Runs processes
Runs agents, stops one at its budget, keeps tenants apart in the database rather than in code
Enforces limits
Monthly caps per agent, checked before the request. A run that fails still records what it spent
Controls access
A permission catalog in code, roles composed from it, grants that widen and never narrow. Approval is the sudo
Talks to hardware
One interface to 27 model providers and to any MCP server by URL — the driver layer
Keeps a filesystem
Collections, skills and context in your own Postgres, with embeddings kept per organization
Gives one shell
One runner behind all eight surfaces, plus a schedule and an event trigger
Writes an audit log
Who ran what, when, what it cost, and who approved it. Written even when the run failed