Agent Systems
Give agents tools, limits
and evidence
Inventory agent activity, define permissions, evaluate behaviour, monitor runtime decisions and expose safe tools through MCP and WebMCP.
Agent inventory
A list, not a surprise
See which agents exist, what they can reach, and where they last ran.
Agent
Last
Which agents exist
A list of what is running — not a surprise in production.
What this agent can reach
Inputs
- Calendarcalendar_write
- Bank sendmoney_out
Check published hours. Hold a free slot. Queue anything outside the rules with the record attached.
Change is reviewed
calendar_write — Everything else stays out.
Permission change
Waiting on a person
1 / 2What they can reach
Tools, permissions, and sensitive actions stay on the record.
Channels
Caller, Tuesday 08:14
Hi —
Booked a follow-up in the hours you already publish. Name, need, and callback window captured.
Queued for a person, with the record attached.
Phone
Where they last ran
Last activity is visible without opening every log.
Calendar write
Sensitive actions stay listed
What they can change is as visible as what they can read.
Permission controls
Least privilege, written down
Each agent gets only the tools and data it needs. The rest stays out of reach.
- 01
What it may read
Hours, inbox facts, the records in the job — named.
- 02
What it may decide
Book, reply, queue. Not an open mandate.
- 03
What it must not change
Bank, legal, or anything you have not listed stays blocked.
What this agent can reach
Inputs
- Calendarcalendar_write
- Bank sendmoney_out
Check published hours. Hold a free slot. Queue anything outside the rules with the record attached.
Change is reviewed
calendar_write — Everything else stays out.
Permission change
Waiting on a person
1 / 2Evaluations
Tested, then maybe shipped
Behaviour is checked on known cases before a change goes near live work.
- 01
Known cases first
Hours questions, complaints, new tools — the set you already accept.
- 02
Before it is near live work
A change waits until those cases pass.
- 03
Then maybe shipped
Shipping is a decision after the test — not the test itself.
Runtime monitoring
Watched, not hoped
Watch live runs for stalls, retries, and actions that need a person.
Watching
Run started — Still on this job
No progress — Stuck past the wait window
Surface the stall — Visible while it is running
This run
Status
Next
Note
Same record
A run that is stuck
Visible while it is still running — not after a weekly export.
This run
Retry on the same run
Hi —
A retry stays on that run — not a new ticket. Context stays attached.
Queued for a person, with the record attached.
Run
The same run record
A retry stays on that run — not a new ticket.
Queued
Actions that need a person
Those wait in a queue, with the record attached.
Failure analysis
A path back, not a shrug
Trace a bad outcome back to the step, tool, or input that caused it. What it called, and what it was given, stay with the outcome. The next action stays on the same record — retry, block, or a person.
Discuss thisLive calendar
Book if a slot is free in the hours you publish. Nothing else.
Slot
Status
Next
Approved inbox facts
Reply from the set you already maintain — not the open web.
Ask for the next step
Person in the queue
Anything outside those rules waits with the context attached.
Outside the rules
Structured actions
Tools the agent may call, with the same limits a person would have.
