Skip to content

Known limits

Robert Sfeir edited this page Oct 6, 2026 · 6 revisions

What VitalAIze does not do yet, and where it can be wrong. This page describes version 0.4.0; see Status.

Your network and your data

  • Some of what you type reaches the hub. A collector's link to the hub is encrypted, and it never sends the agent's replies, tool output, commands or file contents. It does send each session's title, folder, git branch and repository, and the first and latest prompt clipped to 300 characters (500 for Codex). Over a live session, the start of each prompt is sent once. The hub keeps these in its database. See How it works.
  • A new machine cannot tell a fake hub from yours. If something on your network answers a new machine before your hub does, that machine can pair with it and stream to it. Check that the machine's code shows up in your hub's mailbox before you rely on it.
  • Anyone on your network can open the board, unless you set a board password (token, see Settings). They can read pull request titles, what your sessions ask you, and the codes in the mailbox. They cannot approve a machine: with no password, only a browser on the hub's own machine can.
  • The board itself is plain http. Only the link between a collector and the hub is encrypted. Keep the hub on a network you trust.
  • Alerts leave your machines. An alert names the session and says what it asks, such as the question it put to you or the end of Codex's reply. Sent by Messages, that text passes through Apple (and your phone carrier, for SMS). Sent by Slack, ntfy or Pushover, it passes through their servers. Anyone who knows your ntfy topic can read it too, so pick one that is hard to guess, or run your own ntfy server.

Needs you

  • A Codex card can say Needs you for longer than it should.
    • After you approve a command: Codex says nothing when the command starts, so the card stays until the command finishes.
    • A card waiting on your approval stays up to 12 hours, even past the idle time, so you can find it after a night away.
  • At most 20 alerts from other machines go out in 10 minutes. Past that, the hub logs each one it drops.
  • After the hub restarts, sessions on other machines that were already waiting show Needs you again but do not alert a second time.

Codex

  • Codex "Needs you" has not yet been seen working with a real Codex. It may mark a card wrongly or send a wrong alert. You can help check it with the payload recorder.
  • A Codex card can clear too early. If Codex runs other commands at the same time as the one waiting on you, the first of those to finish clears the card although Codex still waits.
  • A chat the Codex app copied in can be saved as a Codex session. A copy of a Claude session the board already reads is left out, so it is not counted twice. A copy of anything else is saved in the Archive as a Codex session, with one token total and no split by kind.
  • Codex Needs you takes a one-time step. VitalAIze puts its one small Codex hook on the machine by itself, but you add it to Codex's hooks.json and trust it in Codex, once on each machine where Codex runs. See Codex.

Other machines

  • Not yet tried by us between two real machines on a network. The collector, pairing and the link were tested on one Mac and by the automated tests on Linux and macOS. If something breaks between your machines, tell us in Issues.
  • A machine you disconnect while it is off learns it late, or not at all. From 0.4.0 it asks the hub when its tries keep failing, so after a long time off it can take up to about three minutes to show it was removed. It never learns it when it is still on 0.3.0, when it was removed after the board's port changed and before it connected again, or when the hub's certificates were made anew; it keeps trying and says the hub is not answering. Pair it again. See Troubleshooting.
  • A card from another machine shows a little less. It has no list of changed files, and its cost is worked out on that machine with that machine's prices.
  • A machine that goes quiet. When a machine's link closes, its cards stay, marked stale, for a day. The hub never guesses that a session ended; only its collector says so.
  • Hubs and collectors run on Mac and Linux. A Windows collector is on the Roadmap.
  • A disconnected machine can take up to 20 seconds to drop when its certificate is cancelled by pairing the same name again. Disconnect on the Settings page is immediate.

Costs and limits

  • Costs are list prices. Claude costs use the API list prices in usage.prices. On a Claude plan your bill is different; read the dollars as a measure of work.
  • Dev and Prod follow the first repository only. Each repository shows its own runs and its own Main on the Git tab, but the two deploy tiles in the status line are the first one's.
  • About six repositories. Past that, the board may run out of GitHub calls. See How it works.
  • Messages alerts need a Mac. On Linux, use Slack, ntfy or Pushover.

Budget, CI minutes and Shipped

  • Budget limits need the archive, and a busy session on the hub counts only once it pauses for archive.settle_seconds (2 minutes), so a long run with no pause passes a limit late. Token limits count cache reads and writes, which are most of the tokens.
  • CI minutes are an estimate of GitHub's bill. GitHub prices its larger runners by size, which the board cannot see, so they count as a standard runner of the same system would, a floor. On a public repository, a job in a runner group that is neither GitHub's standard one nor labelled self-hosted is shown apart as not known. Minutes inside your plan's allowance are counted too, though GitHub would not charge them.
  • A session on a long-lived branch such as develop collects everyone's runs on that branch while it works there (#127), and a develop branch whose last release is older than archive.backfill_days can look like a stacked branch (#125).
  • A Codex session, or a session from another machine, keeps one branch for its whole span, so a switch of branch partway is not seen.
  • Runs saved before 0.4.0 keep only their latest attempt's jobs. They are not read again.
  • A run that finishes days after it started is never saved as finished (#130).
  • A runner's state from GitHub needs admin rights on the repository. Without them, only a collector on the runner's machine can report it, and only when the collector's user can read the runner's folder.

New Relic

  • The checks are set in settings.exs only. The app and vitalaize setup have no place for them yet, so the New Relic tab stays empty until you write new_relic.checks in the file. See Settings.

Clone this wiki locally