Chapter 06
General Agents on the Web
Chat se delegate tak — wahi 6-part harness shape jo har naye AI agent product mein milta hai
Ye chapter CCAO-F ke liye foundation hai, do rival products (Claude Cowork aur ChatGPT Work) ke saath
Core Idea
Pichle 4 chapters mein aap ek chat tab mein kaam karte the: aap poochte, AI jawab deta, aap phir poochte. Har turn aap se shuru hota tha. Ye chapter division of labour badalta hai: chat box aur agent surface ab same address pe agal-bagal baithte hain, aur ek assignment ko plan kar ke, tools use kar ke, aap ke tab band karne ke baad bhi khatam karna, ab ek normal product feature hai.
Chat Box Vs Agent Surface
Chat Box
Aapke turn ka wait karta hai. Aap type karo, wo answer de, phir phir wait kare. Tab band karo, kaam ruk jata hai.
Agent Surface
Aap assignment dete ho. Wo plan banata hai, tools use karta hai, steps complete karta hai. Aap tab band kar do, kaam chalta rehta hai.
Zaroori Terms, Shuru Mein Ek Baar Parh Lo
| Term | Matlab |
|---|---|
| Chat box | Conversation jo har turn aapka wait karti hai, band karo to ruk jati hai |
| Agent surface | Jagah jahan aap outcome assign karte ho, aur system plan bana kar khud steps complete karta hai |
| Agent loop | Wo hissa jo decide karta hai agla kadam kya hai, jab tak kaam finish, block, ya stop na ho |
| Cloud session | Session jiska agent loop vendor ke servers pe chalta hai, aapka tab sirf ek window hai |
| Local session | Session jiska agent loop aapki apni machine pe chalta hai |
| Desktop bridge | Controlled path jo cloud session ko aapki machine ke selected tools (browser, local folder) tak pahunchne deta hai |
| Connector | Permission-scoped, structured access ek service tak (Drive, Gmail, Slack) |
| Human gate | Control jo sahi risk boundary pe insaan ko loop mein rakhta hai |
Part 1 · The Shift
1. Same Address, Do Alag Cheezein
Claude.ai ya ChatGPT.com khol lo, chat box aur agent surface ab same address pe hain. ChatGPT pe to Chat mode aur Work mode screen pe sath sath dikhte hain.
Chat box wahi conversation hai jo Foundations se pehchan chuke ho, har turn aapka wait karti hai, schedule pe start nahi ho sakti, event pe react nahi kar sakti, tab band karne ke baad continue nahi hoti. Ye missing feature nahi hai, ye conversation hone ka matlab hi yehi hai.
Agent surface iske bagal mein baithta hai. Aap usay ek assignment dete ho, message nahi. Wo plan banata hai, tools use karta hai, steps complete karta hai, sirf wahan rukta hai jahan decision ke liye aap chahiye ho, aur aapke dekhna band karne ke baad bhi kaam karta rehta hai.
“Agar main typing rok doon, kya kaam ruk jayega? Chat box: haan. Agent surface: nahi.”
