AI agent army from your phone: the lake, the machine guns, and the missing capsuleArtificially generated
Artificially generatedArtificially generatedArticle 50 of the AI Act requires artificially generated image, audio and video content to be marked as such, detectably and machine-readably. The symbol is the European Commission's official base icon. Using it is voluntary, the marking duty is not.Machine-generated: Text · Image. With human direction.McGrinsey Living Intelligence SystemsMcGrinsey Living Intelligence SystemsLI: Living intelligence of every kind. McGrinsey combines conventional intelligence and novel intelligence into living intelligence systems. These symbiotic systems of machine and human intelligence work together to supply the finest distillates of insight, for every intelligence.
MCG Workshop · AI agent army · 27 August 2026

AI agent army from your phone: the lake, the machine guns, and the missing capsule

Half past nine, a glittering lake, machine-gun chatter from the urban combat range in the woods. In between, a question as old as intelligence services: how does each agent get exactly the knowledge the mission needs, and nothing else?

Steering an AI agent army from your phone, safely and without friction, is the missing control centre of the current AI race. At McGrinsey the stack today is a chat app talking to OpenClaw agents on a Hetzner VPS network. That is already far. The pain is rights: passwords, API keys, tokens, MFA, fingerprints, phone numbers, emails. If you want to run agents and keep secrecy, you can steal the capsule logic of intelligence services. We do not know a finished product. Useful tips are welcome at the local AI mayor.

01 · The lake

Half past nine in Germany. The lake glitters. Machine guns trill from the woods.

I sit by the water. Helicopters and drone training at the urban combat range lay a chatter over the forest that starts to sound like birdsong if you listen long enough. Then the echo of the large-calibre kit. In between I am trying to work out how to steer my virtual AI agent army in the clouds better from a phone.

The mental drill is old. We already put it over another piece: Live in the future and fix what's missing. Live far enough ahead that you see the problems of the day after tomorrow today. Build the fix now, and you can sell it tomorrow. That is a field in the AI race, not a wellness line.

Right now I am unhappy with how my personal AI construction crews are structured. The control centre is a chat app, wired to OpenClaw agents that live on a net of Hetzner VPS boxes. That is already very cool. It brings maintenance, above all in rights management.

09:30
27 August 2026. Lake, range, phone. The army is in the cloud. The capsule is not.
02 · What grates

Passwords, keys, tokens, MFA, fingerprints, numbers, mail. A jumble, not a system.

Whoever executes code as John has long had the fleet. That is in our security plan of 24 July 2026. The fingerprint protects the login, not the running session. An agent with a shell could read the central access file with no prompt. Stage 0 is done: mode 600, named keys. Stage 1, vaults by blast radius instead of by project, is open. That is the ache I feel at the lake.

The AI agent army needs credentials to finish a mission. The render agent needs Adbeamer, not Kraken. The backup job needs rrsync, not the ads account. The writing agent needs the magazine, not the trading key. Today those worlds still sit next to each other in one head, one chat, one session. Mobile makes it worse: the phone is the most convenient door into the army and the thinnest safe.

Definition: An AI agent army is a set of specialised agents on your own infrastructure, steered by one human through a thin device. OpenClaw on Hetzner is our current build, as of 27 August 2026. This is not a product roundup. It is the state the question hangs on.
03 · Capsules in intelligence

How knowledge is encapsulated, and the agent still completes the mission.

The question is as old as intelligence services and as current as the timeline. Wikipedia traces compartmentalization back to the secrecy around Greek fire. The Manhattan Project is the modern school case: at Oak Ridge people ran centrifuges that isolated uranium-235, and most of them did not know that was what they were doing. Ultra in the Second World War carried two stamps at once: the Top Secret level, and a codeword that cut the readership again.

US intelligence wrote this into directives that sit in public. Director of Central Intelligence Directive 1/19 names four locks, not one. Access to Sensitive Compartmented Information (SCI) needs a clearance, a formal access approval, an indoctrination, and a demonstrated need-to-know. Even with all four, you do not get "all the secrets". You get the lowest classification and the smallest compartment that will do the job. Sources and methods are omitted, generalised, or parked in a supplement that is tighter than the report itself.

