Frequently asked questions

95 answers about what a domain agent can and cannot do, how approvals work, connecting your own systems, and what happens when something goes wrong. The same answers the product gives you in context.

Want a definition instead? See the glossary.

Will a domain agent create new fields or objects in my CRM?

No. Domain agents only read and update the records you already have — they never create objects, tables, or fields in your systems, and you never need to add anything for one to run. If a process step says to log changes for audit, that is already covered: every proposed change is recorded with its before and after values, held for approval, and kept in an immutable audit trail here. Nothing is written into your CRM to track it.

Where do I start?

Go to Ingest and describe a workflow in plain English (or upload an SOP). Tacit proposes 1–3 processes; pick one and it compiles a graph you turn into domain agents.

Why does Run now say “Running” and not start another run?

An agent runs one job at a time. While it is running — from your click, a teammate’s, or its own schedule — My agents shows “Running · 41s” with a spinner instead of “Run now”, the “Run it now” card on its page is disabled, and if a second run is requested anyway (two clicks at the same moment, or from another tab) the platform refuses it with “This agent is already running”. The reason is simple: a second run would repeat the same reads and queue the same writes at the same time, for double the cost. Wait for it to finish — the result lands under Results and the button comes back on its own. Previews (“Try it safely”) are simulated and are not held back by a real run.

How do I connect my own work inbox (Outlook 365 or Gmail)?

On Tools → Connections, the Outlook (Microsoft 365) and Gmail (Google Workspace) connectors carry a "Your inbox" badge — these are PER-USER: you click "Connect my inbox" and sign in with your own work account, and the connection is stored just for you. Each teammate connects their own mailbox; your agents only ever act on YOUR inbox, never anyone else’s. Under the hood, when you run an agent that uses your inbox, it resolves the credential tied to your user id (metadata.user_id) — so a mailbox agent you own reads/archives/sends in your mailbox only. Outlook uses Microsoft Graph (/me/messages: list, get, move-to-archive, mark read, send); Gmail uses the Gmail API (list/search, get, archive via remove-INBOX-label, send). This is different from a tenant-wide system connection (like Salesforce) that IT connects once for everyone. One prerequisite (done ONCE, not per person): connecting any Google/Microsoft mailbox needs a registered OAuth app. The clean path is your workspace admin registering your org’s OWN app (in Google Cloud / Entra) marked “Internal” — which needs no Google/Microsoft verification even for the mailbox scopes — via “Use your own OAuth app” on the connector. After that one-time step, every employee just clicks “Connect my inbox” and consents; there is no IT request per person. (Alternatively Tacit provides a shared app, but an external app using restricted mail scopes needs Google’s CASA verification.)

How does my company get connected to Google Workspace (or any OAuth system)?

One workspace = one company, and that company connects its OWN Google Workspace — there is no magic cross-account access. An admin goes to Tools → Connections → Connect Google Workspace, which sends them to Google’s consent screen; they sign in as a Workspace user and grant the scopes (Drive/Gmail/Calendar). Google redirects back and Tacit stores the tokens encrypted, scoped to your workspace only. There are two ways to supply the OAuth app: (1) Tacit’s shared app — just click Connect (but Google requires a security review for restricted scopes on external apps); (2) Bring-Your-Own app (recommended) — you register your own Google Cloud OAuth client and paste its ID/secret, which lets you mark the app “Internal” so no Google verification is needed even for sensitive scopes. For org-wide access without per-user clicks, use the service-account + domain-wide-delegation fields. The key point: connecting always requires a real person at that company to consent — Tacit can never reach a Workspace nobody granted it.

What can a Gmail (Google Workspace) domain agent actually do?

Once Google Workspace is connected, a domain agent can: search/list messages with the normal Gmail search syntax (e.g. "category:promotions newer_than:7d"), read a message, list labels, archive or label messages (single or up to 1000 at once), move a message to Trash, and send email. Archive means removing the INBOX label — the message stays searchable, it just leaves the inbox. These are grounded in the Gmail API, not simulated. Two notes: (1) it needs the gmail.modify scope, so if you connected Google Workspace before this was added, reconnect it (Tacit re-prompts consent). (2) To run automatically on incoming mail today, use a scheduled domain agent that searches recent messages and archives/labels them — a true "new email" push trigger is on the roadmap, not yet available.

An agent runs on its own (a schedule or webhook) — what does IT need to set up?

Open the agent in the IT view. Under “Connections & IT” you’ll find “Automatic triggers — IT setup”. This is separate from tool connections: an agent can show every connection green and still not fire until its trigger is set up AND the process is deployed. For a scheduled trigger: confirm the cron (change when it runs by asking the agent), connect the account it watches, and deploy. For a webhook trigger: click “Generate signing secret” (shown once — copy it), then register the ingress URL + secret in the source system (Salesforce/Stripe/GitHub/…), signing each request as X-Tacit-Signature, and deploy the process. Each trigger shows a “before it fires” checklist so nothing is left in limbo. The business view shows a plain-language note that IT is still setting the trigger up — so “Connections ready” is never mistaken for “fully ready” — plus a one-click “Request IT to set it up” button that sends IT a notification linking straight to this panel.

How do I retire a domain agent or a whole process?

On a domain agent’s detail page (business or IT view) there’s a “Retire” button in the header — it takes the domain agent out of your active list and, if it was live, tears down its running service so it stops working (and can’t bill). On a process page, “Retire process” does the same for the process AND cascade-retires all of its domain agents in one step (it asks you to confirm and shows how many). Retiring is a soft action: nothing is permanently deleted — the item stays as read-only history, and you can “Restore” it later. Requires editor (or owner) permission. Restoring a process reactivates the process itself; its domain agents come back retired, so restore any you still want individually.

I forgot my password — how do I reset it?

On the sign-in page, type your email in the Email field and click “Forgot password?” underneath the password box. We email you a secure reset link (check spam too); open it, set a new password, and sign in. If you originally signed up with Google, there’s no password to reset — just use “Continue with Google”. For security we don’t reveal whether an email has an account, so the confirmation message shows either way.

We’re a staffing firm — what can Tacit do for us, and do I need TempWorks connected?

