Developers
Build AI agents
on your data
An agent is only as trustworthy as what it can see and what it can prove. Both are properties of the data layer underneath it, not of the prompt.
Capabilities
Grounded, permission-aware and auditable
The three properties that decide whether an agent is allowed near a production process.
Tools over the graph
Agents call typed retrieval and traversal rather than scraping a text dump and hoping.
Acting as a user
An agent inherits the permissions of whoever it runs for, and cannot exceed them.
Full trace
What it read, what it called and what it concluded, kept for the conversation that follows an odd answer.
Your own tools
Register your functions alongside the built in ones.
Any model
Route agents to whichever model suits the task, including a local one.
Long-running work
Research-style tasks that run past the length of a request.
Questions for developers
The things worth asking first
Can an agent see more than the user?
Not through the built in tools: they search and read as the user who asked. Your own tool code gets both an unrestricted query and one scoped to the current user. Use the scoped one, and limit who may call a tool with its access groups.
How do I debug a bad answer?
Every agent run is stored as a record: the prompts, each tool call with its arguments, its result and how long it took, and the calls of any agent it handed work to. A wrong answer is a thing you can read rather than guess at.
Can agents write back?
They can call tools you register, including ones that write. What those tools permit is your decision.
Your data. Your infrastructure.