Fig. 01Four locks, one task. DCID 1/19, public at FAS.
01Clearance

The person may see secrets of a given height at all. Without this, the rest falls away.

02Access approval

The compartment itself, often behind a codeword. SCI and Special Access Programs sit above the ordinary ladder.

03Indoctrination

The briefing. You know the rules, and you signed them. That is not a tutorial. It is a contract.

04Need-to-know

Even with the first three: only what this task requires. Being allowed into the room does not mean you take the whole cabinet.

Tearline, ORCON, the case officer and the human agent

A tearline is the second, thinner cut of a report: below a line sits the content a lower-clearance recipient can use without seeing source and method. Homeland security guidance asks for those lines when terrorism leads have to travel to state and local officials. Originator Controlled, ORCON, means the producer decides who may pass the item on. That protects sources. It also creates queues. The 9/11 Commission named ORCON as a brake on sharing.

Important, because we take the word agent literally: in intelligence, the human agent is often the asset in the field, not the person at the desk. The case officer holds the file. The agent outside typically does not know the network, the other sources, sometimes not even the true name of the centre. Cell structures in clandestine work are one-way streets: burn one cell, the map does not fall. That is cruel and effective. It is also the hardest encapsulation this world has.

Need-to-know has a second edge, often forgotten. DCID 8/1 says need-to-know does not merely mean customers get only what they need. It also means they get all they need to do the job. After 11 September 2001 the 9/11 Commission flipped the culture. The executive summary says the system of need-to-know should be replaced by a system of need-to-share. The commission called the refusal to share the biggest impediment to all-source analysis. ODNI wrote in 2008 that Cold War need-to-know had become a handicap. Intellipedia, the community's classified wiki from 2006, was a drill in sharing inside the fences.

The contradiction stays. More heads on a secret raise the risk of compromise. Too few heads raise the risk that nobody connects the dots. Both risks are real. Both have killed people, in different ways. Anyone who solves one by denying the other has not read the file.

What this is not: a kit to copy an intelligence service. It is the public machinery, as far as it sits in DCID, DoD manuals and the 9/11 Commission. No insider tale, no unchecked spy folklore.
04 · Transfer

The same locks, different troops. The agent gets the task, not the vault.

Transferred to an AI agent army, the first rule is: no process sees the whole `.env`. The render agent gets a ticket for a job, not the Hetzner write key. The trading agent gets the money vault, not the magazine. That is need-to-know as a filesystem, not as a poster.

  • ClearanceWhich vaults a process may even name. Planned here as vaults by blast radius: infra, money, AI, marketing, clients. Security plan, stage 1, still open.
  • CompartmentCodeword rooms. One OpenClaw worker on one VPS is a room, not "the cloud". Two agents, two rooms, even on the same Hetzner account.
  • IndoctrinationThe mission file the agent signed: system prompt, allowed hosts, forbidden vaults, expiry. Logged. Revocable.
  • Need-to-knowThe task as a tearline: goal, constraints, return channel. No sources, no master keys, no phone numbers of the humans behind the tokens.
  • ORCONWhoever minted the secret can kill it. Service accounts with an expiry, not a JWT that lives until 2036.
  • Case officer / agentThe phone is the case officer's radio. The file room stays on the VPS. The chat app may call the army. It may not own the fleet.
  • Need-to-shareWhen two agents must work together, a broker opens a time-boxed joint between two rooms. The rooms do not become one file.
  • TearlineWhat appears on the phone is the thin cut: status, next step, alarm. The scan, the key, the dump stay below the line.

9/11 is the warning the other way. If every agent knows only its room and nobody is allowed to see the dots, you build an army that is brilliant locally and blind globally. That is why DCID 8/1 is the second half of the transfer: the agent must get everything the mission needs. Otherwise you have confused security with inability to work.

