The last post set the direction: secure it first, then let the AI do things. Before writing any code, this post answers a more basic question — has someone already built what I want to build?
I'm one person with limited time and money. If someone already does a layer better than I could and will keep doing it, I should borrow it rather than rewrite it. So I surveyed every comparable open-source project, and not just the READMEs: stars, the number of updates in the last month and the licence were all checked through the GitHub API on the day, and I read the architecture docs of the top candidates.
Key Takeaways
- One-line conclusion: splitting a request and dispatching it to many AI tools on many machines is already crowded. But switching when a quota runs out, resuming the same task on another machine, picking idle machines automatically and treating the phone as a real worker are not done by anyone yet.
- Biggest gap: resuming on another machine. Even Claude Code's own cross-machine session resume is still an open feature request; the community workaround is a hand-off document for someone to read.
- Freshly proven need: quota switching. Several projects appeared in September, almost all at the API layer. For subscription-based AI coding tools, only one small project does it, and only on macOS.
- A big vendor arrives: in September NVIDIA announced a tool that routes AI work to idle computers on your local network. It looks at which GPU is free; it knows nothing about subscription quotas or privacy levels.
- No longer unique: signing every AI action into a tamper-evident record is now in Microsoft's beginner course, and several papers are converging on a format. This layer went from unique to necessary — and it has to be compatible with everyone else's.
- Licence traps: some of the most popular projects are not open-source licensed or are GPL. Read them, don't copy them.
- About the numbers: stars and activity were checked through the GitHub API on 2026-09-30 and will change; licences are as stated in each project's LICENSE file.
Seven Questions
My goal: an AI swarm made of my AI subscriptions and all my devices, under my control. The more I genuinely use it every day, the better it understands me and the more it can do for me. To compare it with others, I split it into seven questions I can check:
Break one request into small tasks and send them to many AI tools on many machines
Reported permissions match real ones; stop really stops; approvals count; every action is signed
Know how much each subscription has left, hand work to another when it runs out, even half-done
Save the task and continue tomorrow or on another machine without repeating side effects
Choose by load, quota and privacy level
Stop passive monitoring first, targeted intrusion later
The phone can do work itself, not just act as a remote
One Table
The closest projects that were still being updated in the last month. 0 means none, 1 partial, 2 present, 3 mature:
| A Dispatch | B Honest | C Quota | D Resume | E Idle pick | F Privacy | G Phone | |
|---|---|---|---|---|---|---|---|
| Orca (82k★) | Mature | Present | Partial | Partial | None | None | Partial |
| Paperclip (95k★) | Mature | Present | Partial | Present | None | Partial | Partial |
| herdr (42k★) | Partial | Present | None | Present | None | Partial | None |
| agent-swarm (844★) | Present | Partial | None | Present | None | None | None |
| clodex (120★) | Present | Partial | Present | Partial | None | None | Partial |
| OmniRoute (72k★) | None | None | Mature | None | None | Partial | None |
| cc-router (263★) | None | None | Present | None | None | Partial | None |
| agent-custody (8★) | None | Mature | None | Partial | None | Partial | None |
| NVIDIA PAIR (beta) | Partial | None | None | None | Present | None | None |
Layer by Layer
A Dispatch: crowded, just borrow it
Running several AI coding tools in parallel, each in its own isolated working directory, with status on your phone — Orca (82k★), Paperclip (95k★) and multica (52k★) all do this well and ship almost daily. Alone, I would never catch up.
My approach: not a selling point. Use them as tools.
B Honest and contained: signed records have gone mainstream
I thought signing every AI action into an unalterable chain was something few people did. It turns out:
- agent-custody (Apache-2.0): every tool call through its gateway produces a signed receipt in a Merkle transparency log, verifiable offline; a "belief ledger" requires every memory write to cite the receipt that caused it, so a wrong belief can be traced to its blast radius. Almost the same design as mine.
- Lesson 18 of Microsoft's AI Agents for Beginners is literally called securing AI agents with cryptographic receipts.
- Several 2026 papers do the same thing, and the formats are converging.
My approach: this layer is necessary, not unique. My remaining differences are two: the device that actually ran the work signs (most designs sign at a gateway), and the chain spans devices. And outside verifiers should be able to read my format instead of me inventing one.
C Quota: a proven need, split three ways
Several projects appeared in September to solve "what happens when my subscription runs out", which tells me the pain is real. After reading their designs I split this layer into three:
Read the AI tools' own logs to compute the 5-hour window and weekly limit
One endpoint for many model providers, switch when full, fair sharing within rolling windows
Claude Code, Codex and similar tools metered per account: hand off to another vendor when one runs out
Two design details worth learning from:
- OmniRoute's quota sharing tracks each key's consumption inside a rolling window (Codex's 5-hour window, for example). While the pool is not saturated, a key can borrow idle share; once it is, sharing becomes strictly fair. Its published free-token total is also honest: deduplicated, re-audited every two weeks, and revised downwards when needed.
