Artificially generatedAI agent army from your phone: the lake, the machine guns, and the missing capsule
Half past nine, a glittering lake, machine-gun chatter from the urban combat range in the woods. In between, a question as old as intelligence services: how does each agent get exactly the knowledge the mission needs, and nothing else?
Steering an AI agent army from your phone, safely and without friction, is the missing control centre of the current AI race. At McGrinsey the stack today is a chat app talking to OpenClaw agents on a Hetzner VPS network. That is already far. The pain is rights: passwords, API keys, tokens, MFA, fingerprints, phone numbers, emails. If you want to run agents and keep secrecy, you can steal the capsule logic of intelligence services. We do not know a finished product. Useful tips are welcome at the local AI mayor.
Half past nine in Germany. The lake glitters. Machine guns trill from the woods.
I sit by the water. Helicopters and drone training at the urban combat range lay a chatter over the forest that starts to sound like birdsong if you listen long enough. Then the echo of the large-calibre kit. In between I am trying to work out how to steer my virtual AI agent army in the clouds better from a phone.
The mental drill is old. We already put it over another piece: Live in the future and fix what's missing. Live far enough ahead that you see the problems of the day after tomorrow today. Build the fix now, and you can sell it tomorrow. That is a field in the AI race, not a wellness line.
Right now I am unhappy with how my personal AI construction crews are structured. The control centre is a chat app, wired to OpenClaw agents that live on a net of Hetzner VPS boxes. That is already very cool. It brings maintenance, above all in rights management.
Passwords, keys, tokens, MFA, fingerprints, numbers, mail. A jumble, not a system.
Whoever executes code as John has long had the fleet. That is in our security plan of 24 July 2026. The fingerprint protects the login, not the running session. An agent with a shell could read the central access file with no prompt. Stage 0 is done: mode 600, named keys. Stage 1, vaults by blast radius instead of by project, is open. That is the ache I feel at the lake.
The AI agent army needs credentials to finish a mission. The render agent needs Adbeamer, not Kraken. The backup job needs rrsync, not the ads account. The writing agent needs the magazine, not the trading key. Today those worlds still sit next to each other in one head, one chat, one session. Mobile makes it worse: the phone is the most convenient door into the army and the thinnest safe.
How knowledge is encapsulated, and the agent still completes the mission.
The question is as old as intelligence services and as current as the timeline. Wikipedia traces compartmentalization back to the secrecy around Greek fire. The Manhattan Project is the modern school case: at Oak Ridge people ran centrifuges that isolated uranium-235, and most of them did not know that was what they were doing. Ultra in the Second World War carried two stamps at once: the Top Secret level, and a codeword that cut the readership again.
US intelligence wrote this into directives that sit in public. Director of Central Intelligence Directive 1/19 names four locks, not one. Access to Sensitive Compartmented Information (SCI) needs a clearance, a formal access approval, an indoctrination, and a demonstrated need-to-know. Even with all four, you do not get "all the secrets". You get the lowest classification and the smallest compartment that will do the job. Sources and methods are omitted, generalised, or parked in a supplement that is tighter than the report itself.
The person may see secrets of a given height at all. Without this, the rest falls away.
The compartment itself, often behind a codeword. SCI and Special Access Programs sit above the ordinary ladder.
The briefing. You know the rules, and you signed them. That is not a tutorial. It is a contract.
Even with the first three: only what this task requires. Being allowed into the room does not mean you take the whole cabinet.
Tearline, ORCON, the case officer and the human agent
A tearline is the second, thinner cut of a report: below a line sits the content a lower-clearance recipient can use without seeing source and method. Homeland security guidance asks for those lines when terrorism leads have to travel to state and local officials. Originator Controlled, ORCON, means the producer decides who may pass the item on. That protects sources. It also creates queues. The 9/11 Commission named ORCON as a brake on sharing.
Important, because we take the word agent literally: in intelligence, the human agent is often the asset in the field, not the person at the desk. The case officer holds the file. The agent outside typically does not know the network, the other sources, sometimes not even the true name of the centre. Cell structures in clandestine work are one-way streets: burn one cell, the map does not fall. That is cruel and effective. It is also the hardest encapsulation this world has.
Need-to-know has a second edge, often forgotten. DCID 8/1 says need-to-know does not merely mean customers get only what they need. It also means they get all they need to do the job. After 11 September 2001 the 9/11 Commission flipped the culture. The executive summary says the system of need-to-know should be replaced by a system of need-to-share. The commission called the refusal to share the biggest impediment to all-source analysis. ODNI wrote in 2008 that Cold War need-to-know had become a handicap. Intellipedia, the community's classified wiki from 2006, was a drill in sharing inside the fences.
The contradiction stays. More heads on a secret raise the risk of compromise. Too few heads raise the risk that nobody connects the dots. Both risks are real. Both have killed people, in different ways. Anyone who solves one by denying the other has not read the file.
