Eight Arms, All Billable
I used to perform a ritual every Friday that I suspect you’ll recognize. Timesheets were due in xledger—hours split across projects and activities because my time belonged to multiple budgets. I would fill them out with the confidence of someone who had been present all week, only to realize I couldn’t recall what I’d actually done.
So, I reconstructed it: running git log --since=monday across repos, checking calendars for meetings, and scrolling Slack history to account for missing time. Then I translated this archaeology into tidy quarter-hour blocks and submitted it as fact.
Memory is the worst database. It lacks a write-ahead log, runs compaction nightly whether you like it or not, and every query returns a plausible answer with no indication of its truthfulness.
The tools are all wrong
The obvious fix is a timer: start when working, stop when done, making Friday an export button. But manual trackers fail because they require remembering to use them. I don’t forget how to work; I forget to say that I am working. Any tool relying on me forming a new habit at the precise moment my brain is busy with something else is designed to fail. My collection of abandoned timewarrior databases proves this.
At the other end are “automatic” trackers. They solve forgetting by removing you from the loop entirely. They screenshot your screen every thirty seconds, run it through AI, and upload “productivity insights” to a cloud dashboard—often read by your manager. I work with patient data for a telemedicine company. A tool that photographs my display and posts it to someone else’s cloud isn’t an aid; it’s an incident report with a subscription fee.
This leaves a gap: one end trusts you to remember, the other doesn’t trust you at all.
The sidequest
So, obviously, I built one. This is a proper sidequest: no cloud, no accounts, no roadmap committee, and no ambitions of becoming a company. Just the tracker I wanted, built how any tool touching my work machine should be.
It’s called Clocktopus. Eight arms, all billable.

The insight is embarrassingly simple: your machine already knows what you’re working on. Not via AI—but via pwd. My shells are cd’d into a client’s repo. My tmux panes sit in project directories. A running process has a working directory that names the project outright. The frontmost window title shows the open codebase. None of this needs a vision model; it needs a scorer over deterministic signals and a config file where you write the rules:
[[project]]
name = "Initech"
xledger_project = "T200001"
xledger_activity = "DEV"
dirs = ["~/src/initech*"] # shell / tmux / AI-agent cwds
keywords = ["initech"] # frontmost window title
Longest prefix wins, so ~/src/initech-api beats your ~/src catch-all. Every rule is yours, in a version-controllable TOML file, and every guess shows exactly which signals fired. No vibes.
Suggest, never surveil
This is the core feature. When a project holds my focus for minutes, Clocktopus doesn’t clock me in. It asks. A dashed ghost block appears on the day timeline—“is this Initech?"—with evidence attached. One click confirms it, backfilling to when I started (the whole point: the app remembers the start time I was too busy to announce). One click dismisses it. Nothing lands in the database without my say-so.

The surveillance question is settled by architecture, not policy: the app makes zero network requests. Not for sync, telemetry, or updates—grep the source. Your hours are one SQLite file in ~/Library/Application Support, and the only thing leaving the machine is the CSV you export yourself.
Friday, after
The ritual now: open the week grid (ISO weeks, Monday start), with per-project totals already rounded to the billing increment. I skim it, nudge a block edge if the octopus and I disagree about lunch, and export. The CSV speaks xledger’s upload dialect—semicolon-separated, yyyymmdd dates, decimal hours—because that’s what my Fridays demanded, but it’s just CSV; point it at whatever your accounting department worships.

The archaeology is gone. That’s the entire return on investment, and it pays out weekly.
Questions you’re already typing
“Why not ActivityWatch?” A genuinely good project for passive analytics—it lets you study yourself afterwards. Clocktopus is suggest-and-confirm for billing: nothing is recorded until you approve it, and the output is a timesheet, not a chart. And timewarrior is fine, but it still trusts me to remember. We’ve established how that goes.
“Linux port?” The core—domain models, scoring, rounding, export, ~90 tests—is a pure SwiftPM package with no AppKit, so it’s portable-ish. Signal collectors are the macOS-specific part. If cwd-sniffing on Linux sounds interesting, the repo is MIT.
“Why isn’t it notarized?” An Apple Developer ID is $99/year, and this octopus is young. The release build is ad-hoc signed: right-click to open the first time, or build from source (Gatekeeper has no opinions).
“Can a tmux pane I forgot about bill a client from three days ago?” No. This was the heuristic I sweated most. Background signals—parked panes, long-running agent sessions—can only reinforce a project that also has foreground evidence. A forgotten pane can’t clock you in on its own; it can only corroborate what you are demonstrably looking at.
Coda
Clocktopus is on GitHub, MIT licensed, macOS 13+, Swift/SwiftUI, native menubar app. It has exactly one user in production, whose Fridays are much improved. If your accounting department also worships a CSV, maybe it’ll improve yours.