curiosity

Developers

Build AI agents
on your data

An agent is only as trustworthy as what it can see and what it can prove. Both are properties of the data layer underneath it, not of the prompt.

An agent run, step by step An agent is asked why a pump failed twice. It reads a maintenance log, traverses the graph to the supplier, is refused the supplier contract the user cannot see, reads a supplier notice, and answers with three sources, logged. 01 · ASKWhy did pump P-22 fail twice in March?02 · READTCK-8812 · maintenance log42ms03 · CALLgraph.traverse(part → supplier)11ms04 · DENIEDSupplier contract · not visible to this user05 · READSN-0093 · supplier notice38ms06 · ANSWERSeal batch recall · 3 sources · logged
Every agent run: Grounded, Bounded, Audited Grounded: Context from the graph, with sources. Bounded: The permissions of the person it acts for. Audited: Every step and access recorded. All inside one every agent run. 01 Grounded Context from the graph, with sources 02 Bounded The permissions of the person it acts for 03 Audited Every step and access recorded

Capabilities

Grounded, permission-aware and auditable

The three properties that decide whether an agent is allowed near a production process.

Tools over the graph

Agents call typed retrieval and traversal rather than scraping a text dump and hoping.

Acting as a user

An agent inherits the permissions of whoever it runs for, and cannot exceed them.

Full trace

What it read, what it called and what it concluded, kept for the conversation that follows an odd answer.

Your own tools

Register your functions alongside the built in ones.

Any model

Route agents to whichever model suits the task, including a local one.

Long-running work

Research-style tasks that run past the length of a request.

Questions for developers

The things worth asking first

Can an agent see more than the user?

Not through the built in tools: they search and read as the user who asked. Your own tool code gets both an unrestricted query and one scoped to the current user. Use the scoped one, and limit who may call a tool with its access groups.

How do I debug a bad answer?

Every agent run is stored as a record: the prompts, each tool call with its arguments, its result and how long it took, and the calls of any agent it handed work to. A wrong answer is a thing you can read rather than guess at.

Can agents write back?

They can call tools you register, including ones that write. What those tools permit is your decision.

Your data. Your infrastructure.

Agents that can show their work