If your workspace industry is Staffing, the Catalog shows a set of staffing domain agents (“digital workers”): a Recruiter that screens applicants and drafts bilingual outreach, a Scheduler that fills shifts and handles call-offs, plus Onboarding, Timecard, HR, Safety/Compliance, Ops/Reporting and more. They automate the admin around your workforce — not the physical labor. Every risky action (texting a candidate, booking a shift, editing a timecard, sending a notice) pauses for your approval in the queue. You do NOT need TempWorks connected to evaluate: a pilot runs the agents on seeded sample data (a few workers, an open order, a call-off) so you can see real screening, ranking, and drafting; connect the real TempWorks afterward. Note: scheduled/recurring runs aren’t firing yet, so these run when you start them or on an event for now.

Can I demo the Salesforce / SalesLoft domain agents without connecting a live CRM?

Yes. The sales domain agents — Lead Router (enrich a new lead and route it), CRM Hygiene Fixer (fill gaps and merge duplicate records), and the Follow-up Sequencer — can run on seeded sample CRM data so you see real enrichment, ranking, and record edits with no live Salesforce, SalesLoft, or ZoomInfo connected. When those connectors have no connection, the workspace serves a small built-in dataset (a few accounts with missing fields, a fresh inbound lead, duplicate contacts, and matching ZoomInfo firmographics). Every write (updating a record, creating a SalesLoft person, deleting a duplicate) still pauses for your approval in the queue. Connect the real Salesforce/SalesLoft/ZoomInfo afterward and the same domain agents run against your live data — nothing to rebuild.

How do I adapt a catalog agent to my work when I adopt it?

When you click Adopt, a short dialog opens with a “What should it do for you?” box. Describe your context in plain words — e.g. “Focus on enterprise renewals in North America, use our formal tone, flag any deal over $50k, and pull deal data from Salesforce.” We treat that as authoritative and build the agent around it (not a generic clone). If the agent works with interchangeable platforms, the same dialog asks which one you run. After you hit “Adopt & build”, we take you to the new agent so you can watch it build, then adapt → try it out → submit to IT for review. You can keep refining it any time by opening it or using “Ask for help with this”. (IT users who adopt see setup guidance instead: connect the tools, review, and approve.)

I adopted an agent from the catalog but it’s not in My agents — why?

Adopting builds the agent in the background (usually under a minute), so it appears shortly after, not instantly. While it’s building you’ll see a “Building…” banner on the My agents page, and you get a notification when it’s ready. If the build hit a temporary snag (e.g. the AI provider was briefly overloaded), that same page shows a “We hit a snag” message with a Retry button — one click rebuilds it. Nothing is lost in the meantime.

How do I see what I’ve submitted that’s waiting on IT?

On My agents, the amber “Waiting on IT” section lists every agent with an open approval request and how long it’s been waiting; “View IT queue” jumps to the full queue. Agents that are live show under “Working live” (green), and ones still being set up under “In progress”. Every row also shows the process it belongs to as a blue tag you can click to open. On an agent’s own Overview, once you’ve sent it to IT the tracker shows “Sent to IT — waiting for approval” — it no longer prompts you to submit what’s already submitted.

I changed something — how do I apply it? What does “Update this process” do?

After you edit a process, upload a doc, answer a question in chat, or connect a different tool, click “Update this process” (top-right of the process). We fold your change into the steps and rules and rebuild the agents to match — existing agents get a fresh draft on the platform’s current model (Claude Opus 5 today — an agent otherwise keeps the model it was first built with), and any locked live ones are left untouched until you unlock them for editing and update again. If you haven’t built the agents yet, the button says “Build it” instead. When you resolve a question in chat, a purple “You made a change — update this process to apply it” prompt also appears so you never have to hunt for it. This is the business-friendly way to keep the agents in sync with your process — no technical step needed.

On a process, how do I see only certain domain agents (and what does “retired” mean)?

The domain agent cards on a process show ACTIVE agents by default — the same cards as the Domain Agents page, with what each agent covers and delivers. Click a status chip — production, shadow, draft, or retired — to filter the list to just that group; click it again (or the “Domain Agents” label) to clear. “Retired” agents are old versions that were superseded (e.g. replaced when you recomposed) — they’re kept as history only. Open one and it’s read-only: you can’t run, edit, evaluate, or submit it; the current version is the live one.

Some agents work together as a team — how do I move between them?

When an agent leads a team, its Overview shows a “Works as a team” card listing the helper agents it directs — click any one to open it. If you’re looking at a helper, the same card shows the lead it reports to, so you can jump back up. These agents hand work to each other automatically during a run (the lead delegates to its helpers); the card just gives you a plain-language way to navigate between them without the technical tree. Helpers don’t have their own “Send to IT” or “Connect tools” steps — a helper is checked, approved, and goes live together with its lead, so you manage all of that from the lead agent.

A catalog agent lists several platforms (Salesforce, SAP, Adobe Commerce, Shopify) — do I have to connect all of them?

No. Those show what the agent CAN work with — it adapts to whichever ONE your company runs (most companies have a single commerce/order platform). When you adopt it, a quick picker asks which platform you use and pre-selects the one we detect you’ve already connected; the agent is then built to use just that one. You never connect platforms you don’t use, and you can always tell it which to use in chat.

Who published an agent in our team library, and when?

On the Catalog, each agent under “Your team’s library” shows a byline — “Published by <name> · <when>” (and “Proposed by <name>” for ones still awaiting an owner’s approval). The name is the teammate who shared it (or the owner who approved it); hover to see their full email. So you always know the provenance of anything your team adopts.

How do I use an agent a teammate published?

On the Catalog under “Your team’s library”, an input-driven agent (one you run with your own input, like an RFP analyzer) shows a “Use it” button — click it to open that agent in the chat, then send your input (and attach a document with the paperclip) and it runs and replies with its result. The chat stays focused on that agent until you’re done, then click “Exit” (or just move on — it notices and hands you back to the general chat). Agents that run themselves on a schedule or system event show “Runs automatically” instead — there’s nothing to send; open “View” to see what they do and their results.

Is there a size limit on documents I attach in the chat?

Yes. When you attach a file to use-mode chat, we show its approximate token size in the attachment chip. Large documents use more of your usage budget, so we warn you above ~10k tokens, and very large files are trimmed to the first ~50k tokens before they’re sent — the chip turns amber and says “trimmed to fit”. For a long report, attach only the relevant section, or split it across a couple of turns.

How do I give an agent a reference document (e.g. a sample template) to use at runtime?

