starlings

Product

Feature status

The state of each feature on every platform. We update it as the app changes.

Last updated . What changed, release by release, is in the changelog.

126

Entry, identity, and room access

FeatureStatusNotes
Open a permanent room link and see room / invite contextPermanent personal room / memorable linkHaveBare room links stay opaque; booking tokens can add title, time, and subject.
Book a time from a roomBookable link (/book/<slug>)HaveThe Mac in Join mode opens the public web booking page from Book a time; Host mode has no such button. The phone joins; booking is a web door.
Enter guest name and emailGuest join without accountHaveHuman guests do not need an account and provide email; a declared notetaker omits email and joins through the same owner-admission path.
Before-you-join camera and microphone checkHaveEach surface uses its platform-native permission and device flow.
Ask to join, waiting-room status, cancel, and reconnectWaiting room / admit–denyHaveNo LiveKit media token is issued until the owner admits the request. Every client can withdraw the knock and lands back on Prejoin.
Verified Envisioning owner sign-inHaveGoogle Workspace identity is required for owner actions. On the Mac sign-in belongs to the app, not the mode: Join mode fills in the signed-in owner's own name and email when you call a colleague.
Host presence / lease protectionHost must be onlineHaveThe control plane gates admission and token exchange on the owner device lease.
Token invite shows booking title / time / subjectHaveBooked links reveal that meeting only; bare slug stays opaque.
Guest reschedules / cancels a bookingHaveHandled on Core’s pages so calendar and CRM stay in sync.
Meeting password / passcodeDon't wantLobby + owner admit is the gate.
Disposable / one-off room codesDon't wantPermanent owner rooms only.
Dial-in / PSTN phone audioDon't wantWebRTC clients only.
SIP / hardware room systemsDon't wantOut of scope.

Live audio, video, and stage

FeatureStatusNotes
Mute and unmute microphoneMute / unmute microphoneHaveAvailable before joining and during the meeting.
Start and stop cameraStart / stop cameraHaveCamera-off tiles retain participant identity across clients.
Choose camera, microphone, and output deviceCamera / mic device selectionHaveEvery surface picks camera and microphone before joining and from the same chevron beside mute and camera in the call. iOS output stays with the system audio-route picker.
Spatial audio: voices from where the tiles areSpatial audioHaveMeet places each remote microphone on an arc in front of you, where that person's tile is on the stage, and moves the voice when the tile moves. HRTF on headphones, plain panning on speakers. On by default, with a switch on every surface. Screen-share audio stays centred.
Participant video grid, participant count, and People panelMulti-participant video gridHaveTuned for small rooms with a hard ~100-participant guardrail. People lists who is in the meeting with microphone, camera, and screen-share state; host actions stay native.
Publish a screen shareScreen share (display / window)HaveMac uses a display / window picker; browsers also expose their native tab option.
Watch and identify a remote screen shareHaveShared tiles are named and visually distinguished from camera video.
Stop your own screen shareHaveiOS does not publish screen shares.
Host stops another participant’s screen shareStop someone else’s screen share (host)HaveHost surfaces only; it stops the active share but does not ban future sharing.
Host mutes a participant, or everyone elseMute all / mute others (host)HaveMac and iOS owners. Closes microphones and opens none — unmuting stays with the person muted, on every surface.
Told who muted youHaveThe SFU mute is what silences the mic; the notice is what stops it reading as broken hardware.
Host removes a participant mid-callRemove / kick participant mid-callHaveMac and iOS owners, with confirmation. Disconnects them and spends the admission, so re-entry is a fresh knock.
Told you were removed, not droppedHaveAll clients distinguish removal from connection loss. iOS observes the session phase and shows an ended receipt with the reason and a way to join again.
Background blur and branded background effectsBackground blurHaveMac, web, and iOS have blur, the same small set of Block themes, and your own picture (scaled down and re-encoded on the device, with no metadata carried over; 1.7.8). Segmentation runs on the device — the room sees only composited frames.
Hide self viewHaveHiding the preview does not stop publishing the camera.
Connection quality and reconnect handlingConnection quality indicatorHaveiOS shows per-person quality and an explicit reconnecting state in the participants panel.
Leave the meeting or end it for everyoneLeave meetingHaveGuests and owner companions leave their own session. Mac and iOS hosts can end a personal room for everyone; ending the shared internal room for everyone is a separate confirmed action.
Speaker / output device selectionHaveMac Settings, in-meeting menus, meetctl; web prejoin + settings where the browser supports it; iOS route picker.
Share a region of the screenWantNatural third option in the Mac picker.
Share one browser tabPartialBrowser guests already can; Mac host shares a whole window.
Share computer audio with screenTBDCommon peer feature; not a first-class control today.
End meeting for all (host)HaveOwner finalizes the room and notes path.
Rejoin after brief disconnectHaveAdmitted credential → fresh token while the lease is live.
Speaker / active-speaker emphasisPartialScreen share auto-pins on web; no full Speaker View.
Pin / spotlight a participantDon't wantRemoved. A screen share takes the big tile on its own; there is no local pin and no host spotlight.
Gallery vs Speaker view toggleTBDMeet is grid-first today.
Full screen meeting windowPartialOS window chrome; no dedicated in-app stage mode.
Picture-in-picture / pop-out videoPartialOptional Mac self-view only; it can dock back to the stage. There is no generic participant pop-out.
Immersive / together mode layoutsDon't wantNovelty layouts.
Virtual / brand backgroundsPartialBrand Block themes; not arbitrary image upload.
Beauty / touch-up filtersDon't wantOut of scope.
Browser noise suppression / AECHaveExplicit capture defaults on web.
Advanced voice isolationTBDOS-level on Mac; not a Meet control yet.
HD / 1080p video togglePartialCapture around 720p-class; no user HD switch.
Low-light adjustmentDon't wantOut of scope.
Lock meeting (no new joins)PartialImplicit when the lease dies; no explicit lock toggle.
Co-host / alternate hostDon't wantExactly one verified Envisioning owner per room.
Host tools security menuDon't wantSingle-owner model.
Domain-restricted hostingHaveGoogle Workspace @envisioning.com / @envisioning.io owners only.

In-meeting collaboration and captions

FeatureStatusNotes
Room text chatIn-meeting text chatHaveOne room-wide text channel; file attachments and private DMs are not offered.
Embedded preview for a pasted linkHaveThe Worker reads the page and answers text; no client ever fetches a pasted link, so a site never learns who was in the room. In a meeting the read is authorized by the meeting itself, because a guest has no account. The page’s picture comes through the Worker too, on a signed address — without that signature the route would be an open image proxy.
Ephemeral emoji reactionsEmoji reactionsHaveSix reactions float in the room and are not stored.
Reactions on a chat messageHaveThe same six emoji, on a message rather than on the room. Reliable rather than lossy, because a tally has to still be right in ten minutes — but stored nowhere: they last as long as the chat does, which is the call, and never reach the record or the summary.
Live captions from the owner deviceLive captionsHaveSpeech-to-text runs locally on whichever owner device is the host; only caption text is shared.
Show and hide the live transcript / captions viewShow / hide captions UIHaveiOS keeps the caption strip on the stage and opens the full transcript from More.
Finalized transcript and AI summary deliveryMeeting transcript (finalized text)HaveRead in Meet once finalized, by participants with artifact access; consent-filtered. Share a link to the meeting page (it grants nothing), copy the text, or download .md or .txt: on the web from the meeting page, on the Mac and iPhone from the live transcript. Nothing is emailed and nothing is recorded.
Meeting duration and ended receiptHaveJoining clients explain when the owner ended the room or the session was lost.
Chat file attachmentsDon't wantText only; no file plane.
Raise handHaveStays up until lowered, survives reconnects; badge on the tile, queue count on People. The host can lower every hand at once.
Participant list panelHavePeople panel on every client with per-person mic, camera, and share state; host actions (mute, remove) stay native.
Private / DM chatDon't wantOne room chat.
WhiteboardDon't wantUse external docs.
Collaborative docs / slides in-callDon't wantOut of scope.
Polls / quizzesDon't wantOut of scope.
Breakout roomsDon't wantExplicit non-goal.
Annotation on shared screenDon't wantOut of scope.
Third-party in-meeting appsDon't wantNo marketplace.
AI meeting summaryHaveAvailable in Meet after finalization to participants with artifact access.
Cloud A/V recording + playback URLWantProposed, not decided. Meet does not record today; consent and retention still open.
Local A/V recordingDon't wantCloud recording is the supported path if it ships.
Livestream to YouTube / TwitchDon't wantOut of scope.
Artifact viewer / delete / exportWantNeeded before broad transcript rollout.
CRM / meeting log ingestHaveHosted Meet sessions and Granola notes can sync finalized meeting text into Core interactions; deployment needs the optional Core secret and migration.

