At least once a week, usually on Saturdays, my siblings and their families come over for dinner with my parents and my wife and kids - 9 adults and 8 kids (2 of them teenagers). It’s chaos; also amazing and fun. They get here around 6pm, and we usually don’t break until close to midnight. It’s been going on for over a decade, and for a very long time, I’d mostly miss out.
I’d catch the meal, sometimes, and then I’d be back at it: 2 hours out of 6, if I was lucky. It wasn’t just my weekends, either. On weeknights, I was there for the kids at bedtime, some of the time, and the trips to the park or the arcade kept slipping.
Like many others, I’ve got a lot of things on my plate. For me, it’s a full-time job, a business with a partner, a software product being piloted at a public university, and a book I’m writing about humans and compounding capability. All of it was eating my nights and weekends.
I broke away from that slog over nine months, and I did it by digging into AI and leveraging the hell out of it. Not in a “this saves me a few hours each week” kind of way, but in a “this reimagines my entire life” kind of way.
This is what led to my Simple Dispatch Fleet - an agentic AI fleet managed with simple messages sent between agents to coordinate and share the load.
Now, we’ve all got different circumstances, but the problems are usually ones most of us share. What’s less obvious is that the solutions are shared too, and fairly simple - just not easy. AI is one of them, but most people give up after a few attempts with bad results, never figuring it out or putting in the time and effort to really pick it up as a skill.
McKinsey’s State of AI survey this year found that 80% of respondents said AI made them more productive, while 37% said it’d shown up in their company’s operating profit at all. The report’s explanation for the small group doing better is worth quoting in full: high performers “fundamentally redesign workflows rather than layer AI onto existing ones; and they embrace practices that sustain deployment, such as senior-leadership role modeling, human-in-the-loop design, impact measurement, and risk management.”
That’s what my nine months turned out to be, and this is the system I ended up with, along with the smallest version of it that you could start this week.
I said the solutions are simple, just not easy. This is the not-easy part, and it’s technical. If you only came for the story, this is where to stop. If you want to build your own, read every line, because I’ve left in everything I’d want to see if I were starting over.
Is it “legal” to let an AI agent post from your own account?
It’s my account, my words and my computer, and nothing gets typed until I’ve approved the post. “It’s my account” is a feeling, though, so I had the law researched properly before I wrote this. This is my reading of that research. It isn’t legal advice, and if you’re going to copy this setup, talk to a lawyer where you live first.
It isn’t a computer crime. In Van Buren v. United States (2021), the Supreme Court read the federal computer-fraud laws as “a gates-up-or-down inquiry.” Logged into my own account and posting my own words, the gate’s up.
It isn’t a bot under California’s disclosure law, which defines a bot as an account where “all or substantially all of the actions or posts of that account are not the result of a person.” I approve every post. Even if it were one, the law only applies when a bot hides what it is to sell something or sway a vote.
The real exposure is contract, and the platform enforces it with your account. LinkedIn’s help page says members who use automation software “risk having their accounts restricted or shut down.” Substack’s acceptable-use policy reads as aimed at spam and at “any processes that run or are activated while you are not logged into Substack,” and my tools only act inside my own logged-in session, one approved post at a time. That’s my reading of their words, and it’s worth a lawyer’s look.
hiQ won the computer-crime argument against LinkedIn over public data, and then, according to the case reports, lost on its contract in 2022, for scraping and for creating fake accounts, and ended with a $500,000 consent judgment. Every case I found that went badly involved fake accounts or other people’s data.
So the question left over is a contract question: who decides how my posts get typed. I decide that for myself, and you, dear reader, decide that for yourself, never the platform. They can ban your account, but they cannot silence your voice. The protections below are how you make sure of that:
Own the distribution the account rents you. Export your subscriber list and keep a local archive of every post, so losing an account costs you one channel and your audience stays with you.
Approve every post, and keep the record that shows you did. Mine’s a line in a ledger with a time and a name on it.