Two places, both drag-and-drop: (1) for ONE agent, open it → Knowledge tab → drop the file on “Documents it can look up”; (2) for the WHOLE process (available to every agent in it), the process page has a “Documents for this process” card — drop it there. For example, drop a sample proposal template for a Proposal Generator. Whatever the format — PDF, Word, Excel, CSV, HTML, text, OR a screenshot/image (PNG, JPG, etc.) — we handle it: documents convert to clean markdown (tables and headings preserved, not a flattened blob), and images/screenshots are read by vision (Claude) which transcribes all the text and describes what’s in them (e.g. a screenshot of an invoice becomes a markdown table of its line items). Then we cap it to a sensible size for efficient token use, chunk and embed it so retrieval is sharp. It’s added immediately (no IT approval needed, nothing hardcoded) and shows in the document list. From then on the agent searches it live every run and uses it as a reference — e.g. it drafts new proposals in the shape of your template. To have it ALWAYS apply a rule instead of just look it up, use “Teach it” on the same tab (or the Rules tab for enforceable policies).

Can a deployed agent read documents (PDF, Word, Excel) on its own?

Yes. Agents whose job involves documents (RFP analysis, contract or invoice review, etc.) automatically get a built-in “read document” capability. At runtime the agent can pull in a document — a PDF, Word doc, Excel sheet, CSV, HTML, or plain text — by URL (or one you pass it) and read it as clean text, then deliver its result. It’s read-only, needs no connection or IT approval, and the same size/token limits apply. Spreadsheets and Word docs come through far more cleanly now than before, and uploaded PDFs now keep their tables and headings as structure (not a flattened blob) — so agents read tabular data correctly and retrieval is sharper.

Can I talk to it instead of typing?

Yes. In the chat there’s a microphone button — tap it and just speak; your words are transcribed straight into the message box, so you can describe a process or talk to an agent by voice (great on a phone). Tap again to stop. There’s also a speaker toggle that reads the agent’s replies aloud. Voice uses your browser’s built-in speech features, so it works on most modern phones and laptops; if your browser doesn’t support it, the mic button simply won’t appear.

What happens to a document after it’s used?

It depends how it entered. A file you upload while building a process is kept as that process’s knowledge — the original is stored in your tenant’s private storage and the extracted text in your corpus, so the agent can keep using it. A document you attach in a use-mode chat (“Use it”) is processed in memory and NOT stored — it’s a one-off run. A document a deployed agent reads by URL at runtime is fetched, read, and discarded — not retained. When you Reject/remove a corpus document, its stored original is now deleted too, and your tenant’s retention window ages out one-off/orphan documents (and their originals) automatically. Durable process knowledge persists until you delete the process.

The chat suggested a team agent — what is that?

When you describe something in the chat that a published team agent can already do, the chat offers it inline (“Your team has <Agent> — use it?”). Clicking “Use it” drops you straight into that agent so you don’t rebuild something your team already has. Only agents published to your team’s library are suggested.

How do I add my team’s knowledge so the agents use it?

Click “Add knowledge” on Home or the Catalog (or “Team knowledge (needs OK)” on an agent’s Knowledge tab) and paste a note or drop a file — an SOP, a policy, anything your team knows. It goes to your team’s knowledge scoped to your department and waits for IT to approve it before agents can use it. No technical setup. Once approved, agents retrieve it automatically and answer using your company’s terms and policies.

What is Knowledge & Context, and does it train an AI on our data?

It’s the governed layer that makes every agent competent in YOUR company’s reality — your documents, a business glossary (what your terms mean), your systems of record, and who can use what. IT curates it; business users contribute to it. Agents draw on it at runtime through a small always-on context card plus on-demand lookups. It grounds agents via retrieval + structured context — your data is NEVER used to train a model. Only knowledge IT has approved is ever retrievable.

What’s the difference between a process and a domain agent?

A process is the workflow blueprint (a graph of steps). A domain agent is an AI agent built from part of that process to actually run it.

Do I need to draw a diagram or write a spec?

No. Describe it the way you’d explain it to a new hire. Tacit compiles the diagram and a critic flags anything unclear for you to answer in chat.

How does a domain agent know my specific rules?

From your corpus — the SOPs, docs, and notes you provide. Domain Agent instructions and tests are grounded in it.

Will a domain agent act without my approval?

No — not by default. A new domain agent only drafts decisions for a human. It can act on its own only after it proves itself in shadow and a human promotes it.

The checks didn’t pass — what do I do?

Each failing check now opens with “What happened and what to do”: the platform reads the run itself and tells you in plain words — for example “the rule guard blocked the send under rule 3, so the agent re-queried instead of reusing the supplied count” or “rule 11 and this check disagree on the SKU count scope” — with the buttons to act: apply a suggested rewording of the rule, keep the rule and dismiss the example, disable the rule, tell the agent the rule, re-run, or view the run. It is the same card in the IT Checks & activity tab and in the business view. If an enabled rule changed after the checks ran, a banner says the results may be out of date and offers a re-run. Below the card: open the agent; under “Getting it ready” you’ll see each example the agent disagreed with. A failed check is a DISAGREEMENT, not a verdict: the panel states the one question to answer (“Your agent and this example disagree about record count — which one is right?”) and shows the two sides field by field, highlighting only what actually differs. Fields both sides agree on are collapsed, so you are reading the argument rather than hunting for it. Type the missing rule in plain words (e.g. “Deny refunds past 30 days unless the item arrived damaged”) and click Save & re-check, or upload the SOP that covers it. We update the agent and re-run the checks automatically — no technical editing. If an example is just unrealistic (the agent was actually right), click “This example is wrong” to stop it counting against the agent. Not sure of the rule? Loop in a colleague before sending to IT. Note: for some agents the automatic checks can only verify the OUTPUT SHAPE (not that it does the job) — in that case we won’t let you send it to IT on shape-checks alone. Click “Try it safely” with a real example first (or add a real check); once you’ve genuinely tried it, submit unlocks. Note: the panel separates failures you can fix (a policy/wording gap — “tell us the rule”) from purely technical ones (an output-SHAPE or system-contract check) — the latter never ask you to write a rule; just re-run the checks, and if one persists your IT admin can adjust the agent’s output format.

The Results tab shows green checks — does that mean the checks/evals passed?

No — those are two different things. The Results tab (“What this agent did”) is a LOG of every time the agent ran. A green check there means a run finished and produced an output — not that it was correct and not that the checks passed. Rows tagged “Trial” ran with writes simulated, so nothing real was touched. The actual checks/evals live under “Getting it ready” on the Overview tab; that’s where you’ll see pass/fail. So a run can finish (green in Results) while a check still fails (red under Getting it ready) — “it ran” is not the same as “it ran correctly.”

What does “earn autonomy” mean?

