Agents7 registered104 tools

Doing the work is easy. Stopping the wrong work is the product.

An agent here reads and writes the same records the screens do. It remembers prior context, learns skills from successful work, and organisation pulse acts on weak signals before they become failures. Everything runs under the permissions of the person who asked.

AI agents

Memory, improvement, and action without a prompt.

Semantic recall, skill learning, and proactive pulse ship in the product. Each hits the same tools, permissions, and approval gate as a human click.

Semantic recall

Shared memory across agents: working memory that follows the person, observational notes on long threads, and optional semantic recall over past messages so earlier work is findable by meaning, not only by scrolling the thread.

Self-improving skills

After a multi-tool success, an agent can save a learned skill or improve one it already owns. Seed and human-authored skills are never overwritten by the agent. Admins can disable or delete learned skills; every write is audited.

Organisation pulse

Scheduled and event-driven sweeps across field operations, unowned tasks, risks past review, expiring quotes and project pressure. The point is to surface the gap in the noise before a missed review or stalled job becomes a client issue.

Proactive follow-through

Pulse does more than alert. It creates and assigns board tasks, posts agent comments on projects, links follow-ups to risks and quotes, and assigns work when the rule is clear. Same permissions and approval gate as a human click.

One actor boundary, whichever door the request came through.

Dashboard chat, the REST API, the MCP server, Slack, Teams and inbound email all reach the same 104 tools. Every tool resolves the acting human first.

No key escalation

An API key cannot do something the person behind it could not. A read-only MCP client is refused before the server will even fetch a URL on its behalf.

Scope narrows only

The agent panel is mounted once in the shell and knows which of 22 scopes it is in. A route scope can only ever remove tools, never add them.

No guessed identifiers

The panel refuses to lift a record ID out of the address bar, because a path segment is not a record ID and a wrong one becomes a confident sentence in a system prompt. A screen that knows its record passes the sharper scope itself.

Answers as objects

Tools can reply with a chart, a table, a metric or a diff rather than a wall of JSON.

Fifteen destructive actions, classified once, in one file.

Ten of them write a pending row and let the agent carry on with the rest of the brief. Five stop the run where it stands.

Stops the run5 actions
  • Accept a quote
  • Export a quote to Xero
  • Queue a campaign
  • Publish a social post
  • Promote an estimate to a quote

Each of these puts something in front of a customer, a third party or the public, and no row edit takes it back.

Why queueing beats a modal

The industry pattern is a dialog that stops the agent mid-thought and waits. Here a destructive call writes a row, returns as pending, and the agent reports it as pending rather than done, then keeps working. A human answers the queue later, and the rest of the job did not stall on them.

It cannot be switched off

There is no environment variable that disables the gate. The one that sounds like it would exists only in a test that asserts setting it changes nothing. The gate also does not care where the request came from, so a person chatting in the dashboard is gated exactly as an unattended overnight sweep is.

Standing rules need two people

An approver can pre-authorise a narrow class of action so they stop being the bottleneck. The rule is checked against the policy's own verdict, frozen onto the row when it was queued, so a rule can never approve something the policy said was never auto-approvable. The person who enabled the rule may not be the person whose run it approves.

The queue drains in order

It stops at the first row nobody has answered, so one stale intent walls off the ones behind it. That is deliberate. Declining is not gated at all, because refusing is the fail-safe direction and anyone should be able to say no.

The roster

The seven agents.

Four of them do product work, one routes, and two live in a chat tool. Each carries its own instructions and tool scope, editable in Settings.

Ops

Full product access

The generalist. Reaches the whole tool registry, subject to the permissions of whoever is asking.

Risk

Risk register

Keeps risks and their treatments current instead of leaving the register to rot between audits.

Docs

Library and retrieval

Searches the indexed document library and drafts from templates, answering with citations.

Quote

Estimates and quotes

Builds pricing scenarios and prepares quotes. Promoting an estimate to a quote still stops for a person.

Router

Chat only

Classifies what was asked and dispatches it to the right specialist. It holds no product tools of its own.

Slack

Slack workspace

Answers mentions and direct messages about tasks, risks and document search. Deliberately unreachable from the dashboard or the machine API.

Teams

Microsoft Teams

The same assistant, in Teams channels and chats.

What stops an agent costing you a surprise.

No agent tool can raise its own budget or mute its own alarm, and none of the scheduled sweeps calls a language model at all.

Spend cap

One hard ceiling set by the deployment, which the interface can only tighten under. It refuses a run at the start rather than mid-way, because a turn killed between tool calls can leave a queued action nobody asked for. No agent tool writes the budget table, and that is checked against the live registry rather than assumed.

Traces

A step-by-step record of what an agent actually did on a given run, with sensitive values filtered out of the spans before they are stored.

Audit log

Every write, who made it, and on whose behalf. Agent writes and guardrail violations appear alongside human ones rather than in a separate log.

Configuration

Per-agent instructions, model and allowed tools live in the database and are edited in Settings. Changing what an agent may do is not a deployment.

Handoff

Agents pass work to each other through the task record with a hop budget and audit events, so a chain of three agents is readable afterwards.

Guardrails

Moderation, PII detection and prompt-injection detection on the paths where untrusted text reaches an agent, with violations written to the audit log. Switched on by configuration.

When it cannot answer properly, it says so.

A product that quietly degrades is worse than one that fails loudly, because nobody knows which answers to distrust.

Search

Without an embeddings key, document search falls back to keyword matching and the interface names what still works rather than returning quietly worse results.

Sentiment

Any sentiment figure carries its reasons and a caveat that it is a keyword heuristic, everywhere it appears.

History

A chat thread whose message bodies are missing reports that the history is unavailable, instead of presenting an empty conversation as a real one.

Feeds

Every monitored source states its last item count, last success and consecutive failures, so a feed that has been returning a sign-in page since March does not read as a quiet month.