Learn · Articles

AI Stack S4 (layer 4, agent software + connectors)

Layer 4 of the AI stack is the one everyone asks about first — and it's the one that matters least.

01 · The stack

Where layer 4 sits

(Quick recap of the stack I drew a few weeks back: 1 — files and folders in plain markdown, 2 — written process guides and logs, 3 — scripts and command-line tools, 4 — the AI agents themselves, 5 — email as the front door. Git underneath all of it.)

Layer 4 is where the agents actually live: the software you run them in, plus the connectors that let them reach your email, browser and calendar.

02 · Side by side

A few agents, one company

We run a few side by side. Claude Code in the terminal for heavier work. Cowork on the desktop for people who never open a terminal. Codex when it fits. Different windows into the same company — same files, same guides, same tools underneath.

03 · No lock-in

The part people miss

Here is the part people miss: because layers 1 to 3 are just files, written guides and plain command-line tools, none of them care which agent is running. Swap one agent app for another tomorrow and the company doesn't change — the documentation and the tools stay exactly where they were. That's the opposite of lock-in. The value sits in layers 1 to 3, which you own outright, not in the vendor at layer 4.

04 · Safe access

Why broad access is safe

It's also why I don't lose sleep over giving agents broad access. Two things make that safe, and neither of them is the agent software:

Permissions — what an agent may do on its own, and what has to wait for a human to approve. That lives in the guides at layer 2, not in the tool.

The git foundation under everything — nothing can be permanently deleted, and a human reviews and commits the changes every day. A wrong move is one revert away.

05 · The honest version

The most replaceable layer

So the honest version: your automation level is set by your documentation and your tools, not by which agent app you happen to buy. Layer 4 is the most replaceable layer in the whole stack. We run all of this every day for a real business — biowaste recycling with insects — and the agent we use is the part I think about least.

06 · Start here

Start at layer 1

If you are setting this up: don't start by picking the tool. Start at layer 1 and make layer 4 the last, easiest choice.

07 · Over to you

Which agent are you running?

Which agent software are you running — and would you feel safe handing it broad access to your files today?

Keep exploring

Related topics and pages

Read next

Next step

Keep layer 4 replaceable

Manna can help document the files, guides and tools under a BSF case so the agent software on top stays an easy, replaceable choice.