A domain agent must agree with your team on real cases (default 90%) in shadow mode before it’s allowed to act autonomously. Trust is proven, not assumed.

How do I know a domain agent is reliable before it goes live?

Run its eval suite for a real pass rate, then shadow it against real cases. Both must clear their bars before promotion.

Who can promote a domain agent to production?

Promotion needs passing evals + shadow, connected tools, and an IT/governance approval for the current version. Editors submit; approvers approve.

I submitted domain agents for IT review but they don’t show on the IT approvals page — why?

IT only ever sees validated domain agents, so submission is gated on two things: each domain agent must (1) have its required tools connected and (2) pass an eval run (≥80%). A fresh domain agent with no eval runs is blocked at submit and stays in Draft — nothing reaches the approvals queue. The shadow TRIAL is NOT a submit gate (it can’t be — real agreement is earned only after go-live, from actual human decisions), so a running-or-skipped trial never blocks submission. Open each domain agent, connect any required tools and run its evals, then submit. The submit result lists exactly which domain agents are blocked and what’s missing.

In what order do I do this — build, evals, submit, connect, go live, autonomy?

The business builds and validates; IT connects and approves — a clean handoff. The order: (1) BUSINESS builds the agents and runs evals (≥80% pass) — that’s all it takes to submit; you do NOT need tools connected first. (2) BUSINESS clicks “Submit the whole process for IT review”. (3) IT picks it up: connects the required tools and binds the API fields in Integrations. (4) IT approves — approval is the go-live gate, so it can’t approve until the tools are connected, and nothing ever runs unconnected. (5) It deploys live in domain agent mode. Then the domain agent trial / agreement begins: it works alongside a human who approves each draft in the queue, and earns the right to act UNATTENDED once it agrees with real human decisions ≥90% over ≥10 real cases. IMPORTANT: the “domain agent trial” agreement is NOT a pre-launch step — the platform never fakes “what a human decided,” so the score stays empty until it’s live and people review its drafts. Two separate gates: Evals + IT approval (with tools connected) make it LIVE (human-in-the-loop); agreement with real decisions earns AUTONOMY (unattended).

Can I roll back a change?

Yes. Every version is saved (append-only), so you can always roll a domain agent back to a previous version.

What is the Salesforce Data Hygiene blueprint, and how do I use it?

It’s a pre-built end-to-end process (a "crew" of 5 domain agents) that replaces the manual job of cleaning up messy CRM data and re-importing it. In the Catalog it shows as a Blueprint with the problem it solves, the outcomes it delivers, and the process mapped to each domain agent: (1) Data Quality Auditor profiles the object and reports duplicates/blanks/malformed/stale records; (2) Duplicate Finder & Merger proposes human-approved merges; (3) Field Standardizer normalizes phone/state/country/titles/casing; (4) Data Re-import Loader picks up a cleaned file (SFTP/SharePoint/Drive) and UPSERTS each row by external ID — so re-runs update the same record instead of creating duplicates; (5) Import Reconciliation Auditor verifies the load matched the source. Adopt each step from the blueprint; we build a private copy in your workspace that you can adapt, connected to your own Salesforce. Every write goes through human approval until you trust it.

How do I connect Salesforce / HubSpot / Dynamics 365 / SAP / Slack / Teams / Zendesk / Intercom / SalesLoft / ZoomInfo?

On Integrations, open the platform’s guide, register your own OAuth app on that platform, and paste its credentials (BYO-OAuth, per workspace — IT keeps control). Tacit encrypts them and refreshes tokens. For subdomain/tenant-based platforms (Zendesk, ServiceNow, Snowflake, Microsoft Teams, Dynamics 365) you also enter your account subdomain, Directory (tenant) ID, and/or environment host so Tacit builds the right API URLs. HubSpot (CRM + Service tickets + Marketing) is one-click: click Connect and approve the CRM scopes — it uses Tacit’s HubSpot app, so there’s nothing to build (agent changes show in HubSpot as “via Tacit”; no separate integration user like Salesforce). Enterprises that require their own HubSpot app can still BYO via “Use your own OAuth app”. Intercom (support) is standard OAuth; Dynamics 365 uses Microsoft Entra OAuth + the Dataverse Web API (the app must also be added as an Application User in your Dynamics environment). SalesLoft is standard OAuth (people + accounts, read/write). ZoomInfo uses OAuth 2.0 client-credentials on its current GTM API: create an app in the ZoomInfo Developer Portal and paste its client_id + client_secret (BYO — API entitlement required; enrich calls cost credits, search is free); Tacit mints and refreshes the short-lived token automatically on each run. DocuSign is connected the same way, with one extra step that matters: choose Production or Developer/demo on the connect form, because a developer account cannot be reached from the production host. On approval Tacit looks up which DocuSign region and account you are in rather than assuming one, so it works the same from any region. DocuSign offers two front doors behind one tile — a REST connector for explicit, reviewable agreement actions (send from template, chase a signer, void with a reason, read the signed values) and an MCP connector that discovers DocuSign’s own agreement tools live so they stay current. Once connected, domain agents can read and (with human approval) write through the connection.

How does connecting Slack work per workspace — and with Slack Enterprise Grid?

Each Tacit workspace connects to its OWN Slack. When you click Connect and approve, Slack installs the app into the workspace you are signed into and returns a bot token scoped to just that workspace; Tacit stores it encrypted under your tenant, and the runtime only ever resolves your tenant’s own token — nothing is shared across customers. You have two options: (1) one-click connect using Tacit’s shared, publicly-distributed Slack app, or (2) register your OWN Slack app (Integrations → Slack → “Use your own OAuth app”) so the whole integration stays under your IT policy with no third-party app added to your org — both end in the same per-tenant, encrypted, workspace-scoped token. On Slack Enterprise Grid, app installs are typically gated by your Slack org/workspace admin (app approval / org allowlist): run the connect while signed into the target workspace, and if approval is required the request routes to your admin and finishes once they approve. To install one Slack app into more than one workspace, turn on “Manage Distribution → Activate Public Distribution” (this is NOT the same as an App Directory listing, which is the only part that needs Slack review).

Where does IT see connection requests from business users?

In the Inbox (/foundry/bindings-inbox) — open it from the Operations section of the side-nav (“Inbox”) or the Integrations page. It shows every connection your business users have asked IT to set up, across all agents in the workspace, with each request’s status. It defaults to the Open queue (only bindings that still need action — a fully-configured agent drops off); switch to Configured for the audit trail of already-connected bindings, or All for both. Open ones also roll up on the dashboard under “Needs attention,” and IT gets a bell notification.

