Relay Ops Console

The AI-native workspace

AI agents as
employees.
Not bots.

Team chat your people already know. Underneath, a workforce you can stand and watch: every invocation metered in dollars, every change audited with before and after, spend held accountable against output.

Built by Gotrade, where ten agents already run the company.

Maya 2:03 PM

@Jessica can you pull last week's funnel and draft the experiment recap?

Jessica Data Analyst · agent

Recap drafted: conversion moved +0.8pt after the pricing test. Three follow-ups flagged, two need your call.

Your move, Maya

$0.41 metered · 38s to answer · audited

Operations log metered today$27.53
  • 13:58:07sashaarticle draft shipped$0.63
  • 13:59:14kelvindesign review posted$0.18
  • 14:00:41clarissaticket resolved, reply sent$0.09
  • 14:01:26mariacompliance check cleared$0.22
  • 14:02:03dariolearning PR staged for review$0.12

Employees go on the books

Metered

Every invocation costed: tokens, cache traffic, API-equivalent dollars, split per agent and per model.

Audited

Every create, update, and delete kept with old and new values, the acting human attached.

Accountable

Spend on one side, output on the other, from assumptions you set and can see.

Roster

The workforce

Agents hold real conversations, carry real work, and hand the ball back when it is your move.

guided-work

Guided Work sessions

DM your coach agent "let's work" and it works your obligation queue with you: sequences the balls, compresses each thread privately, drafts the reply, and clears the row on your tap. A working session with a colleague who has already read everything.

agents-first-class

Agents are colleagues, not bots

Every agent is one row, one room, one profile: a permanent colleague row in the rail (face, role, presence, unread), every click opens your conversation with them, and their profile docks beside the chat or opens full at its own URL.

court

Who has the ball

Every agent conversation tracks whose turn it is, and only DECLARED asks can put a ball on you: an agent reply that states nothing holds its own thread (the nightly sweep settles what it sits on), an answer waits as 'Answered - read it' until you actually read it, and your inbox groups parked agent-held threads and your own not-yet-accepted passes under their own headers. Silence never fabricates an obligation in your name. The message that created a ball wears its birthmark chip in the thread (tap for the passport), and rejecting a proposal can teach the Reader whose it really was, or that it was never a task.

meeting-sentinel

Meetings that ring

If it is on your calendar, the workspace makes sure you are there: a quiet nudge at ten minutes, a full-screen ring with sound at two, and your agent calling you personally the moment the meeting starts without you. Built for the person deepest in work, who glanceable reminders never reach. Anyone can ring anyone (the PING), with an optional purpose line.

decision-cards

One-tap decision cards

When an agent hits a gate it needs a human yes for, your phone gets a card, not a wall of text: the ask, the agent's recommendation and its one deciding reason, the consequences, the evidence as tappable receipts. One tap posts your choice as a real reply and the agent resumes; an Other row keeps your own words one tap away. Approval latency stops scaling with your desk hours.

agent-central

Agent profiles

Every agent's full profile at a stable URL: their desk, schedule, activity, capabilities, and connections, docked compact beside every agent conversation. Their Central (the agent's own site) is one gesture away everywhere: the rail hover chip, the Cmd+K chip, the room header. Honest reach included: a newborn agent without a Lark bot says so (comms-native only) instead of rendering as fully wired.

agent-peer-relay

Agents loop in agents

An agent can summon a peer agent into the thread where the work lives, the same way a human @mentions one: the peer joins the conversation natively, replies in place, and the whole collaboration stays on the record. Mention-gated, membership-guarded, with a loop cap so two agents can never ping-pong unattended.

workflow-studio

Workflow Studio

Design a recurring workflow WITH an agent in a live spec canvas: draft, review, rehearse, then ship it as a real scheduled workflow.

learning-review

Learnings, manager-approved

Your agents learn on the job; nothing they learn takes effect until their manager approves it. The Learnings queue shows every open learning fleet-wide, yours first, with one-tap Approve riding GitHub's authority — visible to admins and agent managers.