Ehtiyat
2. Remote Session: Tab Ek Window Hai, Runtime Nahi
Purana simple model tha: agent ya aapki machine pe hai, ya vendor ke servers pe. Ye ab bhi ek acha first picture hai, lekin poora nahi hai. Do axes use karo:
| Axis | Sawal |
|---|---|
| Axis 1 | Agent loop kahan chal raha hai? Cloud session ya Local session? |
| Axis 2 | Tool kahan execute hota hai? Cloud connector, ya bridge ke through browser/local tool? |
Isse 3 common runtime patterns milte hain:
| Pattern | Agent Loop | Laptop Band Ho To? |
|---|---|---|
| Cloud-only | Vendor cloud | Run chalta rehta hai |
| Cloud + Desktop Bridge | Vendor cloud | Cloud run chal sakta hai, lekin bridged tool disappear ho jata hai jab required desktop component offline ho |
| Local | Aapki machine | Run depend karta hai aapki machine online rehne pe |
- Tab band karna cloud run rokna nahi hai, tab sirf ek window hai
- Laptop band karna bridged tool ko cloud session mein maar sakta hai, cloud session mar nahi jata
- Local file bhi cloud mein process ho sakti hai, "laptop se aayi" ka matlab "laptop pe rehti hai" nahi hai
- Scheduling sirf tab device-independent hai jab workflow ka har required tool bhi device-independent ho
3. Do Vendors, Ek Shape
Yehi is chapter ka reading lens hai. Product features badalte rehte hain, lekin har serious agent surface yehi 6 hisse rebuild karta hai:
Heartbeat
Kya kaam start karta hai
Reach
Kya read/act kar sakta hai
Run-until-done Loop
Outcome tak kaise chalta hai
State Spine
Agla run zero se shuru nahi hota
Human Gate
Autonomy kahan rukti hai
Body
Kaam actually kahan execute hota hai
| Part | ChatGPT Work Misal | Claude Cowork Misal |
|---|---|---|
| Heartbeat | Scheduled Tasks aur doosre triggers | Scheduled tasks, on-demand runs |
| Reach | Plugins, cloud browser, desktop browser/local tools | Connectors, plugins, built-in browser, Claude in Chrome |
| Run-until-done | Plan mode ke sath outcome-oriented multi-step kaam | Multi-step task execution, sub-agent coordination |
| State Spine | Sessions, Projects, memory/instructions | Sessions, Projects, cloud memory, instructions, files |
| Human Gate | Approval prompts, product policy | Manual, Auto, Skip modes |
| Body | Cloud Work, cloud browser, desktop execution | Cloud sandbox, optional local session, bridged desktop tools |
2 Warnings
Part 2 · The Surface
4. Account Spine: Ek Stack Hai, Ek Blob Nahi
“Account spine” ka matlab hai aapke saved sessions aur files aapke sath chalte hain. 2026 mein persistent context ek layered stack hai, ek cheez jise sirf “memory” kaha jaye wo nahi:
| Layer | Kya Batati Hai | Lifetime |
|---|---|---|
| Session history | Is particular task mein kya hua | Ek workstream ya task history |
| Project | Is continuing kaam ka kya hissa hai | Weeks, months, ya usse zyada |
| Semantic memory | Konse facts/preferences cloud sessions ke across carry hon | Cross-session, jab tak edit/reset/disable na ho |
| Standing instructions | Assistant generally kaise behave kare | Jab tak aap ya admin change na kare |
| User-owned context file | Aap khud kya portable aur inspectable chahte ho | Jab tak aap file maintain karo |
August Update
Isse ek common beginner mistake fix hoti hai: ek purani session memory nahi hai. Ek Project bhi memory nahi hai. Sab persist karte hain, lekin alag reasons se.
- Sessions ko work products ki tarah naam do
- Ek session ya Project mein ek hi workstream rakho
- Durable instructions sahi layer mein rakho, har prompt mein dobara mat likho
- Operational state vendor spine mein reh sakta hai, lekin critical state ka ek portable source of truth honi chahiye
5. 3 File Tiers: Deliverable Actually Kahan Rehta Hai?
Ye is chapter ka signature concept hai. Har file jo aapka agent touch karta hai, teen tiers mein se ek mein rehti hai:
Tier 1 · Task Filesystem
Session ka scratch space, task khatam hote hi wipe. Kabhi bhi storage nahi samjho.
Tier 2 · Platform Storage
Aapke vendor account mein permanently saved. Survive karta hai, lekin vendor ki custody, vendor ke format mein.
Tier 3 · The Exit
File platform se nikal kar aapke apne control wale system mein jati hai, Drive, email, repo, ya local folder. Sirf yehi tier aapki custody mein hai.
“Finished work platform se exit karti hai. Baaki sab kahin bhi reh sakta hai.”
