Work / AI Systems

Redl

A local-first AI workbench: model store, chat, a gated coding agent and a multi-agent Council in one Tauri app.

Status
built
Role
Solo: wrote the product brief and Council blueprint, directed Claude Code through the build
Timeline
Jul 2026 – Jul 2026
  • Rust
  • Tauri 2
  • tokio
  • reqwest (streaming)
  • React 19
  • TypeScript
  • Vite 7
  • Tailwind CSS 4
  • Monaco
  • SQLite
  • Ollama
  • Hugging Face Hub API
  • Anthropic and OpenAI-compatible APIs
  • Vitest

TL;DR

  • A desktop app with a Rust core: find a model on Hugging Face, see whether it fits your GPU, pull it, chat with it, point a coding agent at a real repo, or convene a multi-agent Council.
  • The coding agent speaks a plain-text protocol, so any model that can follow a format can drive it, and every edit waits on an approve-or-reject diff.
  • I wrote the product brief and the Council blueprint, directed Claude Code through 15 commits in about eleven hours, and pitched Redl to investors in San Francisco in July 2026.

The problem

Running models locally means juggling four tools: a model hub, a runtime, a chat window and an editor. None of them tells you before a multi-gigabyte download whether a model will even fit in your GPU’s memory. Coding agents mostly assume native tool calling, which many local models don’t support. And a single model answering alone has no second opinion.

What I built

Redl is one Tauri app with a Rust core and a React front end.

  • Store. Rust queries the Hugging Face Hub, groups GGUF quantizations and sums their shards, then reads the machine’s hardware to badge which models fit in VRAM. It streams Ollama pulls with cancel.
  • Runtime. Redl finds, spawns and stops the Ollama process, and it never kills an instance it didn’t start.
  • Chat. Streaming tokens over Tauri events, history in SQLite, a per-chat system prompt and temperature.
  • Code. A Monaco editor bundled locally, a file tree and attach-to-chat. File access is jailed to the workspace, and tests check that ../ and /etc escapes are rejected.
  • Agent. An in-house loop that emits fenced read, list, search, edit, create and run blocks. Reads run automatically, edits become diff cards, and shell commands are gated.
  • Council. An editable pyramid of agents: four specialists, then a proposer, a critic and a red team, then a judge. Each seat can be routed to local Ollama or to an OpenAI-compatible or Anthropic model, and a memory-budget recommender tells you when to run local seats one at a time or move them to the cloud.
  • Secrets. Provider API keys stay in the Rust process and never reach the UI.

Key decisions

  • Decision: a text protocol instead of native tool calling. Why: any model that can follow a format can drive the agent, including small local ones. Trade-off: the parser has to find action blocks in free-form output and tolerate the model’s formatting drift.
  • Decision: Rust owns the systems work: processes, downloads, hardware, files and keys. Why: the UI never touches a secret or an arbitrary path. Trade-off: every capability needs a typed Tauri command in both languages.
  • Decision: Aider-style SEARCH/REPLACE hunks for edits. Why: small, reviewable diffs that survive a model rewriting whitespace. Trade-off: a hunk whose search text has drifted too far fails and has to be retried.
  • Decision: per-seat model routing in the Council. Why: seats can mix local and cloud models to fit the machine. Trade-off: by default every seat runs the same local model, so the seats share its blind spots.

The hard part

Making an agent safe and model-agnostic without native tool calling. The protocol is plain fenced text, so the parser has to find action blocks inside whatever the model writes around them. SEARCH/REPLACE hunks have to apply even when the model’s whitespace drifts from the file on disk.

The permission model splits actions three ways. Reads auto-run, because they can’t change anything. Edits become diff cards the user approves or rejects. Shell runs are gated. All of it runs inside the workspace jail, so a confused or adversarial model output can’t reach outside the project. Eleven unit tests cover the agent loop, and a gated end-to-end test drives it against a real local model through Ollama.

Results

  • Built in 15 commits between the afternoon of July 13, 2026 and just after midnight.
  • 20 unit tests (agent 11, Council 9) and 3 Rust tests, plus gated end-to-end tests for both the agent and the Council.
  • Pitched Redl to investors in San Francisco in July 2026.
  • Redl became the base for my next builds: I forked it into Quorum, a local M&A diligence app that reused its Council engine, and then into Concord.

What I’d do next

  • Run one prompt across several models side by side and flag where they diverge, with a disagreement score. The Council synthesizes toward one answer today; this would show where the models split.
  • Signing and notarization, an updater and a public release.
  • The P(error | models agree) vs P(error | models disagree) benchmark from The Council.

Verified numbers

MetricValueSource
Commits from first line to working app (Jul 13 → 14, 2026)15local: CONCORD-TRANSFER/repos/redl.bundle
Coding-agent unit tests11local: redl/src/lib/agent.test.ts
Council unit tests9local: redl/src/lib/council.test.ts
Default Council seats (layers 4 → 3 → 1)8local: redl/src/lib/councilDefaults.ts:26-44
Pitched to investorsSan Francisco, Jul 2026mitansh-confirmed 2026-09-22
m.mittal
Home
Work
Research
Lab
About
Experience
Now
Résumé
Uses
Colophon
Contact
AccountWardin-build
Redlbuilt
The Councilresearch
BEMAresearch
EXIT LIQUIDITYin-build
NEXUSarchived
Warrant + Forgebuilt
Concordarchived
BlueCollarPalin-build
Chispenbuilt
Warrant Portalbuilt
JobAppin-build
Night/Dayexplored
BLACKSITE: NULLin-build
SlugBitesbuilt
Riptidebuilt
AeroBitesarchived
Internbuilt
CAD & 3D printingexplored
ForgeCouncilexplored
ADDE: adversarial due-diligence engineexplored
Model routing in practiceexplored
AI due-diligence market mapexplored
Quorumarchived
Colossus Wakeexplored
FitFindrbuilt
Project Omniexplored
Oblivionexplored
MeetWisebuilt
EyeOSexplored
LinkLeap AIexplored
Up-Toexplored
Offline speech-to-notes (Java)explored
AI-assisted game production pipelineexplored
COLLAPSEarchived
THE TRIALSarchived
EcoNodearchived
ESP32-S3 / LoRa benchexplored
CleanPlaybuilt
Rezonyrbuilt
Habit Tracker Telegram Botbuilt
Job Board Aggregatorin-build
Visual Hand Trackbuilt
CLI Task Trackerbuilt
All work44 entries
Can’t Hallucinate, Can Still Be Wrong: Calibration of a Typed-Decision Model Under Input Noisepaper
Disagreement as Signal: A Hybrid Multi-Agent and Council Architecture for Error Detection in LLM Systemspaper
Killing Good Ideasessay
Uncorrelated Failure Modesessay
ADDE: adversarial due-diligence engineexplored
AI due-diligence market mapexplored
AI-assisted game production pipelineexplored
Aura Chatexplored
Colossus Wakeexplored
EcoNodearchived
ESP32-S3 / LoRa benchexplored
EyeOSexplored
FitFindrbuilt
ForgeCouncilexplored
LinkLeap AIexplored
MeetWisebuilt
Model routing in practiceexplored
Offline speech-to-notes (Java)explored
Oblivionexplored
Print benchexplored
Project Omniexplored
Provably-fair outcome enginebuilt
Quorumarchived
Up-Toexplored
Copy hello@mitanshm.com
Switch theme
Play motion
RésuméPDF
Open GitHub ↗mit37
Open LinkedIn ↗
Toggle layout gridh
Toggle single-key shortcuts/ h