Agentcy Core

Agentcy Core brings client context, named agents, and accountable follow-through into the agency’s working day.

It is a work platform for agencies, built around a Supervisor for each client account and a Chief of Staff for the agency. It combines document reading, reviewed knowledge, a conversational Desk, supported connected actions, and scheduled follow-up, with permissions and records around consequential work.

A cream ledger book on grape linen, tied with a gold ribbon.
Not a chatbot with a client name. A named seat on one account, working from a record you can inspect.

The account knows things. The tools do not.

Client context lives in one person’s head, one thread, and a folder nobody has opened since the pitch. Generic assistants restart from zero every session, so the agency pays for the briefing twice. Five things change first.

01
Context before repetition

Give the team a usable account record, not another place to restart the brief.

02
Help now, curate for later

Discuss the document in front of you while governing what becomes durable knowledge.

03
Action with evidence

Distinguish a draft, a proposal, and a completed action.

04
Follow-up that exists

Put the next step into a supported task or timer rather than leaving it as a promise.

05
Human judgment where it matters

Let agents do authorized work while people retain client relationships and consequential decisions.

Named roles with jobs, not assistants with personalities.

Role

Account Supervisor

A named seat on one Account. It works from that account’s reviewed knowledge, a compiled role doctrine, and a bounded set of capabilities. Its scope is the account, not the agency.

Role

Chief of Staff

The agency-level seat. It creates Supervisor seats, dispatches work across them, and inspects session status — without inheriting unrestricted access to every client’s book.

The Desk

The conversational surface where sessions happen. Slack is an outbound destination for supported messages and configured nudges, not the place the work is done.

The Book

Reviewed account knowledge. Alongside it, the Review Queue holds facts staged for a human decision, and the Audit View holds the record of what was retrieved, decided, and produced.

Tearsheets

HTML work served and shared in the browser with its provenance attached. Link creation is gated; links expire, can be revoked, and can carry a password. Revocation stops future access — it cannot erase a copy someone already made.

Overview and Accounts

The workspace ledger: what is waiting on you, what was filed, which facts have gone stale, which sessions are open. Accounts are client records inside your agency’s tenant. They are not client logins, and there is no shipped client portal.

Reading a document is not the same as believing it.

A Supervisor can read the document in front of it and quote the passage with a locator, without any of that becoming durable knowledge. Facts extracted for an Account are staged and reviewed by a person before they enter live retrieval. Helping now and changing the record are two different acts, and only one of them needs your signature.

Formats

PDF, DOCX, PPTX, XLSX, Markdown, plain text, VTT transcripts, and pasted text, carried through with source locators so a claim can be traced to a page or a slide.

Scanned pages

A vision path handles image-only PDFs. It runs as a fallback, when a file yields no extractable text segments.

Limits

25 MB per file, and processing stops at 300 pages. A larger document has to be split before it can be read.

Promotion

Extracted Account facts enter staging, then a human review decision, and only then live retrieval. Rejection is a normal outcome and is recorded.

Working material is not a privacy boundary: attachment text and tool readings can persist in durable session transcripts.

What an agent can actually do in your systems.

Integrations are usually sold by the number. What matters on a Tuesday is which operation runs, under whose identity, and where it stops. Every path below is implemented, and every one is conditional on the connection being configured, the person being authorized, and the seat being permitted to use it.

Implemented paths — edition v2
Service Supported work Where it stops
Google Drive Find and read documents; file an original; create a text file, a folder, or a blank file; replace file content; read and create comments. Replacing content is a whole-file overwrite, not an append or a patch.
Gmail Create an unsent draft; list existing drafts with their subjects. Not general inbox reading, and not autonomous sending. Draft bodies are not listed.
Outlook Create an unsent draft; read calendar events; list calendars. Specific operations, not a complete Microsoft 365 integration.
Google Calendar Read events and assess availability from busy intervals. Not a scheduling solver. Event creation and invitations are not established.
Google Tasks Create tasks; read task and task-list information. Task work only.
Asana Create tasks; read a project’s own record. Reading a project is not reading every task inside it.
Slack Post supported internal messages; send configured nudges. An outbound destination, not the conversation surface.

A next step is a timer or a task, not a promise.

