An open-source workspace for building, sharing and running AI agents on infrastructure you control.
You ask, it answers. Most teams already use one, often several.
They use tools, read your files and run on a schedule.
Several steps and systems in one process.
Agents set up in the browser: instructions, model, tools. Published as versions.
Your documents, company context and the tools your teams already use.
Budgets, approvals, roles and a record of every run.
Analyse spreadsheets, produce charts and documents.
Choose models and tools, publish versions, share them.
Skills, context and searchable documents.
Interactive pages with stable links and versions.
Dashboards, run history, schedules and budgets.
Roles, department groups and company sign-in.
An AI assistant with instructions, a model and tools, set up for one kind of work.
A written procedure an agent follows, like onboarding notes for a new colleague.
Standing company knowledge: glossary, policies, house style.
Your documents, made searchable so the agent answers from them (RAG).
A page an agent publishes: a report or a dashboard with its own link.
An open standard for connecting agents to other tools, such as Notion or GitHub.
An isolated container where an agent may run code without touching anything else.
An agent that starts by itself: on a schedule or when something happens.

One page per agent, in the browser. Four areas:
“Published, up to date with v6” is the version colleagues use. You edit a draft; nobody sees it until you press Publish. Export YAML keeps a copy in your own repository.
What the agent is for, how it should work and what it must refuse. Written like a brief for a new colleague. Your experts can edit it.
A provider and a model, with your own keys from the vault. Local models work the same way. Changing it is a setting, not a rebuild.

Specialised agents for research, reporting, coding or operations.
Ready-made starting points, or an empty agent you shape yourself.
Organization means everyone in the company may use it; Private means only its owner. Published means colleagues get the released version.

A sales CSV was uploaded with one question: what happened in H1?
Every command the agent ran sits above its answer. Click one to see exactly what it did.
Python in a sandbox, from your file, not a picture the model imagined.
Duplicates, blank fields, invalid dates. Then totals, refunds and what stands out.
The same chat talks to whichever agent you choose, with its own tools and knowledge.


A skill is a procedure written once: how a refund is handled, how a month-end close runs. Every agent that uses it gets the current version.
Open a skill and you see three parts:
The one line the agent reads to decide whether this skill fits the task. The full text loads only when it does.
Plain Markdown, edited in the browser. No code, no deployment.

A glossary, a policy or a house style that every agent can share. This one is a glossary.
Linked keeps it out of the prompt until the agent needs it, which keeps answers fast and cheap.
Write it once; every agent bound to it uses the same definitions.



A knowledge base is a set of documents an agent can search. When asked, it finds the relevant passages and answers from them; this is called retrieval, or RAG.
Type, size, how many pieces it was split into, which parser read it, and whether it is ready.
Pull documents automatically from Google Drive, S3, Git, a website, SharePoint or OneDrive.
Per collection, or differently for one upload: parser, OCR for scans, output format and limits. LlamaParse is a paid cloud service; the other two run locally.


A sales dashboard for Meridian, a fictional company. The agent wrote and published it.
Private by default. Share it with people, a group, or a public link.
Period and region change every number on the page.
The text quotes numbers the page computes from the same data.
When an agent publishes an update, the link stays the same and earlier versions stay readable.
One request; the agent does the rest. Follow along:



Besides web chat and the API, an agent can answer in Slack, Mattermost or Telegram.
On a schedule, such as every Monday at 7:00, or when something happens:
MCP is the open standard for plugging tools into agents. The catalogue lists curated servers and thousands from a public registry.
Each connection is set up with its own sign-in, and you choose which of its tools an agent may call, for example read pages but not edit them.
In AgenticOS, for your members.
A snippet on your site. Allowed sites only; public or signed visitors.
A link you can send, with its own budget, rate limit and pause switch.
Your systems send a task and get the answer.
Streamed answers, token by token, for your own front end.
Mention the bot in a channel or a thread.
For companies that keep chat on their own servers.
A bot people can message directly.

