# Cursor can now reach the agent on your laptop. Your teammates still cannot

> Cursor's Remote Control reaches a local agent from your phone. What the agent writes is still on one machine that has to stay awake. Here is the other half.

Source: https://baalda.com/blog/remote-control-local-agent-notes
Site: Baalda, https://baalda.com
Published: 2026-10-08

**Short answer.** Reachability moved, durability did not. Cursor's Remote Control, shipped 6 October 2026, lets the iOS app message agents running on your own computer, which must stay awake. The written record of a run still lives on that one machine. Giving the agent a shared vault over MCP is what changes whose disk it lands on.

There are two different questions hiding inside "can I reach my agent from anywhere". One is whether you can talk to it. The other is whether anybody else can reach what it produced. Cursor just answered the first one cleanly, and in doing so it made the second one much easier to see.

## What did Cursor ship on 6 October 2026?

Cursor shipped [Remote control for local agents](https://cursor.com/changelog/remote-control-local-agents). Download the Cursor iOS app, sign in, and the computers on your account appear in it. Tap one, approve the pairing request in the Cursor desktop app, and you get a list of the agents running on that machine and a box to message them.

The design decision worth reading twice is the one Cursor states plainly: "Remote control doesn't move your agents anywhere. It keeps running on your computer, and the app connects to it." This is not a cloud agent. Nothing is lifted off the desk.

That has a consequence Cursor is equally straightforward about. The computer has to stay on and online, so the release adds a **Keep this computer awake** setting under Remote Control in the desktop settings, and the machine needs to be plugged in with the lid open for it to apply. Remote control is on by default for most accounts, except Enterprise organisations, whose admins turn it on under Org settings, then Security and identity, then Remote control.

As a feature this is good and the restraint is the best part of it. Keeping execution local keeps the agent's file access, credentials and sandbox exactly where you already reasoned about them. The question is what it implies about everything downstream.

## Why does a reachable agent still leave its work stranded?

Because reachability and durability are different properties, and only one of them moved.

Think about what a long agent run actually produces. There is the diff, which is the part everyone plans for: it goes into git, it gets reviewed, it survives. And then there is everything else. The approach the agent proposed and you rejected at 9pm from a train platform. The two libraries it tried before the third one worked. The reason the retry logic is where it is. The constraint you typed into a phone in one sentence because you were walking.

None of that is in the diff. It is in a session, on one laptop, under one person's account, and it is durable exactly as long as that machine stays awake. [Baalda](/blog/team-second-brain) exists for this half of the output: it is a team second brain, plain markdown files on your own disk, edited by several people at once in real time, with AI reading and writing those same files over the Model Context Protocol. The claim here is narrow and worth stating before the mechanism: git already solved the code half, and nothing in a coding agent's design solves the written half.

The stranding gets worse with exactly the behaviour this feature enables. The point of replying to an agent from your phone is that the run is long and you are not at the desk. A long unattended run is precisely the one that accumulates the most reasoning, and the one whose transcript you are least likely to read back at 11pm. For a team of five to fifty people, that is a steady leak of the only knowledge that was expensive to produce.

Note what is not the problem. This is not Cursor keeping your data; [Cursor's own context design](/blog/cursor-second-brain) has been moving towards files rather than hoarded memory for a while, and it removed its Memories feature in version 2.1. The problem is structural. A session is a place that ends, and a laptop is a place one person has.

## Where should an agent write so a laptop's power state stops mattering?

Into a vault reached over the network, not into a directory on the machine that happens to be running the agent.

Concretely: the agent calls `POST /api/mcp` with an `mcp_` bearer token minted per person from Vault settings, and writes with the same tools a human's edits go through. Creating the note takes a vault-relative path, and every folder in it has to exist already:

```json
{
  "name": "create_note",
  "arguments": {
    "vaultId": "vault_3b1",
    "relPath": "Decisions/retry-backoff.md",
    "content": "# Retry backoff\n\n## Rejected: fixed 5s\n..."
  }
}
```

Adding to it mid-run is `append_note`, which takes a key for the case this feature makes common, an agent that reconnects after the phone dropped off wifi:

```json
{
  "name": "append_note",
  "arguments": {
    "docId": "note_7f2a",
    "text": "\n## Ruled out: p-retry, pulls in 4 deps we already vendored\n",
    "idempotencyKey": "retry-backoff-2026-10-08-c"
  }
}
```

The `idempotencyKey` means a repeat with the same key returns the first result instead of appending again, so a retried call cannot leave the same paragraph in the note twice.

