One TUI tracks agents across many repositories
Agent Deck wraps tmux sessions in an agent-aware terminal interface. It shows whether each session is running, waiting, idle, or in error, and lets an operator search, rename, restart, archive, or jump between them. Claude Code, Gemini CLI, OpenCode, and Codex receive different levels of integration. Claude has status, MCP, fork, and resume support; Codex has status, MCP, organization, conductor, and fork support. Custom commands can also run as managed sessions.
The useful distinction from plain tmux is stored agent state. Groups can set concurrency limits, default paths, and Claude account configuration. Forking can carry conversation context through the underlying tool, create a Git worktree and branch, copy uncommitted state, and match Docker isolation. Cost tracking reads transcripts or command output, while global search spans recorded Claude conversations. Those conveniences become worthwhile when session count, projects, and agent tools have outgrown a handwritten tmux layout.
Worktrees isolate branches while secrets may be copied
A new session can start in a sibling or nested Git worktree, and large repositories can inherit sparse-checkout rules. A .worktreeinclude file copies selected ignored files such as .env or .mcp.json into the new tree, but only when Git already marks them ignored. That is practical for runnable branches. It also means teams should review those patterns like deployment code because one broad entry can duplicate credentials into every agent workspace.
Docker sandboxing protects the rest of the host while bind-mounting the project directory read-write. Host authentication for Claude, Gemini, Codex, and other tools is shared into the container so agents do not need a second login. This boundary reduces host exposure, but it does not protect repository files from the agent. The auto_cleanup option removes containers after sessions end by default; keeping them for debugging leaves more state to inventory and delete later.
What happened when we ran it
Our sandbox installed 269 Go packages in 46 seconds and built commit 47bb210 successfully in 64 seconds. The checkout contained 2,131 files, about 483,480 source lines, and used 166.2 MB before installation. It had 20 CI workflow files, no Dockerfile, and a tests directory. The environment was an unprivileged Debian container with 3 CPUs, 8 GB of memory, no secrets, and the Go 1.24 image.
The test command failed after 568 seconds. Go reported 21 passed and 5 failed out of 26 packages. In the log tail, TestTriageLoop_RateLimitSixthQueued expected one item in triageQueue but got zero, then timed out waiting for a sixth spawn after the queue drained and observed five. The same tail included an intentionally fake Gmail renewal error. It does not establish the cause of the queue mismatch.
Several packages in the tail still passed, including the web package, scripts, an evaluation harness, and a capability-report tool. That partial success should not be read as a clean baseline. Watchers and triage are part of the product's unattended orchestration path, so a failing queue test matters more to a conductor deployment than to someone who only uses the local TUI to switch between sessions.
Conductors move session decisions onto a phone
A conductor is a persistent agent session that monitors other sessions, answers routine prompts, and escalates uncertain cases. The setup wizard can connect Telegram or Slack, and a heartbeat checks fleet state every 15 minutes by default. Watchers can wake a conductor from GitHub events, Gmail messages, ntfy notifications, calendar events, or Slack. This turns Agent Deck from a session browser into an automation service with external inputs.
That service needs explicit credential and channel design. The README requires one Telegram bot per conductor because two long-poll consumers on one token conflict. Bot tokens live in a per-conductor state directory with mode 600. A plugin should be activated only on its owning conductor session, since enabling it across a Claude profile creates competing pollers. These warnings are unusually specific and should be copied into an operations checklist rather than left for the person who first runs the wizard.
Open defects affect accounts, alerts, and tmux state
Open issue 2060 describes a serious Codex account bug. A named account was resolved and stored, but CODEX_HOME did not reach the launched child, so workers used the default account instead. The report says this appeared as idle or stalled work when that default was usage-limited. Anyone separating personal, team, or quota pools should verify the child environment on initial start and resume, not trust the selected label in Agent Deck.
Issue 2061 reports that Agent Deck repeatedly appended the same tmux terminal-features value. One long-lived server reached 5,018 entries, with display corruption reported after weeks of use. The issue provides a configuration workaround that prevents more appends, but says shrinking an existing value needs a manual reset or server restart. Issue 2062 adds a smaller operational gap: dead-letter warnings exist, yet the CLI and TUI cannot inspect, retry, or clear those records.
v1.15.0 is active but operationally busy
GitHub showed 793 stars, 38 combined open issues and pull requests, and a last push on August 24, 2026. Release v1.15.0 was published one day earlier. Issue and pull request updates continued on August 25, including a fast closure for a false report that a delivered multiline message had been dropped. The queue is active, though many current entries touch session delivery, tmux state, conductors, or agent identity rather than minor presentation work.
Agent Deck makes sense when an operator can name the pain it removes: too many sessions to watch, repeated worktree setup, scattered MCP configs, or agents that wait unnoticed. Our failed 568-second suite argues for a staged rollout. Start with local session organization, isolate its tmux socket, test one supported agent and account path, then add remote conductors only after watcher and delivery behavior passes on the machine that will run them.