Owner workspace, scheduling, and operations

FeatureStatusNotes
Home / own room status / copy room linkCopy invite / share linkHaveHome is today on web too — the clock, then the modules in the order you chose in Settings → Home, among them your room with its link, a copy button and Schedule…, with Home / Calendar / Work / Team / Docs navigation. The member room/Meet flow belongs to Home; `/join` remains a direct public room door. On the Mac the launch card is Host mode only. Starting the room is native (see Start room, admit / reject guests).
Connect Google Calendar and subscribed feeds, view the Upcoming agendaHaveAccount attachments, Google calendar selection, and subscribed-feed selection use the shared control-plane contract; refresh tokens stay encrypted there, not on the device. Home Upcoming includes selected Google calendars and subscribed feeds on Mac, iOS, and web; events marked Hide from Next are omitted there and from alerts, while remaining visible in Calendar. Web reads the Google week or month at `/calendar`, shows explicit travel duration metadata when present, and can start the Google connect flow. Its Calendars menu turns each account, Google calendar and the subscribed feeds on or off in the same owner-wide choice the Mac and iPhone read. It can create timed events, edit and delete writable ones, and answer an invitation. EventKit calendars are read on the Mac and iPhone only.
Native Calendar views (Google + EventKit + subscriptions)HaveMac has the full window/sidebar and direct grid move/resize; iOS has day/2-day/3-day/week/month/agenda, source management, and deliberate long-press movement, while resize stays in the editor. Upcoming rows show explicit travel duration metadata when supplied; Meet never estimates routes. Envisioning Internal remains writable shared context but is not a move source or destination; Duplicate is the copy path. Web shows one Google week or one month at a time, with no day or multi-day grid and no drag. It adds read-only Events, Milestones, Tasks, and Core-computed My availability layers, which it toggles only in the browser.
Create a meeting invitation from the owner workspaceSchedule from calendarPartialNative clients create meeting invitations; web creates timed or all-day Google events with invitees, location and notes. Adding a Meet booking token remains native; visitor booking is separate.
Describe an event in one sentenceHaveA field above the new-event form fills in title, times, place and guests from one sentence, on all three surfaces; nothing is saved until Add. One grammar in Swift and TypeScript on one fixture; a sentence it cannot read goes to the notes engine, and the form says so.
Forward a mail to calendar@ and add the events it describesHaveA member forwards a booking or an invitation to calendar@ on the inbound domain; Home proposes each event on the INVITATIONS module with Add and Discard, on all three surfaces. Add writes to the primary Google calendar. The mail body is read once and not kept. Needs INBOUND_EMAIL_DOMAIN, which production does not have yet.
Calendar selection, display preferences, timezone/weather, public events, and contactsHaveSource selection is one owner-wide choice that the Mac, iPhone and web Calendars menu all write, and Upcoming display policy is shared and editable from Settings on all three surfaces. Device-local grid preferences, timezone/weather, and contacts remain native. Web lists and locally toggles the read-only Events, Milestones, Tasks, and Core-computed My availability layers. Web edits all-day dates and chooses This event or All events on a recurring Google event; the Mac adds All future on EventKit calendars, which the browser does not read.
Start room, admit / reject guests, and end roomAdmit / reject waiting guestsHaveiOS hosts its owner’s permanent room: start, waiting room, admit and decline, end. Web still explains the native requirement and offers “Join my room” while the room is open, rather than starting one.
Move the host between devices and membersHaveThe host sees a Host badge on its tile, and so does everyone. Move host… hands the host to another Mac, iPhone or iPad in the call: another of the same member takes it at once; another Envisioning member is asked and, on yes, rejoins as the host, in any room. A connected Mac companion can also take the host; the current Mac drains local transcription and uploads pending text first. When the host leaves or its lease runs out, a connected companion Mac takes host on its own. The room owner keeps room settings and End meeting, and can take the host back. A live phone host is asked to hand over only when it offered the host itself.
Guest knock alerts and host wake protectionWaiting-room knock alertsHaveMac owns waiting-room sound / Dock alerts and the host wake assertion; in Join mode it still sounds and badges a knock at your own room, but holds no wake assertion. iOS posts a local knock notification while the app is running — there is no push — and holds the screen awake instead of a wake assertion.
Account, audio/video, captions, calendar, privacy, and update settingsIn-app settingsHaveMac has the complete settings area, in either mode. Web has Settings at /settings from the header gear — account and picture, Google Calendar connection, the Gmail and Drive grant, appearance, about, sign out; audio, video and background stay in the in-meeting Settings. Privacy remains available from the site footer. iOS exposes its applicable subset.
Team presence — who at Envisioning is around, and call a peerHaveMembers only, never guests. Every client reads the roster and offers Message, Wave, Call, and Join room from a person's context menu; a video mark on the shared avatar shows a live meeting. Agents are messageable but never waved or called.
Profile picture — one face per member, drawn everywhere a person isHaveMembers only, never guests: the roster carries the version, the image is a member-gated read, and every surface falls back to the same initials. Uploaded from the Team window on macOS, the Team tab on iOS, and your own row at `/team`. Seeded once from the Google account picture, which an upload replaces.
Direct messages between membersHaveTeam opens DMs, notes to self and Everyone on all clients. Format message text with bold, italic, strikethrough, inline code, links, lists, quotes, and code blocks; each client renders the same Markdown subset. React to any message, including your own; copy your own text to private Quick Notes for the usual Work triage. Web supports send, older history, visible-tab polling, bounded read receipts, and per-member archive; a new message brings an archived DM back.
Interactive questions in agent conversationsHaveAn agent can ask a short informational question with two to eight choices in its DM or a thread it belongs to. A single choice submits immediately; people select several options and explicitly submit them. Meet stores one winning human reply and resumes the same Eve thread session. Available in Web, Mac and iOS chats. It does not request approval or authorization.
Private group conversationsHaveA DM with more than one other person in it — same kind, same authorization, no name: the people in it are the name. Started from Team on every client, and found there again afterwards. Up to twelve people; past that the answer is Everyone. Not a channel, and not discoverable — you cannot browse to one, only be in one.
Channels on the work itselfHaveOne conversation on each project and lead, reached by opening the subject in Work — never by making a channel. Unread routes to Work on every client: the Mac launch button, the iOS tab badge and Home card, and Work's Mine pane, which lists subjects with something new first. Web opens the subject conversation from Talk in Work.
Projects and leads, with their tasks and issuesHaveWork: Mine, Envisioning Projects, Projects and Leads — a foldable sidebar on Mac and a single work list on iOS, with the same work graph on web. New leads and projects require a Core organization; the Mac, iPhone/iPad and web pickers search Core and can create an organization inline. Create, assign, date, complete and file a task on GitHub; read, comment on, close and file GitHub issues on a linked project. Mine completes in place on every client (a tick on Mac and web, a swipe on iOS) and files on GitHub from the row natively. Team person details on every client also list assigned open tasks and, when GitHub is connected, issues; task rows open in the client task view, and New task starts the usual editor after a searchable project/lead choice. Recently finished work stays available for seven days on all three clients, with a Reopen action for tasks and issues. Overview lists UNOWNED below Mine on all three clients: open tasks and issues on any subject that nobody on Envisioning's side holds. All three clients create and edit supported project/lead fields through the Worker; Core stays the system of record. A member's Claude creates a lead through MCP `task` with `action: "create_lead"`, and Core posts "New Lead Created" in its channel. Web also creates, edits, comments on, closes/reopens and manages metadata for issues.
Goals on a project, decisions on any subjectHaveA goal is a title with a status, a target date and an owner on a project; tasks and decisions point at it. A decision is something the team settled on a project, lead, partner or event, written once, with its source: typed, a channel line marked as one, a Claude through MCP, or the meeting notes. Both live in Core. Every client lists them on the subject, picks a goal on the task sheet, marks a channel line as a decision, and finds both in search; the web meeting page records or dismisses what the notes proposed. Meet#261, #262, #278.
A queue of decisions waiting on youHaveAn agent puts a question to a member through MCP `ask_decision` — options, a recommendation and a default-by day — when nobody is in the conversation with it, instead of burying it in an issue comment. It is the first row in INBOX on every client, overdue first; one tap on an option answers it, with an optional note, and opening it shows the context and links. The agent reads the answer back through `now` or `ask_decision`. An answer on a subject is recorded as that subject's decision in Core. Past the default-by day a decision shows as overdue; the recommendation is applied only when somebody asks for it.
Interaction history on a project or leadHaveA read-only History pane shows durable Core history — Meet and Granola meetings, notes, calls, emails and web touches — with type, date, people, duration/status and a preview.
Every field on a project, lead or partnerHaveA subject's Fields pane draws every field Core's registry lists for the record behind it — the project, the lead, or a partner's organization — and saves only what changed, when you say, as you. Core decides what you may change. Mac and iOS read Core with a device token; the web reads and writes through Meet as the member and holds no Core token. The web edits text, numbers, dates, toggles and choices; relations, lists, countries and industries show read-only there and edit on the Mac, the phone or in Core. An event's fields are its CMS page.
Core in searchHaveSearch lists each Core entity you can read. On Mac and iOS it opens that entity in Work's Core browser, and Search Core finds records across them. On the web the entity opens on Core's own page, and the palette finds Core records below Docs: a project or lead opens on its Fields in Work, anything else on its Core page. Browsing Core entity by entity stays on Mac and iOS.
Keep: client credentials in sealed vaultsHaveKeep holds client credentials in vaults the server cannot read: every value is sealed on the device under keys only the vault's members hold. Mac and iOS open Keep from Work, and a project's menu opens its vault. The web is deliberately without Keep: a browser would have to trust whoever serves its JavaScript with the keys, so a project's Keep vault on the web says to open it on Mac or iPhone and never shows vault material.
Issues that read like GitHub's ownHaveBoth native clients have labels, assignees, milestones, server-backed filters/sort, pagination, issue details, comments and activity, and metadata editing. iOS uses Foundation markdown with fallback text; Mac has its own richer reading surface. Web reads details/activity and supports issue actions with repository metadata pickers; description text preserves markdown source, while native reading remains richer.
Today's work on HomeHaveWhat is overdue and what is due today, on the Mac launch card and menu bar, on the iOS Home and on the web Home (its Work card), each row opening its subject in Work on the Tasks pane. Decided on the device, so "today" is the day you are in. Hidden when there is nothing.
Meet about a project or leadHaveStart your room from a subject in Work and the meeting is filed under it the moment it opens — notes and tasks land where the conversation is. On the Mac a filed meeting's CRM sidebar opens the subject in Work; the phone's hosting screen owns the session and has no door out.
A meeting's trail in its channelHaveA project or lead channel carries quiet lines the work graph writes: a meeting filed here, ended and how long it ran, notes filed, a task the meeting proposed and somebody accepted. Never unread on their own, never the preview. Web renders these event rows in Talk too.
A calendar event knows its project or leadHaveFile any event under a subject from the Mac inspector or the phone's event sheet; the choice is owner-wide. The web event editor names the subject an event is filed on and links to it, but cannot file one. A room started from that event is filed under it, Home and the launch card name it, and Google events arrive filed from the control plane.
Docs: the corpus, read and written from MeetHaveThe fifth surface: newsletters, reports, research, notes and everything written from Meet, on the shared shell. Documents on a subject in Work are the contextual slice of the same store. Connecting is one act in Settings → Account.
Docs graph viewHaveSee up to 5,000 accessible Docs documents in the same graph across Mac, iPhone, iPad, and web. Folders group and color nodes; resolved wikilinks draw connections and pull related nodes closer. Filter groups, pan, zoom, fit visible nodes, and open documents.