Does Tacit get my passwords or admin access?

No. You bring your own OAuth app, so IT keeps control and can revoke anytime. Credentials are encrypted, and domain agents never see them — tool calls go through a governed proxy.

How do domain agents remember things?

Each domain agent has a memory policy: session (this conversation), persistent (durable facts), or RAG (recall similar past decisions). Memory is grounded in your data and redacted.

What are Improvements, and are they safe?

Tacit mines real signals (corrections, eval failures, escalations) and proposes governed upgrades. Each is corroborated, eval-gated, and only goes live after you approve it.

Can a domain agent change itself automatically?

No. Self-learning is proposal-only — a human always approves before anything changes, and a single bad signal can never reach production.

How do I trigger a domain agent from another system?

Give it a webhook trigger and have the external system POST a signed (HMAC) event to its stable URL.

Can I call a domain agent from my own code?

Yes — via the Tacit API (POST /deployments/{id}/invoke) or directly to the runtime endpoint with cloud IAM.

Where do my domain agents run? Can they run in my cloud?

Tacit-hosted by default. You can also deploy into your own GCP project via Workload Identity Federation, or register them in Gemini Enterprise.

How is my data isolated from other customers?

Every query is strictly scoped to your workspace, backed by Postgres row-level security policies for database-enforced isolation, plus encrypted credentials and PII redaction in logs. See the Trust Center (/trust) for the full posture.

What does the Console at the bottom do?

It’s a live, color-coded feed of everything the platform is doing (LLM, tool, eval, retrieval, learning). It’s collapsed by default — open it to watch runs in real time.

How is spend controlled?

It isn’t metered, so there is nothing for you to watch. AI usage is included in your platform subscription and in each process’s price — no per-run charges, no usage meter, no monthly cap on any plan. Behind the scenes every workspace has a safety ceiling that protects against a runaway agent; if a workspace ever reaches it, new production runs pause, nothing is deleted, and we raise it for you — Usage & billing shows “Monthly capacity reached” with a one-click way to ask. (Infrastructure for agents running in your own cloud project is billed at the cloud level on Enterprise.)

Do you support SSO, IP allowlisting, and session limits?

Yes. Roles (owner/editor/viewer), per-workspace IP allowlist, max session lifetime, and audit-log export are live in Settings → Security. Enterprise SSO (Okta / Entra / Google Workspace / generic SAML via WorkOS, SAML/OIDC) is live: an owner sets the provider + email domain and clicks “Set up with your IdP” to complete a self-serve IdP handshake; MFA is enforced by your IdP. New members join as viewers (least privilege); owners can require explicit provisioning (SCIM/invite) and approve access requests on the Team page. SCIM directory sync auto-provisions/deprovisions users.

Are you SOC 2 or ISO 27001 certified?

SOC 2 Type II is in progress and ISO 27001 is planned — the underlying controls are implemented today. See the Trust Center (/trust) for current status and to request our security pack (DPA, whitepaper, pen-test summary, timeline).

Can I export the audit log or set a data-retention window?

Yes. Owners can export the audit log as CSV/JSON and set a retention window that purges old traces, invocations, and chats — the audit log is always kept ≥365 days — in Settings → Security.

Can I schedule a domain agent to run nightly?

Yes. Give the domain agent a schedule trigger (a cron like “0 7 * * *”, UTC unless you set a timezone) and deploy it to production — the platform fires it automatically when the cron is due; you don’t need your own scheduler. Each run shows up in Results/Observability like any other invocation. (You can still point an external scheduler at the domain agent’s webhook or /invoke endpoint if you prefer.)

What’s a Skill vs a Blueprint?

A Blueprint is a starter process template. A Skill is a reusable knowledge pack a domain agent loads on demand at runtime.

Can I pay my invoices automatically?

Yes. On Workforce & billing (/foundry/usage), the owner can "Add a payment method" — this opens Stripe’s secure hosted page to save a card (we never see or store it). Once a card is on file, Auto-pay turns ON and each monthly invoice is charged automatically; you get a "payment received" notification. With no card on file, invoices are instead sent for you to pay manually. Change or remove the card anytime from the same card.

Will I be notified when I have an invoice to pay?

Yes. When a monthly invoice is posted, the workspace owner gets a notification in the header bell — it shows the amount due and links to Workforce & billing (/foundry/usage). It waits there so you see it the next time you log in. Pay it from that page (securely via Stripe); once paid, the status updates automatically.

How do I upgrade my plan?

The workspace owner upgrades in-app — no leaving the product. From Workforce & billing (/foundry/usage) click any "Upgrade" or "Change plan" link, or go to /foundry/billing/upgrade directly. You see the platform tiers (Free / Team / Business / Enterprise) with your current plan marked; pick a higher tier and confirm. The button hands off to Stripe Checkout — you see the exact monthly amount and confirm it there, and no charge happens until you do. Your plan and caps update as soon as the payment is confirmed. Changing between paid tiers is prorated by Stripe, so you are only charged the difference for the remainder of the month. Enterprise is "Contact sales". Only the workspace owner can change the plan.

How do I cancel my subscription, and what happens to my domain agents?

The workspace owner can cancel from Workforce & billing (/foundry/usage) → Plan & subscription. Cancellation is "at period end" and is set on your Stripe subscription at the same moment: the current billing period is charged in full (no refund), Stripe bills nothing after it, and your domain agents keep running until that period ends — the exact date is shown on the card once you confirm. On that date your plan drops to Free and all your digital workers are shut down (their services are deleted, so they stop running and stop incurring compute/AI cost). You can undo the cancellation any time before that date with "Resume subscription", which also clears it at Stripe. Your domain agent definitions are kept, so if you resubscribe you just redeploy them.

Can I deploy domain agents into my own GCP / Vertex Agent Engine?

Yes. By default domain agents deploy to tacitrun-hosted Cloud Run, and the "Vertex Agent Engine" runtime option on a domain agent’s Deploy tab is disabled. To turn it on, an owner connects your own GCP project (BYO project via Workload Identity Federation) and/or a Gemini Enterprise app in Settings → Cloud deployment. Once either is connected, the Vertex Agent Engine option unlocks and domain agents can deploy into your own project — surfacing in your Gemini Enterprise dashboard when configured. On the Enterprise plan you can also turn on Run deployed agents in your project: each domain agent’s Cloud Run service is then created in your GCP project, running as a service account you name, IAM-gated on a public URL or internal behind your own load balancer, with its model calls on Claude models on your Vertex AI.

