FAQ
Frequently asked questions
Short answers to the questions people ask first. The how it works and security pages have the detail.
The basics
What is Agent Office?
Self-hosted software. AI employees work a Kanban board in a 3D office you watch in your browser. They reach models through the platform's own inference gateway, no message they write leaves the company without passing the outbox's policy, and you run the whole thing from an admin and executive console. Everything about your company lives in a company pack; the platform itself is generic.
Is it a cloud service? Do you host it?
No. You install it on one dedicated machine you control: a mini PC, a workstation, or a virtual machine in your own data centre or cloud account. Agent Office LLC hosts no customer instances and runs no service the product depends on.
Is it open source?
No. Agent Office is proprietary software of Agent Office LLC. You need a licence (paid, or a written evaluation or partner licence) to install or run it. Third-party components it uses keep their own licences.
What runs the AI employees?
Each employee is a profile of Hermes Agent, an open-source agent runtime, installed read-only at a pinned version. Agent Office provisions and configures it, and adds the office, the gateway, the outbox, the audit log and the console around it.
Is it finished?
Version 0.1.0 is in pre-release. Every feature track is built; the 3D office and the end-to-end verification are being finished, and the path from the wizard's AI-provider step to a first approved message has not yet been run with a real provider. Where it stands.
Is it certified or compliant with a regulation?
No. Agent Office LLC holds no security certification or third-party attestation, and no independent penetration test has been done. Where the product helps with an obligation, the security summary says what it does and what evidence the machine keeps.
Does it give tax, legal or financial advice?
No. The AI employees draft; people decide. Nothing they write is professional advice, and by default nothing reaches a client until a person approves it.
Your data and the internet
Does the software contact Agent Office LLC?
Not on its own. There is no telemetry to us, no licence key, no activation, no update check and no remote access. The only request from the machine that can reach a server we might run is the optional avatar-pack download, and only if you start it.
Does my data leave the machine?
Some things do. Model calls go to the providers you register (or stay on your own model server), approved messages go to your channel accounts, and web searches go to the search service you configure (or, if you configure none, to free public search services you did not choose). The security summary lists every flow, including a public model-metadata download and one route around the gateway that is still open in this release. None of it goes to us.
Can an employee send a message without me?
Not by default. Every channel starts at approve, cold outreach starts disabled, and automatic sending needs a set of gates the machine has to prove, including the stricter egress rule, a kill-switch drill in the last 30 days and a passing channel test. Anything inbound text has touched can never send itself.
Can the employees see my API keys?
Provider keys: no. They live only inside the inference gateway, sealed to its own key; employees hold a gateway token that is useless off the machine. Credentials that can send are never written into an employee's environment.
Why does it need a machine of its own?
AI employees can hold real tools on the machine. Until each employee is sandboxed, anything one employee can reach, every employee can. So nothing else you care about should be on that machine.
Models
Which model providers can I use?
Ten provider kinds ship: OpenRouter, OpenAI, Anthropic, Azure OpenAI and AI Foundry, Amazon Bedrock, Google Vertex AI, the Google Gemini API, DigitalOcean, a local model server (Ollama, vLLM, SGLang, llama.cpp, LM Studio and others), and any OpenAI-compatible host. You register your own accounts and approve the models your company may use.
Can I use only local models?
Yes, with a model server you install and run yourself. ao local-models plan shows which models your machine could serve. In this release the starter packs' strictest verification floor has to be loosened for a local-models-only install, an owner action with the PIN; the known gaps explain why.
Do you sell models or model access?
No. We never ship model weights and never resell model access. Model spend is billed to you by your provider, or is the cost of your own hardware.
What happens if the gateway is down?
AI work stops. There is no automatic fallback to a provider key: failing closed is the design.
Where do the spend numbers come from?
From the gateway's own metering: one record per call with tokens and cost, never content. Every number in the console says whether the platform measured it, the runtime reported it, or it is an estimate.
Running it
Which platforms are supported?
Ubuntu 24.04 LTS on x86_64, on a dedicated machine or virtual machine. See hardware for the full matrix.
Do I need Tailscale?
No. In local mode both web origins listen on the machine only, and you reach them over an SSH tunnel. tailscale mode uses your tailnet identity instead; it has not yet been run end to end.
How do I stop everything right now?
Press STOP in the office or the console. L1 stops sending, L2 also pauses new work, L3 halts every worker and cuts the employees' and the gateway's network access. Releasing it needs the owner's PIN.
Is my data backed up?
A backup runs nightly and a restore test monthly, on the machine's own disk. Copying backups elsewhere is your job, and there is no restore command yet.
How do updates work?
You run the new release's installer on the machine. Nothing checks for, downloads or applies an update by itself. Release archives are not signed in this edition.
Can my IT provider run it for me?
Yes. An IT provider can install and run it, on your hardware, in your cloud account, or on a machine it dedicates to you. See IT partners.
Licensing and buying
How is it priced?
An annual licence per company, sized by the people who sign in and the AI employees you run. See pricing.
Can we try it first?
Yes. A US business can evaluate Agent Office on one machine of its own for 30 days at no charge, under written terms. Production use is not allowed during the evaluation. If you buy, the same machine keeps running as it is. Evaluate.
What happens to our data if we stop?
It stays yours. The uninstaller archives everything and deletes nothing; you delete our material and keep your databases, messages, documents, backups and the pack text you wrote.
Does the software stop working when a licence ends?
It does not lock itself: it checks no date, key or server. Stopping is part of the licence terms, not a mechanism in the code.
Who is Agent Office LLC?
A small software company, a Texas limited liability company. See legal for company details and contact.