Har brief ke end mein ye ek line add karo, phir tier decision khud handle ho jati hai:
End by listing every file you created and where each one landed: temporary working space, platform storage, or a system I control (connector save, download, local write, or repo commit).
6. Connectors: Reach Aur Exit Door Dono
Connector ab bhi sabse clean tareeka hai, structured, permission-scoped access, screen-driving imitate karne ki bajaye. Lekin ab reach ke 4 raaste hain:
Connector
Structured permission, sabse safe default
Built-in Browser
Portals, forms, jahan connector nahi hai
Your Own Browser Context
Jo page aapke saamne already khula hai
Computer Use
Full GUI control, sabse zyada risk
Default Rule
Jab Agent Read Bhi Kar Sakta Hai Aur Act Bhi
Prompt injection sabse zyada matter karta hai jab do conditions milti hain: agent trusted boundary ke bahar content parh sakta hai, aur consequential action le sakta hai. Anthropic browser surfaces ke liye clear rule rakhta hai: emails ya web content ke andar milne wali instructions complete karna, permission mode kuch bhi ho, prohibited hai. Aapka brief authority hai. External content evidence hai. Us content ke andar milne wali instructions untrusted input hain, agent ka naya boss nahi.
- Trusted sites aur low-stakes accounts se shuru karo
- Banking, medical, identity, ya sensitive systems ke logins casually import mat karo
- Unfamiliar sites, naye plugins/connectors, ya send/spend/delete/publish actions ke liye Manual approval use karo
- Har workflow ko sirf utna connector aur browser reach do jitna zaroorat hai
- Connector ko entry aur exit dono ki tarah use karo, agar finished report Drive mein jani hai, wo destination brief ka hissa banao
Permission Ka Matlab
7. Gate Jo Aapki Pocket Mein Hai
Purani story simple thi: agent kaam karta, phir approval phone pe pahunchti. Idea same hai, implementation update ho gayi hai. Cowork abhi 3 modes ke sath autonomy choice visible banata hai:
Manual
Har consequential action pe rukta hai, aap allow/deny karte ho
Auto
Chalta rehta hai, har action safety-screened hota hai
Skip
Ordinary approvals ke bina, sirf tightly trusted bounded kaam ke liye
Ye mental model do behtar sawalon mein badal deta hai: mujhe bina kya allowed hai? aur action count hone se pehle usay kya rokta ya screen karta hai?
Gate Ko Blast Radius Se Match Karo
| Level | Kaam | Gate |
|---|---|---|
| 1 | Read aur summarize | Low consequence, permissions samajhne ke baad automatic execution reasonable |
| 2 | Draft banao lekin send mat karo | Medium, output system se nikalne se pehle reviewable |
| 3 | Reversible records mein likho | Higher, workflow prove hone tak stronger gate |
| 4 | Send, publish, purchase, delete, ya critical data change karo | High, Manual ya explicit human control use karo |
Gate Test Karo
Part 3 · Working Unwatched
8. Delegation Loop: Brief, Plan, Approve, Review
Product aapke bina kaam kar sakta hai, isliye handoff ki quality pehle se zyada important ho jati hai. Agar workflow clear nahi hai, longer prompt likhne ki bajaye, workflow discovery se shuru karo:
Every Monday I spend an hour checking three places and still miss something. Interview me until you understand what I am trying to accomplish, what sources matter, what I never want changed, and what a good finished brief looks like. Then propose the workflow before doing it.
Manual Mode Ki Guarantee Nahi
Plan review karte waqt 4 checks lagao:
- Scope: sirf wahi kaam aur data touch ho raha hai jo maine bataya, ya job chupke se barh gayi?
- Order: verify karne se pehle act to nahi kar raha?
- Reach: koi connector, browser, send, publish, write, ya delete action to propose nahi ho raha jo maine intend nahi kiya?
