Agents that work on their own, and stay within bounds
An agent in the studio can only do what its role card allows. Every call is checked before it runs, every change is recorded, and the decisions that matter come to a person.
Those rules come from the studio itself, so an agent cannot talk its way past them.
Four layers, each on its own
-
A gate on every call
Each AI colleague has a role card: what it may do and what never. The studio checks every call against that card before it runs; what is not allowed is refused and logged. A mail is read as data: an agent never does what a mail tells it to do.
- Every agent call is checked against its role card before it runs.
- An agent's first mail to someone who never wrote waits for your approval.
-
A record that shows tampering
Every change in the organisation is a record first, in a log that is only ever added to. Each record carries the fingerprint of the one before it, so a change afterwards breaks the chain and shows.
- The organisation's log is hash-chained: you see where it was touched.
-
A person in control
What only a person may decide comes to you, with the options and a recommendation. One button stops every running agent; only a person starts them again. Signing in can require a second step for everyone in the studio.
- One button stops every running agent of the organisation at once.
- Only a person lifts a stop.
- Two-step verification, and a studio can require it of everyone.
Before the stop

After the stop

The emergency stop in a demo studio: three executors running, then none, and every role stopped until a person lifts it. -
Your data, in your own environment
Each organisation has its own studio, in its own environment on a server in Germany. Every night a backup is made of it.
- Your own environment on a server in Germany (EU).
- A backup of your environment every night.
Read next
Autonomous, and still yours
EUR 200 a month per organisation
Leave your email address and Floris contacts you to plan a conversation and a demo with your own work in mind.