on your phone, signed in, and allow notifications.
My Workspace
My requests
Waiting on you
Hand this over — a block to paste into another session
Remind me about something
| # | Task | Repo | Route | Status | PR |
|---|
New Task
Set it up in detail instead
Coding task — a repository, a branch, a pull request. Reports and analysis are built in Reports → Report builder.
Tasks
Your coding and orchestrator work — open, completed, archived — on this project, not on My Workspace.
| # | Task | Repo | Status | PR |
|---|
Sessions
Work done in Claude Code or Cowork on your own machine, brought here so it is visible alongside everything else. These did not run on Sable's runner.
Where do these come from?
One session, by hand: press Import a session above and pick the .jsonl file. Importing the same file again UPDATES that session rather than making a second copy, so it is safe to re-import as work continues.
All of them, from the machine: run the courier, which reads the folder directly:
Only the conversation is carried over — the messages, and counts of the tool calls. Sable does not receive your files, your keys, or the repository itself.
My Profile
My own department
Projects you keep here are yours: they are in none of the estate's departments or rollups, nobody is added to them automatically, and they are left out of the conflict scan. Leave the name empty to call it Personal.
Talk to Iris
Ask Iris a question out loud while you are working in Sable. She is told nothing about your Projects and looks up every answer as you — so she can tell you exactly what you could read yourself, and nothing else. Off unless both you and an admin turn it on, because it bills by the minute.
Project master code
A session uses this to create a Project as you. Five characters, no 0 O 1 I. Give the session this code and any mailbox on Me (primary or linked). Refreshing it does not break existing page links — only new creates need the current code.
—————
What Sable does
What I am responsible for
Text messages
Reaching me on my phone
My Knowledge
✨Facts, decisions and preferences Oracle should carry into every conversation. Company records apply to everyone and win if they conflict with yours.
My email addresses
Any of these signs you in to this account, and a report sent to any of them appears in your Reports. One report is listed once, however many of your addresses it went to.
My usage
What Iris remembers about you
Set up how Iris works for you
My fallback chain (SBL-011)
| Order | Credential | Kind | Env ref | Health |
|---|
Personal accounts power only your tasks. Values are never shown — only the env-var name that holds them.
Link a personal account
Help
What your account can reach, and what the company has written down.
Show me around
Features
What your account can reach, in chapters. The same list Iris reads — it cannot describe a Sable that is no longer here. Features that landed in the last two weeks are marked NEW; older screens have no date, so they do not wear one.
Handbook
What the company has written down, as it is — every row says where it came from and how old it is.
…
Terminal
A shell in the runner container — node, npm, git, python3, pandoc, LibreOffice, Chromium. Work inside it is free. Anything that leaves it — a push, a deploy, publishing — is held for approval, exactly as it is for Oracle.
How to use this
2. Type a command and press Enter — ls, npm test, git status, python3 script.py. cd is remembered between commands, so you stay where you moved to.
3. Three kinds of command. Most run immediately. A few ask first — anything that rewrites history or deletes in bulk. A few are refused outright and become an approval request instead: pushing, deploying, or sending anything outside the container.
4. The container is temporary. It is yours until the session ends. Commit and push (which asks for approval) if the work needs to outlive it — files left in the container are gone when it stops.
Long output is trimmed from the MIDDLE, so the command you ran and its final result are both always visible.
Report Builder
Build a standard report from your files. It stays a draft until Samarth locks it — nothing you do here reaches anybody.
Projects
Spaces
A Space holds files and the conversations about them. Anything you ask Iris inside a Space already has its files — you never attach them twice. Your uploads stay yours: they are not read by the fleet or by any report.
Bug reports
Things handed to Oracle to investigate. Oracle decides whether each one is a fault it can fix, or a change that needs approval first — you are never asked to make that call.
Report a bug
Running now
Your coding runs and the ones you collaborate on — what is working, what is queued, and what has stopped to wait for you. Oldest first, because the thing that has been going on longest is the reason anybody opens this.
