Run long delegated work without babysitting it.

A single long chat drifts: context piles up, the brief blurs, and checking the result always lands back on you. Tandem moves work forward in bounded steps — production and review separate, decisions with you, everything on one inspectable record. What comes back is reviewed, not just finished.

Governed sessions · inspectable outcomes · Ubuntu and WSL2

Tandem
01

Bounded calls

Every step receives a defined mission and only the context it needs.

02

Separate review

The model producing a step does not review its own work.

03

Human authority

Decisions requiring authority stay with the person responsible.

04

Inspectable record

State, evidence, findings and open work survive pauses and model changes.

Long work moves forward in bounded steps, not in one conversation that grows until it drifts.

Each turn gets a bounded mission — and only the context it needs.

A monolithic chat accumulates context indiscriminately, and with it the risk of drift. Tandem proceeds through successive headless executions: every mission is scoped, and the state of the work lives outside the model's context window.

  1. 01Brief

    The human states the intent, the expected outcome and the working constraints. The brief stays canonical for the whole session.

  2. 02Bounded mission

    The runtime issues a bounded assignment to one role. The mission carries only the context that the step requires — not the accumulation of every previous turn.

  3. 03Headless run

    A supported model executes the mission headless. Output, events and receipts come back to the runtime, not to a chat scroll.

  4. 04Review and decision

    The result is judged by a separated role, and the decisions that need human authority are brought to the human with the material required to decide.

  5. 05Next turn or closeout

    The recorded state feeds the next bounded turn, or the session closes with its outcome, open items and evidence.

A pause, a restart or a new turn resumes from recorded facts.

The session state lives in the runtime, not in the model's memory.

Tandem keeps an append-only session history: plan revisions, human acts, results and findings are recorded once, with provenance, and never rewritten. The current state is derived from that history, so recovery resumes from the exact point the record reached — not from whatever a model happens to remember.

History
Append-only record with identity, cause, actor and provenance for every event
State
Derived from the history, not reconstructed from chat or guessed by a client
Recovery
Pause and resume are part of the lifecycle, with idempotent replay instead of duplicated work

Distinct responsibilities, bound to models only at runtime.

A session is a closed set of personalities working with a human. Each personality is a role with a competence, a mission and boundaries; which model executes it is a binding detail resolved at launch — never part of the role's meaning.

01

Orchestrator

Semantic supervision of the whole workflow and the only channel to the human. Routes assignments, judges the adequacy of results and asks for corrections.

02

Planner

Turns the brief into one integrated plan with named responsibilities and dependencies. Does not certify the result.

03

Producer

Executes the assigned product work. Does not close its own steps.

04

Reviewer

Independent conformity judgement with a structured report and evidence. Does not modify the deliverable.

05

Security

Proportioned checks on the concrete risk surface, with a structured report.

06

Auditor / Challenger

Additional independent verification when the work requires it. Findings must be corrected, refuted with evidence or brought to the human.

07

Human

Brief, approvals, authorised revisions and exceptional closures. Not a node in the workflow: the authority.

Production and review carry separate responsibilities.

Review stays independent from production.

The role that produces a result does not approve it. Review, proportionate risk assessment and challenge remain separate responsibilities, and each material claim is checked against defined criteria and supporting evidence before the work moves forward.

One record for what was due, decided, accepted, rejected, verified and left open.

Decisions, findings, evidence, residuals and closeout stay in one inspectable record.

Decisions
Durable acts tied to the exact revision and hash of the material the human or the supervisor saw.
Findings
Facts that must be corrected, refuted with evidence or escalated — recorded, never buried.
Evidence
Structured receipts produced by the runtime; a claim becomes an observed fact only when its receipt is resolvable.
Residuals
Open items and limitations stay declared, so a closeout never reads as more than the evidence supports.
Closeout
The session closes with its outcome, its evidence and its open work — inspectable after the fact.

Supported CLI families and direct provider APIs, chosen per role and per session.

Your models, your choice.

Claude CodeCodexGemini CLIKimiZ.AI GLM

Tandem works with the CLI subscriptions you already pay for — and connects directly to provider APIs when that serves you better. You choose per role, per session: use an API-only model like DeepSeek, reach Qwen or Grok without adding yet another subscription, go direct to the API when your plan's allowance runs out mid-work, or trial a model before committing to a plan. Your model mix stays your choice.

The review caught a capability error before the work closed.

Brief
Restore the verified capability behaviour without widening the supported surface.
Delegated mission
Reconcile the capability matrix across the runtime and the client.
Producer
The matrix was restored and the implementation checks passed.
Review finding
One provider family had been forced into automatic headless execution across all eleven capabilities. Six on/off controls no longer worked and four default-only paths had become unreachable.
Human decision
Correct the divergence before closeout. Preserve the verified surface; do not add new capability.
Closeout
The matrix, save path and launch policy were corrected and reverified.

Start every session from a clear brief and explicit controls.

The New Session view brings the brief, working folder and approval controls together before execution begins, so the session starts with a defined scope and visible authority.

Tandem Console new session screen with a briefing field and strict session controls
Tandem Console / New Session

Start the trial on your own work.

Create an account and put one real, long-running task through bounded work, separate review, human decisions and an inspectable closeout.