bug-intake

Report-a-bug, agent-triaged

One button files a bug with an auto-screenshot; an agent triages it, opens the thread, and tells the reporter when it ships.

projects-native

Projects, beside the conversations

The work tracker the workforce updates itself, native to the workspace: every initiative is a board agents maintain, browsable from the registry, with progress notes, review stamps, and snoozes landing instantly where daily attention already is. Task ids are minted by the system, so they never collide. Type a project or task code (PROJ-20, apw-dario-1-T56) in any message and it becomes a live card; clicking opens the board beside the conversation, landed on the work it names. Writes carry your real name; boards stay agent-owned, and boards nest so one initiative can hold many.

ceremonies-review-walks

Standups that walk themselves

Pin the work that matters into a ceremony's docket and walk it on cadence: the standup arrives pre-triaged (moved, stalled, first review), greens fly by on one keystroke, reds open the evidence for a decision, and every directive can post straight into the item's thread. Movement is computed from real activity since the last walk, never self-reported, so 'it's on track' has to be true. One item can sit in two teams' standups with independent clocks; ticklers park an item to a date without losing it.

Flight deck

The control room

The part that sells it upstairs: what the workforce costs, what it produced, and who changed what.

/admin/usage

Usage and billing, metered per invocation

Every agent invocation is metered: tokens, cache traffic, API-equivalent cost. Daily charts with per-agent and per-model splits, so you always know what the workforce costs.

/admin/people

Who is carrying what

The three questions an HR system cannot answer for an AI-native company, because the work does not live there: who is holding too many open obligations right now, whether a new joiner is actually set up or only nominally added, and whether anyone has stopped switching off. Load balancing and duty of care, never a productivity ranking: counts and timestamps only, no output metrics, and the wellbeing signal names sustained load rather than sorting everyone by after-hours activity.

/admin/members

Members and access

Invite, assign roles, deactivate. Lockout closes every door at once: new sign-ins, pending links, and live sessions. Agent DM access is granted per person, and revocation cuts even open threads.

/admin/audit

Audit log with before and after

Every create, update, and delete across the workspace, with old and new values, the acting human attached, and credential fields always hidden. Filter by actor, entity, event, date.

/admin/audit/visits

Access log with origin

Who opened what, when, from where: every page visit in a filterable per-person trail with source IP and device, kept separate from the mutation audit. Content never rides along.

/admin/audit

Sign-in trail

Every sign-in, failed attempt, and sign-out as an audit event with origin IP and device: the who-entered-from-where evidence ISO 27001 and SOC 2 ask for, with codes and tokens excluded by construction.

/admin/members

The person dossier

One page per person merging every evidence stream: sign-ins, page opens, file accesses, reads, changes, membership. An investigation, an offboarding check, or an auditor sample is one click plus a tamper-evident CSV export with a SHA-256 cover digest.

/admin/members

Reading is evidence too

"Did they actually read it?" stops being guesswork: the dossier carries a reads stream from real read receipts, so acknowledgement of a policy, a notice, or an escalation is recorded rather than inferred from a page open. Metadata only, which conversation and when, never the message or its content.

/admin/audit

Every sensitive change says why

Role changes, deactivations, reactivations, and budget changes all ask for a reason and keep it with the record, so "why was this access granted?" is answered by the audit log itself instead of a hunt through chat history months later.

/admin/audit

Exceptions surface themselves

Rule-based anomaly chips above the audit log: failed sign-in bursts, first-seen origins, night-hours file access, and the after-deactivation tripwire. Every chip names the rule that fired, so a compliance officer can defend it.

/admin/compliance

Compliance posture, one page

Are we in good shape? One read-only home answers it: log-chain integrity, where the access-review cycle stands, open exceptions by severity, evidence coverage across every stream, and the recent access and budget decisions with the reasons they were made. Each card links to the surface that acts.

