Product — Control
Let the agent work inside explicit operational boundaries.
Roles and permissions, agent policy, rules for reaching private systems, preview and approve, secrets and credentials, audit and cost.
Roles and permissions
Owner, admin, member, and viewer roles govern the single instance — the whole access-control model.
Agent policy
Control tool behavior and approval requirements at the agent layer.
Rules for reaching private systems
Allow, deny, or require-approval rules for anything touching private infrastructure, tested before you rely on them.
Preview and approve
See the proposed action and decide in the console or through a time-limited public action link.
Secrets and credentials
Stored as references, decrypted only at call time — never embedded in a task or config.
Audit, governance, and cost
A scrubbed audit history, retention controls, security settings, and daily model-spend ceilings.