One workforce. One set of gates.
An agent can see what the person it works for can see - and nothing more. The fail-closed gate means if it is not allowed, it does not run. There is no separate, weaker permission system for the bots. That is the difference between "we adopted AI" and "we can let AI near real data".
Your AI workforce, on the same chart.
A live, draggable organisation chart where agents appear alongside the humans they work for - same structure, same reporting lines, same rules.
- Agents sit on the reporting lines. Not a separate list of bots in a settings page - the actual chart, with the person accountable for each one. Live
- Unassigned agents are visible. Deployed but nobody's - the chart shows them rather than letting them drift. Live
- Filter by department, rank or type. Pan, zoom, and see the shape of the whole workforce. Live
Ranks that match a real business.
Owner, Director, Manager, Specialist, Implementer - not "admin" and "viewer". Rank and department set what each person, and the agents they run, are allowed to do.
- One authority, checked at the data layer. Every read and every action goes through the same fail-closed service - for people and agents alike. Live
- Finance's agent cannot read HR's files any more than finance's people can. In a multi-department business this is the property that makes AI adoptable at all. Live
- Skills and approval rights per person. A slide-out on each member showing what they can do and what they may sign off. Live
- Import your team. A wizard reads your Slack or Google Workspace directory - name, email, title, department only - and builds the roster. Partial
Give a team an agent.
Groups are teams with shared agents attached - give Marketing a shared strategist in one step, and its work becomes organisational knowledge automatically.
- Shared agents write back. A group agent's work feeds the Knowledge Brain; a private 1:1 agent's does not, unless its user opts in. Live
- Controlled onboarding. Invites and access requests are human-only and routed for approval - an agent cannot invite itself a colleague. Live
- Unlimited human members. No per-seat fee, so governance never argues with headcount. Live
Humans gate the dangerous things.
One queue where everything needing a human decision arrives: agent deployments, listener and workflow go-lives, budget top-ups, high-risk actions - and every client deliverable before it leaves the building.
- Nothing reaches a client unsigned. Agents produce drafts; a deliverable moves draft → pending approval → approved, and only then publishes. Live
- Who may approve is itself governed. Approval rights are an explicit grant, not a job title someone assumed. Live
- Deployments are gated. An agent does not reach a user until a person signs it off. Live
- A lens, never a separate store. The queue is a view over the real items, so approving here is the same act as approving in place. Live
Nobody runs up a five-figure bill.
Every agent carries a budget. When it is spent, the agent stops and files an approval request rather than quietly continuing. Spend against budget is visible in real time.
- A budget per agent. Set it when you deploy, adjust it whenever - and see the run rate against it. Live
- Exhaustion stops the agent. It files an approval instead of overspending. No surprises at the end of the month. Live
- Per-account spend, too. For client work, a soft budget per account - see what serving each client costs without halting delivery mid-month. Partial
- Model tier is a cost lever. Quality, balanced, fast or cheap, set per agent - your executive coach and your data-cruncher need not cost the same. Live
Most AI adoption stalls right here.
Not on capability - on the question nobody can answer: what exactly will it be able to see? A separate permission model for agents means a second thing to audit, and a second place for it to be wrong.
Agents are principals like people. The same rank, the same departments, the same explicit grants, the same fail-closed gate. There is no "bot permissions" screen to reconcile with the real one.
At the data layer, not in each screen that happens to remember. An agent structurally cannot retrieve what its principal is not cleared for.
"It can see what the person it works for can see." That is the whole answer, and it is the one that gets AI past a security review.
Governance is one component.
Answer the security question before it is asked.
A Red Brief maps your departments, ranks and grants onto the workforce you would actually run.
Book a Red Brief