Enterprise · Security & Deployment

Every run is sandboxed, recorded and policy-checked. Deploy in our cloud, a dedicated environment or your own.

workbench.aos.work / settings/usageAdmin Console
Usage & auditShieldon Gateway
Last 24 h
UserModelTokensStatus
a.chenqwen/deepseek-v4-pro6,073Completed
m.ortizanthropic/claude-sonnet-4.512,410Completed
j.liopenai/gpt-52,208Running
schedulerqwen/deepseek-v4-pro3,880Completed

Usage & audit · one row per run, sensitive data masked at the gateway

Sandboxed

Every run executes in a disposable sandbox that is destroyed afterwards.

Recorded

Every task, scheduled or not, leaves an immutable Run Record.

Policy-checked

Shieldon inspects every model call before it leaves the company.

Layered model

A request passes through the workplace, the gateway and the agent runtime. Each layer decides something different, and each leaves its own record.

New task
Workplace layerAOS.work

Who may do what

Accounts, roles and allowed models decide what a person can start. Credentials are collected in secure forms and bound explicitly to Connectors.

  • Role resolved
  • Allowed models applied
  • Connector binding verified
Gateway layerShieldon

What may reach a model

Every model call passes the gateway. Policies detect and mask sensitive data, enforce the allowed model and log the request, the tokens and the outcome.

  • Policy evaluated
  • Sensitive data masked
  • Request logged
Agent layerBasil Harness

What actually ran

The run executes in a disposable sandbox with scoped mounts. Every tool call, checkpoint and result lands in an ordered event stream you can replay.

  • Sandbox created
  • Tool calls recorded
  • Run Record written
Task output, traceable end to end

Execution isolation

Agents never touch an employee's machine or a shared server. Each run gets its own container, exactly the mounts it needs, and a record of every step.

workbench.aos.work / tasks / run 359415397587451qwen/deepseek-v4-pro
containercreatingCancel run
  • /workspacerw
  • resources/skillsro
  • resources/attachmentsrw
  • resources/envrw
seqeventcheckpoints 0
  1. 1run.queuedscheduled task · finance-reconciliation

disposable · created per run · destroyed after

Event ledger · one run, in order, replayable

  • Disposable sandboxes

    Created for the run, destroyed after it. Nothing persists unless it was written to the workspace on purpose.

  • Mounts, not access

    Skills, Works, Connectors, Apps and attachments are projected under /workspace/resources, read-only or writable per path.

  • Cancellable at any time

    Change of plan? Cancel the run. Running processes stop with it, and the record shows exactly where it stopped.

  • Checkpoints to return to

    Context checkpoints mark safe points in a long run, so recovery resumes from known state instead of starting over.

Identity & access

Access is defined in the Admin Console and enforced by the runtime. There is no side door: what a role does not allow, an agent cannot do on that person's behalf.

Accounts and roles

People sign in as themselves. Roles carry what they may see in Explore and which models they may use.

Allowed models per role

A role's model list is intersected with the models the company has configured. Empty means none, and nothing is substituted silently.

Registration by domain

Open registration only for the email domains you allow. Everyone else is invited by an administrator.

One Connection per Connector

Each person holds a single Connection per Connector, callable only after Test Connection passes.

Explicit bindings

Skills declare the Connectors they need and the person binds one on purpose. An invalid binding puts the run into Awaiting Authorization.

Policy Locked

Administrators can lock a Skill, Work or Connector so its configuration cannot be changed by the people using it.

workbench.aos.work / admin/rolesAccounts · Roles

Finance analyst

12 members · Visible in Explore

Role

Allowed models

  • qwen/deepseek-v4-proresolving
  • anthropic/claude-sonnet-4.5resolving
  • openai/gpt-5resolving

roles ∪ → ∩ configured models · no silent substitution

Explore · resource statuses

  • Enabled
  • Update Available
  • Needs Reauthorization
  • Policy Locked

Admin Console · Roles · allowed models resolve per person

Credentials & data

Keys and tokens are entered once, in a secure form, and delivered straight into the sandbox environment. The agent uses them. It never reads them.

workbench.aos.work / connectors/erp-ledgerStatic credential

ERP ledger

Connector · Connection for a.chen

Base URL
https://erp.example.internal/api
API key
••••••••••••••••
Client secret
sk_7f3a9c2e41b8
Test Connection

delivered to the sandbox environment · never to the model

Connector configuration · values masked after save, tested before use

  1. 01

    Secure forms, shown once

    Sensitive values are entered in a dedicated form and never displayed again. Rotating a value means entering a new one.

  2. 02

    Admin-configured fields stay masked

    Values an administrator sets appear as masked fields marked Configured by Admin. People use them without ever seeing them.

  3. 03

    Never in chat, Memory or files

    Credentials are refused in conversation, kept out of Memory and never written to resource files. The runtime is told, not the model.

  4. 04

    Technical success is not acceptance

    A run that completes is not a job that is done. The owner verifies the content and the state of the destination system before signing off.

Audit & observability

Every task, every model call and every output can be traced back to a person, a run and a message. Administrators see the whole picture; people see their own.

Run Records

Each run, including every scheduled trigger, produces an immutable record with its state, its tools and its usage.

  • run …451Succeeded
  • run …452Failed
  • run …453Skipped

Task Outputs that trace back

Files and URLs are collected per task. Back to Original Message opens the request that produced them.

reconciliation-09.xlsxFile Output

Back to Original Message

Usage Overview

Tasks, tokens and model usage across teams in the Admin Console, next to credit consumption per plan.

tokens · by teamCredits 62%

Inbox

Explore updates, scheduled-task results and administrator messages reach people where they already work.

  • Scheduled task · Succeeded
  • Explore · Update Available

Deployment options

The same product, three ways to host it. Models are configured centrally in every option, including the models you host yourself.

Fastest start

AOS cloud

Multi-tenant and operated by us. Workspaces, files and runs are isolated per account from day one.

  • No infrastructure to run
  • Updates applied for you
  • Isolated per account
Your own instance

Dedicated environment

A single-tenant deployment operated by us, with its own AOS.work and Runtime hosts inside its own network boundary.

  • Isolated compute and storage
  • Private connectivity to your systems
  • Change windows agreed with you
Inside your perimeter

Private / on-prem

Installed in your cloud account or data centre and operated by your team, with our delivery team alongside.

  • Your keys, your network
  • Self-hosted models supported
  • Operated by your own team

Model choice

Connect the providers you already trust, or models you host yourself. Each model is configured once, must pass Test connection, and is granted per role.

Capacity planned per environment

AOS.work and the Runtime run on separate hosts, sized for your expected load and verified under load before go-live, with success rate and latency percentiles recorded.

Security checklist

The short version, for the people who have to sign off.

  • Every run executes in a disposable sandbox, never on an employee's machine
  • Every model call passes the Shieldon gateway: policy, masking, audit
  • Roles define allowed models; nothing is substituted silently
  • Credentials live in secure forms and the sandbox environment, never in chat or Memory
  • One Connection per person per Connector, bound explicitly and tested before use
  • Immutable Run Records and Task Outputs that trace back to the original message
  • Skills, Works and Connectors published as immutable versions, released per role
  • Deployment in our cloud, a dedicated environment or your own infrastructure

Security review pack available on request.

Request the review pack

Book a demo and we will set up a workspace with your knowledge, your standards and your guardrails.

Built on Basil Harness · Protected by Shieldon