In practice, for us: the chat on the phone talks to a broker. The broker checks which human is sitting there (device, factor, session). It checks which agent is being called. At runtime it fetches only the references this task needs from the matching vault. Values live in process memory, not in a file on the phone, not in a screenshot, not in a chat the model will quote tomorrow. Unclassified stays the default while we do not trust the system: it fetches, it does not push. That is in the house rules of 31 July 2026. Trust is a check with a clock, not a mood.

05 · The control centre that is missing

How do you steer your AI agent army safely, and easily, from your phone?

I do not know a solution that satisfies. We measured Claude Code Mobile: a chat with upload, no SSH, one repo, no place for your own credentials. The dragon stays on a leash. OpenClaw on Hetzner is the opposite: real troops, real keys, real overhead. Between them sits the product I am looking for at the lake.

Then the other craft. Historical, manual, scrubbing data in the table cellar of the SME museum. The calming effect of a table made by hand. I could sell courses: mandala painting in traditional Excel dress. That is the joke, and it lands, because tables are the only language in which rights chaos becomes visible. If you cannot describe your agent army in a table (who may do what, until when, for which job), you do not have an army. You have a flatshare with a master key.

Useful tips are welcome at the local AI mayor, John. In earnest: how do you steer your AI agent army safely and easily from a phone? Not as a pep question. As a brief. Whoever builds the box in which the case officer can radio without pocketing the file room has something you can sell the day after tomorrow. Live in the future. Fix what's missing.

What we do not claim: that McGrinsey already has this control centre. The security plan is stage 0 done, stage 1 open. This piece is the question, asked in public, with the tradecraft of the services as a foil.
06 · Honesty table
ClaimBasketWhere from
Lake scene, 27 August 2026, range in the woodsFirst-person reportJohn, this morning. No geotagged photo in this piece.
Control centre: chat app, OpenClaw, Hetzner VPSFact of the house architectureCLAUDE.md, Ghostclaw, MCG infra. No third-party product audit.
Four locks for SCIFact of the directiveDCID 1/19, public at FAS.
Need-to-know includes "all that is required"Fact of the directiveDCID 8/1, public at FAS.
9/11 Commission: need-to-share instead of need-to-knowFact of the report9/11 Commission Report, executive summary.
Oak Ridge, most did not know about U-235Standard exampleWikipedia, Compartmentalization. School case, no primary file here.
Vaults by blast radius solve the phone problemHypothesisOur transfer. Stage 1 of the security plan is open. No field trial in this text.
Claude Code Mobile is not an agentOur measurementMagazine, The Dragon on a Leash, August 2026.
07 · Sources
  1. DCID 1/19, SCI handling
    Four locks, need-to-know, sanitizing of sources and methods.
    https://irp.fas.org/offdocs/dcid1-19.html
  2. DCID 8/1, Intelligence Information Sharing
    Need-to-know also means: everything the mission requires.
    https://irp.fas.org/offdocs/dcid8-1.html
  3. 9/11 Commission Report, executive summary
    Replace need-to-know with need-to-share. Biggest impediment to all-source analysis.
    https://9-11commission.gov/report/911Report_Exec.pdf
  4. ODNI, Intelligence Community Information Sharing Strategy, 2008
    Cold War need-to-know as a handicap. Stewardship instead of ownership. ORCON as a queue.
    https://www.govinfo.gov/content/pkg/GOVPUB-PREX28-PURL-LPS93425.pdf
  5. Wikipedia, Compartmentalization (information security)
    Greek fire, Manhattan, Ultra, codeword levels.
    https://en.wikipedia.org/wiki/Compartmentalization_(information_security)
  6. DoDM 5105.21, SCI program
    SCI only to persons with access and a demonstrated need-to-know.
    https://sgp.fas.org/othergov/dod/5105_21v1.pdf
  7. Peter Steinberger / MCG
    Live in the future, build what's missing. A magazine piece and a working rule here.
    https://mcgrinsey.com/magazin/who-the-hell-is-peter-steinberger/
  8. The Dragon on a Leash
    Claude Code Mobile, four fences, not an agent.
    https://mcgrinsey.com/magazin/the-dragon-on-a-leash/

Cut-off: 27 August 2026. Written with the McGrinsey writing skill. Not a company piece, so no McGrinsey Ratio.