- clodex's account identity keys quota by the seat's account label, not by the organisation ID in the API response — the latter follows whichever response came last, so two subscriptions collapse into one flickering number.
And one warning that has to be said: cc-router's README states plainly that feeding subscription keys to a third-party proxy, or rotating several accounts of the same vendor, may violate the terms of service and trigger risk controls. So my version is limited to: different subscriptions, each legitimately mine, and only when one vendor runs out does work move to another. No multi-account rotation within one vendor, and no subscription keys handed to a third-party proxy.
D Resume elsewhere: the biggest gap
The most surprising result:
- Claude Code's own cross-machine session resume request (GitHub issue #31992) is still open today. The built-in
--resumeonly works on the same machine. - The community workaround is almost always a hand-off document — goal, done, not done, next step — for the next AI or person to read. The best-known one has not been updated in three months.
- The closest is agent-swarm: task state lives on a server, workers pull work, and tasks can wait for other tasks or a deadline before waking. That is the same shape as my phone's pull-and-report design.
The hard part of resuming elsewhere is not moving the conversation; it is knowing which side effects already happened and must not happen again. That is exactly the question signed records answer.
My approach: this layer moves from "half empty" to the biggest difference with the least competition. It should come earlier.
E Pick an idle machine: NVIDIA just arrived
At IFA in September, NVIDIA announced PAIR (Personal AI Router), now in beta and described as free and open source (I have not found the source yet). It finds idle, capable computers on your local network and routes agent and subagent work to them; Windows, macOS and Linux, with an RTX 20-series or newer, or Apple M4 or newer.
Its scheduler currently looks at queue depth and GPU utilisation. It does not know how much of my subscriptions is left, which data must not leave a given machine, or whether I have authorised that machine to run the work.
My approach: define machine choice as load + subscription quota + privacy level + authorisation together; once PAIR's source is out, evaluate it as the layer underneath local models.
F Privacy: nobody makes it the main goal
Everyone says self-hosted or local-first, but no project makes "privacy on every device, passive monitoring first" its main goal. As planned, this layer comes after machine picking.
G Phone: still only remotes
The phone projects I found either let an AI on a computer operate phone apps (for testing or automation), or let the phone remote-control an AI on a computer. A phone that is a worker on its own, still doing work when the computer is off, is not done by anyone. It is the most distinctive piece, and also the one with the least outside help and the highest cost.
Licence Traps
The more stars, the more important it is to open the LICENSE file:
| Project | Stars | Licence | Can I copy code? |
|---|---|---|---|
| oh-my-openagent (OmO) | 70k | Sustainable Use License (not an open-source licence) | No, reference only |
| OpenHuman | 40k | GPL-3.0 | Not compatible with my project, reference only |
| multica | 52k | Apache-2.0 with a custom preamble | Read the preamble first |
| OmniRoute, cc-router, agent-swarm, Orca, Paperclip | — | MIT | Yes, with the licence |
| herdr, clodex, agent-custody | — | Apache-2.0 | Yes, with licence and NOTICE |
A Method Anyone Can Use
Even if you don't write code, choosing among AI tools — or deciding whether to build or adopt — works the same way:
- Split what you want into questions you can check, instead of comparing "overall similarity".
- Search each layer separately. The project that looks most similar overall often does only a little of each layer.
- Check whether it was updated in the last month, not just its stars. A project idle for three months can't be depended on, however good.
- Open the licence file. Popular doesn't mean open source.
- Look for gaps, not crowds. Borrow the layer others ship daily; spend your own time only where nobody is.
Next Post
Following this conclusion, the next post is a build log: reading quotas of subscription-based AI tools and re-routing work — only handing off from one vendor to another when one runs out, no multi-account rotation. I'll record honestly how each tool reports its quota, what can be read and what can't.
References
- NVIDIA PAIR announcement (Engadget)
- NVIDIA PAIR announcement (Digit)
- Claude Code issue #31992: cross-machine session resume
- agent-custody: signed receipts for AI agent actions
- Microsoft AI Agents for Beginners, lesson 18: securing AI agents with cryptographic receipts
- Notarized Agents (arXiv)
- OmniRoute
- cc-router
- clodex
- agent-swarm
- ccusage
- Orca
- Paperclip
- herdr
- 9 Open-Source Agent Orchestrators for AI Coding (Augment Code)
- awesome-cli-coding-agents
- Previous post: Security Before Features