- Assumptions: audience, format, ya missing fact chupke se decide to nahi kar raha?
Agar galat plan perfectly execute ho jaye, wo phir bhi galat run hai. Ek sentence se plan redirect karna, complete run ke baad cleanup karne se sasta hai.
9. Scheduled Tasks, Koi Device Online Nahi
Schedule khud heartbeat hai, aapki agli chat turn ke ilawa koi cheez kaam start karti hai:
Once
Ek baar baad mein chalta hai
On A Schedule
Clock pe fire hota hai
On A Trigger
Kisi event par start hota hai
Monitor / Watch
Repeatedly check karta hai, condition true pe surface karta hai
“Ek schedule sirf tab truly device-independent hai jab har required tool bhi bina device ke reach ho sake.”
Schedule karne se pehle 4 sawal likh lo, phir 2 safety sawal:
- Run kya start karta hai? Clock, event, ya watch condition
- Ye kya touch karta hai? Har connector, source, website, plugin, destination
- Kya ye sab devices off hone par bhi reach kar sakta hai?
- Success kaise pata chalega? Ek finished file, dated report, notification, ya observable signal
- Bina approval ke kya allowed hai? Pehle unattended run se pehle gate set karo
- Empty ya ambiguous case mein kya hota hai? "No new items" ek valid result honi chahiye, kaam invent karne ki wajah nahi
Ran Hona, Worked Hone Jaisa Nahi Hai
Beginners ke liye safest scheduled agent wo hai jo read, analyse, aur report karta hai. Workflow ko kam se kam do baar haath se chalao, sources, plan, permissions, output, empty case, aur tier-3 destination inspect karo, tab jaake schedule attach karo. Scheduling ek workflow ko future mein photocopy karne jaisa hai, agar galti hai to schedule usay dilute nahi karti, reproduce karti hai.
Part 4 · Choosing, Aur Open Path
10. Web, Desktop, Ya Terminal: Kaam Jo Touch Kare Us Se Choose Karo
Asal deciding sawal wahi hai: kaam kya touch karta hai? Do aur sawal add karo:
- Kya ye mera device band hone par bhi chalna chahiye?
- Data kaun hold/process kar sakta hai?
| Work Pattern | Best Starting Surface |
|---|---|
| One-off thinking, drafting | Chat |
| Cloud files + connectors, device off rehna zaroori | Cloud-only Cowork / Work |
| Cloud session ko ek approved local folder ya browser chahiye | Cloud + Desktop Bridge |
| Kaam fundamentally local files/apps hai | Local Desktop Agent |
| Repository, terminal, tests, CI | Coding Agent / Terminal |
| Website jiska koi connector nahi | Browser Path |
| Regulated ya contractually restricted data | Stop Aur Verify |
Regulated Data
Ek bridge convenience hai, custody loophole nahi. Agar cloud session Desktop ke through local file parhta hai, file aapki machine se aayi, lekin uska content cloud mein process hota hai. Pehla routing sawal ye hai ke agent loop aur processing kahan ho rahe hain, na ke source file 5 second pehle kahan baithi thi.
11. Open Path: Bina Vendor Cloud Ke
Is book ke har general-agents course mein ek vendor tool aur ek open-source twin pair hota hai. Ye course closed hai (Cowork aur ChatGPT Work), kyunke do rivals ne days ke andar same shape ship ki, jo is book ki thesis ka proof hai. Lekin open path exist karta hai:
- OpenWork: open-source desktop co-worker jo remote ya shared cloud workers se connect ho sakta hai, aap ya aapki organisation infrastructure control karte hain
- OpenCode + apna scheduler: repo-attached kaam ke liye, apna cron ya scheduled GitHub Actions job, koi vendor cloud, koi plan tier nahi
“Companies aapko ek spine bechti hain. Open path aapko wo khud banwati hai.”
