Governance & security

Give colleagues the access they need—and no more.

ColleagueOne puts isolation, identity, model access, budgets, data policy and human approvals around the work loop.

01 / RUNTIME

Isolated cloud computers.

Each colleague runs inside its own Firecracker microVM sandbox.

02 / SECRETS

Credentials stay in the gateway.

Vendor credentials are not handed into the agent runtime.

03 / MODEL ACCESS

Scoped keys and budgets.

The model gateway issues per-run scoped access with budgets at colleague and organisation level.

04 / DECISIONS

Approvals for sensitive actions.

Policy can bring a person into the loop before work crosses a sensitive boundary.

Control plane

Controls your organisation can reason about.

Governance works best when it is visible in the places where colleagues are created and work is reviewed.

Identity
Owner, admin and member roles; Google, Microsoft Entra, SAML and OIDC SSO; SCIM provisioning; email sign-in links; invite-only access.
Data policy
Data classification labels and DLP policy around organisational content.
Accountability
Audit logging and clear review states for results, approvals and questions.
Models
Model-agnostic access to OpenAI, Anthropic and other providers through the model gateway.
Memory
Learned facts are reviewable: people can approve or revert what the system retains.
Regional posture
Built for UAE organisations and aware of UAE PDPL requirements. No claim of UAE data residency is made.

Enterprise identity

Bring member lifecycle and sign-in under organisational control.

SSO & SCIM

Review points

Keep sensitive decisions distinct from routine progress in Needs You.

Approvals guide

Responsible disclosure

Report a suspected vulnerability privately to the Avapti security contact.

Disclosure policy
Invite-only beta

Bring AI work inside an accountable operating model.

ColleagueOne is currently invite-only. Tell us what your organisation wants to hand over.