Call and task reading

FeatureStatusNotes
Call an available colleagueHaveCall asks an available colleague to open their room, waits up to 45 seconds, and joins through the ordinary admission flow when it opens. When a meeting is already live, the person menu offers Join room directly.
Answer an idle-room CallHaveNative clients offer Open room / Not now; the browser explains the native hosting requirement and can decline. Calls do not enable notes by default on the answering native device; notes can be turned on deliberately.
Read a task directly from MineHaveEvery client opens task details and subject navigation from Mine, with edit and completion actions. iOS also opens the same reader from a subject task list.

Clients, ops, and platform

FeatureStatusNotes
CLI / agent control through `meetctl`CLI / agent meeting controlHaveSame-user local socket for status, host, lobby, media, transcript, and leave commands.
Native auto-updateAuto-update (native)HaveMac checks the signed update feed; iOS uses App Store / TestFlight distribution.
macOS native host appHaveAppKit Host mode.
macOS native joinHaveSame admit contract as the browser.
Browser guestHavePrimary guest path.
Windows / Linux nativeDon't wantBrowser covers guests.
iOS / iPad clientHaveSwiftUI Host and Join: start your room, admit at the door, transcribe on device, file the meeting. Screen sharing from iOS is still ahead.
Android clientTBDBrowser may be enough.
Meeting info panelPartialInvite link + room status; no Zoom-style Meeting Info sheet.
Webinar / presenter–audience rolesWantBacklog; do not market webinars until roles and load work exist.
Capacity hard limit (~100)HaveSafety guardrail, not a webinar product.
One wire contract for every clientHaveEvery shape the server sends or accepts is written once, as a schema. The web reads it as types, and the Mac, iPhone and watch read and write Swift generated from it. A field that changes fails the build, not the phone.
Notetakers attend as declared meeting participantsPartialThe listening slice works on every client; the row stays partial for the speaking half. A link-joining recording notetaker declares itself, waits for owner admission, is marked across the room, can be refused per room, and leaves a transcript consent line. Speaking agents, their room-side worker, and live MCP tools remain planned.
Website content from a ClaudeHaveA member's Claude reads and writes envisioning.com content — events, and the other CMS entities the registry publishes — through Meet, as the member, with a cms-editor PAT. On the web, a member with that grant also edits an event's CMS record from the Calendar and Work (meet#530). The same tool lists and reads organizations, contacts, interactions, projects and leads, creates and edits all five (a note is an interaction), and deletes an organization only when no record points at it, as the member.
An agent starts a meetingHave`start_meeting` schedules the meeting in the member's own room and asks their devices to open it: the ask rides `rings` with a 45-second life, and the member answers Open room or Not now. The Worker never hosts and nothing opens a microphone on its own, so an unanswered ask leaves the meeting on the calendar and the room shut. A meeting opened this way transcribes, because it is convened; a walk-up from Call does not.
Agent activity in AdminHaveWeb Admin › Agents shows the last 30 days of handoffs, runtime acceptance or refusal, final replies observed by Meet, and watchdog reset outcomes. It does not show work inside an agent runtime or model costs.

