01Harnesses
One harness, every workspace.
Compose skills, hooks, MCP servers, and prompt overrides into reusable harnesses. Build once for the team, ship to every laptop, update centrally — no per-machine drift, no copy-paste configuration.
Security publishes a `pii-redaction` harness. Every workspace inherits it on the next session.
02Roles
A preset for every role you have.
Start from a growing library of role presets — engineering, qa, finance, design, support, and many more — or compose your own. Each preset is a starting point your platform team customizes bespoke. Permission changes invalidate sessions instantly.
Finance uses the `month-end-close` preset with a NetSuite MCP and a SOX guardrail; design uses `brand-review` with read-only access to the design system.
03Hooks
Guardrails before the model acts.
Hooks fire before, during, or after every tool call — block destructive commands, gate approvals, redact PII, enforce working hours. Templates ship ready; add your own in TypeScript or bash. Enforced on the desktop, audited in the cloud.
Block any external API call that contains an email or SSN. Demand human approval before the agent sends a customer-facing message.
04Skill tuning
Reshape any skill with a click.
Pick a preset — security-focused, onboarding-friendly, executive-summary — or describe the change in your own words. Extender generates three variants, you pick one, and it rolls out to the team as a saved preset.
Finance lead retunes the `report-summary` skill for plain-English exec briefings. Saved as a tenant preset, applied across every analyst workspace.
05Providers
Claude today, your choice tomorrow.
Ships with Claude. v1.x adds OpenAI Codex and any Anthropic-compatible provider — switch per workspace, per skill, per cost target. Skills, hooks, and roles stay provider-agnostic, so your harness travels with you.
Research team on Claude for long-context work, ops team on a cheaper model for routine summaries — same audit, same governance.
06Architecture
Your data on your machine.
Chats and files stay on your laptop. The control plane governs roles, harnesses, and audit — and never sees a prompt unless you opt in. Bring your own API key; no SaaS lock-in on the hot path.
A legal team runs locally on encrypted laptops; the cloud only stores who-changed-what for compliance, never the conversations.