Can the platform use Claude models in my own GCP project instead of Tacit’s model access?

Yes, on the Enterprise plan. Enable Claude Opus 5 / Claude Sonnet 4.6 in Vertex AI Model Garden in your project, complete Cloud deployment (Pattern 2 — your project, WIF audience and service account), then turn on Settings → Bring your own model. The platform’s model calls — composing, on-demand runs, evaluations, chat, reading uploaded images and documents, and knowledge embeddings — then run in your project as your service account: no Anthropic API key, billed to you, in your audit logs. Turn on Run deployed agents in your project as well and each domain agent’s Cloud Run service is created in your project, calling Claude models on your Vertex AI.

Can I use OpenAI models with my own key instead of Claude?

Yes, on the Enterprise plan: Settings → Bring your own model → Provider “OpenAI (your API key)” or “Azure OpenAI (your resource + key)”, then choose GPT-5.6 Sol, GPT-5.6 Terra or GPT-6 Astra. Your key is stored encrypted in Tacit’s vault, used only for your workspace, never shown again, and removed when you switch back. Composing, on-demand runs, evaluations, chat and knowledge embeddings then run on your key; web search is not available on these models and uploaded images are still read by the platform’s Claude models. If the key is ever rejected, calls fall back to the platform default and the owner is notified in the audit log.

What is Workload Identity Federation, and why does Tacit ask for it instead of a key?

Workload Identity Federation (WIF) is Google’s keyless way to let an identity outside your project act inside it. You create a pool that trusts Tacit’s runtime identity and allow it to impersonate a service account you control; Google issues short-lived tokens at call time. Nothing secret is ever created, stored or shared, you can revoke access instantly, and every call shows in your audit logs as your service account. A service-account key file would be a permanent secret held by a third party — the thing security reviews reject.

Do I need to set up skills for my agent?

No. When an agent is built, Tacit automatically attaches the relevant know-how your IT team has published — matched to the systems the agent uses — with zero setup. You’ll see these on the agent’s Knowledge tab as “Playbooks it follows” (IT calls these “skills” and authors them on their side). It’s just part of the agent’s knowledge — nothing for you to manage.

How does pricing work — the plan and the process price?

Two parts, one bill. (1) A PLATFORM subscription for your team’s workspace — seats, security, governance, support (Free $0 / Team $1,999 / Business $2,999 / Enterprise custom). It does NOT cap how many processes you run. (2) Each live PROCESS (the outcome you offload) is priced by its capability tier — Assistant / Operator / Specialist / Orchestrator — as ONE price, no matter how many agents deliver it. You see the exact monthly price AND the value it delivers you on the process before you turn it on. No per-agent charges, no per-run metering, no agent caps. During your 7-day trial you get the whole product: take as many processes live as you like, with as many domain agents as each needs, bring your team in on Team’s seats, and use every integration. When the trial ends, the workspace closes until the owner chooses a plan — nothing is deleted, and everything comes back the moment the plan is active. On Enterprise every process is included in one custom number. Every workspace starts with a 7-day free trial of the plan you pick at signup (Team or Business) — no card needed to begin. Add a payment method any time in those 7 days and the plan starts automatically when the trial ends; without one, nothing is charged — Stripe pauses the subscription on day 7 and the workspace closes behind a “Free trial expired” screen until the owner buys a plan or adds a card. Enterprise pricing is agreed on your onboarding call.

My trial ended and I see “Free trial expired” — what happens now?

Your 7-day trial ended without a payment method on file, so nothing was charged and the workspace closed. Nothing is deleted: processes, domain agents, connections and knowledge are all kept. The owner picks Team or Business on that screen and pays through Stripe Checkout, or schedules a call for Enterprise; the workspace reopens the moment the payment goes through and any deployed agents resume. Team members who are not the owner see the same screen with the owner’s email to ask. If you added a card during the trial instead, the plan started by itself on day 7 and you never see this screen — the header badge reads the plan name rather than “Free trial”.

How is the “value to you” figured out — and how do I make it more accurate?

By default the value is the labor it saves: how many times the process runs a month × how long each run would take a person × a loaded hourly rate for your industry. Both of the first two come from YOUR real runs where we have them — how often it actually ran, and how many records a run actually touches — so the figure moves as the process does real work, and we never claim more runs than we have seen. You see that as “Value to You” + hours saved + an opportunity-cost line (what those hours free your team to do instead — e.g. working pipeline, filling roles, resolving accounts). Most processes are worth MORE than the hours, though — a renewal process protects revenue, a collections process avoids write-offs. So once a process is live we ASK you directly, right under its value card: what is it worth beyond the time it saves? The question names the hours we already count, so you don’t count them twice. You (or IT) give a rough annual figure and pick the kind (revenue it protects/accelerates, risk or cost it avoids, decisions it makes trustworthy) — or click “Not now” and we won’t ask again for that process. You can add or change it any time via “Add/Update the business value this delivers”. We credit a deliberately conservative share of that on top of the labor value, and you always keep the majority — you never see us take a cut, only your net value and the price. And you never have to take the number on trust: click “Value to You” on the process card and it opens its own working — every input, each line marked MEASURED (counted from your real runs), ESTIMATED, or “you told us”, adding up to exactly the figure shown. It also names what is missing: if we have not measured how many records a run touches, it says so and that the figure is therefore an UNDER-count.

What is “What it found” on a process — and how is it different from the value?

It is the one number on that card we MEASURED rather than worked out. Everything else there is labour: how often the process runs, how long each run would take a person, and a rate — plus whatever you told us the outcome is worth beyond the hours. “What it found” is different: it counts the records the process actually read, and how many of those turned out to be wrong. That is the work that WASN’T being done — records nobody knew were bad. It reads like “1 in 4 records was wrong · 448 checked · 112 corrected · 90 approved by a person and written back”. Every figure traces to a real run: “checked” is what the connector really returned, “corrected” is what the agent really changed, and “approved and written back” only counts changes a person approved AND that reached your system of record — an approval on its own is not proof the record changed. It appears once the process has surveyed a real segment on at least three production runs, and only when the process looked at more records than it changed (an agent that only reads the record it is about to fix would otherwise show a meaningless 100%). Until then it is simply absent — we would rather show nothing than a number we cannot stand behind. It never affects your price.

Where do I submit an agent for IT approval?