Managed surface pe sab handed to you hai, working, day one se, lekin unki custody mein, unke format mein, unke price aur rules ke under. Open path mein har cheez aap set up, chalate, aur fix karte ho, badle mein custody aur choice milti hai. Regulated data ke liye custody jeet jati hai, ek solo consultant jo Friday tak brief ship karna chahta hai ke liye working spine jeet jati hai.
12. Ye Surface Kya Nahi Kar Sakta
- Web surface weak work ko good nahi banata, memory ek galat assumption preserve kar sakti hai, browser ek galat plan tez execute kar sakta hai, scheduling ek galti har Monday repeat kar sakti hai
- Vendor abhi bhi harness ke important hisse own karta hai, aap runtime, sandbox, model routing, ya enforcement machinery poori tarah control nahi karte
- Cloud-to-desktop bridge local runtime jaisa nahi hai, ye selected access lend karta hai jab desktop side available ho
- Browser agents ki ek security ceiling hai, arbitrary pages authenticated hokar parhna prompt-injection path banata hai, safety screening risk kam karti hai, khatam nahi karti
- Persistent context leverage aur lock-in dono banati hai, critical instructions aur finished work portable rakho takay vendor chhodna inconvenient ho, catastrophic nahi
“Chat wahan hai jahan aap design karte ho. Agent surface wahan hai jahan delegated work chalta hai. Agent loop aur uske tools alag jagah reh sakte hain. Discipline yehi hai: shape, boundary, aur custody har step pe jaanna.”
Aage Kya
Poora Course, Compressed
- Chat box har turn wait karti hai, Agent surface aap ke tab band karne ke baad bhi kaam karta rehta hai, "agar main typing rok doon, kya kaam ruk jayega" yehi test hai
- Do sawal poocho: agent loop kahan chal raha hai (cloud/local), aur tool kahan execute hota hai, ye dono alag ho sakte hain (desktop bridge)
- Har serious agent product ko 6 hisso se padho: Heartbeat, Reach, Run-until-done Loop, State Spine, Human Gate, Body, same shape, different implementation
- Persistent context ek stack hai: session history, Project, semantic memory, standing instructions, aapki apni context file, sabko "memory" mat samjho
- 3 file tiers yaad rakho: Tier 1 scratch (wipe ho jati hai), Tier 2 platform storage (vendor ki custody), Tier 3 exit (aapki custody), finished work hamesha exit karti hai
- Reach ladder: Connector pehle, phir browser, phir full computer use, jitna narrow tool utna behtar
- 3 gate modes: Manual (rukta hai), Auto (safety-screened chalta hai), Skip (approvals ke bina), gate ko blast radius se match karo
- Delegation loop: Brief → Plan → Approve/redirect → Review, plan review karte waqt scope, order, reach, aur assumptions check karo
- Schedule sirf tab device-independent hai jab har required tool bhi device-independent ho, "ran" hona "worked" hone jaisa nahi hai
- Kaam route karo us se jo wo actually touch karta hai, regulated data ke liye product availability permission nahi hai
“Chat wahan hai jahan aap sochte ho. Agent surface wahan hai jahan delegated kaam chalta hai. Discipline ek hi rehti hai: clear brief, explicit boundaries, checks, aur apna system of record.”
Ab Khud Try Karo: 6 Drills
Har ek 20-45 minutes leta hai, real lekin low-stakes kaam use karo.
- 1
1. Worker/Tool-Location Test
Ek cloud task shuru karo sirf cloud-reachable source se, tab band karo, doosri surface se wapis kholo. Agar Claude Desktop hai, ek harmless task try karo jo connected local folder use kare, dekho desktop offline hone par kya change hota hai.
- 2
2. Three-Tier Audit
Ek real deliverable produce karo, batao kaunsi state layer kaam hold kar rahi hai, aur har output ki file tier kya hai. Confirm karo final deliverable Tier 3 mein hai.
