A private foundation
Workspace identity, membership roles, protected source files, limited file-name search, shared limits, and editorial tools have been tested. The public creator prototype remains a sample.
Our research-backed plan covers 160 proposed capabilities across 16 areas. These are development intentions and acceptance conditions, not a list of available features or promised delivery dates.
Workspace identity, membership roles, protected source files, limited file-name search, shared limits, and editorial tools have been tested. The public creator prototype remains a sample.
Validated imports, supported read-only YouTube access, permission-filtered evidence, evaluated live AI, and a sourced weekly brief with a draft plan.
Exact approvals, durable execution, reviewed skills and extensions, broader workflows, team governance, and later experiments. Each requires its own validation.
Open an area to see the intended behavior. Phase labels indicate the earliest proposed development stage. Even “Foundation scope” entries may include work that is still pending; they do not certify complete implementation.
a user reaches one sourced result without configuring a blank dashboard
all content and agent context change atomically with the selected workspace
the default prioritizes meaningful changes and pending work over raw metric volume
keyboard and touch users can find pages, actions, records, and chats
personal pins persist without modifying colleagues' layouts
comfortable and compact modes retain readable labels and focus states
definitions and the period are available beside every key number
drill-downs retain filters and provide a reliable return path
unknown, zero, not connected, no permission, and failed loads differ
interrupted onboarding and drafts resume from saved progress
every entry states supported operations and current implementation status
consent names accounts, requested access, and destination workspace
secrets are write-only and tested using a minimal permitted request
negotiation, auth, capability discovery, and policy review succeed before use
users enable individual operations rather than an entire unknown server implicitly
supported schemas create a reviewable adapter draft, never immediate unrestricted tools
approved operations and variable validation bound the exposed capabilities
duplicates and invalid signatures cannot trigger repeated work
outbound enrolled bridge accesses only configured internal resources
scope loss, quota exhaustion, expiry, and schema changes have distinct repair states
progress and partial coverage remain visible while backfill continues
committed cursors resume safely after worker restart
data-through time is distinct from fetch time and page load time
periodic comparisons detect missed events without duplicating records
simultaneous edits do not silently overwrite user changes
units, grain, aggregation, and provider definitions accompany each metric
suggested cross-source matches require reliable IDs or explicit confirmation
missing periods and schema changes produce actionable explanations
jobs stop and retrieval access is withdrawn predictably
removed source records and permissions invalidate dependent indexes and caches
permitted files, chats, tasks, and source records appear together
conceptual queries improve relevance without bypassing access filters
type, source, date, and workspace filters never leak restricted counts
claims open a permitted source or explain why it is no longer accessible
extraction quality and original location remain inspectable
queries retain scope and alert settings rather than copying unrestricted results
conflicting sources are shown instead of silently merged
selected content becomes explicit, removable agent context
large/private sources can be queried in place under source authorization
users update a definition with provenance and version history
users ask questions alongside their work without losing page context
titles, search, rename, archive, and reopen work across sessions
the agent shows which workspace, sources, and files it may use
unsupported claims are omitted or labeled uncertain
an answer can become an editable file or task with provenance
multi-step work exposes expected outputs, sources, costs, and side effects
cancellation stops future steps and reports any already-started external operation
users continue or fork a conversation without duplicating side effects
users see, edit, scope, and delete saved preferences separately from chat
tasks show verified outputs, partial failures, and unresolved work
a server-side workspace secret enables an approved generative model
OpenAI, Anthropic, or other adapters pass the same capability contract
only compatible, policy-permitted choices are selectable for a task
simple jobs use a qualified faster model when evaluations justify it
typed classification improves a measured workflow over the baseline
concurrent runs reserve funds and stop before exceeding application ceilings
outages never silently change permitted data destinations or capabilities
users see model, provider, estimated/actual usage, and task cost status
supported local runtimes are reachable only through an authenticated companion
releases show task quality, latency, cost, and safety regression results
a natural-language request produces a validated chart and reproducible query
all important chart values are accessible without interpreting pixels
equal durations, timezones, and incomplete periods are handled explicitly
alerts state baseline, sample sufficiency, and false-positive controls
possible explanations are distinguished from causal conclusions
membership and event definitions remain inspectable
backtesting beats a simple baseline and uncertainty is visible
assumptions and simulated outputs never appear as observed results
target, owner, period, and data source are explicit
every reported quantity traces to a calculation or provider record
files survive chat closure and have explicit ownership
produced files preview, download, and retain source references