The same locks, different troops. The agent gets the task, not the vault.
Transferred to an AI agent army, the first rule is: no process sees the whole `.env`. The render agent gets a ticket for a job, not the Hetzner write key. The trading agent gets the money vault, not the magazine. That is need-to-know as a filesystem, not as a poster.
- ClearanceWhich vaults a process may even name. Planned here as vaults by blast radius: infra, money, AI, marketing, clients. Security plan, stage 1, still open.
- CompartmentCodeword rooms. One OpenClaw worker on one VPS is a room, not "the cloud". Two agents, two rooms, even on the same Hetzner account.
- IndoctrinationThe mission file the agent signed: system prompt, allowed hosts, forbidden vaults, expiry. Logged. Revocable.
- Need-to-knowThe task as a tearline: goal, constraints, return channel. No sources, no master keys, no phone numbers of the humans behind the tokens.
- ORCONWhoever minted the secret can kill it. Service accounts with an expiry, not a JWT that lives until 2036.
- Case officer / agentThe phone is the case officer's radio. The file room stays on the VPS. The chat app may call the army. It may not own the fleet.
- Need-to-shareWhen two agents must work together, a broker opens a time-boxed joint between two rooms. The rooms do not become one file.
- TearlineWhat appears on the phone is the thin cut: status, next step, alarm. The scan, the key, the dump stay below the line.
9/11 is the warning the other way. If every agent knows only its room and nobody is allowed to see the dots, you build an army that is brilliant locally and blind globally. That is why DCID 8/1 is the second half of the transfer: the agent must get everything the mission needs. Otherwise you have confused security with inability to work.
In practice, for us: the chat on the phone talks to a broker. The broker checks which human is sitting there (device, factor, session). It checks which agent is being called. At runtime it fetches only the references this task needs from the matching vault. Values live in process memory, not in a file on the phone, not in a screenshot, not in a chat the model will quote tomorrow. Unclassified stays the default while we do not trust the system: it fetches, it does not push. That is in the house rules of 31 July 2026. Trust is a check with a clock, not a mood.
The phone is the bridge, not the factory.
Plenty of people start like this: an agent app on the phone, API keys in Notes, an SSH client with a root key, Telegram as a catch-all channel. It feels fast. It does not scale. The moment the first agent writes files, touches deploys or hits money APIs, you need isolation. Mobile control means: you issue jobs, confirm gates, read status. The heavy work runs on a server you control. Secrets live in a vault or in server env, never as a standing file in a pocket.
From lock screen to a running task, no laptop.
The device may trigger. It does not carry the vault.
Every job has a sender, a time, a target and a result.
A Telegram topic, a Slack thread or a dedicated bot DM. Allowlisted senders only. Each topic is one job context.
Receives messages, checks auth, queues tasks, writes logs. OpenClaw, a home-built bot or a CI webhook.
Separate sessions or containers. Write rights only on allowed paths. No blind root for routine jobs.
API keys, deploy tokens, database passwords stay on the server. Mobile clients get session tokens with a short TTL.
Hetzner or similar. Agent runtime there. Backups, firewall, only the ports you need. Updates on a schedule, not someday.
One topic per product or pipeline. Magazine here, deploy there. Context stays separable and you can find jobs again.
Known sender IDs only. Reading is cheap. Writing and publishing are expensive. Hard actions sit behind approve.
The magazine worker gets magazine ops, not fleet SSH. The video worker gets render paths, not the billing console. Same cut as the four locks above.
What actually lives on the phone, and what never does.
- MessengerTelegram or Slack with 2FA, a biometric app lock and a separate work account.
- Status viewShort confirmations, progress, errors. No endless log dumps in the chat. That is the tearline from section 04, as UI.
- Approve gatesDestructive or expensive actions need an explicit OK from an allowlisted sender.
- Optional SSHBreak-glass only. An ephemeral key, a jump host, no standing root key in the Files app.
- Not on itProduction .env, cloud-console root, never-expiring PATs, unencrypted notes with secrets.
If you must terminal from the phone: short sessions, a hardware-backed keystore where you can, and close the access after the job. Day-to-day control stays the chat.
| Area | Default | Why |
|---|---|---|
| Channel | Telegram forum topic or Slack thread | Context sticks to the job |
| Auth | Sender allowlist, bot token only on the server | A stolen chat history is not enough on its own |
| Secrets | Server env / vault, never a standing chat paste | Losing the phone stays survivable |
| Rights | Least privilege per worker | One compromised job does not eat everything |
| Publish | Draft first, live only on a clear command | unless you explicitly demand live |
| Logs | Short in chat, long on the server | The chat stays usable |
As of 27 August 2026. Drawn from the running OpenClaw / Ghostclaw setup and ordinary least-privilege practice.
