MP@MinglongPan

← All writing

2026-07-24Updated 2026-08-298 min read

Valhalla: the product layer between agents and attention

My agent fleet can research, build, monitor, and prepare work in parallel. Valhalla is the product boundary that stops all of that activity from becoming my problem. It answers one question: what, if anything, needs me now?

That sounds like a dashboard. It is almost the opposite. A dashboard rewards looking; Valhalla is successful when I can read one verdict, take one action, and leave.

The screenshots below use synthetic content rendered by the real Valhalla frontend. No career threads, financial records, health data, private hostnames, or credentials are present.

The phone experience: one memo, one lead

The phone is the primary surface. It opens on a memo rather than a grid of metrics:

A phone-sized Valhalla memo showing one primary review action, one secondary reading action, a quiet weekly line, and a five-app dock.
A privacy-safe demo of the phone memo. The content is synthetic; the layout and renderer are the real product.

The headline is already a judgment: one verdict leads, one other item can be answered, and everything else can wait. The first block gets the only solid action. Lower-priority work is still reachable, but it does not compete for visual volume.

A normal visit is short:

  1. I open Today and read the verdict.
  2. See the work opens the evidence without losing the memo.
  3. A safe action such as Accept it records the decision.
  4. The finished block collapses to a struck one-line receipt, and the next item inherits the visual weight.
  5. I leave. Healthy systems do not ask for a victory lap.

That collapse matters more than it sounds. Earlier versions left a completed card at full size with a checkmark. Mechanically it was done; perceptually nothing had changed. A decision surface has to make state transitions legible or users stop trusting it.

The bottom dock contains doors into workspaces, not another feed. If a task belongs in a reading tool, practice app, or editor, Valhalla deep-links to the exact action inside that app. It does not send me to a lobby and ask me to navigate again.

The desk experience: the same truth, re-composed

The desktop does not fetch a richer private dataset or become a control-room dashboard. It re-composes the same ranked state as a broadsheet: the lead stays dominant, while the wider canvas can separate decisions, reviews, ambient ledgers, and notices.

A desktop Valhalla broadsheet with a synthetic review card, a learning item, a settled receipt, quiet system state, and a navigation index.
The desktop broadsheet uses the same synthetic state as the phone. Career and freedom rooms are omitted from this public capture.

The left index answers where things live. The center answers what to do. The right edge carries standing context that may explain the decision but does not deserve a card. This distinction is deliberate: rank determines order; kind determines volume. An important fact can remain quiet when it asks for nothing.

Phone and desktop therefore have different grammars over one state:

SurfaceOptimized forShape
Phonea 30-second decisionone memo, one loud action, details folded
Desktopcomparison and reviewone lead, then Decide / Review / Board / Notices
Satellite appdoing the workthe exact verb or artifact, opened in place

The responsive breakpoint changes composition, not meaning. A card cannot be urgent on the phone and ambient on the desk simply because there is more room.

Frontend: deterministic copy over typed state

Valhalla's frontend is a small HTML, CSS, and JavaScript application. There is no language model in the render path. The server returns structured state; deterministic templates turn the same fields into the same sentence every time.

That choice buys three things:

  • Trust. A deadline cannot be paraphrased into a different level of urgency between refreshes.
  • Inspectable failure. Missing or stale sources render as unknown or unavailable, never as a confident empty state.
  • Cheap re-composition. The phone memo and desk broadsheet can share data and judgment while using different layouts.

The top-level navigation stays intentionally small: Today for the next decision and Index for the state of the whole system. Deeper rooms are hash-routed views, and standalone apps open in a framed overlay. The frame owns the shared identity and way home; the embedded app hides its duplicate header. That sounds cosmetic, but two headers make a product suite feel like a pile of websites.

The renderer also preserves local reading state across refreshes. An open fold stays open, a completed action keeps its receipt, and a body-level sheet is not destroyed when the memo's data refreshes. Live data is useful only if it does not keep resetting the human interaction wrapped around it.

Backend: projections instead of database reach-through

The backend is a read-mostly aggregation layer. Each app owns its data and exposes a narrow read contract. Valhalla consumes those contracts and command-line projections; it does not open another app's database and invent a second interpretation of its state.

The path is intentionally boring:

LayerOwnsRefuses
Producersdomain state and attention itemsdirect user notification by default
Projectionsnormalization, expiry, and actionabilitywriting another app's substrate
Aggregation APIranking, caching, and partial-failure truthtreating a failed source as “all clear”
Browserdeterministic presentation and local interaction stategenerating judgment with an LLM
Action gatea small set of reversible, pre-authored verbsarbitrary browser text becoming a command

The main read combines domain cards, review work, and quiet app state. A separate attention projection carries asks, snoozes, completed receipts, and informational lines. The browser composes them into one memo so the headline count and the visible sections cannot disagree.

The hard part is failure semantics. If a domain projection, review queue, or app feed is unavailable, silence would look exactly like a healthy morning. Valhalla therefore fails visibly: unknown is a product state. Slow ambient sources may serve a marked last-known value while they refresh, but anything that can change the next action gets a short deadline and no fabricated fallback.

What happens when an action is tapped

The browser does not send a shell command. It sends a constrained verb plus an identifier—or, for a decision card, the index of an answer the producer already authored.

The backend then:

  1. checks the owner session and same-origin write boundary;
  2. validates the identifier and verb against a small allowlist;
  3. re-reads the stored action contract instead of trusting browser-supplied command text;
  4. executes fixed server-side arguments;
  5. records the real result and refreshes the projection.

This is why the interface can offer useful actions without turning a browser button into a general remote shell. Destructive, financial, or open-ended judgment calls stay in a higher-friction conversation or operator path.

The four friction laws

The architecture follows four product laws learned from flows that did not stick:

  1. Capture goes to the conversation. I log or park something where I already type; I do not open an app merely to enter data.
  2. The ask travels to where I already look. Apps publish a one-line read model into Today instead of minting another inbox.
  3. Starting is logging. If a task uses a timer, finishing the timer creates the record. There is no bookkeeping round after the work.
  4. Deep links land on the verb, not the lobby. A reading opens at the assigned text; a practice link starts the rep; an agent handoff opens the relevant conversation.

These rules are less about saving taps than preserving motivation. Every extra destination asks the user to reconstruct why they arrived. The system should carry that context to the action.

What I would reuse elsewhere

Valhalla is personal infrastructure, but four patterns transfer to other agent products:

  • Put an admission rule in front of the UI. “Does this need a decision now?” is more valuable than another sorting control.
  • Let domains own their public read models. Aggregators should consume contracts, not databases.
  • Separate read freedom from write authority. Rich projection can remain read-only while a tiny action gate is heavily constrained.
  • Treat completion and failure as designed states. A quiet system, an unavailable source, and a finished action must look different.

The central idea is simple: agent productivity is not the amount of work agents produce. It is the amount of useful work they can complete without making a human continuously supervise them. Valhalla is the boundary where that claim either becomes true or falls apart.