Give Access, Not Control.
Manifold gives AI agents selective access to your files and email, with privacy checks, audit trails and rollback built in.
Subtext
Your AI work should not be locked inside a chat box.
Most AI tools keep context inside their own interface. Your files, edits and agent history become tied to that vendor.
Manifold runs locally on your Mac, keeping your selected files, version snapshots and AI activity timeline in one place, so you can switch tools without losing control of your work.
What Manifold does
One control layer for files and email. AI agents need context to do useful work. Manifold gives them access to the context you choose, without opening everything by default.
Files and email work differently, so Manifold handles them differently. Project files are selected deliberately. Email is filtered continuously. Both are governed by the same permissions, privacy checks, audit trail and rollback.
Files — Share project files deliberately
Curate your project context once, then decide what each AI agent can see. Claude can access customer notes and proposals. Codex can access technical documents and code. Sensitive files stay out of scope unless you choose otherwise.
Email — Filter your inbox before AI sees it
Connect the inboxes you choose, then create rules for what can be shared. Manifold can route relevant messages to the right agents, filter sensitive content, and keep everything else private by default.
Inside the app — See and control what every AI can access
When an AI agent reads a file, uses an email, proposes an edit or triggers a rule, Manifold logs it with the time, source, permission and file version. You can approve writes, deny them, allow them once or add them to your default rules. If something changes, roll back to an earlier snapshot from any session, even if you switch AI tools.
Local-first privacy checks
Manifold includes the OpenAI Privacy Filter as a preflight rule. Before shared files or messages reach an AI agent, common sensitive data can be detected locally and masked, warned or blocked according to your rules.
Supports 2FA codes, addresses, names, phone numbers, account numbers and government IDs. Runs on Apple Silicon via MLX, with no Manifold cloud required.
Get started — Install locally. Choose context. Work with control.
- 01 Connect. Connect Claude, Codex or supported agents through Manifold on your Mac.
- 02 Choose. Select the files, folders and email threads each agent can access. Everything else stays denied by default.
- 03 Work. Review what agents read, changed and created. Roll back files and reuse context across future sessions.
Open source. Local-first. Mac native.
Manifold is open source under Apache 2.0. The app, runtime and MCP bridge live in one repo, so users can inspect how access decisions are made. Project context, version history and usage timelines stay on your Mac, with no Manifold cloud required.
Download for Mac · View on GitHub · macOS 26+ · Apple Silicon · Apache 2.0
For a full AI-readable description of Manifold, see llms-full.txt.