A control plane for your digital workforce
SyftOS is the governed runtime between your digital workers and your tools. Workers reason and propose; a person approves what matters; and every action is recorded. Deploy a digital department, set up a repeatable workflow, and keep a human in the loop by default. Here is how the whole loop fits together.
One governed loop, every time
Whether it runs once or a thousand times, every department and every worker moves through the same five steps: connect, deploy, run, approve, audit.
- 01
Connect
Connect your tools with scoped credentials held in an encrypted vault. Read access runs inline; anything that changes the outside world is gated.
- 02
Deploy
Deploy a department or an agent from the library, or describe what you need to the conversational builder. Published versions are immutable, so every run is reproducible.
- 03
Run
Workers execute on a queue — never inline in a request. They reason over your context, call read tools freely, and prepare the actions that change things.
- 04
Approve
Every side-effecting action pauses in the Approval Centre for a human decision. No autonomous side effects: approval is the default, not an add-on.
- 05
Audit
Every event is projected to an append-only, tamper-evident log, and Insights turn run history into cost, reliability and time-saved you can show the board.
Workers propose. People decide.
Read-only tools run inline: listing tasks, reading a thread, pulling a balance. But the moment a worker wants to change the outside world, that action stops and waits in the Approval Centre.
- Human approval is the default, not a feature you remember to switch on.
- Workers never approve their own work — that permission is reserved for people.
- Every decision, approved or rejected and why, is written to the audit trail.
Guardrails before the gate
Approval is the last line, not the only one. Before an action ever reaches a person, you have already shaped what a worker can do, how much it can spend, and where its data may go. That layered governance is what holds the work, long before any model gets a say.
Human approval by default
Side-effecting tool calls become actions that wait in the Approval Centre. Agents propose; people decide. An agent can never approve its own work.
Tamper-evident audit trail
Every event is written to an append-only log that is hash-chained per tenant. Any edit, deletion or reorder is provably detectable, and the trail exports with a signature.
Earned autonomy, never assumed
Relax the gate one notch at a time for a proven agent and action, only on a measured trust score, always reversible, and snapped back on any failure. High-risk actions never auto-approve.
Tool guardrails
Constrain what each tool may do with allow-lists, payload caps and PII redaction, so an agent stays inside the lines you set, before approval is ever reached.
Per-agent budgets
Cap spend and usage per agent and per workflow. When a budget is reached, work stops — no runaway costs, no surprises on the invoice.
Provider & residency controls
Choose which AI providers an agent may use, opt them out of data retention, and control how long run history is kept. Governance over the model, not lock-in.
Set up the work, your way
Deploy one of the built-in digital departments, or describe what you need to the conversational builder and have it draft a governed worker for you. You can drive that same builder by microphone. Everything starts as a draft you review.
Conversational builder
Describe what you need in plain language and the builder drafts a governed agent, or a multi-step workflow, for you to review. It only ever produces a draft, defaulted to the strictest approval policy.
Voice build
Drive the same governed builder by push-to-talk microphone, with the transcript always on screen and confirm-before-commit. (Microphone only — no telephony.)
Department & agent catalogue
Deploy a pre-built department or a single agent from the built-in catalogue, or save your own setup as a reusable template. Installing only ever creates a draft your team reviews; templates carry safe config only, never credentials or data.
Grounded knowledge (RAG)
Ground agents in your own documents, retrieved as cited, top-k passages. Each source is cited in the run timeline, so grounding is auditable rather than a black box.
MCP bridge & custom tools
Connect external MCP servers or declare your own HTTP-call tools without platform code. Each is classified for risk and flows through the same approval gate and audit as native tools.
Immutable versions & dry-run
A published agent version can never be edited — only superseded. Test any version against real context with every side effect simulated, before its first real run.
Run it like a real operation
A digital workforce only earns its place if you can see what it did, what it cost, and what it saved. SyftOS gives you the queue, the numbers and the record — Insights surface an indicative £-value of time saved, shown for your own judgement and never invoiced.
Approval Centre
One queue for every pending action, with the full context behind each one. Approve, reject with a reason, or make governed bulk decisions. The gate never weakens.
Agent Control Centre
A single pane of glass: a 30-day cost-and-outcomes snapshot, a cross-agent activity feed, pending approvals, rolled-up failures and governor alerts for overdue approvals and integration health.
Branching workflows
Chain agents into workflows that branch, run steps in parallel and take a different path on a condition, for the processes you run again and again, still gated and audited end to end.
Governed delegation
A supervisor agent can hand work to specialists, and the handoff is itself an action you approve and audit. A worker is never granted more authority than it already holds.
Value & performance insights
Run reliability, cost per outcome, the auto-handled-vs-reviewed split, time-to-approval and an indicative £-value of time saved — measured, not guessed (a shown estimate, never invoiced).
Triggers, schedules & API
Start a run by hand, on a schedule (in your own timezone, DST-correct), from a governed inbound webhook, or from your own systems via a scoped, token-authenticated public API.
Built for the questions procurement asks
SyftOS is multi-tenant from the ground up, with strict isolation between organisations. Single sign-on and a SOC 2 readiness evidence pack are there for the people who sign off the rollout, and a Data Processing Agreement is available on request.
Single sign-on & SCIM
One identity provider per tenant over SAML 2.0 or OIDC, with attribute and role mapping, plus SCIM directory-driven provisioning and de-provisioning. (Available from the Growth tier.)
Code Governance
Govern the pull requests your AI coding tools already produce: a distinct-approver merge gate and an immutable attestation binding the diff, the detected tool, the named approver and CI status. It governs the change — it never runs your code. (GitHub today.)
Multi-tenant isolation
Every tenant is strictly walled off by automatic query filtering, ownership re-checks, per-tenant file prefixes and isolation tests that gate every release. Cross-tenant access simply does not exist.
Encrypted secret vault
Integration credentials and tokens are held encrypted and scoped per tenant, connected by OAuth or API key, never exposed to an agent.
SOC 2 readiness evidence
An auditor-facing evidence pack maps the SOC 2 Trust Service Criteria onto controls already implemented in the platform. This is readiness tooling and evidence, not an issued SOC 2 certification.
Data Processing Agreement
UK GDPR-aligned processing, named sub-processors and a Data Processing Agreement on request, with provider and data-residency controls available on Enterprise terms.
See the loop on your own tools
Book a 30-minute demo and we will run the governed loop on your own tools — your real work, with you approving every step.
SyftOS is in early access — creating a workspace starts a guided setup with a dry-run sandbox, not instant billing.