Two equivalent places. (1) On a single agent’s Overview: once its two gates are green — required tools connected + checks passed — a “Send to IT to approve” button appears. (2) On the PROCESS page (business or IT view): a “Submit N for IT review” button submits every ready agent in that process at once and shows a per-agent result (submitted / already in queue / needs validation first). Either way, only an owner or editor can submit, and IT gives the final OK before anything goes live. If an agent isn’t ready (e.g. connections still missing), it won’t be included — open it to finish setup first.

What’s the difference between “checks” and a “trial” — aren’t both just simulations?

Both run on MOCKED tools (nothing real is touched), but they check different things. CHECKS (evals) auto-grade CORRECTNESS: the system runs the agent on sample situations with known-good answers and scores whether its output is right — you need ≥80% to send to IT. A TRIAL is a simulated dry-run where its PROPOSED decision is compared to what a human would do (agreement) — pre-launch it’s just a preview you can watch, and it is NOT required to send to IT (only checks + connections are). The REAL domain agent trial happens AFTER go-live: the agent works alongside a person who approves each draft in the queue, and it earns unattended autonomy once it agrees with real human decisions ≥90% over ≥10 cases. WHERE to run the mocked trial: in the BUSINESS view, click “Try it safely” at the top of the agent; in the IT view, open “Checks & activity → 2 · Domain Agent trial”. IMPORTANT: the IT view also has a “3 · Simulate (live)” tab — that one runs against your LIVE connections (real writes can hit Salesforce) and is the last check before Deploy, so it is NOT the mocked trial; use Domain Agent trial for a no-side-effects run. Neither checks nor the pre-send trial touches production — live connections only happen once IT approves and it’s deployed.

Do I have to test my agent or run checks before it can go live?

No — Tacit runs the checks for you, automatically. As soon as you finish describing it (or change it), we quietly run the quality checks and a safe trial in the background. The agent’s Overview shows a simple tracker — Built → Checking it works → Approved by IT → Live. When the checks pass and any needed platforms are connected, the agent points you to “Submit the whole process for review” — agents go to IT together as one process, not one at a time. Your IT team gives the final OK before anything goes live — you never have to run evals or trials by hand.

Do I submit and deploy each agent separately, or the whole process at once?

The whole process, together. A process (the outcome you offloaded) is often delivered by a small crew of agents, so Tacit submits, approves, prices, and goes live at the PROCESS level — not agent by agent. It’s a clean handoff: the BUSINESS submits when the agents are built and pass their checks (you do NOT need tools connected first), then IT connects the tools, binds the fields, and approves. The process page shows one clear status banner with the single next step — for the business: Building → Ready for IT review → In IT review → Live; for IT: Awaiting submission → Connect, then approve → Ready to approve → Live. One “Submit the whole process for IT review” sends every agent to IT as a unit. Individual agents still have a Deploy tab, but that’s an advanced option to host just that one agent as its own dedicated cloud service — most teams never need it; normal go-live is the process submit.

When do I need to redeploy an agent?

Two reasons, and the second one surprises people. (1) You changed the agent itself — recomposed it, edited its rules or evals, or changed which tools it uses. The Deploy tab flags this and the button says so. (2) You want it running the latest platform version, or you want to lift a limit it was deployed with. An agent with its own cloud service runs the runtime image it was deployed with — and the run time limit it was deployed with, so an older service can stop a run after a couple of minutes even while the agent is still working. The Deploy tab tells you the limit and what a redeploy would raise it to. It keeps both until you redeploy — so an agent you have not touched in weeks is still running the platform as it was on the day it went live, even though we ship improvements continuously. Redeploying rolls it onto the current runtime on the same URL, with no downtime and no change to what the agent does. This only applies to agents with their OWN cloud service (schedule/webhook agents). On-demand agents run on the shared runtime and are always on the current version — there is nothing to redeploy. Redeploy from the agent’s Deploy tab → “Redeploy with current spec”; the Deployments page has Pause/Resume only.

Do my agents need to be “deployed” to run, or is “Live” enough?

It depends on how the agent is triggered — and most don’t need a separate deploy. TWO run models: (1) ON-DEMAND — you run it with “Run now”, in chat, or by calling its API. These run instantly on the shared platform runtime the moment IT approves, so their status is “Live” and there is NOTHING to deploy. (2) UNATTENDED — the agent fires on its OWN, on a schedule (cron) or a webhook. Those need a cloud service to receive the trigger, so after approval they show “Needs deploy”, and the process page shows a “Deploy process” button that spins up the services for the whole crew in one click; once done they read “Deployed”. So: Live = approved + runs on demand (no cloud service); Deployed = has its own running cloud service for scheduled/webhook firing. If your process “Runs on demand” (no schedule/webhook), Live is the final state — just click Run now. (Subagents ride their parent and are never deployed on their own.)

How does an agent use the knowledge I give it?

Three ways. Rules you set (Rules tab) are applied on every run. “Always remember …” facts (Knowledge → Teach it) are kept in memory and used every run. Uploaded docs and plain notes go into its knowledge base, which the agent searches on demand while it works — so a new note takes effect immediately, no rebuild needed. You don’t pick where things go; the platform decides (you can override with the Rule/Reference buttons).

How do I give a domain agent a rule it must follow?

Open the domain agent → Rules tab and write the rule in plain English (e.g. “Never send a quote with a discount over 20% without deal-desk approval”). It’s injected into the domain agent’s instructions every run, so the domain agent carries and applies it with judgment — no rule language or setup. Mark a rule “critical” and an AI rule-guard also checks every write against it before it happens — blocking the action or holding it for human approval (it can even look up data, e.g. “don’t delete a contact that still has open opportunities”). You usually won’t start from scratch: when a domain agent is first built, the platform reads your process — its steps and decision points, the tools it uses, your source docs, AND the conversation you had describing it — and pre-fills the Rules tab with proposed rules tagged “Proposed by AI”. They arrive DISABLED, so they never affect a run until you review each and tick “Enabled” (delete the ones that don’t fit). You can also click “Suggest rules” any time to get more. Use “Test a rule” to preview how the guard judges a scenario. The guard-activity line shows how many writes the guard actually CHECKED and how they came out — allowed, held, blocked — so “it ran and everything complied” is visibly different from “it never ran” (which is what happens when every critical rule is switched off). Governance: once a domain agent is live in production, only an owner can change its rules (editors can still review and test) — every change to a live domain agent is audited and announced. Rules are different from Skills: a Rule constrains what the domain agent may do; a Skill is know-how it pulls in on demand to do a task better. To see this across ALL your agents at once — which ones are enforcing their critical rules and which wrote rules but left them switched off — use the Rules column and the “Rules enforced” tile on Governance.

