Spools
Spools computer: observe your agent's cloud workspace
Enable a team's cloud computer, observe its read-only desktop, understand automatic tools, and protect work beyond its limited checkpoint.
Before you start
Section titled “Before you start”Open the account menu → Agents, the actual entry for Spools. Spools is in early access and only appears for accounts that have been given access. Access to Spools and eligibility for a computer are separate: an eligible paid plan enables the computer capability, but does not grant early access. The computer service must also be available.
The current computer is a cloud Linux desktop shared by the agents in one of your teams, not a separate private machine for every agent. It is not your local device. Plan around shared files and browser state; do not give agents in the same team conflicting file-editing tasks.
The panel is Live view (read-only). You can observe it but cannot take over its mouse or keyboard, click through a login, or manually edit its files from that viewer. The agent operates the computer through its tools.
Do not share the viewer URL: it contains a temporary access token. Anyone with a valid link can view the running desktop without a separate Neurothread sign-in, even though the VNC server refuses mouse and keyboard input.
When to use this
Section titled “When to use this”Use the computer when the task needs browser interaction, command execution, or files in a working directory rather than just a text answer. Start with disposable demonstration data and a task whose effects are easy to inspect. If web search or an MCP read is enough, leave the computer disabled to avoid unnecessary capability and cost.
An enabled computer can browse, click, type, run shell commands, read files, and create or replace files automatically. Do not use it for sensitive work on the assumption that every destructive action will ask for approval. Restrictive instructions communicate intent, but are not an enforced permission boundary.
- Select the agent and open Agent settings. Under Tools, enable Own computer (browser, terminal, files) and select Save. The switch is locked on a plan without computer eligibility. Verify that the chosen model supports tool calls; screenshot-based desktop work also needs vision support.
- State the task, the exact files or destination it may use, and what it must not do. For an initial exercise, ask it to create a small demonstration file, not to modify production files, make purchases, or send messages.
- Send the message. The computer starts automatically when a computer tool is first needed, not simply because you open the viewer. There is no manual start-computer control in this panel and no guaranteed startup time.
- Select Computer in the conversation header to open the panel. Computer activity may also open it automatically. Turning the computer on… indicates startup; a running desktop appears when its viewing link is available.
- Observe the desktop and the conversation’s tool cards. Expand Arguments and Result where available. Shell work may not produce a visible desktop change, and the short tool-card result may omit part of the full output.
- Use Refresh if the view is stale or its link expires. Closing the panel only hides the viewer; it does not stop the agent or revoke computer access. You cannot click or type into the remote desktop to fix a stuck task.
- If the work is wrong or unsafe, use Stop in the agent conversation, including the separate stop control if it is waiting for MCP approval. Stopping requests an end to the run; it cannot undo completed file writes, browser submissions, or a command already in progress.
- Review the deliverable and preserve important results outside the temporary machine as appropriate. With the canvas tool enabled, you can ask for a finished report to be saved as a canvas document and verify its location. For future tasks that do not need the computer, disable it in Agent settings and Save; do not rely on a settings change alone to halt already-started work.
Worked example
Section titled “Worked example”Illustrative exercise, not an executed run: ask an Engineering agent with Computer enabled: “Create a small Markdown checklist with three fictional acceptance criteria under your home directory. Read it back and show its path and contents. Do not access external accounts, install packages, or change existing files.”
The agent may write and read the file automatically; a separate Allow card is not required for those integrated operations. Check the returned contents. If you also enabled the canvas, ask it to save the verified checklist in a named workspace and then check that node yourself. This guide has not started a machine or executed that exercise.
What happens next
Section titled “What happens next”The team computer is reused while running. When released after work or stopped for inactivity, the service attempts to save a checkpoint of /home/agent, including its browser profile, and restore it on a later cold start. This is a workspace checkpoint, not a complete machine image, process snapshot, or guaranteed continuation of a browser session. Logins and open application state may not survive or may expire independently.
Dependencies such as node_modules and .venv, caches, and oversized individual files are excluded. Temporary files in /tmp are not part of the home-directory checkpoint. The overall ceiling is checked against the compressed checkpoint archive, not the uncompressed home directory. If that archive is too large, the new checkpoint is skipped and the previous one retained. A failure or abrupt stop can also mean the latest changes were not saved. Keep independently verifiable copies of important results rather than treating the computer as the only durable store.
External MCP approvals remain separate: read-only MCP calls run automatically; other MCP calls pause for your decision. Integrated computer tools, remembered notes, and canvas writes do not use that same gate. The agent is instructed to ask before important deletions, purchases, or sending messages, but that instruction is not a universal technical approval mechanism.
Cost and limitations
Section titled “Cost and limitations”Computer use adds credits per started minute of the run’s measured computer-use time, separately from model work and any applicable searches. That time can include work after the computer first starts, not just the moments when commands execute. Pauses, failed tasks, and stopped tasks can still have partial charges. BYOK affects model billing only when a saved key matches the selected provider model and the plan allows it; Neurothread house models, including the default agent model, still use platform billing. It never makes computer use free. Rates and plan quotas are configurable; do not assume a permanent numeric allowance from this guide.
Shell commands have timeouts, file operations have size limits, and tool output can be truncated before reaching the model or being stored in a card. Only the latest computer screenshot is retained in model context during tool work; there is no guaranteed complete visual replay. A model without vision cannot interpret screenshots, though shell-based work may still be possible with tool support.
Web pages, files, skill scripts, and tool results are untrusted content. They can contain prompt-injection instructions or code that tries to redirect the task. Do not provide passwords, API keys, payment details, or private customer data in prompts, files, or the desktop. A read-only viewer prevents your manual input; it does not prevent the agent from changing things or guarantee that sensitive data is protected from the model or visited service. Limit tools and external permissions to what the task actually requires.
Troubleshooting
Section titled “Troubleshooting”- Computer is locked: computer capability requires an eligible paid plan, separately from Spools access. A paid plan alone does not unlock the early-access area.
- The panel says the computer is off: it starts when the agent actually uses a computer tool. Opening the panel does not start it.
- The panel is unavailable even on a paid plan: service availability is another requirement; do not assume the plan message rules out an outage.
- The view expired or froze: use Refresh to request a fresh view. Check the agent’s conversation for current activity instead of assuming a frozen image means the task stopped.
- Clicks and typing do nothing: this is intentional; the view is read-only. Give instructions in chat or stop the run instead of attempting manual takeover.
- The agent cannot see the page: check vision support in the selected model. A text-only model cannot interpret the screenshot.
- Files, dependencies, or login state are missing later: distinguish a restored home workspace from a full machine/session. Excluded or temporary files are not preserved, and the latest checkpoint may have failed or been skipped.
- A risky command ran without approval: built-in computer tools are automatic. Stop if appropriate, inspect its effects, and disable unnecessary capabilities; do not confuse this with MCP approval.