By surface

macOS HostAuthoritative host: starts rooms, admits guests, and runs local transcription.
macOS JoinThe Mac app in Join mode: joins another room as a guest through the same waiting-room and media contract as the web. Calendar, Work, Team, Docs and Settings are the app's windows, open in either mode; Home's launch card, hosting and moderation are Host mode only.
WebZero-install guest, booking, and signed-in workspace; live hosting still hands to a native owner client.
iOS / iPadOSHosts, admits, and transcribes on device, alongside joining and owner scheduling.
WorksPartialHandoffNot available

Entry, identity, and room access

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
Open a permanent room link and see room / invite contextWorksWorksWorksWorksBare room links stay opaque; booking tokens can add title, time, and subject.
Book a time from a roomNot availableHandoffWorksNot availableThe Mac in Join mode opens the public web booking page from Book a time; Host mode has no such button. The phone joins; booking is a web door.
Enter guest name and emailWorksWorksWorksWorksHuman guests do not need an account and provide email; a declared notetaker omits email and joins through the same owner-admission path.
Before-you-join camera and microphone checkWorksWorksWorksWorksEach surface uses its platform-native permission and device flow.
Ask to join, waiting-room status, cancel, and reconnectWorksWorksWorksWorksNo LiveKit media token is issued until the owner admits the request. Every client can withdraw the knock and lands back on Prejoin.
Verified Envisioning owner sign-inWorksWorksWorksWorksGoogle Workspace identity is required for owner actions. On the Mac sign-in belongs to the app, not the mode: Join mode fills in the signed-in owner's own name and email when you call a colleague.
Host presence / lease protectionWorksWorksWorksWorksThe control plane gates admission and token exchange on the owner device lease.

Live audio, video, and stage

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
Mute and unmute microphoneWorksWorksWorksWorksAvailable before joining and during the meeting.
Start and stop cameraWorksWorksWorksWorksCamera-off tiles retain participant identity across clients.
Choose camera, microphone, and output deviceWorksWorksWorksPartialEvery surface picks camera and microphone before joining and from the same chevron beside mute and camera in the call. iOS output stays with the system audio-route picker.
Spatial audio: voices from where the tiles areWorksWorksWorksWorksMeet places each remote microphone on an arc in front of you, where that person's tile is on the stage, and moves the voice when the tile moves. HRTF on headphones, plain panning on speakers. On by default, with a switch on every surface. Screen-share audio stays centred.
Participant video grid, participant count, and People panelWorksWorksWorksWorksTuned for small rooms with a hard ~100-participant guardrail. People lists who is in the meeting with microphone, camera, and screen-share state; host actions stay native.
Publish a screen shareWorksWorksWorksNot availableMac uses a display / window picker; browsers also expose their native tab option.
Watch and identify a remote screen shareWorksWorksWorksWorksShared tiles are named and visually distinguished from camera video.
Stop your own screen shareWorksWorksWorksNot availableiOS does not publish screen shares.
Host stops another participant’s screen shareWorksNot availableNot availableWorksHost surfaces only; it stops the active share but does not ban future sharing.
Host mutes a participant, or everyone elseWorksNot availableNot availableWorksMac and iOS owners. Closes microphones and opens none — unmuting stays with the person muted, on every surface.
Told who muted youWorksWorksWorksWorksThe SFU mute is what silences the mic; the notice is what stops it reading as broken hardware.
Host removes a participant mid-callWorksNot availableNot availableWorksMac and iOS owners, with confirmation. Disconnects them and spends the admission, so re-entry is a fresh knock.
Told you were removed, not droppedWorksWorksWorksWorksAll clients distinguish removal from connection loss. iOS observes the session phase and shows an ended receipt with the reason and a way to join again.
Background blur and branded background effectsWorksWorksWorksWorksMac, web, and iOS have blur, the same small set of Block themes, and your own picture (scaled down and re-encoded on the device, with no metadata carried over; 1.7.8). Segmentation runs on the device — the room sees only composited frames.
Hide self viewWorksWorksWorksWorksHiding the preview does not stop publishing the camera.
Connection quality and reconnect handlingWorksWorksWorksWorksiOS shows per-person quality and an explicit reconnecting state in the participants panel.
Leave the meeting or end it for everyoneWorksWorksWorksWorksGuests and owner companions leave their own session. Mac and iOS hosts can end a personal room for everyone; ending the shared internal room for everyone is a separate confirmed action.

In-meeting collaboration and captions

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
Room text chatWorksWorksWorksWorksOne room-wide text channel; file attachments and private DMs are not offered.
Embedded preview for a pasted linkWorksWorksWorksWorksThe Worker reads the page and answers text; no client ever fetches a pasted link, so a site never learns who was in the room. In a meeting the read is authorized by the meeting itself, because a guest has no account. The page’s picture comes through the Worker too, on a signed address — without that signature the route would be an open image proxy.
Ephemeral emoji reactionsWorksWorksWorksWorksSix reactions float in the room and are not stored.
Reactions on a chat messageWorksWorksWorksWorksThe same six emoji, on a message rather than on the room. Reliable rather than lossy, because a tally has to still be right in ten minutes — but stored nowhere: they last as long as the chat does, which is the call, and never reach the record or the summary.
Live captions from the owner deviceWorksWorksWorksWorksSpeech-to-text runs locally on whichever owner device is the host; only caption text is shared.
Show and hide the live transcript / captions viewWorksWorksWorksWorksiOS keeps the caption strip on the stage and opens the full transcript from More.
Finalized transcript and AI summary deliveryWorksWorksWorksWorksRead in Meet once finalized, by participants with artifact access; consent-filtered. Share a link to the meeting page (it grants nothing), copy the text, or download .md or .txt: on the web from the meeting page, on the Mac and iPhone from the live transcript. Nothing is emailed and nothing is recorded.
Meeting duration and ended receiptWorksWorksWorksWorksJoining clients explain when the owner ended the room or the session was lost.

