hal BIT HAUS WINDOW REVIEW SPEC LIMITS DOWNLOAD
SPEC-DRIVEN DEVELOPMENT, WITH SEVERAL CODING AGENTS RUNS ON YOUR MAC / MONTHLY SUBSCRIPTION

Your spec is the source of truth.
The agents build to it.

hal is a native Mac app for spec-driven development. A product-manager agent keeps your specification as the source of truth, plans each release from it, and cuts the work into stories that coding agents build against. You run several agents at once, across several repositories, and the window tells you which one needs a decision.

Download for macOS v— · — MB · macOS 26 OR LATER
APPLE SILICON + INTEL · SIGNED + NOTARIZED
MONTHLY SUBSCRIPTION · SIGN IN ON FIRST LAUNCH
3
PLACES A DECISION REACHES YOU
2
VENDORS — ONE WRITES, THE OTHER REVIEWS
1
DEVELOPER, ONE MACHINE, YOUR OWN CHECKOUTS
The hal window on Grid: one tile per repository, coloured pips per work item, and a needs-you band naming the waiting decision.
FIG. 1 — GRID. ONE TILE PER REPOSITORY, NOT ONE CARD PER AGENT. RED BAND = SOMETHING IS WAITING ON A PERSON
01 — THE ATTENTION PROBLEM

One tile per repository. One dot per work item.

Cards per session multiply with how many agents you run. Tiles per repository are bounded by how many repositories you have. Each tile carries the version in flight and one dot per work item: green working, amber stopped, red waiting on you, hollow unstarted. Click a dot, land on that agent. Click a hollow one, start one.

02 — WHERE IT FINDS YOU
  • 01Dock tile, badged with the decisions waiting, with a running dot while any worker runs.
  • 02Notification Center, with Decide and Later on the alert, when the window isn't in front.
  • 03Needs-you band on the tile, and one pill in the toolbar that opens the oldest waiting decision.

A NATIVE MAC APP, SO A DECISION CAN REACH YOU OUTSIDE THE WINDOW.

03 — REVIEW

Reviewed by a model from a different vendor.

A model grades its own work generously, and carries the blind spots it was trained with. So by default a model from a different vendor reads every plan before you see it, and every change before it is called done. Findings come back as blocker, should or nit. A story can't close while a blocker is open, and approving over one is recorded.

84%

of 248,641 AI-reviewed AI pull requests were reviewed by the same product.

93%

of findings, across four AI reviewers on one codebase, were caught by exactly one of them.

Focus: one worker's transcript beside the rail, where a submitted change offers Review the change or Diff, with the read-only story beneath it.
FIG. 2 — FOCUS. THE RAIL HOLDS WHATEVER NEEDS A PERSON, OLDEST FIRST.

Confirmation is the default, and it offers five answers: run once, don't ask again for this command this session, yolo for this session, skip, or skip with feedback in your own words — which the model reads as a failed command and adapts to. Escape never approves.

04 — A PRODUCT MANAGER THAT OWNS THE SPEC

The spec is the plan. Work is cut from a version.

A product-manager agent owns your specification — Markdown in your own repository — and is the only thing that writes it. It interviews you, reads the spec and the code, stages a diff per document, and cuts the work into stories with acceptance criteria and declared dependencies. Stories run in waves as their dependencies close.

You can read any document as of any version, with that version's changes highlighted in place and a banner saying how the older reading was found. No repository is touched behind your back: opening a folder gets a cheap, read-only scan and an offer.

A version's detail: four work items with the spec sections each implements, and the record of the spec at this version.
FIG. 3 — ONE VERSION’S WORK ITEMS, EACH CITING THE SPEC SECTIONS IT IMPLEMENTS.
01

You say what you want, in your own words.

02

It asks only what it can't infer, then reads the spec and the code and says what it's assuming.

03

It stages a diff per document and plans the stories. Nothing touches disk.

04

The other vendor's model reads the plan before you do. Two rounds by default.

05

You approve, revise or abort. Approving makes the version ready. It cuts no work yet.

06

You start it, or queue it behind the one in flight.

07

Coders build, reviewers check, you close. The last story done releases the version.

You do the merge to main.

ALWAYS
05 — ONE AGENT, TWO CLIENTS

Start a session in a terminal and it appears in the window. Start one in the window and pick it up in a terminal. They share sessions, the product manager, and open questions: answer in one place and the question withdraws from the other. The app carries the agent in its bundle and starts it for you.

06 — MODELS AND KEYS

Claude, GPT, Gemini, DeepSeek and Kimi, with your own API key or a short-lived credential-router token, so that revoking hal's access is one act. Commands run locally by default, or in one Docker container per repository. Docker is the containment boundary; plan mode's read-only check is not.

07 — COST AND CONTEXT

Cost per session and per day. The context window drawn by segment, each marked cached or fresh and pinned or compactable, and labelled an estimate. Compaction runs on its own at a threshold, so there is no compact now button.

08 — WHAT IT DOESN'T DOAS OF v—
macOS 26 only. One user, one machine.
No cloud agents, no scheduled runs, no team features, no mobile.
No browser pane for you — the browser is the agent's driver, on a profile of its own.
Docker runs with the shared tree only. A worktree inside a container isn't built.
The Diff pane has no line comments. Feedback reaches a worker through Review and Decide.

Download hal. Sign in on first launch.

hal.zip

hal is a monthly subscription, billed to your Bit Haus account. One subscription covers the Mac app and the terminal client. Sign in once and the app starts its bundled agent for you; if a terminal already started one, it attaches to that instead.

hal © 2026 BIT HAUS · hal.bit.haus TERMS PRIVACY DOWNLOAD