Features

Everything between a sentence someone types and a safe, audited change in your software.

The model proposes. It never executes.

Every call an agent suggests is independently re-checked against tool ownership, the argument schema, the acting user's permissions and your policy before anything reaches your systems. That is what makes it safe to point at production.

Universal connections

One connector interface covers MCP servers, REST APIs, OpenAPI documents, PostgreSQL and MySQL. Whatever the source, discovered capabilities are normalised into a single tool registry with input schemas, a risk level and an operation type.

  • Auto-discovery of endpoints, tables and relationships
  • Credentials envelope-encrypted, never in a prompt
  • SSRF protection re-checked on every request

Automatic agent generation

Point AgentOS at a connection and it reads what is there, then produces an agent identity, written instructions, a tool selection and an approval policy for you to review before deploying.

  • Deterministic — the same connection gives the same agent
  • Destructive tools included but gated, not hidden
  • Versioned, with rollback applied forward

Policy and approval engines

Reads flow through. Deletes, bulk operations and anything high-risk stop and wait for a named human, in the dashboard or from wherever the request came from.

  • An approval covers one call, not a capability
  • Bound to a fingerprint of the exact arguments
  • Expires rather than going stale

Execution traces

Every run records its steps as they happen: what the model proposed, what was validated, what policy said, what ran and how long it took.

  • Includes the calls that were refused
  • Survives a crash mid-run
  • Cost recorded per call in integer micro-cents

Structured reporting

Agents return structured results, not markup. The interface renders them as tables and charts, and exports them as CSV, real Excel or PDF.

  • A model can never inject UI
  • Saved questions run on a schedule
  • Export is its own permission, and audited

Reach it from anywhere

Web chat with live reasoning, or Telegram so people can ask without opening a dashboard. Same runtime, same checks, different door.

  • A channel sender carries nobody’s permissions
  • Allow-list starts empty, meaning nobody
  • Signed, verified inbound requests

Governance

The parts that matter when this stops being a demo.

Five roles

Owner, admin, manager, member and viewer, with per-member grants and denials. Denials win.

Hash-chained audit

Every consequential action, linked to the one before it, so a gap is detectable.

Tenant isolation

Enforced by a global scope that fails closed — no tenant, no rows.

Configurable retention

Executions, conversations and audit entries each expire on your schedule.

Connect something and see what it builds.

Free plan available. No credit card required.