Owner workspace, scheduling, and operations

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
Home / own room status / copy room linkWorksNot availableWorksWorksHome is today on web too — the clock, then the modules in the order you chose in Settings → Home, among them your room with its link, a copy button and Schedule…, with Home / Calendar / Work / Team / Docs navigation. The member room/Meet flow belongs to Home; `/join` remains a direct public room door. On the Mac the launch card is Host mode only. Starting the room is native (see Start room, admit / reject guests).
Connect Google Calendar and subscribed feeds, view the Upcoming agendaWorksWorksPartialWorksAccount attachments, Google calendar selection, and subscribed-feed selection use the shared control-plane contract; refresh tokens stay encrypted there, not on the device. Home Upcoming includes selected Google calendars and subscribed feeds on Mac, iOS, and web; events marked Hide from Next are omitted there and from alerts, while remaining visible in Calendar. Web reads the Google week or month at `/calendar`, shows explicit travel duration metadata when present, and can start the Google connect flow. Its Calendars menu turns each account, Google calendar and the subscribed feeds on or off in the same owner-wide choice the Mac and iPhone read. It can create timed events, edit and delete writable ones, and answer an invitation. EventKit calendars are read on the Mac and iPhone only.
Native Calendar views (Google + EventKit + subscriptions)WorksWorksPartialPartialMac has the full window/sidebar and direct grid move/resize; iOS has day/2-day/3-day/week/month/agenda, source management, and deliberate long-press movement, while resize stays in the editor. Upcoming rows show explicit travel duration metadata when supplied; Meet never estimates routes. Envisioning Internal remains writable shared context but is not a move source or destination; Duplicate is the copy path. Web shows one Google week or one month at a time, with no day or multi-day grid and no drag. It adds read-only Events, Milestones, Tasks, and Core-computed My availability layers, which it toggles only in the browser.
Create a meeting invitation from the owner workspaceWorksWorksPartialWorksNative clients create meeting invitations; web creates timed or all-day Google events with invitees, location and notes. Adding a Meet booking token remains native; visitor booking is separate.
Describe an event in one sentenceWorksWorksWorksWorksA field above the new-event form fills in title, times, place and guests from one sentence, on all three surfaces; nothing is saved until Add. One grammar in Swift and TypeScript on one fixture; a sentence it cannot read goes to the notes engine, and the form says so.
Forward a mail to calendar@ and add the events it describesWorksNot availableWorksWorksA member forwards a booking or an invitation to calendar@ on the inbound domain; Home proposes each event on the INVITATIONS module with Add and Discard, on all three surfaces. Add writes to the primary Google calendar. The mail body is read once and not kept. Needs INBOUND_EMAIL_DOMAIN, which production does not have yet.
Calendar selection, display preferences, timezone/weather, public events, and contactsWorksWorksPartialWorksSource selection is one owner-wide choice that the Mac, iPhone and web Calendars menu all write, and Upcoming display policy is shared and editable from Settings on all three surfaces. Device-local grid preferences, timezone/weather, and contacts remain native. Web lists and locally toggles the read-only Events, Milestones, Tasks, and Core-computed My availability layers. Web edits all-day dates and chooses This event or All events on a recurring Google event; the Mac adds All future on EventKit calendars, which the browser does not read.
Start room, admit / reject guests, and end roomWorksNot availableHandoffWorksiOS hosts its owner’s permanent room: start, waiting room, admit and decline, end. Web still explains the native requirement and offers “Join my room” while the room is open, rather than starting one.
Move the host between devices and membersWorksWorksNot availableWorksThe host sees a Host badge on its tile, and so does everyone. Move host… hands the host to another Mac, iPhone or iPad in the call: another of the same member takes it at once; another Envisioning member is asked and, on yes, rejoins as the host, in any room. A connected Mac companion can also take the host; the current Mac drains local transcription and uploads pending text first. When the host leaves or its lease runs out, a connected companion Mac takes host on its own. The room owner keeps room settings and End meeting, and can take the host back. A live phone host is asked to hand over only when it offered the host itself.
Guest knock alerts and host wake protectionWorksPartialNot availablePartialMac owns waiting-room sound / Dock alerts and the host wake assertion; in Join mode it still sounds and badges a knock at your own room, but holds no wake assertion. iOS posts a local knock notification while the app is running — there is no push — and holds the screen awake instead of a wake assertion.
Account, audio/video, captions, calendar, privacy, and update settingsWorksWorksPartialPartialMac has the complete settings area, in either mode. Web has Settings at /settings from the header gear — account and picture, Google Calendar connection, the Gmail and Drive grant, appearance, about, sign out; audio, video and background stay in the in-meeting Settings. Privacy remains available from the site footer. iOS exposes its applicable subset.
Team presence — who at Envisioning is around, and call a peerWorksWorksWorksWorksMembers only, never guests. Every client reads the roster and offers Message, Wave, Call, and Join room from a person's context menu; a video mark on the shared avatar shows a live meeting. Agents are messageable but never waved or called.
Profile picture — one face per member, drawn everywhere a person isWorksWorksWorksWorksMembers only, never guests: the roster carries the version, the image is a member-gated read, and every surface falls back to the same initials. Uploaded from the Team window on macOS, the Team tab on iOS, and your own row at `/team`. Seeded once from the Google account picture, which an upload replaces.
Direct messages between membersWorksWorksWorksWorksTeam opens DMs, notes to self and Everyone on all clients. Format message text with bold, italic, strikethrough, inline code, links, lists, quotes, and code blocks; each client renders the same Markdown subset. React to any message, including your own; copy your own text to private Quick Notes for the usual Work triage. Web supports send, older history, visible-tab polling, bounded read receipts, and per-member archive; a new message brings an archived DM back.
Interactive questions in agent conversationsWorksWorksWorksWorksAn agent can ask a short informational question with two to eight choices in its DM or a thread it belongs to. A single choice submits immediately; people select several options and explicitly submit them. Meet stores one winning human reply and resumes the same Eve thread session. Available in Web, Mac and iOS chats. It does not request approval or authorization.
Private group conversationsWorksWorksWorksWorksA DM with more than one other person in it — same kind, same authorization, no name: the people in it are the name. Started from Team on every client, and found there again afterwards. Up to twelve people; past that the answer is Everyone. Not a channel, and not discoverable — you cannot browse to one, only be in one.
Channels on the work itselfWorksWorksWorksWorksOne conversation on each project and lead, reached by opening the subject in Work — never by making a channel. Unread routes to Work on every client: the Mac launch button, the iOS tab badge and Home card, and Work's Mine pane, which lists subjects with something new first. Web opens the subject conversation from Talk in Work.
Projects and leads, with their tasks and issuesWorksWorksWorksWorksWork: Mine, Envisioning Projects, Projects and Leads — a foldable sidebar on Mac and a single work list on iOS, with the same work graph on web. New leads and projects require a Core organization; the Mac, iPhone/iPad and web pickers search Core and can create an organization inline. Create, assign, date, complete and file a task on GitHub; read, comment on, close and file GitHub issues on a linked project. Mine completes in place on every client (a tick on Mac and web, a swipe on iOS) and files on GitHub from the row natively. Team person details on every client also list assigned open tasks and, when GitHub is connected, issues; task rows open in the client task view, and New task starts the usual editor after a searchable project/lead choice. Recently finished work stays available for seven days on all three clients, with a Reopen action for tasks and issues. Overview lists UNOWNED below Mine on all three clients: open tasks and issues on any subject that nobody on Envisioning's side holds. All three clients create and edit supported project/lead fields through the Worker; Core stays the system of record. A member's Claude creates a lead through MCP `task` with `action: "create_lead"`, and Core posts "New Lead Created" in its channel. Web also creates, edits, comments on, closes/reopens and manages metadata for issues.
Goals on a project, decisions on any subjectWorksWorksWorksWorksA goal is a title with a status, a target date and an owner on a project; tasks and decisions point at it. A decision is something the team settled on a project, lead, partner or event, written once, with its source: typed, a channel line marked as one, a Claude through MCP, or the meeting notes. Both live in Core. Every client lists them on the subject, picks a goal on the task sheet, marks a channel line as a decision, and finds both in search; the web meeting page records or dismisses what the notes proposed. Meet#261, #262, #278.
A queue of decisions waiting on youWorksWorksWorksWorksAn agent puts a question to a member through MCP `ask_decision` — options, a recommendation and a default-by day — when nobody is in the conversation with it, instead of burying it in an issue comment. It is the first row in INBOX on every client, overdue first; one tap on an option answers it, with an optional note, and opening it shows the context and links. The agent reads the answer back through `now` or `ask_decision`. An answer on a subject is recorded as that subject's decision in Core. Past the default-by day a decision shows as overdue; the recommendation is applied only when somebody asks for it.
Interaction history on a project or leadWorksWorksWorksWorksA read-only History pane shows durable Core history — Meet and Granola meetings, notes, calls, emails and web touches — with type, date, people, duration/status and a preview.
Every field on a project, lead or partnerWorksWorksWorksWorksA subject's Fields pane draws every field Core's registry lists for the record behind it — the project, the lead, or a partner's organization — and saves only what changed, when you say, as you. Core decides what you may change. Mac and iOS read Core with a device token; the web reads and writes through Meet as the member and holds no Core token. The web edits text, numbers, dates, toggles and choices; relations, lists, countries and industries show read-only there and edit on the Mac, the phone or in Core. An event's fields are its CMS page.
Core in searchWorksWorksWorksWorksSearch lists each Core entity you can read. On Mac and iOS it opens that entity in Work's Core browser, and Search Core finds records across them. On the web the entity opens on Core's own page, and the palette finds Core records below Docs: a project or lead opens on its Fields in Work, anything else on its Core page. Browsing Core entity by entity stays on Mac and iOS.
Keep: client credentials in sealed vaultsWorksWorksHandoffWorksKeep holds client credentials in vaults the server cannot read: every value is sealed on the device under keys only the vault's members hold. Mac and iOS open Keep from Work, and a project's menu opens its vault. The web is deliberately without Keep: a browser would have to trust whoever serves its JavaScript with the keys, so a project's Keep vault on the web says to open it on Mac or iPhone and never shows vault material.
Issues that read like GitHub's ownWorksWorksPartialWorksBoth native clients have labels, assignees, milestones, server-backed filters/sort, pagination, issue details, comments and activity, and metadata editing. iOS uses Foundation markdown with fallback text; Mac has its own richer reading surface. Web reads details/activity and supports issue actions with repository metadata pickers; description text preserves markdown source, while native reading remains richer.
Today's work on HomeWorksNot availableWorksWorksWhat is overdue and what is due today, on the Mac launch card and menu bar, on the iOS Home and on the web Home (its Work card), each row opening its subject in Work on the Tasks pane. Decided on the device, so "today" is the day you are in. Hidden when there is nothing.
Meet about a project or leadWorksNot availableNot availableWorksStart your room from a subject in Work and the meeting is filed under it the moment it opens — notes and tasks land where the conversation is. On the Mac a filed meeting's CRM sidebar opens the subject in Work; the phone's hosting screen owns the session and has no door out.
A meeting's trail in its channelWorksWorksWorksWorksA project or lead channel carries quiet lines the work graph writes: a meeting filed here, ended and how long it ran, notes filed, a task the meeting proposed and somebody accepted. Never unread on their own, never the preview. Web renders these event rows in Talk too.
A calendar event knows its project or leadWorksWorksPartialWorksFile any event under a subject from the Mac inspector or the phone's event sheet; the choice is owner-wide. The web event editor names the subject an event is filed on and links to it, but cannot file one. A room started from that event is filed under it, Home and the launch card name it, and Google events arrive filed from the control plane.
Docs: the corpus, read and written from MeetWorksWorksWorksWorksThe fifth surface: newsletters, reports, research, notes and everything written from Meet, on the shared shell. Documents on a subject in Work are the contextual slice of the same store. Connecting is one act in Settings → Account.
Docs graph viewWorksWorksWorksWorksSee up to 5,000 accessible Docs documents in the same graph across Mac, iPhone, iPad, and web. Folders group and color nodes; resolved wikilinks draw connections and pull related nodes closer. Filter groups, pan, zoom, fit visible nodes, and open documents.

