# Context is a volume you plug in

*2026-09-10*

> Grok Bot, Muse, and Perplexity Computer all give the agent a machine. The context that builds up while you use it still sits in their infrastructure. I want a volume I can plug into any of those VMs, then unplug and take the working copy.

Context is a volume you plug in. Not a chat history. Not a memory the company keeps after I close the tab. A disk I attach to the agent VM, then unplug and take with me.

[Grok Bot](https://x.ai/news/designing-grok-bot), [Muse](https://about.fb.com/news/2026/09/introducing-muse-personal-ai-agent/), and [Perplexity Computer](https://www.perplexity.ai/hub/blog/how-we-built-security-into-computer) all give the agent a machine. Sandboxed. Isolated. The work can run without sitting on my laptop. That's the part that shipped.

The part that didn't: I still don't trust those companies to hold the context that accumulates while I use them. Identity, skills, knowledge. I want that on a volume I own.

## Agent computers share a shape, not ownership

SpaceXAI's Grok Bot runs on a persistent cloud computer. Meta's Muse sits in a Secure VM. Perplexity Computer runs tasks in isolated sandboxes. Same shape: the agent gets a machine. The machine is theirs.

I'm not saying they are the same product. Muse has a Confidential VM on the roadmap, encrypted so Meta says even they can't read it. That is privacy from the operator. It is not a disk I take to Grok Bot.

Perplexity also ships [Portable Computer](https://www.perplexity.ai/hub/blog/introducing-portable-computer-for-local-first-ai), a local-first stack on NVIDIA hardware. Still a machine I have to run, not a volume I plug into a different vendor's VM. Perplexity Computer can snapshot a session and move it across their own nodes. That context travels inside Perplexity, not out of it.

The miss isn't isolation. Isolation is the point of the VM. The miss is treating that VM, or that vendor's snapshot, as the place my context should stay.

## Context is what accumulates while you use the tool

Not the prompt I typed this morning. The longer I use the tool, the more it knows. That pile is the asset. It is also the lock-in.

| Layer | What it is | Where it lives today |
| --- | --- | --- |
| Identity | what the agent remembers about me | their store |
| Skills | how it learned to work my way | their store |
| Knowledge | decisions, style | their store |
| Files I wrote | docs I already keep | Notion / Drive |
| Agent disk | workspace on their VM | their machine |

I can export a Drive file. Muse says I can [inspect, edit, and download](https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-muse) the files in the VM, including memory. That is still a Muse-shaped dump. It is not a volume Grok Bot or Perplexity Computer will mount.

Grok Bot keeps memory on the Bot. I have not seen an export I can plug into the next machine. Context is how these tools get useful. I still have to ask whether I trust them to hold what will not move with me.

## A Drive folder is not the memory

I already keep durable things in Notion and a drive. Mine is OneDrive. That's useful. It is not ownership of the agent relationship.

The files I wrote are on my side. The memory of how I work, the conversations, the traces: those stay in their infrastructure. Connecting Notion or Drive through MCP does not move that. It lets the agent peek at a folder I already own. Disconnecting the connector does not unplug identity, skills, or knowledge.

So the storage ecosystem helps, and it stops short. The agent can read my notes. It still accumulates a second copy of me that I don't hold.

## I want a volume I can unplug

The product I want is a portable volume I plug into the virtual machine.

- Mine
- Governed by me
- No vendor lock-in
- Switchable across agent computers
- A working copy I can take
- Any agent I want

The agent keeps the VM. I keep the disk. Plug it in, the agent has the identity, skills, and knowledge I can write down. Unplug it, the relationship ends on my side.

I know that does not wipe their logs, backups, or safety audit. It does not move whatever the model only holds in their store. I still want the working copy to leave with me. Complete ownership of that copy is still what I'm longing for. I don't think that standard exists yet. I think it is a business.

![The agent keeps the VM. Context sits on a disk you unplug.](/blog/diagrams/context-is-a-volume-you-plug-in-volume.png)

Until that volume exists, I'm borrowing a computer whose memory I cannot plug into the next vendor.

## Mount the cloud drive. Don't wrap it in MCP

MCP is for tools. A mount is a home directory. Those are different jobs.

If the agent has a real machine, my Drive should show up as a folder on that machine. Not as another connector with a few allowed actions. A place the agent can open. Files I already own, sitting where the work happens.

MCP can still book a flight or ask Notion a question. That is tools. Wrapping Drive in MCP still keeps my files inside their verbs. A mount puts the files on the machine. That is the shape I want for anything that is supposed to move with me.

They may never let me attach a disk they didn't provision. Isolation is how they contain the agent. Then the product is a volume they agree to attach, or I don't use their VM.

Hygiene sits next to that, not after it:

- Keep personal junk off the agent volume. Photos, tax docs, family stuff stay elsewhere.
- The volume is for work the agent is allowed to touch. Mixing the two is how a useful disk becomes a leak.

## Meantime the durable layer stays where I own it

I don't wait for the product. I keep the durable layer on my side so I can switch tools without starting from zero.

1. Notion as the context state engine: identity, skills, knowledge, decisions, writing style.
2. OneDrive for the files, shared on my device.
3. Switch agent computers when I want. The notes and the files come with me. The agent's memory does not.

That is what I do today. It is not the volume. Notion and OneDrive sit beside the VM. They are not plugged into it. The agent's memory and traces still live where I don't govern them. The meantime only covers the layer I already owned.

## Takeaways

- The computer shipped. Ownership of context did not.
- I don't want these companies holding my identity, skills, and knowledge.
- A Drive folder is files. Memory is still theirs.
- The product I want is a volume I plug in and unplug. The working copy comes with me.
- MCP is for tools. A mount is the home directory. Wrapping Drive in MCP is not the same thing.
- Keep personal junk off the agent volume.
- Meantime: Notion and OneDrive on my side, so I can switch.
- I want that ownership without becoming the sysadmin. Open-source stacks exist for people who will run them. As a consumer I still want the power without that complexity.

These tools are amazing. Portable context still isn't figured out. I want the working copy to leave with me.
