Architecture

Three layers: control · orchestration · isolated execution

Web Portal for UX; Control Plane for org & audit; Runtime for playbooks; L1 Runners for hands-on work.

1
Intent from chat@ colleagues, + digital employees, permission pre-check
2
OrchestratorPlan / Sub-agent / tools — REPL stays visible
3
Isolated runnersPageAgent + sandbox, fail-closed by default
4
Delivery & auditArtifact preview/export, CDP recording + logs
Security & compliance

Control plane and execution plane separated

Policy at the BFF; AI at Runtime; hands in isolated Runners.

CP
Control PlaneIdentity · tenant · audit · quotas
RT
AI Harness RuntimeOrchestrator · LLM · tool dispatch
RN
L1 RunnersPageAgent · code-exec · mcp-runner
  • Fail-closed by default

    Sandbox denies egress unless allowlisted tools or CDP actions — everything else is logged and blocked.

  • PageAgent CDP recording

    Every click, input, and navigation tied to session ID for internal control and compliance audits.

  • Tool approval + Hard Rules

    Sensitive tools like outbound email or payments can require @ approvers; deny beats model inference.

Deployment

Public cloud, private, or air-gapped

Hybrid cloud

Keep core data on-prem; burst compute to cloud.

Web-only entry

Use from the browser — no client install.

Open integration

Embed in ERP/IM/portals without replacing existing systems.

Put AI on the org chart — not just the bookmarks bar

Sign up free, or book a demo to see your first closed loop across ERP, portals, and IM.