Call and task reading

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
Call an available colleagueWorksWorksWorksWorksCall asks an available colleague to open their room, waits up to 45 seconds, and joins through the ordinary admission flow when it opens. When a meeting is already live, the person menu offers Join room directly.
Answer an idle-room CallWorksNot availableHandoffWorksNative clients offer Open room / Not now; the browser explains the native hosting requirement and can decline. Calls do not enable notes by default on the answering native device; notes can be turned on deliberately.
Read a task directly from MineWorksWorksWorksWorksEvery client opens task details and subject navigation from Mine, with edit and completion actions. iOS also opens the same reader from a subject task list.

Clients, ops, and platform

CapabilitymacOS HostmacOS JoinWebiOS / iPadOSNotes
CLI / agent control through `meetctl`WorksNot availableNot availableNot availableSame-user local socket for status, host, lobby, media, transcript, and leave commands.
Native auto-updateWorksWorksNot availableNot availableMac checks the signed update feed; iOS uses App Store / TestFlight distribution.
Notetakers attend as declared meeting participantsWorksWorksWorksWorksThe listening slice works on every client; the row stays partial for the speaking half. A link-joining recording notetaker declares itself, waits for owner admission, is marked across the room, can be refused per room, and leaves a transcript consent line. Speaking agents, their room-side worker, and live MCP tools remain planned.
Agent activity in AdminNot availableNot availableWorksNot availableWeb Admin › Agents shows the last 30 days of handoffs, runtime acceptance or refusal, final replies observed by Meet, and watchdog reset outcomes. It does not show work inside an agent runtime or model costs.

How it fits together

Every service Starlings runs on, what each one stores, and what data moves between them, down to each bucket and queue.