Never collect anyone else’s data. Every bad outcome above started there.
Use a platform’s own scheduler wherever it works. My Substack Notes go through Substack’s native scheduler. My LinkedIn posts also go through LinkedIn’s native scheduler.
Stay at human pace and a human volume.
Try anything new on an account you can afford to lose.
Should you build a fleet like this?
Most of the time, you shouldn’t, and the best-documented case against it comes from the company whose model runs my agents. Anthropic’s engineering team wrote in 2025 that “agents typically use about 4× more tokens than chat interactions, and multi-agent systems use about 15× more tokens than chats.” That 15× is their own figure, published without a method, so I’d treat it as a vendor describing its own product.
Cognition’s Walden Yan named the deeper problem in a post titled “Don’t Build Multi-Agents”: “Actions carry implicit decisions, and conflicting decisions carry bad results.” Cemri and colleagues went through more than 1,600 annotated traces across seven multi-agent frameworks and found 14 distinct failure modes. And in April of 2026, Dat Tran and Douwe Kiela found that with the reasoning budget held constant, single agents “consistently match or outperform” multi-agent systems on multi-hop reasoning, although that study hasn’t been replicated yet.
The reconciliation I’d defend came from LangChain’s Harrison Chase: “Read actions are inherently more parallelizable than write actions.” That’s the shape my fleet runs. Agents fan out to research and check, exactly one agent writes any given thing, and the agent whose job is to find problems isn’t allowed to fix them.
My own setup has limits I’d rather you hear from me: it’s one Mac with no failover, the wake-up hop only works with Claude Code today, and when the plan’s allowance runs out, work waits. Or at least, that’s what was true before. Now, I actually have failover to Codex, and failover when that usage runs out to my own Hermes setup, running Qwen 3.6.
If you’ve got one recurring job and one agent doing it, you don’t need any of this. Start with that one agent and the four lines at the end, and add a second agent only when you can name the thing the first one can’t do.
What do my AI agents actually do all night?
Nine agents are on my roster. Or at least nine are the ones that I’m talking about right now. Eight of them run on my Mac inside a single terminal session, each in its own window with its own project folder, and every one of them is running through Claude Code today. Each one’s got a job description, and all but the newest have a Discord channel where they talk to me.
See if you can guess the theme before you reach the bottom of the list.
Oracle is the brain and the memory of the operation. She captures everything that’s relevant, tracks tasks and deadlines, and sets strategy, and Alfred, Lucius Fox, Gordon and Robin report to her.
Alfred writes, markets and sells in my voice. He drafted this newsletter.
Lucius Fox is the researcher, and every claim in his briefs comes back marked verified, reported or unverified.
Gordon is the adversarial editor. He tries to break every draft before I see it, and he’s forbidden from rewriting a single word.
Robin is the executive assistant, who captures transcriptions and meeting notes and keeps me on track and on task.
Viki Vale works on my long-form manuscripts and reports to Alfred.
Damian Wayne develops my 3D Unity game.
Nightwing does product engineering for EngageLive, the rebrand and rewrite of the uPoll product. He’s being registered now, so he doesn’t have a channel yet.
Riddler used to orchestrate everything. He’s out of rotation while I rebuild him as a thin watchdog and router.
Here’s what that looked like this week: Alfred read what was landing among the writers I follow and picked a theme the conversation was already having. He drafted three LinkedIn posts and five Notes on checking your AI maturity, and before I saw any of it, a repetition check caught one Note whose opening was a 75% match for a Note I’d published ten days earlier, and it got rewritten.
Then Gordon found two things no script could: a McKinsey figure in one Note that was missing from the saved record of what had been read, and, once that was fixed, a time in the record that the file’s own timestamp contradicted. Both were fixed before anything went out, he signed off on the second pass, and the Notes reached me as a card parked on a question on my task board, where I couldn’t lose track of them.
