Security

Control everything before you delegate

Every action is decided by your policy before it happens and recorded after. Approvals, boundaries, audit trail and budgets in one place.

Built-in control

Everything an agent needs. Nothing it shouldn't have.

The convenience of ChatGPT or Claude, with what a company needs before it lets an agent near its systems.

⌘

A computer per coworker

Its own Chromium, workspace and browser profile, so it stays signed in between turns. Watch it live, and take the wheel at a login wall or 2FA prompt.

computer.help_requested2FA
computer.control_takenyou
computer.control_released→ bot
✓

Approvals that escalate

Consequential actions wait for a person, escalate to a backup, and expire safely.

Submit the expense report for ¥48,200?
Allow onceDeny
⚖

Your rules, decided first

CEL policies that fail closed, with version history, rollback and optional four-eyes approval.

deny: tool.name == "browser.type" && element.type == "password" allow: page.host in ["arxiv.org"]
◉

An audit trail you can read

Search it, export it to CSV, stream it to your systems with signed webhooks.

browser.navigate · arxiv.orgpermitted
browser.type · passwordrefused · rule 3
file.write · report.mdpermitted
¥

Usage & budgets

Tokens and cost per coworker, with monthly caps.

⇄

Any model, per coworker

Choose the provider and model for each coworker.

claude-sonnet-5-5claude-opus-5-5gpt-5.5custom…
⚙

Governed connectors

Google Drive, Notion, Composio and your own MCP servers — granted tool by tool, with health checks.

500capabilities catalogued
400+live today, each with proof
13coworkers ready to work
EN · JAthe whole workspace, in both

Put your first coworker to work

Sign in, open a channel, and ask it to do something real on the web.

Open the workspace→