One platform in the middle; every connection passes the same roles, budgets, approvals and record.
Hosted providers, your Azure, Bedrock or Vertex contract, or local models through Ollama and vLLM.
99 curated MCP servers and 5,700+ registry listings. You choose which of a server's tools each agent may call.
Google Drive, S3, Git, websites, SharePoint and OneDrive, synced on a schedule into searchable knowledge bases.

What managers and administrators look at first. Six parts:
How many runs, how many finished, what they cost, and how many people used agents.
Failed runs, runs waiting for a person's approval, and runs a budget stopped.
Web chat, the API, schedules: all counted in the same place.
Which agents people actually use, and which nobody opens any more.

A “run” is one task an agent carried out. The Activity page lists all of them.
Tokens, cost and time; the question and the answer; the tools it called; what went into the prompt. This one came from Slack.
The limit is checked before each request to the model, not added up at the end of the month.

You choose which tools must ask first, for example running commands or sending email.
The agent pauses. The approver reads precisely what will run and presses Approve or Reject.
Who asked, who decided, and when. Exportable for audit.
Monthly caps per agent and organisation, checked before each model request.
A sensitive tool waits for a person, who sees exactly what will run.
Hide emails, IBANs and card numbers in prompts, answers and tool results.
Every run recorded with agent version, tools, tokens and cost. Exportable.



Access follows your organisation chart.
An agent, a skill, a knowledge base or a page. A private strategy assistant can be shared with the board group only.
Each person has a role in the organisation.
all: everything in the organisation · shared: what was shared with you · own: what you created.
API keys and passwords for models and tools. Encrypted, and never shown again after saving.
Agents, skills, context, knowledge bases, artifacts
plus grants to people or groups:
Plus magic links and password reset.
Sign in with a Google account.
Entra ID, Okta, Keycloak, Auth0, Authentik, Google Workspace.
Active Directory, OpenLDAP, FreeIPA.
Kerberos: a domain-joined browser signs in by itself. Add-on image.
A directory group becomes a role and a group, applied at every sign-in.
Every secret has its own key, wrapped per organisation and key version. Keys rotate; values are never shown again.
The API never holds the Docker socket. No network unless needed; CPU, process and time limits; gVisor optional.
Published pages run sandboxed with no network access and a strict content security policy.
Hash-chained per organisation, verifiable and exportable. Kept at least six years.
Short-lived tokens, revocable sessions, “sign out everywhere”, rate limits on sign-in, API and embeds.
Guardrails, emails and tokens redacted in logs, retention sweeps per data class.
Provider, model and key saved once per organisation, with a fallback if the first fails.
On by default for Anthropic and OpenRouter, which cuts the cost of long instructions.
OpenAI, OpenRouter, or local models through Ollama for document search.
Upload txt, md, docx, pdf, office files, images, or sync:
Three parsers:
Recursive, Markdown-aware or fixed chunks; size and overlap per collection.
OpenAI, OpenRouter or local Ollama models; stored in PostgreSQL with pgvector.
Vector search with filters, optional query expansion and wider context, and citations.

Code the agent writes runs in containers, never in the platform itself.
On your own hosts or a supported remote backend. The access token stays in the vault, and the API never holds the Docker socket.
One script checks prerequisites, asks for a model key and starts a working agent. Windows through WSL2.
Pin a version; database migrations run on start. Not zero-downtime.
PostgreSQL, the media volume and the settings file that holds the vault key.
Dev, staging and production point at published versions. Promote or roll back; export agents as YAML.
Built-in run history and dashboards, Logfire tracing, user ratings, CSV exports.
Console in English, Polish and German. Documentation in English, Polish, German and Spanish.
Deploy, watch capacity, review releases, plan upgrades.
Databases, files and keys backed up, and a restore actually tested.
Keep documents, instructions, skills and published versions current.
Identities, grants, provider keys and their rotation.
Inspect runs, route incidents, name who may approve.
Review every model, parser, tool, channel and tracing destination.
Its documents, and the person who judges the answers.
With the model and the access rules you choose.
With your people. Then decide on the next team.
We set it up with you, test it on your material, and you decide what comes next.