A platform for governed AI agents
Agents that can only do what you said they could
Build an agent from a template and decide, outside the prompt, which tools it gets, who may run it, which model it uses, what it may spend, and what a person has to approve first. Today it changes group membership in Microsoft 365 and Google Workspace and reads Jira and Confluence. Every call and every decision lands in a record you can hand to an auditor.
Free for sixty days, no card. Setup takes about fifteen minutes and needs a directory administrator once.
Dana needs access to the Finance shared drive to close the month
- Who asked
- Dana Whitfield
- For how long
- 30 days
Reference R-FINDRIVE
Approving adds Dana to the group in Microsoft 365 and emails her. It cannot be undone.
Decline this request
Three things you always know
Getting an agent running is the easy half. The hard part is the question that comes after: what is it allowed to touch, what has it already done, and what is it costing us.
- Who can do what
- Each agent runs with a list of tools you approved and a list of people who may run it. Both are settings checked at the gateway, outside the prompt, so nothing written into a document or a request can widen them. Every tool call is checked against that list and recorded, whether it went through or not.
- What they did
- Every model call goes through one gateway and every tool call through another. Each one leaves a row: who or what acted, on whose behalf, under which rule, and what changed. The record is append-only, covers every table that belongs to your organization, and exports in a format you can read. We cannot edit it either.
- What they spent
- Every agent runs against a budget you set. The model is chosen and the spend reserved in one step before the call is made, so two runs at once cannot both take the expensive option and slip past the cap. As the budget tightens the run steps down to a cheaper model, and each step-down is recorded. Your organization's monthly cap is enforced at the gateway itself.
What an agent can act on
The first agents ship as access requests because that is where a wrong action costs the most and is easiest to check. The reach is stated in three tiers, because the honest answer is different for each.
- Changes it makes today
- Group membership in Microsoft 365 and Google Workspace: add someone when a request is approved, remove them when the period ends or a reviewer takes it back. Every write carries a reference you can find in your own Microsoft or Google logs.
- Systems it reads today
- Jira and Confluence, through a connector we wrote and run, using your own credential against your own site. What it may read there is approved tool by tool before any agent can call it.
- How the next system arrives
- As a connector we build and operate, reviewed the same way. The limits, the approval gate and the record are the same for an agent that reads an order queue or drafts a supplier reply as they are for one that grants a licence. Which systems come next is decided with the organizations in the beta. Plugging in your own MCP servers is not supported yet.
How you get there
- 1
Pick a template
Start from a shipped agent rather than a blank prompt. The first shapes are internal: IT access, Snowflake access, SaaS seats, VPN access, leavers. The controls around them are what you are evaluating.
- 2
Set the limits
Which model, which tools, which people may run it, what it may spend, and what a person has to approve first. Each change is a version you can approve, reject or roll back.
- 3
Put it to work
It runs against your directory and the systems you connected. Anything that needs a person waits on a durable checkpoint and reaches a named reviewer on their phone.
The same system, read three ways
- For the CEO
- Say yes to AI without betting the company on it. Nothing an agent does is invisible, and nothing you marked sensitive happens without a person deciding first.
- For the CFO
- A spend cap per agent, checked before the call is made rather than discovered on an invoice. You see what each agent spent today and this month, by model, and every step-down it took to stay inside the line.
- For the CIO
- One gateway for models, one for tools, and an approval that survives a restart. Each organization is separated in the database itself, not in application code, and our own operators read across organizations through a read-only role whose reads are logged.
If you are a larger organization
A retailer or a group with several brands evaluates this differently from a forty-person company, and asks different questions first. Here are the answers.
- One organization per business unit, brand or country, each with its own directory connection, connectors, agents, budgets and record. Switching between them is a menu, not a second login.
- An approval gate for any action an agent proposes, not only access. The run pauses on a durable checkpoint, the reviewer decides from a signed link or a Teams card, and the decision is on the record with who made it and when.
- Access given for a period is taken back on time, in your directory, and the person is told. A page and an export list who currently holds what and when each piece ends.
- Your data sits in our tenant in the United States, encrypted where it is a credential, with no choice of region yet. Say so early if that is a problem; it is a boundary, not a surprise we want you to find later.
- Anthropic models run in production today. OpenAI and Google models are routable and priced through the same gateway, and have not carried customer traffic on this deployment.
The pilot page says what a pilot looks like, what we need from you, and what we will not promise.
What this is not, yet
We are in beta and would rather you knew the gaps now than found them on a consent screen.
- You build agents from the templates we ship, not from a blank page. Authoring a new agent type still takes us.
- Beyond your directory, one connector today: Jira and Confluence, read only, with your own credential. Plugging in your own MCP servers is not supported yet. The templates for Snowflake, SaaS seats and VPN decide and record; they do not yet change those systems.
- In the beta every request an organization sets up goes to a person. Clearing low-risk requests without one is built into the gate and not yet switched on for customers.
- Everything runs as an outbound call from our infrastructure in the United States, so anything behind your firewall or on a private network is out of reach, and there is no choice of region.
- A decision, once made, cannot be undone. Access can be taken back; the approval stays on the record.
- No SOC 2, no service level agreement, and no single sign-on enforcement. If those are requirements today, this is not ready for you.
The security page has the rest of it, including what the model sees, where data lives, and who else is involved.
Fifteen minutes, and no card
Connect Microsoft 365 or Google Workspace, put one agent to work, and watch what it does and what it costs. If you stop, your data comes out in a format you can read, and the record comes with it.