Sonder

System.

How Sonder fits together · live counts

№ 01

Architecture today

9,071 entries · 158 versions · 13 MCP tools
WHO CALLSFRONT DOORS SONDER APP · VERCELNEON POSTGRES OUTSIDE SERVICES Claude DesktopClaude CodeClaude mobileclaude.ai webCoworkGemini MCP over HTTPS · OAuth bearer token Browser sonder.diythe one home · MCP at /mcp fb.ltd/sonderlegacy · redirects to sonder.diy ericshamlin.com/sonderlegacy · redirects to sonder.diy serves 301 301 Next.js · sonder.diy proxy.jsClerk on /mcp, /connect, /settings /mcpMCP server · 13 tools · owner-only / dashboardpublic · sensitive text redacted /api/vieweye toggle · 3-digit PIN /settingsconnect your own MCP servers /connect/granolaone-time OAuth hookup Postgres · 1 workspace memories9,071 rows · every entry memory_versions · 158 app_state · 1 connections · 0 integrations · 1 tenants · 1 read · write · search counts · classify wrong-PIN count sealed tokens OAuth tokens verify token gemini_call granola_* connection_call ClerkOAuth · accounts.sonder.diy Gemini APIsecond opinion Granola MCPnot connected yet Your MCP serversadded in Settings
Everything lands in one table. Every Claude surface talks to the same /mcp endpoint, so a note written from your phone is readable from Code a second later. The three web addresses are doors into one Vercel app. Clerk guards the MCP endpoint, the Granola hookup and Settings; the dashboard is public with sensitive text removed on the server.
№ 02

The full picture

What flows in, what flows out
INTHE STOREOUT Claude surfacesdesktop · code · mobile · web · coworkliveGemini bridgegemini_callliveYour MCP serversSettings → connection_callliveGranolameetings + transcriptsbuiltiMessage · SMS · WhatsApptext Sonder anywherebuiltChatGPT + Claude bridgeshared threadsbuiltGmail · 5 accountsPersonal, FireBringer, Tiresias, Argo, CalderaplannedGoogle CalendarschedulesplannedSlack · Teamschannels, chatsplannedZoomtranscriptsplannedFigma · Google Drivefiles as contextplanned Every Claude surfacereads via MCPliveDashboardsonder.diyliveGoogle TasksFireBringer to-dosplannedCalendar holdsFireBringer calendarplannedCall Sondervoice agentplannedDaily briefingsscheduled digestsplannedPush notificationsnudges, deadlinesplannedsonder@fb.ltdemail in and outplanned SONDER one Postgres store per-workspace · versioned privacy-flagged
Three inputs and two outputs are live. Messaging, Granola and the ChatGPT bridge are built and waiting to merge or connect. Mail, calendars, chat and the outbound side (tasks, holds, the voice agent, briefings) are the roadmap.
№ 03

One Sonder, many minds

1 workspace today · built for more

Sonder is named for the realization that every passerby lives a life as vivid and complex as your own. The multi-tenant version gives each of those lives its own workspace on the same engine: same tools, same entry structure, nothing shared between them unless the owner publishes it.

Tier 1 · Public

Logged out

What Sonder is, why it's called that, and a waitlist. No one's data, ever.

Landing page next
Tier 2 · Guest

Invited workspace

An empty workspace of your own on the same MCP: connect your tools in Settings, write your own entries. The prototype product, and how peers learn the mechanism without seeing Eric's data.

Modeled · invite-only
Tier 3 · Owner

Eric's full instance

The complete working brain. Features are proven here first, then hardened and moved down into the guest tier.

Live
Collaborator slices

Scoped views of real data

Close collaborators get a narrow, published slice of Eric's workspace through their own Claude: a co-writer sees a project's creative entries, a producer its production entries, a marketing lead marketing and design. Slices are point-in-time releases, not Eric's live working copy. Collaborators can suggest writes that Eric merges. Financial entries never leave, whatever the role.

Data model
  • tenants one row per workspace · tier owner or guest
  • tenant_members which signed-in users belong to which workspace
  • connections each workspace's MCP servers, tokens sealed with AES-256-GCM
  • memories.tenant_id every entry belongs to exactly one workspace
  1. done

    Foundation

    Workspaces, members and per-workspace connections in the database. Every existing entry belongs to Eric's owner workspace.

  2. done

    Bring your own MCP

    Settings connects any HTTPS MCP server; tokens sealed at rest; every Claude surface can call it.

  3. next

    Workspace credentials

    Scoped service tokens per workspace, so peers, voice platforms and collaborators connect without signing in as Eric.

  4. next

    Isolation

    Entry paths unique per workspace; every read and write filtered by workspace at the query layer.

  5. later

    Guest invites

    Eric invites a peer; they get an empty workspace with the same tools. Proven features graduate down from the owner workspace.

  6. later

    Collaborator slices

    Published, point-in-time slices of Eric's data by project and facet, read plus suggested writes Eric merges. Financial facets never leave.

  7. later

    OAuth connections

    Connect services that need a browser sign-in (Gmail, Calendar, Slack) per workspace, like Granola today.