Operations
Scoped authority,
and a record of everything.
Agents get their own name, their own key, and exactly as much of your work as you decide — until you take it back.
Agents
A party, not a costume
A plug-in runs as you: everything you can see, no record that it was there, nothing a counterparty can verify. An Altimist agent is a separate party with an identity of its own — which is what makes both trust and revocation possible.
Its own handle and key
Named, resolvable and distinguishable from you in every thread, every document and every payment.
A mandate you can revoke
What it may reach, what it may spend and until when — written down, enforced, and cancellable in one action.
An audit trail by default
Not a logging feature you switch on. Every operation is signed as it happens, and nothing is exempt.
Billed like a colleague
Charged per agent per month for identity, with intelligence metered separately — see Pricing.
A mandate, in full
Image placeholder
The Operations console. Left: the agent list with live mandates and a countdown on one that expires today. Right: the op-log streaming — each row a signed operation with actor handle, object, action and a revert control; one row expanded to show the signature and the grant it acted under. This is the screenshot a sceptical enterprise buyer will zoom into, so the data must be plausible and the typography exact.
16:9 · 2400×1350 · webp
The op-log
Every change signed, reversible, and attributable to a named party.
Not a feed of notifications. The op-log is the record the product itself runs on: each operation carries who did it, under which grant, against which object, and can be reversed from the same row. Export it whole, or query it.
Attributable
Human or agent, always by handle. “Someone on the team” is not an answer the system can give.
Reversible
An operation can be undone as cleanly as it was applied, because the operation — not the file — is the unit.
Exportable
Continuous audit export on Business and above, in a form your auditors can read without our help.
Treasury
The difference between advising and doing
An assistant that can only write hands the work back at the last step. Treasury is what closes it — under a mandate, with a limit, and with a record.
Observe
Read-only. Balances, transactions and invoices in view, with no funds held and nothing to authorise. Included from Team.
On
Agent wallets, spending mandates and settlement — the agent watches the price, books it and tells you it is done. Business and above.
Administration
What an administrator actually gets
| Control | What it does | From |
|---|---|---|
| Grants & mandates | Scope any person or agent to named objects, with an expiry and a spend limit | Personal |
| Op-log | Signed, attributable, reversible record of every operation | Personal |
| Org Brain | Retrieval across the whole corpus, respecting every grant on the way | Team |
| Pooled allowances | Intelligence, storage and agents pool at the account, never per seat | Team |
| Isolated tenant compute | Your corpus and its index on compute nobody else shares | Business |
| SSO & SCIM | Directory-driven joining and leaving, enforced at the door | Business |
| Audit export & DPA | Continuous export, data-processing agreement, Zero Data Retention | Business |
| Dedicated deployment | Your own hardware in your own building, or a dedicated tenant on ours | Sovereign |
Give it three folders and until Friday.
Start with one agent and one project. Widen the mandate when it has earned it — and narrow it in a single action when it hasn't.