A Supervisor can arm a one-shot timer, list what is armed, and cancel it. When the timer fires it opens a new session carrying its note, so the follow-up arrives as work rather than as a memory. What happens next depends on who started it and what class of action it is.

Person-initiated

Execute-class work asked for by a person is gated and recorded, and runs without a second approval card. You already asked.

Timer-initiated

Execute-class work raised by a fired timer stays proposed until someone approves it on the Desk. It surfaces under “Needs you,” with a Slack nudge where that is configured.

Class matters

Reading and drafting are not writing. An email draft stays unsent in the drafts folder. A document comment is a real write, made under the identity of the person whose connection was used.

One live timer → approval → task sequence is recorded end to end. That is a pre-beta proof point, not a service level.

A stone gate set into a long wall, photographed in black and white.
Allowed means the work was not blocked by the checks that are implemented. It is not a verification that every claim in it is true.

Governance that supports the work, described exactly.

The Gate

Deterministic rules run against configured policy and return a versioned verdict. When a rule needs a model and none is available, the Gate reports it as skipped rather than passing it quietly.

Evidence

Artifact records, retrieval snapshots, review decisions, policy versions, and action receipts are inspectable. That is an operational record. It is not regulatory compliance, insurance eligibility, or an audit attestation.

Tenancy

One instance and one database per agency, with Account-scoped access inside it. Seat proofs bind service access to stored identity and account assignment rather than to a scope the model asserts about itself.

Where boundaries end

Account boundaries govern the account record. They do not partition a person’s own connected Drive or calendar, which the person already has access to.

Architecture

A hosted orchestration runtime with durable session and turn storage, tool dispatch, cancellation, budgets, and checkpoint resumption. Adapters exist for Anthropic, OpenAI, and Google; the hosted process runs one selected backend rather than switching models per turn.

Model routing

Document intake uses a platform-funded Anthropic lane and the embedding path uses OpenAI. “Only your own model provider sees your data” would therefore be untrue, so it is not claimed.

What is built, and what is not.

This is a pre-beta system described against a reviewed commit, not a launched product with a customer list. The second column is the more useful one.

Evidence-backed today

  • Seats and orchestration. Account Supervisors and the Chief of Staff running on the hosted runtime with durable sessions.
  • Reviewed knowledge. Staging, human review, and live retrieval, with freshness on the record.
  • The Desk and intake. Conversational sessions, document reading with locators, and the vision path for scanned pages.
  • Supported connected actions. The operations in the table above, under configured connections.
  • One-shot timers. Armed, listed, cancelled, and fired into a new session.
  • Administration. User management and connection setup.
  • Policy checks. Deterministic rules and judgment-doctrine tests, plus recorded internal demonstrations.

Not yet, incomplete, or unproven

  • No SOC 2 claim. There is no basis for one, so none is made.
  • No customer traction and no quantified ROI. An external client-book pilot is still ahead.
  • Brand fidelity is not measured. There is no score behind an on-brand claim.
  • Role-agent catalog is narrow. Two roles are implemented; a broad catalog is not.
  • Skills and plug-in distribution are limited, as is recurring automation authoring and support-ticket escalation.
  • No self-serve onboarding, billing, or tenant secrets plane. Setup is done with us.
  • Packaging is proposed, not published. The intent is to price the agency platform and the client book rather than employee seats: onboarding work, a platform base, per-book Supervisors, and a possible compliance add-on. No price list and no billing system exist yet.

A practical pre-beta engagement.

The useful shape is deliberately small: one agency team, one authorized client account, a bounded document set, and one workflow that repeats often enough to judge. Four things are agreed before anything connects.

  1. Which systems connect. Named connections, with the operations from the table above and nothing assumed beyond them.
  2. Who reviews durable facts. A named person decides what enters The Book, and rejection is expected.
  3. Which actions may execute. Read, draft, and execute classes are settled up front rather than discovered live.
  4. How success is measured. Agreed before the first session, so the result is a finding rather than an impression.

Five workflows are worth testing first: RFP and SOW understanding, brief and status preparation, coordination across a book, follow-through on what was promised, and account continuity when people move on.

Pre-beta access is arranged directly with Sandbox Group LLC.