Your runs
Reports
Upload a report
Fleet — AS Agents
Purpose and department come from the fleet roster; status comes from the
fleet's own /status. An agent in the roster that is not reporting is shown as
such rather than hidden. The reconcile never wires an agent up by itself — it tells you one
appeared, and a person decides what it is for.
Sable bot
Leave an instruction for a bot; it does the work and posts back here. Never put a password, key or token in an errand — the text is readable by every bot on the seat and cannot be recalled. Name where the value lives instead.
How it has been doing
The desk asks each bot what became of its run every minute. For the Sable bot a run cannot be reached once it has started — nothing here can call into that machine — so an errand whose run ended without sending anything back is shown as exactly that, rather than as done. The Claude bot does not have that gap: its transcript outlives the run, so the desk can still read the answer out of a session nobody was watching.
Settings
Running now
Store health …
Which code is running …
Access
Groups
Repositories
What needs you
NetSuite write access
Who may create or update records in NetSuite. Reads are never restricted. A grant is scoped to exact record types and either expires the same working day (break-glass) or stands until revoked, reviewed every 30 days.
Item register
Iris replies
Recorded judgement, not a computed flag. ok
or fix — empty returns the cell to unreviewed. Identities are already
removed. The status workbook stays at four tabs.
NetSuite replica
Email subject controls — Superadmin
Stop Sable emails whose subject contains any phrase below (case-insensitive). One phrase per line. Removing a phrase allows future sends again. Suppression does not approve actions or mark emails sent.
Loading…
Code review
Review policy — estate default
Who reviews a pull request, how many rounds, and what each covers. The estate default here (superadmin); the superadmin may also set a different policy on one Project from its Settings, where a Project admin reads it but cannot change it. Sessions read the effective policy from the Project brief and invent no rounds.
Models: usage and spend
What the models Sable uses cost — not the reviewers, which is Performance next door. Metered inside llm.chat, so every path that calls a model is counted, including the worker's and Iris's. Costs are estimates: tokens priced from a rate table, never a provider invoice.
By model
By slot — which part of Sable spent it
By day
Performance
Pulled from the pull requests every Project names, hourly; nothing here is typed. The rating is computed: unique critical + high per run, less half the share of findings that were repeats or lower, discounted by the median wait.
Sequence — when one pull request saw more than one reviewer
Learning — did the run use what it was given?
Accepted lessons — the markdown to paste, by hand
Browser tests
Team — who is using Sable, and how much
| Member | Role | Tasks | Done | Failed |
|---|
Settings
0 = never send by itself — the mic types what you said into the box and you press Send. Above zero, Iris waits that many seconds after you stop speaking and then sends on its own.
Default OFF. With it off, Iris drafts an email and you press Send — so a misheard voice command can never mail a colleague or customer. Turning it on removes that gate for every outbound action. Change is audit-logged.
Default ON. Coding tasks (including orchestrator children) run on Cursor.
Uncheck to force the Claude Agent SDK instead. Needs CURSOR_API_KEY — without
it the runner falls back to Claude and says so on the task. Change is audit-logged.
Default ON. The runner copies the message that started a task — private content, typed into a private tool — onto a comment on a PUBLIC pull request, so a reviewer can see what was asked for. Uncheck it and the review is code-only, and says on the pull request why. A value the code does not recognise is read as OFF: unknown falls to the side where being forgotten is safe. Change is audit-logged.
DashScope US and intl are always allowed. Add another vendor's hostname here
(comma or space separated). An admin then wires the credential — ENGINE_* /
COMPAT_* / FUTURE_* variable, https URL on that host, model, order.
Localhost and private addresses are refused. Railway COMPAT_ENDPOINT_HOSTS is
the same list without a deploy. Change is audit-logged.
A session link is a bearer credential handed to a program outside Sable; this is how long one reads the Project before it must be accepted again. The browser's own binding still ends after its idle hours or at the daily hour. Change is audit-logged.
Recent is hours of a human save; Today is Eastern calendar. Day cuts are increasing whole days; more-than is past the last cut. Opening a card is not activity. Iris and machine writes are not. Change is audit-logged.