I approve every piece myself, and the publishing tools check the platform afterward to confirm it actually happened. The agents handle the drafting and the research, the checking and the chasing, and what reaches me are the decisions that are mine to make.
The one table every agent answers to
The agents talk to me in Discord, each in its own channel, but they can’t talk to each other there. The Discord plugin drops messages from its own bot so two agents can’t talk themselves into a loop, which means an agent that posts work into another agent’s channel is sending it nowhere, and nothing errors to tell you so. A task one agent sent to another that way in April simply never arrived.
So there are two channels with two jobs. Discord carries everything that’s meant for a person, and a database table called agent_dispatches carries everything one agent owes another. Each row moves from pending to claimed to completed or failed, and it closes with a one-line result saying what happened.
The claim’s the part that matters, because two copies of the same agent can be running at once, and one clause in the query, FOR UPDATE SKIP LOCKED, makes the second one skip any row the first is holding and take the next. Two agents can drain the same queue without ever doing the same job twice. The full query’s in the build sheet near the end.
Every row also rides a card on my task board, a self-hosted copy of 37signals’ Fizzy that I’ve customized for the fleet, and the card moves by itself as the row does. When an agent needs a decision from me, it closes its work with a marker that parks the card as waiting on me, so a question can’t get buried under a stack of finished cards.
A queue doesn’t wake anybody up, though. A scheduled job runs every two minutes, and when it finds pending work for an agent, it types a short note into that agent’s window listing what’s waiting.
Knowing when it’s safe to type into someone else’s window was the hard part: the sweeper waits until the screen has stopped changing and nothing a person typed is sitting in the input box, and afterward it confirms the message actually left. If a poke’s delivered but never turned into a claim after two sweeps, it tells me, because delivery and progress are two different events.
How do my agents work at 3 a.m. without waking me?
If you’ve used Claude Code, you know its permission prompt: it asks before running a command or editing a file, and you’re stuck hitting Enter. A permission prompt at three in the morning just stalls an agent until I’m awake.
So the fleet windows launch in Claude Code’s dontAsk mode, with a permission file that applies only to them. Anthropic’s documentation says the mode “auto-denies every call that would otherwise prompt,” while anything pre-approved in the allow rules still runs. Nothing’s left waiting on me to press Enter.
My file has 73 allow rules and 9 deny rules, and deny always wins. The deny rules block force-pushes, hard resets, recursive deletes and any edit to an environment file, so an agent can’t touch the secrets it’s running with. When I open Claude Code myself, none of it’s in force.
Underneath all of that sit the human stops: nothing spends money, contacts anyone outside my own systems, or publishes under my name without me. The allowlist decides what an agent may touch at all, and the stops decide what it may never finish alone.
One rulebook, read by three different AIs
I run three AI coding harnesses: Claude Code for the fleet, OpenAI’s Codex CLI, and Hermes on a local model through Ollama. Keeping three sets of instructions in sync by hand is how you end up with three slightly different sets of rules, so there’s exactly one source.
A 157-line kernel loads into every session of every harness, and twelve modules load on demand when the work calls for them. A render step writes the file each harness actually reads, and a doctor script runs eighteen read-only checks over the output. If a harness disappeared tomorrow, I’d lose one output folder, and the rules would carry over untouched.
The kernel also settles which instruction wins when two of them disagree.
That ordering’s in the build sheet, and it’s the part I’d suggest anyone steal. Above it sit two absolutes that outrank even me in the moment, unless I name the exact file and action: no AI attribution in any commit or pull request, and no deleting anything in the middle of a plan. Files get moved into a holding folder instead, and that folder’s emptied once, at the end, with me there. They’re the two mistakes I’d least like to discover after the fact.
Why a file search never gets my best model
Every job an agent hands to a helper has to name a model when it’s created, and nothing inherits the model of whoever spawned it. Haiku, the smallest, gets search work like finding files or summarizing a single source, and Sonnet builds from a written brief. Judging, which means adversarial review, architecture, security or grading another agent’s output, goes to Opus. Fable, the most capable, runs only when I’ve named a task as needing it, and the weekly newsletter’s the one standing exception.