The part that actually answers the power-state problem is what happens on the server after that call. Baalda's write path has two branches. If someone has the note open, the write mutates the live document, which persists it, re-indexes it, and broadcasts it to every connected editor, the same path a human keystroke takes. If **nobody** is connected, the server hydrates a detached copy of the document from stored state, applies the change, and persists the single incremental update itself. The next client to open the note loads that state.

That second branch is the whole point. The write lands with zero editors online, zero desktop apps running, and the originating laptop closed. Postgres holds opaque binary sync updates, and each device re-derives its own `.md` files from them when it next connects. So a decision filed at 11pm by an agent on a machine that then went to sleep is a plain markdown file on a colleague's disk in the morning, at a path they can open, without anyone having stayed awake for it.

That is a different guarantee from the one remote control gives you. Remote control extends how far **you** can reach. This changes whose disk the record ends up on.

## Where does a shared vault not help here?

It is not a remote control, and it does not replace the thing Cursor shipped.

Baalda will not let you steer a running agent, will not show you its progress, and will not keep your Cursor session alive. If what you want is to reply to an agent from a train, that feature is the thing that does it and nothing here substitutes for it. There is also no Baalda mobile app to read the result on: it is a desktop app for macOS, Windows and Linux, with iOS planned. So the honest version of the pairing is that you steer from the phone with Cursor and the written record lands somewhere the team shares, and you read it on a laptop later.

It also does not belong anywhere near your repo. Code sync is git's job, it is good at it, and a CRDT vault is the wrong tool for a working tree. The vault is for the prose that git never sees.

And the oldest limit still applies: an agent given append access can append something confidently wrong, and a wrong decision note is read as obediently as a right one. What changes is that the wrong thing now has a path and a revision, so one person corrects it once. If that makes you nervous, keep the agent's writes to a folder with [its own permissions](/blog/shared-agent-memory-whose-disk) until the diffs stop surprising you.

## What is worth doing about this week?

If you have turned remote control on, assume your long unattended runs just got longer, because that is what the feature is for.

Then pick the smallest possible habit to go with it. One folder, say `Decisions/`, one instruction in your `AGENTS.md` telling the agent to file what it ruled out and why before it finishes, and write access scoped to that folder. The agent will not do it perfectly. It will do it more often than the transcript you were never going to reopen.

The agents are going to keep getting easier to reach. Cursor just made yours reachable from a pocket. What they leave behind is still landing wherever you pointed them, and by default that is still one laptop, and it is still asleep.

## FAQ

### What is Cursor's Remote Control for local agents?

A feature shipped on 6 October 2026 that lets the Cursor iOS app see and reply to agents already running on your own computer. You sign in, the computers on your account appear, you tap one and approve a pairing request in the Cursor desktop app. Cursor states that "remote control doesn't move your agents anywhere. It keeps running on your computer, and the app connects to it." It is on by default for most accounts, except Enterprise organisations, whose admins enable it under Org settings, then Security and identity, then Remote control.

### Does my computer have to stay on for Cursor Remote Control to work?

Yes. Because execution stays local, the machine has to remain on and online. The release adds a "Keep this computer awake" setting under Remote Control in Cursor's desktop settings, and Cursor notes the device needs to be plugged in with the lid open for it to apply.

### Can an AI agent write to a shared note when nobody has it open?

Yes, and that is the part that matters for an unattended run. Baalda's MCP write path has two branches. If a client is connected, the write mutates the live document, which persists it, re-indexes it and broadcasts it to every connected editor, the same path a human keystroke takes. If no client is connected, the server hydrates a detached copy of the document from stored state, applies the change and persists the incremental update itself, and the next client to open the note loads that state.

### Should an AI agent's code and its notes go to the same place?

No. The diff belongs in git, which is good at it, and a CRDT-backed vault is the wrong tool for a working tree. The vault is for the half git never sees: what the agent proposed and you rejected, what it ruled out, the constraint you typed in one line from a phone. That is the part with no home today.

### Does Baalda have a mobile app?

Not yet. Baalda is a desktop app for macOS, Windows and Linux, with iOS planned. So it does not replace what Cursor shipped: you still steer the agent from the phone with Cursor, and the written record lands in a vault you read on a laptop. Baalda changes where that record is durable, not how you reach the running agent.
