Product

An intent gets worked, not filed.

A conversation on one side, a record being built on the other — questioned, evidenced and agreed, growing as the work is understood, until it is strong enough for someone, or something, to act on.

How an intent progresses

What an intent picks up as it is worked.

Five things, and none of them is a stage it passes through — they are all live at once. The agent revisits what is understood and whether it is ready on every turn, which is why an intent gets stronger by being worked rather than by advancing.

  • Capture

    What is being asked for?

  • Understand

    What do we still not know?

  • Gate

    Is this strong enough yet?

  • Approve

    Who is answerable for it?

  • Publish

    What exactly did we agree?

What the record holds

A conversation on one side. A record being built on the other.

It exists from the first message and grows as you talk. The eight below are where most intents start, not a form to complete — people and agents add to them, revise them, and put claims under them as the work is understood. Every part carries the evidence behind it and a state saying how solid it is, so “we never decided that” stops being a conversation anyone has to have.

At a glance

What is this, for someone arriving cold?

Goal

What are we actually trying to achieve?

In scope

What is inside this piece of work?

Out of scope

What is explicitly out — so nobody assumes it in?

Definition of done

How will we know it worked?

If it breaks

What happens when it goes wrong?

Systems affected

Which systems and teams does it reach?

Why now

What changed to make this worth doing now?

Three claims, three states

Every line in an intent is a claim, and every claim carries where it came from and how solid it is. A disagreement is a state the record holds, in plain sight, until somebody settles it.

At a glanceGoalIn scopeOut of scopeDefinition of doneIf it breaksSystems affectedWhy now
In scope3 items · 1 contested
The line comes down during the August shutdown.Agreed
Fromwhat was said in the Q3 planning review
Proposed by Dev Anand’s agentAccepted by Marcus Rivera
The new tooling is tested and signed off before the line comes down.Proposed
Fromtooling-qualification-plan.pdf
Waiting on quality to accept.
The whole changeover fits into one weekend.Contested
Fromthe tooling takes six weeks to arrive and nobody has ordered it yet
Supply chain disagrees. Open until somebody settles it.

Illustration — one section of an intent: what is agreed, what is still proposed, and what is contested.

Readiness is computed from those states — shown as vague, actionable or ready, never a score. A number would invite an argument about the number instead of about the work.

The knowledge graph

Records do not sit apart. Five intents across one workspace and the core they share — each node is something the organisation established once, and each edge says how the two relate. Nothing here was entered twice.

touchessettledhitinheritsreusesbookscitesreusescitesbooksrevisesINT-0142Line 4 changeoverINT-0155Meridian second sourceINT-0163Q3 tooling orderINT-0171Line 7 changeoverINT-0188Housing spec revisionpartDrive housingconstraintTooling: 6-week leaddecisionTwo weekends, not oneevidenceValidation run · passedwindowAugust shutdown

Diagram — the knowledge graph across a workspace. Drawn, not captured: this is the shape of the record, not a screen.

How the intent gets deeper

It asks before it assumes.

Most tools in this category are competing to ask you less. This one is built the other way round — because the questions nobody asked are exactly what the agent ends up guessing.

It asks in batches

Questions arrive together with the options already laid out, so answering is a few decisions rather than an interview.

What it infers, it marks

Anything the agent worked out rather than was told is flagged inferred — confirm. It is never quietly folded in as though you had said it.

It shows what is thin

Every part of the intent carries a state — weak, ambiguous, conflicting — so the gaps are visible before the build, not discovered after it.

It cannot assert what it cannot cite

An agent that has no grounding for a claim has to ask instead. Its uncertainty becomes a question in your queue rather than a guess twenty steps deep.

Every proposal is the agent’s. Every acceptance is yours.

That is where the grounding actually comes from — not from the model being careful, but from a person having said yes. It is also what makes it safe to let the model propose freely: nothing it says can settle anything on its own.

How it holds

Why an agent here asserts less than it otherwise would.

01

An agent may not assert what it cannot cite.

Grounding is mandatory. An agent that cannot ground its move must ask instead — so its uncertainty becomes a question in your queue rather than a guess twenty steps deep.


02

An agent acts for someone, and never exceeds them.

Authorship is always “Priya’s agent, for Priya”. A commenter’s agent cannot write a claim, because she cannot. This is a check on the write path, not a label.


03

Nothing is erased.

The record is append-only and replayable. Deletion is a state, not an erasure — so any past decision, and the reasoning under it, can be reconstructed.


04

Nothing happens that is not attributable, grounded, bounded, and revocable.

The envelope holds wherever you set the autonomy dial. It is what makes the dial safe to move at all.

Anything a person must defend in an audit is code. Anything that only has to be helpful is the model.

What an agent is given

You don’t write the harness. You build the intent.