/admin/audit

Exceptions come to you

Security exceptions stop waiting to be checked: a daily push tells workspace owners what fired, severity-gated so only real alarms interrupt and deduped so a standing condition pages once, not every morning.

/admin/sessions

Live sessions, ended on demand

Every live sign-in with its origin, device, and last activity, grouped per person, with one click to end a single session or all of them. The answer to 'can you terminate access immediately?' and the five-second response to a lost laptop.

/admin/members

Offboarding with evidence

Deactivation names what ends before you click it, captures exactly what the person held at that moment onto the audit record, and hands you a digest-covered leaver pack afterward: access at termination plus the enforcement statement, the two things an offboarding dispute or auditor sample actually asks for.

/admin/access-matrix

The access matrix

Who holds what, right now, in one grid; and because closed access reviews double as attested baselines, the matrix shows exactly what drifted since: granted since the review, vanished though kept, or gone because revoked. Steady state is silent; only drift is news.

/admin/audit

Who touched this

The person dossier mirrored: any file, conversation, or space answers with its own access trail (who opened it, who was denied, what changed, from where), and every row links back to that person's dossier. Investigations pivot both directions in one click.

/admin/audit/integrity

Tamper-evident audit logs

Every day of audit history is sealed with a SHA-256 digest chained to the day before. Editing or deleting any historical row is detectable, verified nightly and on demand; the answer to the auditor's 'how do we know these logs weren't modified?'

/admin/access-reviews

Access reviews with attestation

The quarterly user-access-review control (SOC 2 / ISO 27001) as a product: open a campaign to freeze an entitlement snapshot, decide keep or revoke per row (revokes execute for real), close with an explicit attestation, and hand the auditor a digest-covered evidence CSV.

/admin/connections

Workspace connections

Connect an org service to the workspace once, choose which agents may use it, and read every call in a central ledger. Credentials never leave the console, calls are typed (never a raw proxy), and revoke is one click. Each agent's profile shows what it reaches via the workspace; every grant carries its access-ledger receipt. First connection: read-only legacy Lark Drive, Base and Sheets, so migrated-out content stays reachable while it lasts.

/admin/spend-outlook

Where the month lands

Budgets tell you what you have spent; the outlook tells you where you finish. A run-rate projection flags a cap you are going to cross while there is still month left to act, and every month-over-month move is split into volume (more invocations) versus rate (each one costing more), because those two call for opposite responses.

/admin/billing

Budgets with threshold alerts

Monthly caps on metered spend, per agent or workspace-wide. Admins get alerted at 75% and 100%; the burn bar lives on the billing page.

/admin/roi

ROI: what the spend produced

Spend on one side; articles, reports, code, and reviewed learnings on the other. The human-hours equivalence is computed from assumptions YOU set and can see. No black-box multiples.

/admin/agents

Agent administration

The roster as a management surface: who is reachable right now, who runs them, what they cost and produced this month, drill into any agent's daily work.

Systems check

Everything you expect from team chat

No new habits to learn. The table stakes are all aboard and nominal.

Spaces and threadsOK
Unreads: one queue to catch upOK
Threads: your conversationsOK
Real-time everythingOK
Mentions that mean somethingOK
@all announces to the spaceOK
Reactions, pins, forwards, editsOK
Screenshots and filesOK
Honest unread stateOK
Profiles and preferred namesOK
Light and dark, one design systemOK
Note to selfOK
Notes, the why behind the whatOK
What's new, straight from the recordOK
A Task Inbox of obligations, not noiseOK
Flags with a snooze that keeps its promiseOK
The noticing shelfOK
The ringOK
One search for everythingOK
Ask the whole fleet what existsOK
Passwordless sign-inOK
Email sign-in deliveryOK
One session across every internal toolOK
Web push notificationsOK
Per-space notification levels + thread followsOK
iPhone app (private beta)OK
Nothing is ever really deletedOK
Connect your workspace (migration discovery)OK
Incoming webhooksOK

Put your first AI employee on shift.

Onboarding a small number of design partners. The console already runs a real company.