Türkçe Open the panel

Agents write,
you approve.

Pendra is a pipeline that produces social media content on your behalf: LinkedIn, Bluesky, Mastodon, Threads, Telegram, Discord. But nothing goes out before you have seen it — there is a wall in the middle, and you hold the key.

The journey of a post

Who does each step matters: some are agents, some are plain code, one is you.

  1. 1 Scout · agent

    Reads the web, gathers material

    It reads the sources you follow and saves what looks worth writing about. Scout has no access to your accounts or to publishing at all — the agent that reads outside content cannot touch the system's ability to write.

  2. 2 Curator · agent

    Filters and scores

    Not everything gathered deserves a post. Curator gives each finding a score from 0 to 100 with a reason; anything below the threshold is never written. "Nothing worth saying this week" is a valid answer. It also looks at what you rejected before.

  3. 3 Writer · agent

    Writes in your voice

    It reads your character file and your format profile and turns the chosen finding into a post. The draft lands in the queue as a suggestion. It cannot publish — there is no such tool in its hands.

  4. 4 You · human

    Approve, edit or reject

    The draft is shown the way it will look on LinkedIn: line breaks, where the feed will cut it, images. If you change the text, your version is what goes out. If you reject it, you are asked why.

  5. 5 Publisher · code

    Publishes at the time you picked

    An approved post joins a queue and goes to the account's platform when its time comes. No agent here: publishing needs no judgement, it is deterministic work. Every job carries an identity, so the same post never goes out twice.

  6. 6 Responder & Analyst · agent

    Drafts replies, learns from results

    Responder reads the LinkedIn notifications in your mailbox and drafts replies to comments — they go through the same approval queue. Analyst looks at the metrics of published posts and updates your format profile.

  7. 7 Writer · agent · on request

    Writes long articles too, if you have your own site

    Connect your site to Pendra and AI-written long articles go through the same approval queue: once you approve, the article is published on your site, and then short versions of it go out to social media carrying the article's address — and those posts have to wait until the article is actually live.

    Your site states the rules: which languages, which content types, what length. Pendra does not know them, it asks — and it has your site validate every article before anything enters the queue, so a broken article never opens a proposal. After publishing it also checks that the page really opened; if it did not, the job is not treated as done.

    Corrections and retractions are proposals too: the agent proposes to correct or remove an article, the decision is yours. When you retract one, the panel counts the published posts that carry its link — those are left alone, because Pendra cannot delete posts on those platforms and a path that claims to delete without deleting was not written.

    If you have no site, nothing changes: this step only exists on an account with a site connected, and the automatic run never triggers it.

No agent can write to any platform.

This is not a setting, it is the architecture. Agents hold only "suggest" tools; the authority to publish lives somewhere else entirely, and only your approval reaches it.

  • Approval always rests on a human action — the panel, Telegram, or the link in a notification. Where it came from is recorded.
  • A post you write yourself joins the queue too. There is no path that goes straight out.
  • No browser automation, no scraping, no detection evasion. Only the official platform APIs.
  • Your platform access tokens and mailbox password are stored encrypted; nothing sits anywhere in plain text.

The agents and what they may do

Each agent holds only the tools its job needs. A call to a tool outside that list is refused and recorded.

AgentIts jobWhat it cannot do
ScoutReads sources, saves findingsCannot touch accounts or publishing at all
CuratorFilters, scores, reads rejectionsCannot write drafts
WriterWrites drafts into the queueCannot publish
ResponderSuggests replies to commentsCannot send them itself
AnalystReads metrics, updates the format profile, proposes interests and sourcesCannot produce content or read the web
OperatorReviews studio runs and providers, sends studio drafts to the queueCannot publish or read the web

What's in the panel

Each section answers one question.

Waiting for approval

Drafts the agents produced. Approve, edit or reject them next to a LinkedIn preview.

Write your own

A post you write yourself. It joins the queue too and goes out once you approve it. You can pick the time.

Rejected

What you turned down and why. Agents read this so the same suggestion doesn't come back.

Outbox

Approved but not yet published work. If something failed, the reason is here.

