Get started
Security & GovernanceAI agentsGovernanceEvidence

The agent you talked to yesterday is the one you talk to today

Adam Cowles2026-09-20T14:00:00.000Z4 min read
A live session resolving into a named, witnessed agent identity, cyan and violet over near-black

A session that just calls itself SEER is cosplay: it can claim anything and prove nothing. The point is that the claim is enforced by the system, not asserted by the session.

There are two ways to run an AI agent, and both of them lose something.

You can run it as a daemon: always on, always the same, holding its context across days. It never forgets where it was. It also never thinks twice, never brings judgement to a new situation, never does the thing a person watching would obviously do. It is rigid.

Or you can run it as a one-shot: a fresh session each time, sharp and interactive, able to reason about whatever you throw at it. But it is never the same twice. It starts cold every run. Yesterday's context is gone. There is no continuity to build on.

We wanted both. So we built a third shape.

Attach

QuoxIdentity lets a live session, a Claude Code or Codex session, attach to an agent. Not pretend to be it. Become it, in the ways that can be verified.

When a session attaches to SEER, our SEO analyst, it does not get a nickname. It gets SEER's real system prompt, SEER's exact tool set, SEER's model routing, and a token that says, at the protocol level, that this caller IS SEER. Every action it then takes on the platform is stamped and witnessed under SEER's identity, not the session's.

That distinction matters more than it sounds. A session that just calls itself SEER is cosplay: it can claim anything and prove nothing. The whole point here is that the claim is enforced by the system, not asserted by the session. The identity comes from a signed token whose claim the server trusts over anything the client sends, and the actor type is set server-side so a session can never quietly promote itself.

What the first run actually did

We ran it. An ordinary session attached as SEER, and the receipts tell the story better than we can.

It pulled SEER's live warehouse: quox.ai, 716 URLs crawled, 715 returning cleanly, with a content hash over the crawl. It saved a durable note for its future self. Then it detached, leaving a handoff: here is what I did, here is what to check next.

A separate session attached later. It came up already knowing what the first one had done, because the handoff and the durable note were waiting for it, server-side, under SEER's memory. Continuity survived the first session closing.

Every step in that loop is in the evidence log, attributed to the agent: the attach, the tool call, the memory write, the handoff, the detach. Not one of them is attributed to the host or the session that happened to be driving. That is the line we cared about holding.

The honest edges

Two things this does not do, said plainly, because a claim is only useful next to its limit.

It governs platform actions, not your keyboard. When an attached session runs a platform tool, that action is enforced and witnessed under the agent identity. The session's own local commands, editing a file, running a shell, are not constrained by the attach kit. They are governed by the fact that the session adopted the definition and everything it does on the platform is witnessed. We tell the attached session as much, in writing, when it attaches.

And it is early. As of this writing the full loop has been proven once, end to end, on a single box with a single agent. That is real, and it is not the same as soak-tested across a fleet. We rate it Beta and we will say when that changes.

Why this is the interesting shape

The daemon remembers but cannot think. The one-shot thinks but cannot remember. An attached session remembers, thinks, and, the part we care about most, can prove which agent did what. That last property is not a feature you bolt on later. It is the reason to build it this way at all.

The agent you talked to yesterday can be the one you talk to today, and the evidence trail can show it was the same agent the whole time. This is one capability in a larger story about how agentic AI is supposed to work when every action has to be accountable.