- 3
3. Gate Lab
Ek harmless test folder use kar ke pehle Manual mode mein workflow chalao, har interruption note karo, phir agar mumkin ho Auto mode mein rerun karo. Purchases, sending, deletion ke liye Skip use mat karo.
- 4
4. Pehla Cloud Schedule
Sirf cloud-reachable sources se ek Monday brief banao, trigger, touch, device independence, success signal, autonomy, empty case likho, do baar haath se chalao, phir schedule karo.
- 5
5. Ek Task, Do Harnesses
Agar dono products access hain, same low-stakes assignment Cowork aur ChatGPT Work dono ko do, jo dekho usay heartbeat, reach, loop, spine, gate, body pe map karo.
- 6
6. Portability Drill
Socho aapka vendor kal gayab ho jaye. Sirf Tier 3 files aur user-owned context se ek working workflow reconstruct karo, jo reconstruct nahi ho saka wo likh lo.
6 Hands-On Projects (Book Ke Original)
| Project | Waqt | Kya Banega |
|---|---|---|
| 1. Worker/Tool-Location Test | 20 min | Agent-loop location aur tool-execution location ka farq bina product names use kiye explain kar sako |
| 2. Three-Tier Audit | 30 min | Final deliverable Tier 3 mein exist kare, aur pata ho vendor account gayab hone par kya lost hota |
| 3. Gate Lab | 30-45 min | Pata ho kya automatically allowed hua, kya escalate hua, real workflow ke liye kaunsa mode chunoge |
| 4. Pehla Cloud Schedule | 30 min + 1 hafta | Kam se kam 2 baar laptop band hone par fire ho, har run Tier 3 mein verifiable success signal chhode |
| 5. Ek Task, Do Harnesses | 45 min | Ek page comparison jo teen parts mein kam se kam ek implementation difference name kare |
| 6. Portability Drill | 60 min | Ek written list jo aapka lock-in exposure aur agla portability backlog batati ho |
Ehtiyat
Is Chapter Ke Naye Terms
Exam ke liye ye poori glossary yaad rakho, koi bhi term skip mat karo:
| Term | Matlab |
|---|---|
| Chat box | Conversation jo har turn ka wait karti hai, band karne par ruk jati hai |
| Agent surface | Jagah jahan outcome assign hota hai aur system khud steps complete karta hai |
| Agent loop | Agla kadam decide karne wala hissa, jab tak finish, block, ya stop na ho |
| Cloud session | Agent loop vendor ke servers pe chalta hai |
| Local session | Agent loop aapki apni machine pe chalta hai |
| Desktop bridge | Controlled path jo cloud session ko selected local tools tak pahunchati hai |
| Tool execution location | Wo jagah jahan ek particular action actually hoti hai |
| Connector | Permission-scoped, structured access ek service tak |
| Browser agent | Agent jo browser se pages parhta aur (jahan allowed) click/type/navigate karta hai |
| Task filesystem (Tier 1) | Temporary scratch space, task khatam hote hi wipe |
| Platform storage (Tier 2) | Vendor account mein saved files, vendor ki custody mein |
| The exit (Tier 3) | Deliverable ek system mein jaati hai jo aap control karte ho |
| State spine | Poori persistence stack: sessions, Projects, memory, instructions, files |
| Semantic memory | Facts/preferences jo assistant cloud sessions ke across carry karta hai |
| Standing instructions | Rules jo repeatedly apply hoti hain |
| Human gate | Control jo sahi risk boundary pe insaan ko loop mein rakhta hai |
| Approval mode | Agent kitni baar permission ke liye rukta hai (Manual/Auto/Skip) |
| Scheduled task | Clock ya doosre trigger pe shuru hone wala kaam |
| Custody | Aapka data kiske paas hai, kis machine pe, kis rule ke under |
| Delegation loop | Brief → Plan → Approve/redirect → Review ka 4-step cycle |
Source Note
Self-Test
Khud Se Poocho
Pehle khud answer do, phir sawal pe click kar ke answer check karo.