A harness is four things: the tools an agent may use, the boundary it may not cross, what it needs to know, and how anyone can tell it worked. An intent already contains all four.

  • Tools

    What may be acted on

    systems affected

    The systems this intent reaches — named, and agreed by the people who own them.

  • Permissions

    What may not

    in scope · out of scope · if it breaks

    The boundary, stated positively and negatively, plus what happens when it goes wrong.

  • Memory

    What it must know

    why now + evidence

    The context, the attached evidence, and the prior intents this one builds on.

  • Verification

    How we know it worked

    definition of done

    The success criterion, agreed in advance rather than argued afterwards.

How an intent's history is kept

Revisions run down the spine and each build hangs off the revision it came from. Two builds from one revision are siblings: both valid, neither replacing the other.

Revision 4Current
Deprecated v1 — superseded by v2 · SOC 2 sign-off recorded
Release v3In useRollback step added · Alex Johnson · yesterday
Release v2ReleasedSSO scope added · Alex Johnson · yesterday
Two builds from one revision — siblings, both valid, neither replacing the other.
Revision 3Superseded
Released v1
Release v1ReleasedFirst published plan · 4 days ago

Illustration — revisions run down the spine; each build hangs off the revision it came from.

So the thing an agent runs on is compiled from evidence your team already agreed on — not written from memory, per model, and rewritten every release.

Which is also why it can be governed at all: prose has nothing to attribute, nothing to attest against, and no basis on which to widen what an agent may do.

Capabilities

What you actually get.

Five clusters, each doing one job in the same product. Every one lists what it refuses as well as what it does — usually the more informative half.

01

The shared understanding

A conversation on one side. A record being built on the other, growing as you talk.

The record exists from the first message. Eight typed sections, from at a glance through to what happens if it breaks. Each carries the evidence behind it and a state saying how solid it is. Readiness is computed from those states and shown as vague, actionable or ready.

  • Every value carries the evidence it came from
  • Claims can be proposed, contested and resolved in the open
  • Inference is marked inferred — confirm, never quietly folded in

what it refuses

Readiness never renders as a number. A score invites an argument about the score instead of about the work.

02

Collaboration and assurance

Many people and their agents on one intent, live — and a way to say who is answerable.

Three independent layers that combine rather than compete. What you may do (viewer, commenter, contributor). What you are answerable for (reviewer, attestor, approver, evaluator). And where you belong (org admin, workspace admin, member, guest). One person can be a contributor and a reviewer; an outside auditor can attest without ever seeing the workspace.

  • Every contributor is equal — there is deliberately no owner role
  • Attestation is bound to a named standard, and blocks publish
  • Presence, competing proposals and changes arriving without a refresh

what it refuses

An agent never appears as the person it works for. Authorship is always “Priya’s agent, for Priya”.

03

Artifacts and the registry

What the understanding produces, versioned and addressable.

A build produces an OKF bundle — vendor-neutral markdown plus a relationship graph, not a proprietary container. Checkpoints give free undo while a draft is moving; versions are immutable published snapshots you can point at. The registry is the catalog across every intent your organisation has worked.

  • Checkpoints are one-click undo; versions are permanent
  • Every version is addressable and shareable
  • The format is open, so the knowledge is not trapped in a schema only we can read

what it refuses

There is no download button. Hand-off is a scoped credential with a read log, because a downloaded file cannot be recalled.

04

The knowledge graph

The same understanding, kept — and everyone can build one of these. Few can afford to run one.

This is the first cluster at a different scale, not a second product. The shared understanding one intent reaches — its claims, its evidence, its decisions, the systems it touched — is exactly what accumulates here. Bring your own sources and every intent contributes back, until what you have is a grounded map of how your organisation actually works and each new intent starts richer than the last.

  • The position is cost: construction, search, refresh and maintenance
  • Vocabularies capture your organisation’s own controlled language
  • Evaluations define what “good” means for your work, not ours

what it refuses

We do not claim to support every source under the sun. What is connected is what is connected.

05

Control and economics

What makes the rest of it safe to grant.

Token consumption is visible before a run, measured after, and capped by policy at workspace level — so unsupervised work has a floor rather than an open exposure. Every action is attributable and the record is append-only. And the whole thing runs as a managed service or inside your own network, from the same artifact.

  • Spend caps at workspace level, set by an admin
  • An append-only audit trail; deletion is a state, not an erasure
  • SaaS or your own infrastructure, twelve-factor, no SaaS-only dependencies

what it refuses

Consumption is shown as a governance signal, never as a bill and never as a number to be impressed by.

The ask

See it on one of your own intents.

The fastest way to understand Intent Studio is to walk something you are actually working on through it. Half an hour, your intent, no slides.

A demo is a conversation with the people who build it. Try it now opens the app sign-in.

Next upwhat we can prove, and what we cannot.

Trust