Audio, video and screenNever: A recording. Nothing iswritten to disk, here oranywhere.Audio, video and screenNever: A recording, and nevera stream before the owner hasadmitted you.Transcript text, summaries,admissions and room stateNever: Audio, video, or thescreen. The words leave; thesound does not.The knock, admission status,chat, and every workspacereadA media token, minted onlyonce the owner has admittedthe guestNever: Media. No stream passesthrough the Worker.Room state, the words, theledger, the files, the jobsThe meeting, its notes andits tasks, filed on asubjectDocuments and comments, onthe member's behalfNever: A Docs token into thebrowser. The Worker keeps itsown, per owner.The owner's day, and themeetings scheduled from MeetMeetings from outsidesources — a webhook in, apaced job pulling historyTranscript text to write thenotes from, and a mail toread into eventsNever: Audio. A model readsthe words the device wrote,never the sound.A signed hand-off out, theagent's answer backNever: A seat in the room. Anagent has no device and nomedia.The outbox: transcriptsegments, idempotent bysegment UUIDNever: A tear-down of mediawhen it fails. The roomoutlives the outbox.The same outbox, from thephone when the phone is thehostMessages, reactions andmentions, liveA note taken in a hurry,from whichever surface isopenA finalization job, once themeeting endsThe filed interaction, itstasks, and the subject itbelongs toA transcript to read, andthe summary and tasks itcomes back withChat from every network,into the channel of thesubject it is aboutThe conversations Core's Machelper syncs, on their wayto a subjectThe same notes, synced byCore's Mac helper as wellA note from a call Meet didnot host, on its webhookGitHub events on a project —issues, pull requests,releases — into its channelThe Work board's issues andtheir agent:* labelsChannel history, paced intothe subject's channelWhich kind, which subject —the suggested filing for animported noteNever: A decision. The answeris drawn as a pre-filledcontrol and never written onits own.Sign-in with the Workspaceaccount that makes somebodyone of usThe same sign-in, natively,and the calendar the ownerattachedA bot check before a knock astranger may sendThe token from that check,verified before the knock istakenA forwarded mail, as onemessage from the member whosent itOne fetch of a pasted link,to show what it points atAn organization, reading andwriting the subjects itshares with usNever: More than the sharedsubject. A peer is a thirdprincipal on one door, not anew one.The credentials a member mayseeInvitations and the noticesa guest getsA notarized release zip, onthe updater's checkIn the meetingThe devices a person is looking at.MediaAudio and video, end to end, never recorded.The control planeOne Cloudflare Worker. Text only — it never sees a stream.What it keepsRoom state, the words, the ledger, the files.The rest of the companyServices Meet reads and writes on a member's behalf.The hosting deviceOne owner device opens the room, admits guests, andwrites the transcript on its own hardware.The browserGuests join at /room/<slug> with no account; asigned-in member gets the five surfaces too. It neverhosts.LiveKit CloudLiveKitCarries audio, video and screen between the people inthe room. Nothing is recorded, and no stream isstored.Meet control planeCloudflareOne Worker: the door, the routes, and the SPA infront of them. It holds text and never media.Stored in Durable Objects: one per room, perconversation, per memberMeet's own storeCloudflareThe ledger, the tokens, the files and the job queuebehind the Worker. Text and files — no media bucket.Stored in D1, two KV namespaces, four R2 buckets andtwo queues, all on our own Cloudflare accountCoreEnvisioningThe CRM. Subjects, tasks andinteractions, read and written overHMAC — a meeting is filed on theproject it belongs to.Stored in Supabase (Postgres)DocsEnvisioningWhere documents and their commentslive. Every read goes throughMeet's Worker; the browser neverholds a Docs token.Stored in Cloudflare D1, and R2 forwhat is attachedKeepEnvisioningWhere client credentials live. Meetreads what a member may see, over aservice binding.Stored in Cloudflare D1 — and everyitem is encrypted on the devicebefore it gets thereGoogle WorkspaceGoogleBoth halves of Google: who is oneof us at sign-in, and the owner'sday once they attach a calendar.The modelsWhere the writing happens: thenotes after a meeting, a forwardedmail read into events, suggestedtasks and filing.AgentsVercelPeers with no device. Each is onerow in the roster; a hand-off issigned, and an unanswered one isreset every five minutes.ConnectorsEvery outside source that writesmeetings into Meet. One card eachon /admin/connectors; the next oneis a card, not a page.TurnstileCloudflareThe bot check in front of theroutes anyone may POST withoutsigning in. Its keys are theswitch; a native knock skips thewidget.Cloudflare Email RoutingCloudflareMail to a subject's address, or tocalendar@, handed to the Worker asone message from the member whosent it. The address exists once azone is named.The open webThe page behind a link somebodypasted, fetched once so the messagecan show what it points at.A peer MeetAnother organization's Meet: itspeople and agents reach oursthrough the door a member's Claudealready uses, per shared subject,and neither company's conversationsleave the Meet that holds them.Designed, not built.PostmarkPostmarkOutbound mail — invitations and thenotices a guest gets — sent fromcontact@envisioning.com.Mac appAppKit. Host and Join,local speech-to-text,the five windows, andthe meetctl socket.iPhone and iPad appSwiftUI. Hosts, admitsand transcribes ondevice, with the LiveActivity and widgetsbeside it.Apple WatchA companion to thephone. Readsagenda.json out of theapp group; never atoken.Chrome extensionTells the Mac who isspeaking in a call Meetdid not host, soambient capture hasnames.RoomA Durable Object perroom: who knocked, whowas admitted, consent,the transcript text,the summary.ThreadsA Durable Object perconversation: messages,reactions, mentions,and the attachments'keys.Quick NotesA Durable Object permember: the notes takenin a hurry, from anysurface.MCP doorA member's Claude callsMeet's tools as thatmember, under a grantthey issued.Static AssetsThe built web app,served by the sameWorker. The Worker runsfirst, so every routeis checked before theapp answers.Rate limitingSeven per-minute burstguards: the knock,presence, feedback,error reports, linkpreviews, the agentdoor and MCP.Cron triggerEvery five minutes: theagent watchdog, thecalendar sweep,favorites and GitHubsync, pruning, and thedaily backup plan.Workers LogsOne request in ahundred is logged. Afailure is also countedin D1, and the count iswhat mails a person.Workers BuildsEvery push to mainbuilds the web app anddeploys the Worker,with its D1 migrations.D1 meet-usageThe usage ledger, thepeople, their roles andtheir work preferences.KV namespacesCALENDAR_TOKENS: theGoogle Calendar refreshtokens, one per ownerwho attached acalendar. CORE_CACHE:sixty seconds of theCore reads the boardand the feed fan outto.R2 bucketsFour buckets:meet-downloads forrelease zips,meet-avatars,meet-attachments forthe files in aconversation, andmeet-backups, the dailytext backup of everyDurable Object, kept inthe EU for 30 days. Noaudio, no video.Queuemeet-artifact-jobsFinalization, CRMfiling and the nightlybackups, one consumerat a time. Threefailures and a jobwaits onmeet-artifact-jobs-deadfor an admin.Queuemeet-import-jobsThe Granola, GitHub andSlack imports, on theirown queue so a bulkimport never holds up ameeting's notes. Samepolicy, and its owndead queue,meet-import-jobs-dead.D1 docsCloudflareEvery document, its comments, whoit is shared with, and thesignatures on it.R2 docs-filesCloudflareThe images in a document, a savedlink's preview, and a signature'simage.The Docs WorkerCloudflareStatic Assets for its own app. Anhourly Cron that mirrorsdocuments out to the surfacesthat need them as files. Ratelimiting on claiming a sharedlink and on signing. WorkersLogs, with traces.The Keep WorkerCloudflareStatic Assets for its own app.Rate limiting on revealing anitem, 300 a minute. Workers Logs,with traces.D1 keepCloudflareEvery vault today: wrapped keysand sealed items, in Keep's owndatabase.SupabaseSupabaseA vault kept in Postgres assealed rows. Supabase Vault addsnothing here; the item is alreadysealed on the device.VercelVercelA vault kept in VercelMarketplace storage, NeonPostgres or Blob, as sealed rows.Workers AICloudflareThe small models on the sameaccount: the summary a meetingends with, and the tasks itsuggests from what was said.Vercel AI GatewayVercelOne door, for the decision modelthat suggests where an importedGranola note should be filed.GitHubGitHubThe Work board is issue labels onenvisioning/meet; the connectormaps repositories to subjects.SlackSlackChannel history read into thesubject's channel by a paced jobchain.BeeperBeeperChat from every network in oneclient. Two ways in: straightinto the subject's channel, andthrough Core's Mac helper, whichsyncs it too.GranolaGranolaNotes from calls Meet did nothost. Two ways in: Meet's ownbridge on the webhook, and Core'sMac helper, which syncs them too.

In the meeting

The devices a person is looking at.

The hosting device
One owner device opens the room, admits guests, and writes the transcript on its own hardware.
Mac app
AppKit. Host and Join, local speech-to-text, the five windows, and the meetctl socket.
iPhone and iPad app
SwiftUI. Hosts, admits and transcribes on device, with the Live Activity and widgets beside it.
Apple Watch
A companion to the phone. Reads agenda.json out of the app group; never a token.
Chrome extension
Tells the Mac who is speaking in a call Meet did not host, so ambient capture has names.
The browser
Guests join at /room/<slug> with no account; a signed-in member gets the five surfaces too. It never hosts.

Media

Audio and video, end to end, never recorded.

LiveKit CloudLiveKit
Carries audio, video and screen between the people in the room. Nothing is recorded, and no stream is stored.

The control plane

One Cloudflare Worker. Text only — it never sees a stream.

Meet control planeCloudflare
One Worker: the door, the routes, and the SPA in front of them. It holds text and never media.
Room
A Durable Object per room: who knocked, who was admitted, consent, the transcript text, the summary.
Threads
A Durable Object per conversation: messages, reactions, mentions, and the attachments' keys.
Quick Notes
A Durable Object per member: the notes taken in a hurry, from any surface.
MCP door
A member's Claude calls Meet's tools as that member, under a grant they issued.
Static Assets
The built web app, served by the same Worker. The Worker runs first, so every route is checked before the app answers.
Rate limiting
Seven per-minute burst guards: the knock, presence, feedback, error reports, link previews, the agent door and MCP.
Cron trigger
Every five minutes: the agent watchdog, the calendar sweep, favorites and GitHub sync, pruning, and the daily backup plan.
Workers Logs
One request in a hundred is logged. A failure is also counted in D1, and the count is what mails a person.
Workers Builds
Every push to main builds the web app and deploys the Worker, with its D1 migrations.

What it keeps

Room state, the words, the ledger, the files.

Meet's own storeCloudflare
The ledger, the tokens, the files and the job queue behind the Worker. Text and files — no media bucket.
D1 meet-usage
The usage ledger, the people, their roles and their work preferences.
KV namespaces
CALENDAR_TOKENS: the Google Calendar refresh tokens, one per owner who attached a calendar. CORE_CACHE: sixty seconds of the Core reads the board and the feed fan out to.
R2 buckets
Four buckets: meet-downloads for release zips, meet-avatars, meet-attachments for the files in a conversation, and meet-backups, the daily text backup of every Durable Object, kept in the EU for 30 days. No audio, no video.
Queue meet-artifact-jobs
Finalization, CRM filing and the nightly backups, one consumer at a time. Three failures and a job waits on meet-artifact-jobs-dead for an admin.
Queue meet-import-jobs
The Granola, GitHub and Slack imports, on their own queue so a bulk import never holds up a meeting's notes. Same policy, and its own dead queue, meet-import-jobs-dead.

