Operations
Built to run unattended.
Beyond the agent loop: persistent coworkers, delegated jobs, memory, governance, optional computer use, configured notifications, durability, and observability for self-hosted runs you can inspect and steer.
jobs submit/list/status/logs/cancel/rerun exposes persistent background work with recorded attempts and configured retry behavior. In-process async work can also be inspected through hub jobs.
Optional OS-process isolation per worker over Unix sockets, with operator-configured resource limits and independent process lifecycles.
Subprocess hooks let operators gate or enrich runs: PreToolUse can allow or deny, PostToolUse can add context, and Stop can request a controlled continuation.
Cancellation tokens propagate through the worker tree; classified errors can be retried with Retry-After. Web-content boundaries and loop detection add guardrails to long runs.
With stream: true, text deltas reach the TUI as they arrive and tool calls are assembled from stream fragments; providers can be configured for a non-streaming path.
Governance can pause side-effect tools such as save_contacts or git_push for an operator decision: y/n in the TUI or POST /api/v1/sessions/:id/approve in the API.
Workers can ask the operator mid-task. Configure the unattended policy for how a run proceeds when no operator is connected.
run --repeat runs a task on an operator-selected cadence, compares results between runs, and can send configured webhook, Telegram, or email notifications.
BPE token accounting (tiktoken cl100k_base), a CJK-aware fallback, per-tool truncation, persisted context, and cooldown-aware compaction keep long worker runs bounded.
Workers can produce PDF, HTML, JSON, or DOCX reports and notify configured webhook, email, or Telegram channels when a run completes.
Configured amoCRM, Bitrix24, or HubSpot tools can push contacts and findings with crm_id-based deduplication where supported by the connector.
run --profile selects a built-in or operator-defined TOML profile with prompt, model, depth, and tool settings. Per-role models use [agent.role_models].
After fan-out, an LLM judge can compare results with the goal and request configured gap-filling rounds. Reflection is useful for research and outreach workflows, not a quota guarantee.
Session limits and budget-capped sub-agent results help bound spend; per-tool latency and token statistics are available from real runs when observability is enabled.
An append-only JSONL ledger can record configured checks — email syntax, domain MX, SMTP probe, phone normalization, or social profile — with pass, fail, or inconclusive verdicts.
Interrupted sessions can be detected and state reconstructed so completed workers remain visible and unfinished subtasks can continue under operator policy.
Worker file modifications can be tracked for review, and undo can revert the last recorded change when an operator needs to recover.
Session-scoped TTL caches can reuse fetched URLs and DNS MX lookups, reducing duplicate network requests within a run.
Concurrent write serialization coordinates workers that share a workspace and avoids overlapping writes to the same file.
A session-shared ledger gives coworkers a place for notes, partial results, and status updates during delegated work.
Per-tool byte and line caps plus turn budgets bound context growth; oversized outputs carry an explicit truncation marker.
hub supports peer messaging, list, jobs, and activity updates; steer can redirect a live run. Workers may park and revive, while batch spawn accepts configured task groups with output schemas and handoffs.
The daemon tool starts, stops, restarts, lists, and reports status for long-running processes, with optional port or log-regex readiness checks.
Operator-configured warn and kill timeouts, heartbeat monitoring, and cancellation propagation help identify stuck workers and stop their descendants.
Durable worker profiles and collaboration channels retain identity, goals, and delivery surfaces across sessions.
An optional scheduler can trigger coworker work on cron-like schedules; atomic claims coordinate runs when multiple server processes are active.
Store named secrets through the authenticated API; list responses expose metadata while secret values remain server-side.
Inspect governed action history through a bounded replay endpoint, with credential values redacted before persistence.
When enabled, Prometheus metrics and a bounded summary endpoint expose live sessions, tokens, tool calls, and governance audit counts.
Test configured webhook, email, or Telegram channels through a bounded symbolic-channel endpoint; destinations and credentials stay server-side.
An authenticated, optionally configured computer relay can provide navigation, accessibility snapshots, screenshots, files, and human-control leases.
Autonomous Chief of Staff
Continuous Inbox Sweep & Multi-Persona Triage
Sweeping 41 active threads, filtering low-priority marketing noise, drafting context-rich executive replies, and orchestrating delegated tasks across specialized personas.

Fig 7.1 — Chief of Staff Persona: 41-thread sweep, noise archival, priority triage, and multi-persona execution.
Agency Multi-Tenancy
Agency Fleet Scaling & Client Pods
Managing 12 isolated client coworker fleets from a unified control plane. Dedicated Docker sandboxes, separate SQLite memory graphs, and white-label branding with 92% net margins.

Fig 7.2 — Agency Fleet Manager: 12 client worker pods operating in isolation with 92% net profit margin.
One runtime, several operator surfaces
The self-hosted distribution provides CLI, TUI, HTTP/SSE, AG-UI, and MCP surfaces from the Fathom runtime; enable workers and optional integrations in your deployment.
fathom run "..." # one-shot
fathom run --repeat 24 ... # every 24h with diff alerts
fathom jobs submit "..." # durable background
fathom serve # API + dashboard
fathom tui # interactive
fathom mcp-serve # MCP server