Meet Salix, Comma's agent harness

Salix runs your Comma agent around the clock, and it calls a large model only when the work needs one.

Salix at work

An example you can click through. You asked Comma to watch #support and your inbox for bug reports, and it wrote a Loop for it. The Loop woke Comma for a customer's bug report. Comma started a Task, and its Worker reproduced the bug on the cloud computer and opened a fix for your review. Beside the window, an editor shows two of the Lean proofs in Salix's kernel.

Inside Salix

Loops keep watch, 24/7

Your agent writes a small program, a Loop, that watches your inbox, a repo or a feed. It runs day and night, and wakes the agent only when something needs it.

About Loops

Quick decisions with Jev

Loops ask fast decision models like Jev whether an email or an event needs you. A quiet hour uses no large-model tokens.

How Loops decide

Built in Elixir and Lean

Elixir keeps your agent running when a part of the system fails. The core of the agent loop is written in Lean, with proofs that your data goes only where it is allowed.

How Salix works

Works on your Mac

Salix attaches your Mac, so Comma can open and update your files there. An agent can also run Codex or Claude Code on it.

About devices

FAQs

What can a Loop watch, and how do I start or stop one?

A Loop can watch a connected app such as Gmail, GitHub or Slack, poll a web API, or receive events at its own secret webhook URL. Ask Comma in chat to follow something, such as a pull request or a thread, and it sets up and starts the Loop; ask it to pause or delete the Loop when you no longer need it. An agent can run up to 20 Loops at a time.

What does a Loop cost while it waits?

A waiting Loop is a small program on the Salix cluster, not a cloud computer. It calls no model and has no meter of its own, so it costs credits only through what it calls, such as questions to Jev, which use credits even if you bring your own model key, and the agent turns it wakes, which bill like any other turn. It can wake the agent at most six times in each ten-minute window.

What does Jev decide, and what if it is unsure or wrong?

Jev answers the questions a Loop asks, such as whether a new email needs you, and it cannot send messages, change anything or grant access. When Comma follows a pull request, an issue or a thread for you, its Loop stays quiet only when Jev answers "quiet" with a confidence of 0.9 or more, and anything else, errors included, goes to your agent, which is told to check the source before it writes to you. If Jev is confidently wrong about "quiet", that update does not reach you.

What happens to the data a Loop reads?

It stays data: an email or an event cannot change the Loop's code or add to its fixed list of capabilities. An incoming event is stored only until the Loop acknowledges it, and the Loop keeps one checkpoint of at most 16 KB. What it reads goes further only through the Loop's own calls, such as a question to Jev, which TypeSafe AI runs, or a wake message to your agent.

What happens when part of Salix fails?

Each agent runs as its own process on the Erlang VM, so a failed part restarts and the other agents keep running. Messages that Salix has accepted survive the restart, and an interrupted action that changes something is not run again on its own. A Loop resumes from its last checkpoint after a restart or a move to another node, and if its own program faults, it restarts at most three times an hour, then stops and tells your agent.

What do the Lean proofs guarantee, and what do they not?

The core of the agent loop runs as Lean code, and a machine checks its proofs. They show that work Salix has accepted is kept through failures and restarts, that a failed reply does not count as done, and that each action that changes something is recorded before Salix starts it and is started at most once. They rest on stated assumptions about the code around the kernel, and they do not prove storage, the model's judgment, or that a task succeeds.

What can Comma do on my Mac, and how do I take access back?

At first, Comma can only read files on a connected computer, your Mac included. To let it change files, run commands and use the coding agents installed there, turn on Allow operations for that computer in Settings > Devices. Turn it off at any time: running commands stop, and Comma is back to read-only.

Which coding agents can Salix run on my computer?

When Codex, Claude Code, Pi or Kimi is installed on a connected computer and Allow operations is on, Comma can hand work to it. The coding agent does the work on that computer, and Salix keeps the conversation. If the computer goes offline, the work waits or fails with an error, and Salix does not move it to another machine on its own.

Try Comma, Now.

Get started