PRODUCT
Kimene: your AI workforce got real machines. Now it needs a control plane
7 min read
2025 made the terminal agent normal: Claude Code, Codex CLI and their peers now run for hours on real machines, and teams quietly operate fleets of them. What nobody shipped alongside is the operations layer — which account ran what, on which host, why that route, and who says it is done. Kimene is that layer: pooled accounts, models and machines, an immutable decision record, evidence-gated completion, and tmux sessions that survive everything you close.
2025 was the year the coding agent moved into the terminal and stayed there. Claude Code, OpenAI’s Codex CLI, Gemini CLI and their peers turned “ask the model a question” into “give the agent a task”, and the task stopped fitting in a chat window: real repositories, real test suites, runs measured in hours. Teams noticed, and then did the natural thing — they multiplied. One agent became several, on several provider accounts, across several machines, with different models for different work. Which is to say: somewhere in 2025, without a headline, organisations acquired a workforce. What they did not acquire is everything a workforce normally comes with — an org chart, an assignment logic, a completion standard, an audit trail. The work runs under whoever’s account was handy, on whatever machine was awake, and “done” is whatever the agent last printed. The interesting question for 2026 is not whether the agent can do the work. It is: which account, which model, which machine did the work — who decided that, on what grounds, and who says it is finished?
A workforce without an org chart
Run a fleet for a month and the gaps organise themselves into a list. Bindings fossilise: the account that once ran a project becomes “the project’s account”, hard-wired in a config nobody dares touch, and capacity sits idle on one side while another queues. Four different things — provider capacity, concurrency policy, resource leasing, priority — get squeezed into the one word “quota”, and from that day on nobody can say which limit they actually hit. Routing happens, because something always picks the account and the model, but it happens implicitly — and when you ask why this run went through that account, the honest answer is a shrug rendered as “the AI chose it”. Status is self-reported: the worker that did the work also writes its own grade. And the security version of this list is one we already wrote down: in September’s post on agentic attackers we argued that an agent with unmediated reach is a supply-chain actor whoever it works for. The operational version is quieter but the same shape — a workforce nobody can account for is a liability even when nothing goes wrong, because you cannot answer the questions a workforce exists to answer.
Self-reported: the worker grades itself
Evidence-gated: the state asks for proof
“The AI chose it” is not an explanation
Kimene’s first discipline is that assignment is a decision, and decisions get written down. The raw material is pools: accounts, models, hosts, projects, roles and tools live side by side with no permanent binding — no account pinned to a project, no model welded to an account. The match is made at execution time, holds for that one run, and is recorded. The matching itself is two honest stages: hard eligibility first — an account at its concurrency limit, a host that is offline, a model unavailable on that account are out, each with a reason code — then weighted scoring over what survives: verified model, provider capacity, capability match, session continuity, locality, preference, minus penalties like rate-limit proximity. The chosen route and every rejected candidate land in an immutable record, component by component: total = components minus penalties, and there is no third path. A route simulator replays the same scoring against hypothetical inputs — what if that host went down — so the answer is arithmetic, not folklore. None of this makes the choice smarter by magic. It makes the choice defensible, and reversible, and auditable — which is what separates an operations layer from a lottery.
Done is a claim. Evidence is a fact
The second discipline touches the sorest spot in agent operations: who says the work is finished. The self-report problem is not hypothetical, and it is not even specific to machines. In METR’s randomized trial last year, experienced open-source developers using AI assistance believed they were about 20% faster; the measurement said they were 19% slower. If human self-perception misses by forty points, an agent grading its own homework is not a status system — it is a hope. Kimene’s answer is structural: a task reaches completion only through review or approval, the evidence contract comes from the task type itself — a code change wants a review and a passing run, not a confident sentence — and the API has no path to write the state directly. Credentials get the same boundary treatment: the control plane stores no credential bodies and carries none between machines; it knows paths and references, and provider isolation is established through the process environment. The plane that decides everything is, by construction, unable to leak the one thing everyone worries about.
Where Kimene stands
Kimene is our AI workforce control plane, and the part that is easiest to underestimate is that it is real all the way down. Every session runs on an actual host through the provider’s own CLI, inside a tmux session started by the node agent on that machine — the control plane never talks to a provider CLI directly. That indirection is what makes interruptions harmless: close the browser, redeploy the server, drop the SSH — the session stands, the screen redraws from where you left it, and every keystroke you send is applied exactly once. The wall shows the fleet side by side — one tile typing, one waiting for an approval, one finished — and an operator takes the keyboard at any moment, because supervised is not the same as absent. It is self-hosted on your infrastructure with your own provider accounts, and it is built by our engineering team at the METU Technopark in Ankara, in Go, React and tmux — the same platform conviction this site describes everywhere else, applied to the layer where AI actually does work.
- Separate pools — accounts, models, hosts, projects, roles — matched only at run time, on the record
- Immutable route decisions: score components, penalties, and every elimination with its reason
- Real execution: the providers’ own CLIs in tmux sessions that survive browser, deploy and SSH drops
- Completion only through review or approval — no API path writes the state directly
- No credential bodies in the control plane; self-hosted, on your own machines
What we will not claim
Three honest limits. First, Kimene does not make your agents smarter. A control plane governs work; it does not improve the model doing it. If the agent writes bad code, Kimene’s contribution is that you find out at review — with the run, the route and the record in front of you — rather than in production. Second, Kimene is not a way around provider limits, and we state this as bluntly as the product does: it manages the operator’s own trusted profiles, it is not a credential-sharing service, not a multi-tenant proxy, and complying with the providers’ terms of use is the operator’s responsibility. The decision record exists to make your usage more accountable, not less visible. Third, self-hosted means self-run: the plane lives on your machines, and uptime, backups and patching live there with it — the same trade we described for Talky, stated for the same reason. Kimene is a young product sold through a demo, not a self-serve trial, because fleets differ and honest scoping beats a signup form.
“The AI picked it” is not an explanation. One route, one decision, one record — and “done” only when the evidence says so.
For teams in Türkiye this is the operational half of an argument we have been making all year. In June we argued agents should reach tools through a governed layer; in September, that the path is the moat when attackers operate at machine tempo — and Article 12 of the KVKK and the Cybersecurity Law No. 7545 already expect you to demonstrate control over exactly this kind of surface. Qevron governs what your AI calls; Kimene governs what your AI does: who works, where, on whose account, with what proof of completion — inside your own perimeter, because the control plane self-hosts like everything else we build. Your fleet already exists; the only question is whether its decisions are written down. Built at the METU Technopark in Ankara, from Arpanet Bilişim A.Ş. Book a demo, or contact us and we will scope it with you.