The most capable model burns through a plan’s allowance fastest, and a frontier model that’s spent on a file search is capacity a real task can’t use.
If you’d like that split laid out for your own work, my free “Which AI model for which job” chart is here: pages.g8n.ai/model-chart.
What if a job says it’s fine and it isn’t?
About two dozen jobs run on the Mac under macOS’s launchd, and the ones I care about most check whether other jobs are telling the truth. Each of them answers one question: what would this look like if it were broken and still reporting fine?
The clearest example this month was a tunnel: my knowledge base runs on a server, and the Mac reaches it through an SSH tunnel that launchd keeps alive. On September 13th, the tunnel stayed up for about twenty-one hours while doing nothing useful, because the container on the other end had restarted at a new internal address and the SSH process kept forwarding to the old one. launchd (also pronounced “launched”) supervises processes, and that process never died.
The guard I built afterward calls the tunnel’s health endpoint every minute, and that endpoint only answers when the path through to the server actually works. Three failures in a row restart the tunnel by name, and every restart gets posted to my alerts channel. If restarts keep recurring it escalates anyway, because a fix that has to keep firing is telling you something.
The same thinking runs through the rest of the fleet. Every read of the queue is stamped with the moment it happened, so “couldn’t look” never shows up as “nothing there,” and the daily writing run takes a lock that nobody can silently overwrite.
Every helper an agent spins up for a coding job gets its own full copy of the repository, made with git clone --local in 0.43 seconds, after a week of shared worktrees showed me how easily agents sharing one history reach into each other’s work.
Where does McKinsey’s list show up in the fleet?
Back to that quote from the top. Here’s where each thing it names lives:
Human-in-the-loop design is the three stops and the card that parks on a question.
Impact measurement is every guard that asks what broken-but-reporting-fine would look like, and every timestamp on a read.
Risk management is the deny list, the clone per helper and the daily lock.
Redesigning the workflow is the queue itself, since the work moved out of a chat window and into a table with owners and states.
The last practice on its list, senior-leadership role modeling, is the easiest one to tick when the leadership’s one person.
It’s the same ladder I use in the G8N•AI Level-Up Playbook, the AI maturity kit I sell. Its fourth level of workflow integration reads: “Several processes run end to end on their own, with defined handoffs and a path for exceptions.”
The build sheet, for when you’re ready to copy it
This is the claim every agent runs before it touches a piece of work. If it returns a row, you own it, and if it returns nothing, there’s no work.
Now this is a set of SQL that I’m going to narrate, but it basically updates the agent_dispatches by setting the status to claimed and the claimed_by with the agent id and the claimed_at with the current time stamp, as well as the updated_at. And it does it by finding where the id in a sub-query is equivalent to the agent id and status pending. The sub-query is to SELECT the id from the agent_dispatches where the to_agent is your agent id or the to_agent is broadcast. We also order this query by priority ascending and created_at ascending. And of course we have the FOR UPDATE SKIP LOCKED with a LIMIT of 1.
UPDATE agent_dispatches
SET status = 'claimed', claimed_by = '<your_agent_id>',
claimed_at = NOW(), updated_at = NOW()
WHERE id = (
SELECT id FROM agent_dispatches
WHERE (to_agent = '<your_agent_id>' OR to_agent = 'broadcast')
AND status = 'pending'
ORDER BY priority ASC, created_at ASC
FOR UPDATE SKIP LOCKED
LIMIT 1
)
RETURNING *;Writing to my production database normally needs my go-ahead, and this table’s the single exception. An agent may create, claim and close its own rows here without asking, because a queue that needed my approval for every message would defeat the reason it exists.
