A ROOK device is a work machine with its own server and on-device warehouse. Several devices can form one operator's fleet, but their records do not merge into a central ROOK cloud.

A desktop or phone app is a surface onto one selected origin. It reads the origin's record and sends answers to that origin. One active connection keeps it clear which device the operator is looking at.

[Visual 5.1 - An origin device in the centre contains "server + warehouse". Two more work devices sit beside it as a personal fleet. A phone surface points to exactly one origin with a solid line; the other possible connections are grey and inactive.]

Origin, fleet and surface

  • Origin device: the machine doing the work and holding the authoritative record.
  • Fleet: the operator's set of work devices, each with its own origin record.
  • Surface: a window onto one origin. The phone is a surface, not a device in this vocabulary.

The distinction matters when a machine disappears. Another surface cannot silently take ownership of its work. It can only show what the selected origin currently exposes.

Identity comes from the mesh

Identity is the private mesh. There are no ROOK tokens to paste, store or rotate. Removing a node from the mesh revokes it from this connection model.

That is an identity and connectivity boundary, not a claim that the whole system is offline or free of outside services. Tailscale coordinates the mesh, and the coding CLI still calls a model provider.

Limit

The device model describes authority and connection. It does not establish public platform support, multi-user operation or a released installation path.

Next

See how the operator reads and changes fleet state in device control.