Human decisions / machine work

Let them act.
Know what you allowed.

Inspect a request before you decide. Approve it once, deny it, or deliberately give a supported action a standing permission.

Burgundy doors with a narrow lime-lit opening
An interactive explanation

One answer.
Two very different futures.

Try an ordinary approval, then repeat the request. Reset and grant a standing permission to see what changes.

permission request

Run “weekly research”

Scope: this named workflow. Its individual actions still meet their own permission checks.

A simplified demonstration of supported workflow permissions. Nothing runs. No permission is stored after you leave.

The controls in practice

Be specific
about authority.

A single request

Approve once.

An ordinary approval answers this request. It does not quietly become a rule for future work.

A supported scope

Grant permission.

Choose a standing permission explicitly. Future matching requests may use it while valid. Permissions can expire, exhaust their uses or be revoked.

A recorded decision

Return to the evidence.

Inspect the action, decision and execution events in a local hash-chained log. Tamper-evident does not mean impossible to alter.

ntndOS / product capture
The product’s permissions, activity and control surface
The product’s permissions, activity and control surface · 8 September 2026. Development data shown.
Costs are a decision too

Choose the model.
Watch the spend.

Cloud usage is estimated from the calls and prices the engine knows about.

Budget checks run before another call. A call can take spending past the limit, and unpriced models are not covered by the same estimate. Treat the figure as an operating signal, not an exact billing invoice.

A local fallback requires a suitable model available through Ollama.

Read the model and storage details ↗︎
Choose a provider + model↓Check the current estimate↓Proceed, stop, or use a configured local fallback
Questions that deserve straight answers

What does the gate
actually mean?

Does every connector action always ask me?

Rules differ by action and connector. Some read actions and replies within an allowed context can proceed under existing authority. Review the actual request and permission scope; the website does not promise a prompt before every action.

Can an agent’s instructions override permissions?

Instructions describe the job. They do not themselves create runtime authority. A skill is a method, and a permission is a separate control.

Does a valid permission mean the result is good?

No. Permission answers whether an action may proceed. Review the delivered file for accuracy and usefulness. The richer result-review cycle is on the roadmap.

Is the audit trail immutable?

It is hash-chained and designed to make alteration detectable. It is a local record under the operator’s control, not a claim that modification is impossible. Removing the newest entries can escape detection without an independent checkpoint.

The next move is yours.

A company you can direct.

Tell us about the work you would explore and its boundaries.

Request alpha access
Nova / a working session
Expanded product screenshot