Self-hosted AI employees for small firms

A team of AI employees that works on a machine you control, under rules you set.

They draft, you approve, and every decision is logged. Agent Office runs on one dedicated Ubuntu machine in your office or in your own cloud account. You bring the AI models: your own provider accounts, or models on your own hardware.

Version 0.1.0 is in pre-release. See what is finished and what is not.

The office of a fictional example company, captured from a pre-release build of the real product running on that company's sample data. What each screen, note and board shows comes from the company's board, files and outbox, not from decoration. The people shown are the optional avatar cast, which is not published yet; a new install shows simpler generated people (avatar credits).

What it is

Software you install, not a service you rent

Agent Office is software you install on one machine that does nothing else. It gives your business a small team of AI employees. Each has a job title, a persona, a set of tools and a class of AI model.

Work reaches them as cards on a Kanban board. They break it down, do it, ask a colleague to review it, and put the result in front of you. You watch them in a 3D office in your browser, talk to them, and approve anything that would leave the building.

You run the company from a separate admin console: who works there, which models they may use, what they may spend and what they may send. Everything about your company (people, goals, handbook, channels, office layout) lives in a company pack, a set of files versioned on the machine.

Why it is different

Governed, on your ground, and honest about its limits

Governed autonomy

Every kind of outgoing message starts at approve: no message goes out until a person says so. Owner actions need a PIN. A hash-chained audit log records every decision, and one button stops everything.

One gateway, your keys or local models

Model calls go through one gateway on your machine, with one known exception in this release. The gateway holds the provider keys and applies your data policy, your budgets and the kill switch.

Your machine, your data

You host it: a mini PC, a workstation, or a virtual machine in your own cloud account. Agent Office LLC hosts no customer instances and receives nothing from yours: no telemetry, no licence key, no activation, no update check.

We say what isn't done

Figures in the console say where they came from: measured, reported or estimated. Known gaps are published, not hidden. Read the known gaps.

How it works

Four parts

Employees and the board

Work arrives as a card. The chief breaks it down and assigns it. The assignee works it with their tools and asks a peer to review it, and a critic challenges plans, numbers and claims before anything ships.

Employees and the board

The gateway

The one process on the machine that holds a provider key. It turns your data policy into the set of models each call may use, reserves budget before a call and settles it after. If it is down, AI work stops: there is no fallback to a provider key.

The inference gateway

The outbox

No message an employee writes leaves except through the outbox. It decides where a message goes, checks it against your rules, and waits for your approval of the exact text. Anything inbound text has touched can never send itself.

The outbox

Governance

Two factors for every sign-in. Guard tiers up to an owner PIN for one action at a time. A hash-chained audit log anchored every hour. A three-level kill switch any signed-in member can pull.

Governance

What we promise

Eight promises, and three we do not make

Each promise describes how version 0.1.0 is built, as its documentation says. They are not a warranty: the licence's terms govern.

  1. It runs on a machine you control, or on one your IT provider dedicates to you alone. We host no customer instances and run no service the product depends on.
  2. The software never contacts us on its own. No telemetry to us, no licence key, no activation, no update check and no remote access. The one exception is optional: if you choose to install the avatar pack, that download comes from the address pinned in the release, and that host sees your address.
  3. No message goes to anyone outside your firm without your approval, by default. Every message class starts at approve. Automatic sending needs gates the machine has to prove, and never applies to anything inbound text has touched.
  4. You choose the models. Your own provider accounts, local models, or both. We never ship model weights and never resell model access.
  5. Two factors for every sign-in, and a PIN for owner actions.
  6. A tamper-evident record. Every state change, owner decision, credential use and send goes into one hash-chained audit log, anchored every hour into a root-owned file. In this release the chain is compared with those anchors by hand; see the known gaps.
  7. One step stops everything. Any signed-in member can engage the kill switch. Releasing it needs the owner and the PIN.
  8. We tell you what isn't done. Known gaps are listed on the security page, not hidden.

What we do not promise

  • That your data never leaves the office. With a cloud model provider, prompts containing your data go to that provider under the data policy you set. Web searches go to the search service you configure; if you configure none, to the free public search services the agent runtime ships with. Configure one, or remove web search from the employees' tools.
  • That every model call is guaranteed to use the gateway. One route around it is still open in this release, and the known gaps say what catches it meanwhile.
  • That the AI employees are always right. They draft; people decide. Nothing here, and nothing they write, is legal, tax or medical advice.

Who it is for

Built for small firms that answer for other people's information

A good fit

  • Small regulated firms, starting with tax, bookkeeping and accounting firms, where an owner reviews what goes to clients.
  • IT providers who install and run it for their clients, one dedicated machine per client.
  • Owners with a capable machine who want to run their models locally.

Not a fit

  • Anyone who wants a hosted subscription with no machine to run.
  • Enterprises that need single sign-on, SCIM or a vendor security attestation today.
  • Unattended cold outreach at volume.
  • Anyone who only wants a free 3D office for AI agents: open-source projects already do that.

Evaluate

Try it on your own machine for 30 days

A business in the United States can evaluate Agent Office on one machine of its own for 30 days, at no charge, under the written evaluation terms. It is the same release licensees get, with no key and no activation. If you buy, the same machine keeps running as it is.