Features
Everything between a sentence someone types and a safe, audited change in your software.
The model proposes. It never executes.
Every call an agent suggests is independently re-checked against tool ownership, the argument schema, the acting user's permissions and your policy before anything reaches your systems. That is what makes it safe to point at production.
Universal connections
One connector interface covers MCP servers, REST APIs, OpenAPI documents, PostgreSQL and MySQL. Whatever the source, discovered capabilities are normalised into a single tool registry with input schemas, a risk level and an operation type.
- ✓ Auto-discovery of endpoints, tables and relationships
- ✓ Credentials envelope-encrypted, never in a prompt
- ✓ SSRF protection re-checked on every request
Automatic agent generation
Point AgentOS at a connection and it reads what is there, then produces an agent identity, written instructions, a tool selection and an approval policy for you to review before deploying.
- ✓ Deterministic — the same connection gives the same agent
- ✓ Destructive tools included but gated, not hidden
- ✓ Versioned, with rollback applied forward
Policy and approval engines
Reads flow through. Deletes, bulk operations and anything high-risk stop and wait for a named human, in the dashboard or from wherever the request came from.
- ✓ An approval covers one call, not a capability
- ✓ Bound to a fingerprint of the exact arguments
- ✓ Expires rather than going stale
Execution traces
Every run records its steps as they happen: what the model proposed, what was validated, what policy said, what ran and how long it took.
- ✓ Includes the calls that were refused
- ✓ Survives a crash mid-run
- ✓ Cost recorded per call in integer micro-cents
Structured reporting
Agents return structured results, not markup. The interface renders them as tables and charts, and exports them as CSV, real Excel or PDF.
- ✓ A model can never inject UI
- ✓ Saved questions run on a schedule
- ✓ Export is its own permission, and audited
Reach it from anywhere
Web chat with live reasoning, or Telegram so people can ask without opening a dashboard. Same runtime, same checks, different door.
- ✓ A channel sender carries nobody’s permissions
- ✓ Allow-list starts empty, meaning nobody
- ✓ Signed, verified inbound requests
Governance
The parts that matter when this stops being a demo.
Five roles
Owner, admin, manager, member and viewer, with per-member grants and denials. Denials win.
Hash-chained audit
Every consequential action, linked to the one before it, so a gap is detectable.
Tenant isolation
Enforced by a global scope that fails closed — no tenant, no rows.
Configurable retention
Executions, conversations and audit entries each expire on your schedule.
Connect something and see what it builds.
Free plan available. No credit card required.