Autonomy
Capability is purchasable. Defending letting it act is not.
You decide how much your agents settle on their own, and widen it as your own evidence supports — with every step attributable, grounded, bounded and revocable.
The dial
You set the line. Then you move it.
Every other product picks a point on this and hard-codes it. Copilots stay propose-only, so the human is the throughput ceiling forever. Autonomous agents act by default, which is unsellable into a regulated process.
Propose
where you startNeeds: Nothing. This is the safe floor.
Suggest claims, questions and evidence. A person agrees to everything.
Settle the immaterial
Needs: That materiality is defined by policy, not by the model’s judgement.
Close low-consequence items alone; escalate anything material.
Settle within a domain
Needs: A track record that is measured, and specific to that domain.
Act unsupervised inside an intent type where its record supports it.
Build and prepare
Needs: That the gates still hold — attestation and approval unchanged.
Produce artifacts and ready them for release without a human in each step.
Act, with gates
Needs: Halt and revoke are instant, and every step is reconstructable.
Carry work through, stopping only where policy demands a named human.
Use the arrow keys, or pick a position. Set per workspace, per intent type, per risk class.
What holds wherever you set it
Nothing happens that is not attributable, grounded, bounded, and revocable.
That envelope is what makes the line safe to move at all — and why widening it is a decision you can defend afterwards rather than a leap of faith.
Who may do what
Three layers that combine, rather than one list that forces a choice.
What you are allowed to do, what you are answerable for, and where you belong are separate questions — so one person can be a contributor and a reviewer, and an outside auditor can attest without ever seeing the workspace.
Participation
One per person
- ViewerRead the intent, the evidence and who signed what
- CommenterEverything a viewer can, plus thread on anything
- ContributorFull authorship — shape it, talk to the agent, run builds, spend
Every contributor is equal. Nobody needs an author’s permission to move work forward, and there is deliberately no owner role.
Assurance
Zero or more per person
- ReviewerA colleague’s second pair of eyes — advisory, never blocking
- AttestorSigns off against a named standard — SOC 2, GDPR, a customer contract. Blocks publish
- ApproverHolds release authority, and can halt or revoke afterwards
- EvaluatorConfirms after the fact that the output met its own definition of done
Compliance people do not call themselves reviewers — they attest. The specialist role gets the specialist word and the plain role keeps the plain one.
Membership
Workspace level
- Org adminBilling, SSO, workspaces
- Workspace adminInvites, policy, spend caps
- MemberCreate and contribute; share a single intent outward
- GuestSees only the intents shared with them — never the workspace
Guest scoping is how an auditor, a consultant or a customer contact comes in without the workspace coming with them.
Built for the enterprise
The questions procurement asks, answered structurally.
Runs on your infrastructure
SaaS and on-premises from the same artifact — 12-factor config, no SaaS-only dependencies. The only runtime external dependency is the model provider you configure.
Nothing leaves as a file
There is no download button. Hand-off is a scoped credential bound to a published version, with a read log, revocable at any time — because a downloaded file could not be recalled.
Every action is attributable
Who did what, when, and why — append-only and replayable. Deletion is a state, not an erasure, so any past decision can be reconstructed.
Spend is bounded, not open-ended
Token consumption is visible before a run, measured after, and capped by policy at workspace level — so unsupervised work has a floor.
How you run it
Some work can’t leave the building. That’s a deployment question, not a compromise.
The same artifact runs as a managed service or inside your own network. Twelve-factor configuration, no SaaS-only dependencies, and the only thing it reaches out to is the model provider you choose.
available today
Managed
We run it. You sign in and start working an intent — nothing to install, nothing to provision.
talk to us
Your own infrastructure
The same artifact, inside your network. Your intents, your evidence and your audit trail stay on infrastructure you control, pointed at your own models.