What is an AI operating layer?

An AI operating layer is a layer that sits across the applications a business already runs (CRM, commerce, ERP, service desk, email) and carries out the work between them with AI agents, without replacing any of those systems or moving their data. The systems of record stay where they are; the layer does the reading, deciding and writing that people used to do by hand across them.

Why a layer, not another application

Operations work is rarely inside one system. A replenishment order starts in a spreadsheet, is checked against inventory in one platform and placed in another; a lead is enriched in one tool, routed in a second and sequenced in a third. Buying another application adds a system; a layer connects the ones you have and runs the process across them.

tacitrun connects through each system’s own API, with the customer’s own credentials handled by IT, and through a customer’s in-house APIs or MCP servers where no built-in connector exists. Every operation an agent can perform is declared, bound to fields by IT, and executed through the same approval gate.

What the layer adds that the systems lack

A process graph that spans systems, agents composed from it, evaluation cases derived from it, a queue where a person approves each cross-system write, and one audit trail for the whole process instead of a fragment in each application. That is the operating part: the work has an owner, a record and a control point, not just a set of integrations.

The terms, as the product defines them

Process

A workflow, mapped as a step-by-step graph.

A business workflow — like vendor onboarding, invoice approval, or returns intake — captured as a graph of steps (a BPMN-style diagram). Each step is done by a person, a system, or a domain agent. A process is the blueprint; domain agents are what run parts of it.

Integration

A connected platform, authorized with your own credentials.

A platform you've connected by registering your own OAuth app and pasting its credentials. Tacit encrypts them, refreshes tokens, and never holds admin access to your systems.

Tool / Connector

A capability that lets a domain agent read or act in another system.

A connector to a system of record (Salesforce, SAP, Slack, ServiceNow, Snowflake, …). A domain agent only gets the tools it needs, calls them through a governed proxy, and never sees the raw credentials.

Questions people ask about this

How do I connect my own work inbox (Outlook 365 or Gmail)?
On Tools → Connections, the Outlook (Microsoft 365) and Gmail (Google Workspace) connectors carry a "Your inbox" badge — these are PER-USER: you click "Connect my inbox" and sign in with your own work account, and the connection is stored just for you. Each teammate connects their own mailbox; your agents only ever act on YOUR inbox, never anyone else’s. Under the hood, when you run an agent that uses your inbox, it resolves the credential tied to your user id (metadata.user_id) — so a mailbox agent you own reads/archives/sends in your mailbox only. Outlook uses Microsoft Graph (/me/messages: list, get, move-to-archive, mark read, send); Gmail uses the Gmail API (list/search, get, archive via remove-INBOX-label, send). This is different from a tenant-wide system connection (like Salesforce) that IT connects once for everyone. One prerequisite (done ONCE, not per person): connecting any Google/Microsoft mailbox needs a registered OAuth app. The clean path is your workspace admin registering your org’s OWN app (in Google Cloud / Entra) marked “Internal” — which needs no Google/Microsoft verification even for the mailbox scopes — via “Use your own OAuth app” on the connector. After that one-time step, every employee just clicks “Connect my inbox” and consents; there is no IT request per person. (Alternatively Tacit provides a shared app, but an external app using restricted mail scopes needs Google’s CASA verification.)
How does my company get connected to Google Workspace (or any OAuth system)?
One workspace = one company, and that company connects its OWN Google Workspace — there is no magic cross-account access. An admin goes to Tools → Connections → Connect Google Workspace, which sends them to Google’s consent screen; they sign in as a Workspace user and grant the scopes (Drive/Gmail/Calendar). Google redirects back and Tacit stores the tokens encrypted, scoped to your workspace only. There are two ways to supply the OAuth app: (1) Tacit’s shared app — just click Connect (but Google requires a security review for restricted scopes on external apps); (2) Bring-Your-Own app (recommended) — you register your own Google Cloud OAuth client and paste its ID/secret, which lets you mark the app “Internal” so no Google verification is needed even for sensitive scopes. For org-wide access without per-user clicks, use the service-account + domain-wide-delegation fields. The key point: connecting always requires a real person at that company to consent — Tacit can never reach a Workspace nobody granted it.
We’re a staffing firm — what can Tacit do for us, and do I need TempWorks connected?
If your workspace industry is Staffing, the Catalog shows a set of staffing domain agents (“digital workers”): a Recruiter that screens applicants and drafts bilingual outreach, a Scheduler that fills shifts and handles call-offs, plus Onboarding, Timecard, HR, Safety/Compliance, Ops/Reporting and more. They automate the admin around your workforce — not the physical labor. Every risky action (texting a candidate, booking a shift, editing a timecard, sending a notice) pauses for your approval in the queue. You do NOT need TempWorks connected to evaluate: a pilot runs the agents on seeded sample data (a few workers, an open order, a call-off) so you can see real screening, ranking, and drafting; connect the real TempWorks afterward. Note: scheduled/recurring runs aren’t firing yet, so these run when you start them or on an event for now.
Can I demo the Salesforce / SalesLoft domain agents without connecting a live CRM?
Yes. The sales domain agents — Lead Router (enrich a new lead and route it), CRM Hygiene Fixer (fill gaps and merge duplicate records), and the Follow-up Sequencer — can run on seeded sample CRM data so you see real enrichment, ranking, and record edits with no live Salesforce, SalesLoft, or ZoomInfo connected. When those connectors have no connection, the workspace serves a small built-in dataset (a few accounts with missing fields, a fresh inbound lead, duplicate contacts, and matching ZoomInfo firmographics). Every write (updating a record, creating a SalesLoft person, deleting a duplicate) still pauses for your approval in the queue. Connect the real Salesforce/SalesLoft/ZoomInfo afterward and the same domain agents run against your live data — nothing to rebuild.
A catalog agent lists several platforms (Salesforce, SAP, Adobe Commerce, Shopify) — do I have to connect all of them?
No. Those show what the agent CAN work with — it adapts to whichever ONE your company runs (most companies have a single commerce/order platform). When you adopt it, a quick picker asks which platform you use and pre-selects the one we detect you’ve already connected; the agent is then built to use just that one. You never connect platforms you don’t use, and you can always tell it which to use in chat.

More in the FAQ and the glossary.

Related

See it on one of your own processes. Free for the whole product for a trial period, no card needed to start, every write held for your approval.