The rest of the company

Services Meet reads and writes on a member's behalf.

CoreEnvisioning
The CRM. Subjects, tasks and interactions, read and written over HMAC — a meeting is filed on the project it belongs to.
DocsEnvisioning
Where documents and their comments live. Every read goes through Meet's Worker; the browser never holds a Docs token.
D1 docsCloudflare
Every document, its comments, who it is shared with, and the signatures on it.
R2 docs-filesCloudflare
The images in a document, a saved link's preview, and a signature's image.
The Docs WorkerCloudflare
Static Assets for its own app. An hourly Cron that mirrors documents out to the surfaces that need them as files. Rate limiting on claiming a shared link and on signing. Workers Logs, with traces.
KeepEnvisioning
Where client credentials live. Meet reads what a member may see, over a service binding.
The Keep WorkerCloudflare
Static Assets for its own app. Rate limiting on revealing an item, 300 a minute. Workers Logs, with traces.
D1 keepCloudflare
Every vault today: wrapped keys and sealed items, in Keep's own database.
SupabaseSupabase
A vault kept in Postgres as sealed rows. Supabase Vault adds nothing here; the item is already sealed on the device.Planned — envisioning/keep#1
VercelVercel
A vault kept in Vercel Marketplace storage, Neon Postgres or Blob, as sealed rows.Planned — envisioning/keep#1
Google WorkspaceGoogle
Both halves of Google: who is one of us at sign-in, and the owner's day once they attach a calendar.
The models
Where the writing happens: the notes after a meeting, a forwarded mail read into events, suggested tasks and filing.
Workers AICloudflare
The small models on the same account: the summary a meeting ends with, and the tasks it suggests from what was said.
Vercel AI GatewayVercel
One door, for the decision model that suggests where an imported Granola note should be filed.
AgentsVercel
Peers with no device. Each is one row in the roster; a hand-off is signed, and an unanswered one is reset every five minutes.
Connectors
Every outside source that writes meetings into Meet. One card each on /admin/connectors; the next one is a card, not a page.
GitHubGitHub
The Work board is issue labels on envisioning/meet; the connector maps repositories to subjects.
SlackSlack
Channel history read into the subject's channel by a paced job chain.
BeeperBeeper
Chat from every network in one client. Two ways in: straight into the subject's channel, and through Core's Mac helper, which syncs it too.
GranolaGranola
Notes from calls Meet did not host. Two ways in: Meet's own bridge on the webhook, and Core's Mac helper, which syncs them too.
TurnstileCloudflare
The bot check in front of the routes anyone may POST without signing in. Its keys are the switch; a native knock skips the widget.
Cloudflare Email RoutingCloudflare
Mail to a subject's address, or to calendar@, handed to the Worker as one message from the member who sent it. The address exists once a zone is named.
The open web
The page behind a link somebody pasted, fetched once so the message can show what it points at.
A peer Meet
Another organization's Meet: its people and agents reach ours through the door a member's Claude already uses, per shared subject, and neither company's conversations leave the Meet that holds them. Designed, not built.
PostmarkPostmark
Outbound mail — invitations and the notices a guest gets — sent from contact@envisioning.com.

What runs between them

  • The hosting device ↔ LiveKit CloudAudio, video and screen · WebRTCNever: A recording. Nothing is written to disk, here or anywhere.
  • The browser ↔ LiveKit CloudAudio, video and screen · WebRTCNever: A recording, and never a stream before the owner has admitted you.
  • The hosting device ↔ Meet control planeTranscript text, summaries, admissions and room state · HTTPSNever: Audio, video, or the screen. The words leave; the sound does not.
  • The browser ↔ Meet control planeThe knock, admission status, chat, and every workspace read · WebSocket
  • Meet control plane → LiveKit CloudA media token, minted only once the owner has admitted the guest · HTTPSNever: Media. No stream passes through the Worker.
  • Meet control plane ↔ Meet's own storeRoom state, the words, the ledger, the files, the jobs · Cloudflare binding
  • Meet control plane ↔ CoreThe meeting, its notes and its tasks, filed on a subject · HTTPS
  • Meet control plane ↔ DocsDocuments and comments, on the member's behalf · Cloudflare bindingNever: A Docs token into the browser. The Worker keeps its own, per owner.
  • Meet control plane ↔ Google WorkspaceThe owner's day, and the meetings scheduled from Meet · HTTPS
  • Connectors ↔ Meet control planeMeetings from outside sources — a webhook in, a paced job pulling history · HTTPS
  • Meet control plane ↔ The modelsTranscript text to write the notes from, and a mail to read into events · HTTPSNever: Audio. A model reads the words the device wrote, never the sound.
  • Agents ↔ Meet control planeA signed hand-off out, the agent's answer back · HTTPSNever: A seat in the room. An agent has no device and no media.
  • Chrome extension → Mac appWho is speaking in a call Meet did not host · On the device
  • Apple Watch → iPhone and iPad appagenda.json, out of the shared app group · On the deviceNever: A token. The watch holds no credential.
  • Mac app ↔ RoomThe outbox: transcript segments, idempotent by segment UUID · HTTPSNever: A tear-down of media when it fails. The room outlives the outbox.
  • iPhone and iPad app ↔ RoomThe same outbox, from the phone when the phone is the host · HTTPS
  • The browser ↔ ThreadsMessages, reactions and mentions, live · WebSocket
  • The browser ↔ Quick NotesA note taken in a hurry, from whichever surface is open · HTTPS
  • Room → Queue meet-artifact-jobsA finalization job, once the meeting ends · Queue
  • Queue meet-artifact-jobs → CoreThe filed interaction, its tasks, and the subject it belongs to · HTTPS
  • Queue meet-artifact-jobs ↔ Workers AIA transcript to read, and the summary and tasks it comes back with · Cloudflare binding
  • Beeper → Meet control planeChat from every network, into the channel of the subject it is about · HTTPS
  • Beeper → CoreThe conversations Core's Mac helper syncs, on their way to a subject · HTTPS
  • Granola → CoreThe same notes, synced by Core's Mac helper as well · HTTPS
  • Granola → Queue meet-import-jobsA note from a call Meet did not host, on its webhook · HTTPS
  • Core → ThreadsGitHub events on a project — issues, pull requests, releases — into its channel · HTTPS
  • Meet control plane ↔ GitHubThe Work board's issues and their agent:* labels · HTTPS
  • Meet control plane → SlackChannel history, paced into the subject's channel · HTTPS
  • Meet control plane ↔ Vercel AI GatewayWhich kind, which subject — the suggested filing for an imported note · HTTPSNever: A decision. The answer is drawn as a pre-filled control and never written on its own.
  • The browser ↔ Google WorkspaceSign-in with the Workspace account that makes somebody one of us · HTTPS
  • The hosting device ↔ Google WorkspaceThe same sign-in, natively, and the calendar the owner attached · HTTPS
  • The browser ↔ TurnstileA bot check before a knock a stranger may send · HTTPS
  • Meet control plane → TurnstileThe token from that check, verified before the knock is taken · HTTPS
  • Cloudflare Email Routing → Meet control planeA forwarded mail, as one message from the member who sent it · HTTPS
  • Meet control plane ↔ The open webOne fetch of a pasted link, to show what it points at · HTTPS
  • A peer Meet ↔ MCP doorAn organization, reading and writing the subjects it shares with us · HTTPSNever: More than the shared subject. A peer is a third principal on one door, not a new one.
  • Meet control plane ↔ KeepThe credentials a member may see · Cloudflare binding
  • Meet control plane → PostmarkInvitations and the notices a guest gets · HTTPS
  • Mac app → R2 bucketsA notarized release zip, on the updater's check · HTTPS

Surface snapshot 2026-10-01. Intent statuses are not a build tracker. packages/contracts/src/capabilities.ts.