Runs in your cloud, on your models
What the Enterprise plan includes for IT, exactly as the pricing page states it:
- SSO and SCIM — Okta, Microsoft Entra, Google Workspace
- Bring your own model — Claude models on Vertex AI in your own GCP project, keyless via Workload Identity Federation, billed to you, in your audit logs
- Or your own OpenAI / Azure OpenAI key — GPT-5.6 Sol, GPT-5.6 Terra and GPT-6 Astra, key encrypted in the vault and used only for your workspace
- Run agents in your own GCP project — each agent’s Cloud Run service lives in your project, as your service account, on your Vertex AI; IAM-gated URL or internal behind your load balancer; Vertex AI Agent Engine too
- Custom MSA, DPA and security review · SOC 2 Type II in progress
Control at every step, evidence at every step
Business users cannot deploy around IT: an agent must pass evaluation cases derived from its process before it can even be submitted, IT connects the systems and binds the fields, and IT approval is the go-live gate. Approval locks the version; a change means a new version and a new approval.
At runtime the gate is on the call, not on the agent’s judgement. A write the agent proposes is held in a queue with what it wants to change and why, a person accepts, modifies or rejects it, and the corrected arguments are what execute. Figures the run cannot trace to something it read are refused. Every run leaves a trace.
Isolation is enforced in the database (row-level security per tenant), with an immutable audit trail and per-tenant spend caps. Workspaces can opt in to agent change history: the value before and after each field an agent changes, visible only to that workspace's owners and editors. Our certification status, controls and sub-processors are stated plainly on the trust page; the DPA is public.
How an engagement starts
- Pick one process a team dreads. We map it with the people who run it and compile the graph.
- Agents are composed and tested against the process, then run in shadow beside the team on real work.
- Your IT connects the systems, reviews what each agent will do, and approves. Writes stay gated.
- Value is measured as time returned per approved decision, so the next process is a decision made on evidence.
- Every process included in one custom subscription — no per-process price, unlimited seats
- Dedicated onboarding and a named CSM
- Platform onboarding and setup included — knowledge and process
Questions enterprises ask
- How does my company get connected to Google Workspace (or any OAuth system)?
- One workspace = one company, and that company connects its OWN Google Workspace — there is no magic cross-account access. An admin goes to Tools → Connections → Connect Google Workspace, which sends them to Google’s consent screen; they sign in as a Workspace user and grant the scopes (Drive/Gmail/Calendar). Google redirects back and Tacit stores the tokens encrypted, scoped to your workspace only. There are two ways to supply the OAuth app: (1) Tacit’s shared app — just click Connect (but Google requires a security review for restricted scopes on external apps); (2) Bring-Your-Own app (recommended) — you register your own Google Cloud OAuth client and paste its ID/secret, which lets you mark the app “Internal” so no Google verification is needed even for sensitive scopes. For org-wide access without per-user clicks, use the service-account + domain-wide-delegation fields. The key point: connecting always requires a real person at that company to consent — Tacit can never reach a Workspace nobody granted it.
- I forgot my password — how do I reset it?
- On the sign-in page, type your email in the Email field and click “Forgot password?” underneath the password box. We email you a secure reset link (check spam too); open it, set a new password, and sign in. If you originally signed up with Google, there’s no password to reset — just use “Continue with Google”. For security we don’t reveal whether an email has an account, so the confirmation message shows either way.
- How do I adapt a catalog agent to my work when I adopt it?
- When you click Adopt, a short dialog opens with a “What should it do for you?” box. Describe your context in plain words — e.g. “Focus on enterprise renewals in North America, use our formal tone, flag any deal over $50k, and pull deal data from Salesforce.” We treat that as authoritative and build the agent around it (not a generic clone). If the agent works with interchangeable platforms, the same dialog asks which one you run. After you hit “Adopt & build”, we take you to the new agent so you can watch it build, then adapt → try it out → submit to IT for review. You can keep refining it any time by opening it or using “Ask for help with this”. (IT users who adopt see setup guidance instead: connect the tools, review, and approve.)
- How do I connect Salesforce / HubSpot / Dynamics 365 / SAP / Slack / Teams / Zendesk / Intercom / SalesLoft / ZoomInfo?
- On Integrations, open the platform’s guide, register your own OAuth app on that platform, and paste its credentials (BYO-OAuth, per workspace — IT keeps control). Tacit encrypts them and refreshes tokens. For subdomain/tenant-based platforms (Zendesk, ServiceNow, Snowflake, Microsoft Teams, Dynamics 365) you also enter your account subdomain, Directory (tenant) ID, and/or environment host so Tacit builds the right API URLs. HubSpot (CRM + Service tickets + Marketing) is one-click: click Connect and approve the CRM scopes — it uses Tacit’s HubSpot app, so there’s nothing to build (agent changes show in HubSpot as “via Tacit”; no separate integration user like Salesforce). Enterprises that require their own HubSpot app can still BYO via “Use your own OAuth app”. Intercom (support) is standard OAuth; Dynamics 365 uses Microsoft Entra OAuth + the Dataverse Web API (the app must also be added as an Application User in your Dynamics environment). SalesLoft is standard OAuth (people + accounts, read/write). ZoomInfo uses OAuth 2.0 client-credentials on its current GTM API: create an app in the ZoomInfo Developer Portal and paste its client_id + client_secret (BYO — API entitlement required; enrich calls cost credits, search is free); Tacit mints and refreshes the short-lived token automatically on each run. DocuSign is connected the same way, with one extra step that matters: choose Production or Developer/demo on the connect form, because a developer account cannot be reached from the production host. On approval Tacit looks up which DocuSign region and account you are in rather than assuming one, so it works the same from any region. DocuSign offers two front doors behind one tile — a REST connector for explicit, reviewable agreement actions (send from template, chase a signer, void with a reason, read the signed values) and an MCP connector that discovers DocuSign’s own agreement tools live so they stay current. Once connected, domain agents can read and (with human approval) write through the connection.
- How does connecting Slack work per workspace — and with Slack Enterprise Grid?
- Each Tacit workspace connects to its OWN Slack. When you click Connect and approve, Slack installs the app into the workspace you are signed into and returns a bot token scoped to just that workspace; Tacit stores it encrypted under your tenant, and the runtime only ever resolves your tenant’s own token — nothing is shared across customers. You have two options: (1) one-click connect using Tacit’s shared, publicly-distributed Slack app, or (2) register your OWN Slack app (Integrations → Slack → “Use your own OAuth app”) so the whole integration stays under your IT policy with no third-party app added to your org — both end in the same per-tenant, encrypted, workspace-scoped token. On Slack Enterprise Grid, app installs are typically gated by your Slack org/workspace admin (app approval / org allowlist): run the connect while signed into the target workspace, and if approval is required the request routes to your admin and finishes once they approve. To install one Slack app into more than one workspace, turn on “Manage Distribution → Activate Public Distribution” (this is NOT the same as an App Directory listing, which is the only part that needs Slack review).
- Where do my domain agents run? Can they run in my cloud?
- Tacit-hosted by default. You can also deploy into your own GCP project via Workload Identity Federation, or register them in Gemini Enterprise.
Tell us the process and the systems it touches. We will come back with how it would run, what your IT would approve, and what it is worth.