Account Supervisor
A named seat on one Account. It works from that account’s reviewed knowledge, a compiled role doctrine, and a bounded set of capabilities. Its scope is the account, not the agency.
Agentcy Core · Sandbox Group LLC Pre-beta
It is a work platform for agencies, built around a Supervisor for each client account and a Chief of Staff for the agency. It combines document reading, reviewed knowledge, a conversational Desk, supported connected actions, and scheduled follow-up, with permissions and records around consequential work.
01 / What changes Agencies of 10–75 people, 5–40 client books
Client context lives in one person’s head, one thread, and a folder nobody has opened since the pitch. Generic assistants restart from zero every session, so the agency pays for the briefing twice. Five things change first.
Give the team a usable account record, not another place to restart the brief.
Discuss the document in front of you while governing what becomes durable knowledge.
Distinguish a draft, a proposal, and a completed action.
Put the next step into a supported task or timer rather than leaving it as a promise.
Let agents do authorized work while people retain client relationships and consequential decisions.
02 / The product people work with Two implemented roles
A named seat on one Account. It works from that account’s reviewed knowledge, a compiled role doctrine, and a bounded set of capabilities. Its scope is the account, not the agency.
The agency-level seat. It creates Supervisor seats, dispatches work across them, and inspects session status — without inheriting unrestricted access to every client’s book.
The conversational surface where sessions happen. Slack is an outbound destination for supported messages and configured nudges, not the place the work is done.
Reviewed account knowledge. Alongside it, the Review Queue holds facts staged for a human decision, and the Audit View holds the record of what was retrieved, decided, and produced.
HTML work served and shared in the browser with its provenance attached. Link creation is gated; links expire, can be revoked, and can carry a password. Revocation stops future access — it cannot erase a copy someone already made.
The workspace ledger: what is waiting on you, what was filed, which facts have gone stale, which sessions are open. Accounts are client records inside your agency’s tenant. They are not client logins, and there is no shipped client portal.
03 / Knowledge Working material ≠ reviewed knowledge
A Supervisor can read the document in front of it and quote the passage with a locator, without any of that becoming durable knowledge. Facts extracted for an Account are staged and reviewed by a person before they enter live retrieval. Helping now and changing the record are two different acts, and only one of them needs your signature.
PDF, DOCX, PPTX, XLSX, Markdown, plain text, VTT transcripts, and pasted text, carried through with source locators so a claim can be traced to a page or a slide.
A vision path handles image-only PDFs. It runs as a fallback, when a file yields no extractable text segments.
25 MB per file, and processing stops at 300 pages. A larger document has to be split before it can be read.
Extracted Account facts enter staging, then a human review decision, and only then live retrieval. Rejection is a normal outcome and is recorded.
Working material is not a privacy boundary: attachment text and tool readings can persist in durable session transcripts.
04 / Connected work Specific actions, not a connector count
Integrations are usually sold by the number. What matters on a Tuesday is which operation runs, under whose identity, and where it stops. Every path below is implemented, and every one is conditional on the connection being configured, the person being authorized, and the seat being permitted to use it.
| Service | Supported work | Where it stops |
|---|---|---|
| Google Drive | Find and read documents; file an original; create a text file, a folder, or a blank file; replace file content; read and create comments. | Replacing content is a whole-file overwrite, not an append or a patch. |
| Gmail | Create an unsent draft; list existing drafts with their subjects. | Not general inbox reading, and not autonomous sending. Draft bodies are not listed. |
| Outlook | Create an unsent draft; read calendar events; list calendars. | Specific operations, not a complete Microsoft 365 integration. |
| Google Calendar | Read events and assess availability from busy intervals. | Not a scheduling solver. Event creation and invitations are not established. |
| Google Tasks | Create tasks; read task and task-list information. | Task work only. |
| Asana | Create tasks; read a project’s own record. | Reading a project is not reading every task inside it. |
| Slack | Post supported internal messages; send configured nudges. | An outbound destination, not the conversation surface. |
05 / Follow-through Read · Draft · Execute
A Supervisor can arm a one-shot timer, list what is armed, and cancel it. When the timer fires it opens a new session carrying its note, so the follow-up arrives as work rather than as a memory. What happens next depends on who started it and what class of action it is.
Execute-class work asked for by a person is gated and recorded, and runs without a second approval card. You already asked.
Execute-class work raised by a fired timer stays proposed until someone approves it on the Desk. It surfaces under “Needs you,” with a Slack nudge where that is configured.
Reading and drafting are not writing. An email draft stays unsent in the drafts folder. A document comment is a real write, made under the identity of the person whose connection was used.
One live timer → approval → task sequence is recorded end to end. That is a pre-beta proof point, not a service level.
06 / Governance The Gate · tenancy · architecture
Deterministic rules run against configured policy and return a versioned verdict. When a rule needs a model and none is available, the Gate reports it as skipped rather than passing it quietly.
Artifact records, retrieval snapshots, review decisions, policy versions, and action receipts are inspectable. That is an operational record. It is not regulatory compliance, insurance eligibility, or an audit attestation.
One instance and one database per agency, with Account-scoped access inside it. Seat proofs bind service access to stored identity and account assignment rather than to a scope the model asserts about itself.
Account boundaries govern the account record. They do not partition a person’s own connected Drive or calendar, which the person already has access to.
A hosted orchestration runtime with durable session and turn storage, tool dispatch, cancellation, budgets, and checkpoint resumption. Adapters exist for Anthropic, OpenAI, and Google; the hosted process runs one selected backend rather than switching models per turn.
Document intake uses a platform-funded Anthropic lane and the embedding path uses OpenAI. “Only your own model provider sees your data” would therefore be untrue, so it is not claimed.
07 / Maturity Edition v2 · pre-beta
This is a pre-beta system described against a reviewed commit, not a launched product with a customer list. The second column is the more useful one.
Evidence-backed today
Not yet, incomplete, or unproven
08 / Engagement One team · one account · one workflow
The useful shape is deliberately small: one agency team, one authorized client account, a bounded document set, and one workflow that repeats often enough to judge. Four things are agreed before anything connects.
Five workflows are worth testing first: RFP and SOW understanding, brief and status preparation, coordination across a book, follow-through on what was promised, and account continuity when people move on.
Pre-beta access is arranged directly with Sandbox Group LLC.