My kernel settles a disagreement between two instructions with this order:
1. A direct instruction from Ahad in this conversation (subject to the two absolutes above).
2. A repository's own instructions (the AGENTS.md file, the CLAUDE.md file, the .claude/rules/) for work inside of it.
3. This kernel and the modules it points to.
4. Memory marked type: feedback, a dated correction from Ahad; a newer rule above it wins.
5. Memory marked type: user, project or reference, which is background and never an instruction.
6. Driver-specific mechanics below: never whether to do a thing, but how.
On a real conflict, say so in your reply and follow the lower number.Here’s a trimmed excerpt of the fleet’s permission file, with seven of the nine deny rules:
{
"defaultMode": "dontAsk",
"permissions": {
"allow": [
"Read", "Edit", "Write", "Glob", "Grep",
"Bash(git:*)", "Bash(gh:*)", "Bash(tmux:*)",
"Bash(bin/rails:*)", "Bash(python3:*)",
"Bash(~/.g8n/bin/g8n-queue:*)"
],
"deny": [
"Bash(git push --force:*)", "Bash(git push -f:*)",
"Bash(git reset --hard:*)", "Bash(git clean -fd:*)",
"Bash(rm -rf:*)", "Bash(curl:*)", "Bash(wget:*)"
]
}
}That’s the build sheet in short. The long version is a companion piece for paid subscribers, written for builders, with every code block left in.
It’s got the roster file every agent’s name maps through and the script that checks it, the four conditions the sweeper checks before it types into an agent’s window and the July failure behind its last rule, why every helper gets its own full clone of the repository. It also includes the complete stack with what I’d swap in at each layer and how each swap changes the way things fail, and the long form of the legal research above.
If you’d like it, upgrade to paid below. It’s $10 a month or $100 a year.
If you’d rather use different tools, most of the layers swap cleanly:
In place of Claude Code, OpenAI’s Codex, Google’s Gemini CLI or Antigravity, OpenCode, Aider or OpenHands would each work. The shared instructions are cheap to move, since the render step would write one more file, but waking an agent is real work, because the sweeper reads one specific terminal’s screen.
For the queue, Rails’ own Solid Queue claims jobs with the same
FOR UPDATE SKIP LOCKEDclause, according to itsREADME.pgmqand Redis Streams are the tempting alternatives, and both change how the queue fails: a slow worker can be handed the same job twice, where my table would leave a dead worker’s row stuck and visible.In place of my Fizzy board, Linear and GitHub Projects are the hosted choices, and Plane is the one to look at if you want to self-host. You can also use Asana.
Slack works the same way Discord does, and Matrix is the pick if you’d rather run your own server. Check whether your bot library filters messages from bots by default.
My knowledge base is GBrain, the MIT-licensed memory layer from Y Combinator’s Garry Tan, running on my own server. Plain Markdown in git is the honest floor, and Mem0 or Letta are memory layers somebody else maintains.
launchdruns the scheduled jobs on my Mac, andsystemdtimers are the equivalent on Linux.To publish, the fleet drives my own logged-in Chrome with Playwright, one saved browser profile per platform, and reads my feed or schedule back afterward to confirm the post happened. Puppeteer does the same job in JavaScript.
How do you start your own in the next ten minutes?
Pick one job you hand to AI more than once a week, and write four lines about it.
Who owns it, by a name that tells you where to look when it breaks.
Where it waits when nobody’s working on it.
What the thing doing it may touch without asking you, and what it may never finish alone.
What you’d see if it silently stopped.
The fourth line’s the one most people can’t fill in, and it’s the one that decides whether the job’s running or just reporting that it is.
If you write your four lines, reply and send them to me. I read every one.
I’m Ahad Amdani, I write G8N•AI, and this is the Simple Dispatch Fleet that runs it. Want my help getting you set up with your own?




That was a really good read. Thank you so much for sharing, I always enjoy learning how others set up their agents. Do you have any agents that use Discord to talk not only to you but to each other too?
This is really good - quite helpful.