Learn · Articles
AI Stack S4 (layer 4, agent software + connectors)
Layer 4 of the AI stack is the one everyone asks about first — and it's the one that matters least.
01 · The stack
Where layer 4 sits
(Quick recap of the stack I drew a few weeks back: 1 — files and folders in plain markdown, 2 — written process guides and logs, 3 — scripts and command-line tools, 4 — the AI agents themselves, 5 — email as the front door. Git underneath all of it.)
Layer 4 is where the agents actually live: the software you run them in, plus the connectors that let them reach your email, browser and calendar.
02 · Side by side
A few agents, one company
We run a few side by side. Claude Code in the terminal for heavier work. Cowork on the desktop for people who never open a terminal. Codex when it fits. Different windows into the same company — same files, same guides, same tools underneath.
03 · No lock-in
The part people miss
Here is the part people miss: because layers 1 to 3 are just files, written guides and plain command-line tools, none of them care which agent is running. Swap one agent app for another tomorrow and the company doesn't change — the documentation and the tools stay exactly where they were. That's the opposite of lock-in. The value sits in layers 1 to 3, which you own outright, not in the vendor at layer 4.
04 · Safe access
Why broad access is safe
It's also why I don't lose sleep over giving agents broad access. Two things make that safe, and neither of them is the agent software:
Permissions — what an agent may do on its own, and what has to wait for a human to approve. That lives in the guides at layer 2, not in the tool.
The git foundation under everything — nothing can be permanently deleted, and a human reviews and commits the changes every day. A wrong move is one revert away.
05 · The honest version
The most replaceable layer
So the honest version: your automation level is set by your documentation and your tools, not by which agent app you happen to buy. Layer 4 is the most replaceable layer in the whole stack. We run all of this every day for a real business — biowaste recycling with insects — and the agent we use is the part I think about least.
06 · Start here
Start at layer 1
If you are setting this up: don't start by picking the tool. Start at layer 1 and make layer 4 the last, easiest choice.
07 · Over to you
Which agent are you running?
Which agent software are you running — and would you feel safe handing it broad access to your files today?
Keep exploring
Related topics and pages
- Articles library — the written guides this post joins
- BSF business course — where documented assumptions shape a case
- BSF start-up course — the validation steps a small team can run with shared records
Read next
- AI Stack S5: Email as the front door — the layer above this one, on email as the front door
- AI Stack S3: Scripts and command-line tools — the layer below this one, on scripts and command-line tools
- AI Stack S2: Document your processes like you onboard a new hire — the layer below that, on written process guides and logs
- Our AI stack, demystified — the layered overview this series extends
Next step
Keep layer 4 replaceable
Manna can help document the files, guides and tools under a BSF case so the agent software on top stays an easy, replaceable choice.