exports are validated and visually reviewed where needed
editing preserves recoverable prior revisions
untrusted content cannot execute in the authenticated app origin
users can compare extracted fields against their original location
rights, versions, tags, and project usage remain visible
the companion can access only the user-selected workspace root
divergent file edits offer comparison and recovery
workspace files and metadata export in documented formats
supported authorized analytics are explained with freshness and definitions
planned items are distinct from provider-confirmed scheduled posts
inputs, intended audience, and cited research remain editable
source content rights and destination constraints are checked
approved tone, terms, examples, and assets are versioned
permitted comments are grouped without inventing sentiment certainty
obligations, deadlines, and evidence of delivery are linked
destination, account, content, and timing are confirmed before sending
hypotheses and outcomes are recorded without claiming guaranteed growth
source leads require review; no invented live cricket reporting
authorized business sources produce a reconciled weekly brief
linked records preserve source identity and permission boundaries
suggestions route tickets with human escalation and monitored error rates
owners, blockers, deadlines, and evidence of completion are visible
orders, refunds, and fulfillment are distinguished from profit
currencies, fees, refunds, and recognition assumptions stay explicit
authorized notes become reviewed tasks with traceable origins
repository and issue data produce a sourced progress summary
evidence tables and citations support writers, educators, and analysts
administrators compose views and tools without changing core navigation
generated steps are reviewable before activation
manual, scheduled, and event triggers show scope and timezone
simulated actions are unmistakable and cause no external mutation
restarts resume without repeating committed external effects
proposed actions, reviewers, expiry, and decisions remain centralized
transient errors back off; permanent errors stop with repair guidance
duplicate events and retries do not duplicate supported writes
users inspect inputs, outputs, waits, and redacted errors
only chosen meaningful changes interrupt users
imported versions disclose capabilities and require workspace configuration
valid SKILL.md packages load only within granted capabilities
author, origin, version, license, and requested tools are visible
updates cannot silently expand tools, dependencies, or network access
skill code runs without production credentials or arbitrary network access
developers implement typed lifecycle hooks and compatibility tests
organizations approve and revoke internal packages
moderation, vulnerability reporting, and maintenance status exist first
scoped service identities access approved resources with rate limits
external agents receive the same authorization restrictions as the UI
authenticated A2A tasks carry bounded scope and inspectable results
server checks prevent self-granted administration
access can be narrower than whole-workspace membership
recipient permissions govern records and generated summaries
notifications follow access and user preferences
expiry and explicit client separation prevent accidental oversharing
only currently authorized reviewers can approve an action
joiner, mover, and leaver workflows revoke access predictably
authorized admins can export tamper-evident redacted records
removing a member does not orphan critical connections or artifacts
workspace rules restrict source categories, models, regions, and retention
API, SQL, search, files, queues, and caches reject cross-workspace access
encryption keys are separate from encrypted credentials and access is audited
multiple instances enforce the same user/workspace/provider budgets
verified identity, revocation, CSRF protection, and secure cookies are tested
retrieved text cannot grant tools or redirect sensitive data
custom endpoints cannot reach cloud metadata or unauthorized internal networks
users can inspect retention, export, disconnect, and request deletion
administrators revoke a compromised connector, model, skill, or workflow
size/type limits, malware handling, archive checks, and safe rendering apply
incident response, recovery drills, dependency review, and reporting paths exist
every core flow works without a pointer
controls, task status, and errors have meaningful announcements
core tasks work at narrow widths and enlarged text
no essential task depends on animation
dates, numbers, timezones, and currencies are unambiguous
users can flag a wrong answer, bad source, or failed action separately
connection and metric explanations appear where users need them
a user can share an explicitly reviewed, redacted diagnostic bundle
users can leave without a hidden export or billing obstacle
product decisions use observed task success and retained value
constrained UI components improve completion over ordinary forms
suggestions are useful enough to justify interruption
explicit capture, transcript review, and equivalent text controls are available
cited text accompanies audio and sensitive output stays private
selected entities and evidence improve investigation over search
agreed actions are evaluated later without claiming causal proof
scoped parallel work beats a single-agent baseline on measured tasks
local processing meets quality and hardware constraints
artifacts, definitions, skills, and references move without secrets
agents test a plan against synthetic conditions with no production side effects
Connections need real provider access and tested synchronization. Answers need supported evidence. Actions need exact authorization and verified outcomes. A prototype screen does not establish a production integration.
We will validate customer usefulness, accessibility, tenant isolation, arithmetic, source quality, recovery, and serving costs before expanding access.
Read the company overview