Choose a maker and reviewer for research or code. Camus keeps the contract, identities, checks, findings, and human decisions attached to the exact result. Experimental code never lands without you.
Run settings: decisions, recorded
Saved locally under ~/.camus; tracked public defaults stay unchanged.
MODEL QUALIFICATION
Qualification proves that this machine can reach the exact maker or reviewer tuple and parse its output. It is not a quality endorsement or production-review admission. Launch checks it again.
Connect a model server — declarations only
Choose a starter, inspect the exact JSON, replace every placeholder, and save it to local operator state. Saving makes a tuple visible, not trusted; qualification is a separate explicit provider call.
CONNECTION DECLARATION
This exact declaration is written locally. It may contain an environment-variable name, never a credential value. Transport and lineage facts are derived by the local server.
This is what the reviewer holds the work to. Change it and any earlier review of this work no longer counts.
add a clause:
3 Choose the kind of work
4 Choose maker and reviewer, then run
maker→reviewer
One model makes the work. A separate reviewer tries to break it; independence is earned only when the recorded identities support it.
Off. The pairing shown above stays in control.
Flexible Build uses both selected seats. Start from a clean repository. Changes stay in a separate worktree; review is advisory and nothing is automatically committed, merged, or published. Stop and resume preserve the same candidate, contract, and budget usage.
Flexible mode: empty means untested. Supply your test command to verify the candidate. It executes locally with credential environment variables removed, not in an OS sandbox; use trusted projects. The proof gate can detect the stack. No $, backticks, quotes, backslashes, or newlines: put complex commands in a script.
Camus offers a native harness only after a spend-free local version and artifact check. Provider/model qualification is separate; credentials remain in the host-owned one-model gateway.
Camus bounds time and observed tools. Model calls count Camus dispatches, not Devin’s internal inferences; the token budget is a planning reservation, not a spending cap. Uses your saved Devin login, with no API-key fallback. Check your plan’s current allowance.
Recovery and budget limits
Without this authorization, an additional verification pauses for permission. No changed contract or model is allowed on resume. These are global run limits, not per-round allowances.
Token limits reserve capacity before a call; they are not provider-enforced billing caps. Unreported usage remains unknown. Inactivity detection is off by default: a quiet model may still be working.
After a run, inspect its receipt without a provider call: camus build --inspect RUN_ID.
Drafts can lean on Hivemind, Myosin's private research knowledge (on staging today).
Off by default. Turning this on is explicit consent for the finished words artifact to leave this machine.
Quick, from Settings. Change it there; it applies to the next run.
SAME BRIEF, TWO CLAUDE MODELS
This words-only comparison uses the built-in Claude maker catalog and one saved Codex reviewer. Both arms get the same frozen brief and contract, then exactly one draft and one review: no live tools, repairs, re-review, publication, or content answers. Build harnesses are not compared here.
BLINDED CALIBRATION
Judge the artifact, not its maker.
Private workspace · no model calls
GOAL
PINNED ACCEPTANCE CONTRACT
Deliverable
running0:00
The deliverable appears here as the loop drafts it.