Project codes, comma or space separated. * releases the whole estate.
Empty means nothing is swept — the sweep fails closed rather than falling back to
all, and the worker says so in its log. The sweep moves a noisy entry off a Project’s
business tab and onto its Log; nothing is deleted. Change is audit-logged.
The sweep takes non-IT Projects first, on the owner’s order. Departments are renamed on this page (R39), so the names that count as IT are read from here rather than typed into the code. Left empty, a usual set of spellings is assumed.
Rename a department in its row; archive one to take it out of every picker (what already holds it is unchanged); People… sets who is in it — a person may be in several. The super admin may add a department with its report letter; keys and letters are permanent.
Iris voice connection
Blank addresses use the built-in provider endpoints. Only approved HTTPS provider origins are accepted. This does not enable voice or change anyone's microphone permission.
Meeting sources
Only the mailboxes listed here are authorized for calendar and transcript reads. Accepting an invitation does not add its organizer. Blank fields use deployment settings. Microsoft access permissions still apply.
Email addresses — what each one is for
Card map
Superadmin. Change a card’s parent. The id never changes. A card with no loader cannot be invented here. Family letters and card width are the estate’s — revision 7 — and apply on the next paint.
Loading…
Personas — SABLE & IRIS (name, colour, mark — no deploy)
SABLE is the platform (the app icon). IRIS is your assistant (the ✨ helper). A change applies the moment you save — no deploy.
Credentials — org keys & per-user keys
| Label | Assigned to | Kind | Env var (IT sets value) | Status |
|---|
Per-user keys serve only that user's tasks. Sable stores the variable NAME only — IT pastes the value into Railway under that exact name. A future Anthropic-compatible engine: pick that kind, name an ENGINE_* / COMPAT_* / FUTURE_* Railway variable, the base URL (DashScope, or a host a super-admin added under Settings), the model, and the order. Coding walks it after Teams and Max automatically — no deploy.
Routing rules (SBL-012) — edit, no deploy
| Ord | Task class | Match keywords | Model | Runner |
|---|
Reports, IRIS and Oracle
VM · Sonnet 5 first, Terra 5.6 as backup, OpenRouter · Sonnet 5 third. Coding and escalation are not this chain.
Model routing — other routine calls
The day's ceiling — what the whole estate may spend
Devices
A person at their limit cannot sign in on a new device until one below is revoked. Revoking frees the slot and signs that device out immediately.
| Model | Coding | Sable | Live now | Quota |
|---|
| Seat | Stop at | Quota | Last heard |
|---|
Coding limits by account and pool
Allow coding jobs blocks new claims and asks active work to pause after its current turn. Require usage check is a separate allowance check and cannot override a coding pause, STOP or account revocation. Blank a stop override to inherit its account or global limit.
| Account | Pool (supervised) | Coding stop | Allow coding jobs | Require usage check | Usage | Status |
|---|
Coding pause receipts
Off routes nothing. Pilot routes ONE Project's Iris refreshes to the VM's subscriptions; then every Iris refresh; then every machine ask. One notch up at a time; off in one move. A row a worker cannot take waits — nothing falls back to a metered provider until that rule is written.
A session working a Project by its link writes a checkpoint at least this often. Past the interval the Project goes amber and the brief says overdue; past the stop its write doors answer 409 until it checkpoints; past the notify the output's admins get a notice. A Project's own interval, set on that Project, wins over the first number.
Signing in on a device keeps that person signed in for the number of days above, without asking again — being idle does not end it. Revoking the device ends it at once, which is what makes a long session safe to offer. A browser we have no device for keeps the shorter limits in Settings.
Who may open Build
Build stays locked. sam@gashley.com always opens it. Extra mailboxes here also open the tab and may approve a Project to build (or waive an incomplete one). A Sable admin does not, unless named.
Users
| Coding | Reports | Admin | Active |
|---|
Test users · find them and switch them off in one press — nothing is deleted
A person who does both registers for both services under one login. Report-only users never see coding; coding-only users never see reports. Admin and services are independent — an admin may legitimately lack a service.