How Drover fits around your agents.

Product guide

Drover is a native iPhone surface for work that remains inside official Herdr on your own machine. The public beta is still in development; this guide describes the intended boundaries.

The system model

Drover for iPhone
The native iOS 18+ interface for viewing state and sending supported input. Desk and iPad clients are deferred.
Drover Host
droverd, the small companion daemon beside Herdr on macOS or Linux. Desk and iPad clients are deferred.
Herdr
User-installed official Herdr, compatible with Drover’s capability floor. Drover does not bundle Herdr, create a direct PTY, or provide another runtime fallback.
Cloud control plane
Minimal signaling, short-lived relay credentials, generic push hints, and entitlement checks. Terminal payloads remain end-to-end encrypted.

Objects you navigate

Herdr owns the runtime hierarchy; Drover presents the same objects through a paired, authenticated surface:

HostSessionWorkspace → Tab → Pane

A pane opens only with a current exact live route. Unavailable, ended, and stale panes remain visible and read-only with an explanation. The verified hostname is always visible where host identity matters; a nickname never replaces it.

Terminal rendering

Herdr remains authoritative for the PTY, process, terminal history, and controller. The iPhone uses the native Ghostty Surface for VT state, input encoding, selection, accessibility, and rendering; Drover does not interpret terminal text.

Connection order

  1. LAN direct: local discovery and an encrypted direct session.
  2. WAN direct: peer-to-peer WebRTC when the network permits it.
  3. Managed TURN fallback: an encrypted blind relay when a direct path cannot be established.

Capability status

Drover beta capability status
CapabilityStatusBoundary
Herdr topologyIn progressHost → Session → Workspace → Tab → Pane.
Prompt / terminal inputIn progressExact pane route and current capability only.
Off-network + pushAvailable after gates passPro entitlement at launch.
Native approve / deny cardsOutside launch scopePermissions stay in the authoritative TUI.
Interrupt / stop / manage agentAvailable after gates passNot represented as available until end-to-end verified.

Where to go next

Keep your agents within reach.

Join beta updates for installation access and product progress.

Join beta updates