Mailbox

Where LinkedIn comment notifications are read. The mailbox opens read-only: nothing is moved, deleted or marked as read.

Notifications

Connect Telegram and you can approve from your phone; the post looks there the way it will look on LinkedIn.

Quota

What the agents spent this month and how close you are to LinkedIn's daily ceilings.

The generation provider

The model that writes the drafts runs on your own key. The key is entered once and never read back: not in the panel, not in a response, not in a log. You recognise the stored one by its last four characters. You can also add a model the list does not show by hand; that row carries a "by hand" badge, because its name was not verified.

Which stage, which model

You can assign any of your connected providers to a stage, and a different one per platform if you want: LinkedIn takes three thousand characters, Bluesky three hundred. The order is platform-specific assignment, then the stage's general one, then your try order. When it is not known which account the draft is for, the first step is skipped.

Run history

Every step of a generation run in one place: which stage, with which model, from which setting, how many tokens, how long, and why it failed if it did. A step that did not run shows up too — with its reason. The full input and output are kept for thirty days and then deleted; the row itself stays.

Format profile

Format preferences learned from metrics: which length, which time, which opening works. Analyst updates it over time. Your tone is not here; it lives in the character file in your workspace.

It connects to Claude

You can run Pendra on your own AI subscription; a separate API bill is not required.

Pendra exposes its tools over MCP. You define one connection per agent in Claude, and then you just talk to Claude:

What happened in .NET this week? Draft something.

Claude reads the sources, looks at your character file, your format profile and at what you rejected before, writes the draft and puts it in the approval queue. It does not publish — it cannot. No such tool exists in its hands.

You do not have to name the agent. Claude picks tools by their descriptions: ask it to scan your inbox and it reaches for Responder's tools; ask about metrics and it reaches for Analyst's.

The connection boundary is a security boundary, but at the connection level. No connection has a publishing tool; the connection of Scout, the agent that reads the open web, has no proposal tool either. If the connections run in separate sessions, what Scout reads cannot reach the writing tools. If you add them all to the same session — the convenience described above — the page that was read and Writer's proposal tool sit in the same model context, and an instruction on the page can get a draft opened. The last defence is then the approval queue: the worst outcome is a poisoned draft, not a post. Claude's own web tools are in every session too; a separate session only separates Pendra's tools.

What is next

These are not done yet. This is a to-do list, not a feature list.

Platforms today

What Pendra can do on each platform. The table is generated from the platform catalog in the code; it is not written by hand. On LinkedIn, comments are read from e-mail notifications, and metrics are collected only when the analytics app (CMA) is connected.

PlatformPostReplyRead commentsMetricsTested with a real account
LinkedIn✓✓✓✓no
Bluesky✓✓——no
Telegram✓———no
Mastodon✓✓——no
Threads✓———no
Discord✓———no
Website————no

Trying it with real accounts

Six platforms and several accounts per platform are written; each platform has its own length and conventions, and the agent writes knowing them. None has been tried with a real account yet — and code that looks right is not the same as code that works.

Generated images

Platforms like Instagram do not accept text-only posts. That needs a generator that turns text into a card, and the image goes to approval with the text.

Frequently asked

Can something be published by accident?

Not without your approval. The only path to publication is the approval queue, and that queue moves only on a human action. Even a post you wrote yourself goes through the same door.

What happens if I don't like a draft?

You pick a reason when rejecting: off topic, wrong tone, repetitive, bad timing, inaccurate, too promotional. Agents read those reasons, and a topic you rejected is not suggested again.

Can I change the text?

Yes. You can edit it on the approval screen; your text is what gets published, and the record says "approved with your edit".

Can I approve from my phone?

Yes, once you connect Telegram. The notification shows how the post will look on LinkedIn — with the image, if there is one — and carries the approval buttons underneath.

What happens to my mail?

The mailbox is opened read-only and only LinkedIn notifications are looked at. No mail is moved, deleted or marked as read. You can remove the connection whenever you like.

Why can't I sign in right away?

Signing up does not grant access; an administrator approves your account. A door that opens by itself is not a door on a public address.