The layers are standing. The control centre that feels like a product is not.
Four layers, allowlist, vault, tearline in chat: that is how we run it today as practice. We measured Claude Code Mobile: a chat with upload, no SSH, one repo, no place for your own credentials. The dragon stays on a leash. OpenClaw on Hetzner is the opposite: real troops, real keys, real overhead. Between them sits the box in which the case officer can radio without pocketing the file room.
- Allowlist is onOnly your user ID and explicitly granted senders get through.
- Bot token not in chatThe token lives in server env. Rotation is rehearsed, not just documented.
- Destructive ops need approveDelete, money, prod deploy, wide SSH: a gate, not politeness.
- Worker scope is tightThe magazine jail writes posts, not user tables and not .env.
- Status contract is clearStart ACK, result link, error with a snippet. No silent ten-minute job.
- Break-glass is separateEmergency SSH and day-to-day chat are two paths. The everyday path stays thin.
Once that is in place, mobile management is boring in the best way: you write the job, the server works, you get the link. The capsule UI that shows need-to-know as a surface instead of chat folklore is still missing. Useful tips are welcome at the local AI mayor, John.
Then the other craft. Historical, manual, scrubbing data in the table cellar of the SME museum. If you cannot describe your agent army in a table (who may do what, until when, for which job), you do not have an army. You have a flatshare with a master key.
| Claim | Basket | Where from |
|---|---|---|
| Lake scene, 27 August 2026, range in the woods | First-person report | John, this morning. No geotagged photo in this piece. |
| Control centre: chat app, OpenClaw, Hetzner VPS | Fact of the house architecture | CLAUDE.md, Ghostclaw, MCG infra. No third-party product audit. |
| Four locks for SCI | Fact of the directive | DCID 1/19, public at FAS. |
| Need-to-know includes "all that is required" | Fact of the directive | DCID 8/1, public at FAS. |
| 9/11 Commission: need-to-share instead of need-to-know | Fact of the report | 9/11 Commission Report, executive summary. |
| Oak Ridge, most did not know about U-235 | Standard example | Wikipedia, Compartmentalization. School case, no primary file here. |
| Vaults by blast radius solve the phone problem | Hypothesis | Our transfer. Stage 1 of the security plan is open. No field trial in this text. |
| Claude Code Mobile is not an agent | Our measurement | Magazine, The Dragon on a Leash, August 2026. |
| Four layers: channel, gateway, worker, vault | Practice note | Running OpenClaw / Ghostclaw, 27 August 2026. No vendor review. |
| No standing secrets on the phone | Default, sourced | OWASP Secrets Management Cheat Sheet. House rule, stage 0. |
- DCID 1/19, SCI handlingFour locks, need-to-know, sanitizing of sources and methods.https://irp.fas.org/offdocs/dcid1-19.html
- DCID 8/1, Intelligence Information SharingNeed-to-know also means: everything the mission requires.https://irp.fas.org/offdocs/dcid8-1.html
- 9/11 Commission Report, executive summaryReplace need-to-know with need-to-share. Biggest impediment to all-source analysis.https://9-11commission.gov/report/911Report_Exec.pdf
- ODNI, Intelligence Community Information Sharing Strategy, 2008Cold War need-to-know as a handicap. Stewardship instead of ownership. ORCON as a queue.https://www.govinfo.gov/content/pkg/GOVPUB-PREX28-PURL-LPS93425.pdf
- Wikipedia, Compartmentalization (information security)Greek fire, Manhattan, Ultra, codeword levels.https://en.wikipedia.org/wiki/Compartmentalization_(information_security)
- DoDM 5105.21, SCI programSCI only to persons with access and a demonstrated need-to-know.https://sgp.fas.org/othergov/dod/5105_21v1.pdf
- Peter Steinberger / MCGLive in the future, build what's missing. A magazine piece and a working rule here.https://mcgrinsey.com/magazin/who-the-hell-is-peter-steinberger/
- The Dragon on a LeashClaude Code Mobile, four fences, not an agent.https://mcgrinsey.com/magazin/the-dragon-on-a-leash/
- OWASP: Secrets Management Cheat SheetNo secrets in clients, short life, rotation.https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html
- NIST SP 800-63B Digital Identity GuidelinesAuthenticator and session hardness, ground for mobile access.https://pages.nist.gov/800-63-4/sp800-63b.html
- CIS Benchmarks / hardened server baselineFirewall, unused services off, patch rhythm for the home base.https://www.cisecurity.org/cis-benchmarks
- Telegram Bot FAQ / privacy modelBot-token protection, what bots see and what they do not.https://core.telegram.org/bots/faq
Cut-off: 27 August 2026. Written with the McGrinsey writing skill. Not a company piece, so no McGrinsey Ratio.