Do you have blueprints for private equity / deal teams?

Yes. Pick "Private equity" in Blueprints to get the full deal lifecycle (origination → diligence → execution & close with IC + signing gates → value creation → exit), plus the cross-portfolio value-creation playbook as standardized levers (working capital, FP&A, pricing/margin, spend analytics, JML access) that deploy identically across every portfolio company. Human-approval gates are built into the deal-close and IC steps. On Ingest, choosing "Private equity" also offers starter templates — Deal Sourcing & Screening, DD Red-Flag Log, IC Memo & Approval, and 100-Day & Value-Creation Plan.

Do you have a blueprint for software/SaaS renewals?

Yes. Pick "Hi-tech / SaaS" in Blueprints (or "Software Renewal — Quote-to-Cash" in Ingest) to get the full renewal motion: ~90 days out it builds the renewal quote, ensures a CRM Opportunity exists and attaches the quote with the correct products, the rep reviews/sends it, and on the customer’s acceptance it turns the quote into an order, creates the contract and submits it to the CLM, and updates the CRM — with human approval on discounts and saves. The order/ERP system is connectable today; the CLM and CRM write-back are per-tool connect steps.

Do you have a blueprint for revenue operations (RevOps)?

Yes. Pick "Hi-tech / SaaS" in Blueprints — the "Revenue operations" category covers the front-of-funnel and ops layer: lead routing & first-touch SLA, pipeline hygiene (stale / missing-next-step / mis-staged opportunities), forecast roll-up (commit/best-case/pipeline by segment with week-over-week deltas), and CRM data quality (dedupe, required-field fill, normalization). It complements the existing Deal desk approval and Renewals / Quote-to-Cash domain agents, so a RevOps team can stand up the whole lead-to-renewal motion. Reads/writes are bound to your CRM fields on the domain agent’s Bindings tab, with human approval on stage/close-date changes, merges, and forecast submission.

Do you have a blueprint for health plans / healthcare payers?

Yes. Pick "Healthcare — payer (health plan)" in Blueprints (or its starter templates in Ingest) for the core payer operations: prior authorization / utilization-management intake, pended & exception claims adjudication, member appeals & grievances, provider credentialing & re-credentialing, provider data / roster load & directory accuracy, and member enrollment (834) + coordination of benefits / overpayment recovery. It maps the usual systems (Facets / QNXT / HealthEdge / Epic Tapestry, Availity, MCG / InterQual, CAQH, X12 270/271/278/837/835/834). Safety is built in: domain agents gather, draft, and auto-approve clean criteria only — clinical adverse determinations (denials) are always made by a licensed clinician, and domain agents never auto-deny.

Do you have a blueprint for consumer lending / fintech (loans, debt relief)?

Yes. Pick "Consumer lending & fintech" in Blueprints (or its starter templates in Ingest) for the core consumer-finance operations: loan application intake & document collection, underwriting / credit decisioning support, funding & disbursement readiness, debt-settlement case management & creditor negotiation, collections & hardship handling, and member onboarding / enrollment. It maps the usual systems (loan origination like nCino / Blend / MeridianLink, the credit bureaus + FICO, Plaid, identity verification, debt-settlement platforms, Salesforce Financial Services Cloud). Safety and compliance are built in: domain agents verify, gather, draft, and auto-approve only clean-within-policy cases — credit decisions, adverse-action (denial) notices, debt-settlement authorizations, and fund disbursement are always made by a human, and domain agents never auto-deny credit or move money (FCRA, ECOA/Reg B, TILA, FDCPA, UDAAP).

Can a domain agent clean up or de-duplicate my CRM data (e.g. Salesforce contacts)?

Yes. Describe the cleanup in plain English on Ingest — what makes two records duplicates, which one should win, and what to standardize — and Tacit composes a domain agent that finds the candidates (it can text-search and page through your whole org, not just the first batch), proposes each merge for a human to approve, standardizes the surviving record, re-parents the related records, and removes the duplicate. Reads and writes are bound to your exact CRM fields on the Bindings tab; deletes and merges run with human approval; every change is audited and reversible by version. The same approach extends to any other system you’ve connected (clean one, then keep the others in sync). For Salesforce, Tacit can also use the native merge (re-parents the duplicate’s related records and removes it, one duplicate at a time, with human approval); SalesLoft and ZoomInfo are connectable too, so you can cascade the cleanup across systems and enrich records. New provider write paths are validated against your live org as you connect them.

What’s the decision queue for?

It’s where domain agents send decisions for a human to approve. Your accept/modify/reject becomes a learning signal.

What's the difference between assistant mode, autonomous, and automation?

They're run modes for the same kind of agent — the mode describes how it runs. In assistant mode you run or talk to it for a task (it drafts, you decide). Autonomous means it runs on its own on a schedule or trigger, making judgment calls with the human oversight you choose. An automation is a simple "when this happens, do that" that runs by itself with no guesswork. Describe your task and Tacitrun picks the right shape.

I just want to automate something simple — can I?

Yes. Describe the repetitive task ("when an invoice is 30 days overdue, send the reminder") and Tacitrun builds a straightforward automation that runs on its trigger — no judgment calls, no setup screens. Webhook/event and manual runs work today; time-based "every morning" schedules are rolling out.

How do I get an agent to help with my work?

Go to "Ask for help" and describe the task the way you'd explain it to a new teammate. Tacitrun builds it in the background and may suggest a ready-made agent you can adopt and adapt.

Why does my agent need to connect to a system, and what if I don't have the login?

To do real work, an agent needs access to the systems it touches (like Salesforce). If you have the login you can connect it; if not, choose "Ask IT" and your IT team gets the request and connects it for you. You'll be told when it's ready — no technical work for you.

What does “waiting on IT” mean?

A setup step — usually connecting a system — was handed to your IT team. Your agent is paused on that step until IT completes it; you'll get a note when it's ready to try.

Can I share an agent with another team or region?

Yes — within your company. A great agent built by North America Sales can be adopted by EMEA Sales and adapted to how they work. Sharing stays inside your company's workspace; it never crosses to another company.

Who can see the agents I build?

Your company's IT administrators can see everything your team builds — every agent and automation, including drafts — so they can keep it safe and compliant. No one outside your company can ever see them; every workspace is fully isolated.

Still not answered?

Ask us directly — we answer these ourselves.