate may spend

      Devices

      days

      A person at their limit cannot sign in on a new device until one below is revoked. Revoking frees the slot and signs that device out immediately.

      min min min :00 Eastern

      A session working a Project by its link writes a checkpoint at least this often. Past the interval the Project goes amber and the brief says overdue; past the stop its write doors answer 409 until it checkpoints; past the notify the output's admins get a notice. A Project's own interval, set on that Project, wins over the first number.

      Signing in on a device keeps that person signed in for the number of days above, without asking again — being idle does not end it. Revoking the device ends it at once, which is what makes a long session safe to offer. A browser we have no device for keeps the shorter limits in Settings.

      Who may open Build

      Build stays locked. sam@gashley.com always opens it. Extra mailboxes here also open the tab and may approve a Project to build (or waive an incomplete one). A Sable admin does not, unless named.

      Users

      EmailCodingReportsAdminActive
      Nobody is selected, so nothing below can be changed.
      Test users · find them and switch them off in one press — nothing is deleted

      Can they sign in at all?
      This takes effect immediately and does not wait for Save. Nothing of theirs is deleted either way.
      Says what Sable is, how to sign in, and where Help is. Safe to send again — it contains no code or link that can expire.
      What they can see
      Which departments' data reaches them — admins see all; unticked is blocked on every channel (Teams, portal, SMS, email)
      How Sable reaches them

      A person who does both registers for both services under one login. Report-only users never see coding; coding-only users never see reports. Admin and services are independent — an admin may legitimately lack a service.

      Audit (last 100)

      IIris your guide 🔊 « 🗑