Autonomy

How much your agents decide on their own.

Capability you can buy. Being able to defend having let it act is the part nobody sells you. How much your agents settle for themselves is something you set, and can widen. This page is everything that has to be true around that: who may move it, what an enterprise needs in place first, and whose network the whole thing runs in.

Who may do what

Who may do what, who answers for it, and where they belong.

Three separate layers that combine, rather than one list of roles forcing a choice between them. So one person can be both a contributor and a reviewer. An outside auditor can attest without ever seeing the workspace.

What lands in front of a person

Only the decisions a person has to make, each carrying the reason it could not be settled by an agent.

Open · 2
ReviewExtend the line 4 shutdown to two weekendsOverdue 2h
INT-0142asked yesterday
Policy flag: personal data leaving the org boundary. Recommend reject, or approve with an anonymisation condition.
ApproveWith conditionsAsk for changesReject
ApprovalQualify Meridian as second-source for the drive housing4h left
INT-0155asked yesterday · chased twice
Financial impact above the requester’s delegated authority. Scope is bounded; suggested condition: exclude EU suppliers.
ApproveWith conditionsAsk for changesReject

Illustration — what is asked of you, and the reason each item needs a person rather than an agent.

Participation

One per person

  • ViewerRead the intent, the evidence and who signed what
  • CommenterEverything a viewer can, plus thread on anything
  • ContributorFull authorship — shape it, talk to the agent, run builds, spend

Every contributor is equal. Nobody needs an author’s permission to move work forward, and there is deliberately no owner role.

Assurance

Zero or more per person

  • ReviewerA colleague’s second pair of eyes — advisory, never blocking
  • AttestorSigns off against a named standard — SOC 2, GDPR, a customer contract. Blocks publish
  • ApproverHolds release authority, and can halt or revoke afterwards
  • EvaluatorConfirms after the fact that the output met its own definition of done

Compliance people do not call themselves reviewers — they attest. The specialist role gets the specialist word and the plain role keeps the plain one.

Membership

Workspace level

  • Org adminBilling, SSO, workspaces
  • Workspace adminInvites, policy, spend caps
  • MemberCreate and contribute; share a single intent outward
  • GuestSees only the intents shared with them — never the workspace

Guest scoping is how an auditor, a consultant or a customer contact comes in without the workspace coming with them.

Built for the enterprise

The questions procurement asks, answered structurally.

Runs on your infrastructure

SaaS and on-premises from the same artifact — 12-factor config, no SaaS-only dependencies. The only runtime external dependency is the model provider you configure.

Nothing leaves as a file

There is no download button. Hand-off is a scoped credential bound to a published version, with a read log, revocable at any time — because a downloaded file could not be recalled.

Every action is attributable

Who did what, when, and why — append-only and replayable. Deletion is a state, not an erasure, so any past decision can be reconstructed.

Spend is bounded, not open-ended

Token consumption is visible before a run, measured after, and capped by policy at workspace level — so unsupervised work has a floor.

Where it runs

Some work can’t leave the building. That’s a deployment question, not a compromise.

Today we host it. The same artifact also runs inside your own network — twelve-factor configuration, no SaaS-only dependencies, and the only thing it reaches out to is the model provider you choose.

available today

Hosted by us

We run it. You sign in and start working an intent — nothing to install, nothing to provision.

talk to us

Your own infrastructure

The same artifact, inside your network. Your intents, your evidence and your audit trail stay on infrastructure you control, pointed at your own models.

The ask

See it on one of your own intents.

The fastest way to understand Intent Studio is to walk something you are actually working on through it. Half an hour, your intent, no slides.

A demo is a conversation with the people who build it. Try it now opens the app sign-in.