-
-
Secure BYOK model setup with separate primary and secondary roles, native credential protection, and visible connection-test results.
-
Persistent product-knowledge imports with traceable processing state, unresolved facts, and restart-safe job recovery.
-
A guided account connection workflow with visible login state and controlled browser-based execution boundaries.
-
A query-backed campaign overview showing campaign state, automation level, filtering, and authoritative refresh.
-
Controlled campaign configuration with goals, assisted automation, budget limits, stop conditions, and Human Acceptance safeguards.
-
A redacted audit timeline showing successful workspace, account, and campaign operations without exposing sensitive data.
-
The Today dashboard summarizes campaigns, pending tasks, approvals, runtime health, and restart-reconstructed activity.
-
A persistent Emergency Stop state that blocks new write operations and requires an explicit user-controlled recovery.
Inspiration
Small AI, SaaS, developer-tool, and productivity teams often understand their products deeply but do not have a dedicated growth operations team. Their workflow is fragmented across documents, AI chats, content tools, spreadsheets, approval messages, and social platforms.
Most AI tools stop at generating suggestions, while fully autonomous tools can hide important decisions and create unacceptable account, privacy, and brand risks. We built Helmquill to explore a better model: useful automation with explicit authority, human approval, safe recovery, and a complete audit trail.
What it does
Helmquill is a local-first desktop workspace for planning and operating product growth workflows.
It helps teams:
- Import product material and turn it into traceable product facts.
- Create, validate, and manage multi-platform campaigns.
- Generate and review content and short-form media.
- Connect model providers through a secure BYOK workflow.
- Review permission, risk, capability, account, and content-version details before an action.
- Coordinate controlled browser-based workflows with human takeover.
- Pause, resume, or emergency-stop operations from the application.
- Detect uncertain remote outcomes and require verification instead of performing an unsafe retry.
- Review redacted activity and audit history.
- Use the interface in English or Simplified Chinese without changing business payloads or generated content.
Helmquill is designed around X, Reddit, Instagram, TikTok, and YouTube, while treating every platform capability independently.
The current build has completed Engineering Verification. Real-account canaries and advanced automated public interactions remain intentionally gated until Human Acceptance is completed.
How we built it
The desktop application uses Electron, React, TypeScript, and Vite. A typed IPC boundary separates the Renderer from trusted application processes, so the UI never directly accesses credentials, the database, browser automation, or media workers.
The core domain and policy modules run locally, with SQLite providing durable state, restart recovery, request outcomes, audit history, and version-bound mutations.
Browser workflows are isolated behind a Playwright-based Browser Broker. Model credentials are entered through a native .NET credential window and stored in Windows Credential Manager; the Electron Renderer receives only opaque handles and never sees the secret.
Media processing uses isolated workers with FFmpeg, FFprobe, Tesseract.js, and programmatic HTML/CSS rendering. The project is tested with Vitest, Playwright, Testing Library, and axe-core.
Challenges we ran into
The hardest challenge was not generating content—it was defining exactly when automation is allowed to act.
We had to handle stale approvals, changing account capabilities, duplicate requests, application restarts, browser-page changes, user takeover, credential isolation, and remote actions whose final outcome cannot be confirmed.
We solved these problems with narrow typed interfaces, version-bound approvals, persistent request outcomes, fail-closed capability checks, explicit OUTCOME_UNKNOWN handling, and an emergency-stop state that survives restarts.
Another challenge was making the interface bilingual while ensuring that switching the display language never changes prompts, provider requests, protocol values, persisted domain data, or generated business content.
Accomplishments that we are proud of
- A complete local-first desktop workflow covering knowledge, campaigns, content, media, approvals, accounts, and activity.
- A native credential boundary that keeps API keys out of the web-based Renderer.
- Explicit human takeover, emergency stop, and no-unsafe-retry behavior.
- English and Simplified Chinese presentation without altering operational payloads.
- An engineering baseline verified by 1,062 automated tests across unit, integration, security, accessibility, governance, and production Renderer flows.
- An MIT-licensed, source-only release model with deterministic build and provenance controls.
What we learned
Useful AI autonomy depends as much on authority, recovery, and observability as it does on model quality. A safe system must make uncertainty visible, preserve user control, and treat every external action as a governed operation rather than a simple button click.
We also learned that local-first architecture can provide strong privacy without sacrificing a rich product workflow.
What's next for Helmquill
The next step is a structured 7–14 day product pilot with 3–5 real users from the target audience. We will evaluate time saved, campaign usefulness, revision effort, trust, safety incidents, and opportunity quality.
Human Acceptance will remain separate from automated evaluation. Only after the pilot and human review pass will we consider narrowly scoped real-account canaries and advanced public-interaction capabilities.
We also plan to add a separately governed real-time event publishing layer while preserving the existing security and authority boundaries.
Log in or sign up for Devpost to join the conversation.