In ROOK, a device is a machine that does the coding work. The phone is a surface: it shows recorded state and lets the operator answer a decision, but it does not become another work machine or another source of truth.

That distinction keeps the model small. Each work device owns its server and warehouse. Surfaces reach the device over the operator's private mesh and read the same contract.

[Visual 5 - Three work devices sit inside one private-mesh boundary. Each device contains its own warehouse. A desktop window and a phone window point to one selected device at a time. The windows are labelled "surface, not authority".]

Work stays with its origin

The authoritative record stays on the machine doing the work. A surface can display that record and send an answer back to it, but it does not keep a competing copy. Writes require a live path to the origin device. When that path is unavailable, the honest state is read-only rather than an offline queue that may conflict later.

The local record still has external dependencies. The coding CLI reaches its model provider, and device identity and connectivity depend on Tailscale's coordination service.

This section

PageWhat it explains
The device modelOrigin device, personal fleet and surface vocabulary
Device controlLive, stale, draining and stopped states

Limit

This model does not mean ROOK works on every platform or can be installed by another person today. It explains ownership and communication between the parts that currently exist. Packaging and distribution remain outside this handbook.

Next

Read the device model.