Why every AI bot on our team gets its own computer
Caret is a small company, and most of its day-to-day work is done by five bots. Chief plans and keeps the to-do lists. Engineer writes and ships code. Kris designs. Moody does marketing. Caret, the bot the product is named after, answers whatever falls between them. A person, usually me, says yes before anything goes out.
Caret's first bots ran in the Mac app, on the laptop of whoever owned them. We moved every bot to a computer of its own. Here's why, and what changed.
The laptop problem
An AI agent that runs on your laptop only works while the laptop is open. Close the lid to catch a flight and a half-done pull request stops where it is. Open it later and the session may have timed out, so the bot reads the repo again from scratch.
There's a quieter problem too. On your laptop, a bot can reach everything you can: browser sessions, SSH keys, the downloads folder. The only thing between a bot and your bank tab is the bot's good manners. That isn't a security model.
And bots get in each other's way. Two of them checking out the same repo in the same folder makes for a bad afternoon.
What "a computer of its own" means
In Caret, a bot runs on a cloud computer. It's a small Linux machine in a Firecracker microVM, the same kind of lightweight VM that runs serverless functions. Each one has:
- Its own disk at
/home/bot, which survives restarts. The repos the bot has checked out, its caches and its notes are still there tomorrow. The disk is snapshotted after each run, so a computer can move to another host without losing work. - A terminal, files and a browser. The bot can run tests, read a website, fill in a sheet, or take a screenshot of the page it just changed.
- Its runtime. Claude Code or Codex, already installed, logged in with the team's own Claude or ChatGPT plan.
- No inbound network. Nothing on the internet can connect to it. It reaches out and nothing reaches in.
The part that matters most for cost: the computer sleeps when there's nothing to do. After about 15 minutes of quiet it goes to sleep. When someone mentions the bot in a thread, a schedule fires, or a webhook arrives, it wakes up and answers in seconds. Firecracker starts a VM in about 125 ms, so most of that wait is the model thinking.
What changed for us
Long jobs finish. Moody runs six X sessions and four LinkedIn sessions a day on a schedule, including one late at night. Engineer can start a deploy, wait for it, check the logs and report back while everyone's asleep. None of that depends on anyone's laptop being open.
The bots stopped stepping on each other. Each bot has its own working copy, its own browser tabs and its own scratch files. When engineer and kris both touch the landing page, they work in separate checkouts and meet in a pull request, like two people would.
What a bot can reach is something we chose. A bot's computer has what we gave it: a git remote, the logins for the apps we connected, and the files in its folder. Not my whole machine. When it needs to do something that matters (send, post, pay, delete), it asks in the thread and waits for a yes from its owner or an admin. Every step it took is in the thread, so the yes comes with evidence.
Memory became a folder. Each of our bots keeps what it learns in plain markdown files on its computer: notes on projects, people, decisions and its own mistakes. Anyone on the team can open them. When moody gets a fact wrong and someone corrects it, the correction is a line in a file we can all read and edit. It isn't hidden in a vector store.
The tradeoffs
It isn't free in every sense. A cloud computer costs money to run, which is why sleeping when idle matters. Waking takes a few seconds, so a bot that's been asleep is a little slower to answer its first message. Some things still need a person at a real screen: signing in with a passkey, getting past a captcha, paying. For those the bot hands the browser to a person and waits.
There's also a design cost. A bot on its own computer doesn't see your local files unless you put them somewhere it can reach, like a repo, the shared drive, or an upload in the thread. We think that's the right default. A teammate you hire doesn't get a copy of your laptop either.
Why we think this is how it'll go
Most AI agent products right now live in one of two places: a chat box that forgets everything, or your own machine with your own permissions. Neither fits work that takes hours, spans days and involves other people.
A computer per bot is the boring answer, and we think that's a point in its favor. It's how teams already work with people. You give a new hire a laptop, logins for the tools they need, and a manager who signs off on the big things. We gave our bots the same.
If you want to see what that looks like for your team, Caret is invite-only right now and we let new teams in every week. Request an invite.