Governed employee teams · in your VPC

Run AI employees your auditors can verify.

Employee teams inside your VPC — capability-bounded, hash-chain audited, quality-gated.

run #4812governed
documents.search
data.cluster
http.request → stripe.com
eval · golden-suite
sha256 3a9f…c17chain verified·no data left VPC
A real run: two tool calls allowed, one denied out of scope, the verdict and hash chain recorded.

100%

tool calls audited

0

data leaves your VPC

sha-256

tamper-evident chain

your model

Anthropic · OpenAI · Ollama

A sentence in. A governed team out.

You do not assemble employees by hand and hope the wiring is right. You describe the job, review the shape, and run it — with the bounds and the record already in place.

  1. Describe the job

    It designs the team — a coordinator, two to six specialists, a writer, and the order they work in. You land on the shape and can rename, rewrite or rewire any of it before the first run.

  2. It runs where your data lives

    Each employee gets only the tools and domains you allowed, fail-closed. Anything past a risk, cost or domain threshold waits for a person instead of proceeding.

  3. You get a record, not a claim

    Every tool call, approval and config change lands in a sha-256 hash chain. Replay it, verify it, hand it to an auditor — including the calls that were refused.

You write

“Every Monday, check our three competitors’ pricing pages, flag anything that moved more than 5%, and write it up for the sales team.”

You get

flowprice-scout, page-watcher -> change-analyst

  1. Coordinatorwatch-coordinatorsplits the job, delegates
  2. Workersprice-scout · page-watcherrun together
  3. Synthesizerchange-analystwrites the brief

Real employees and a real preset, yours to rename or rewire

Governance is the product.

Self-hostable, capability-scoped, fully audited, quality-gated, model-agnostic — one engine, on your infrastructure.

Capability bounds

Per-agent allowed domains and denied tools, fail-closed. Dry-run the guard before it goes live.

Audit trail

Every tool call, approval, and config change in a sha-256 hash chain. Replay and verify on demand.

Quality gates

Golden-suite evals score each run. Failing runs self-heal — retry or replan to an alternate employee.

Approvals

Policy-driven human gates by risk level, cost, and domain. Timed-out approvals park the run, not the worker.

Cost control

Per-org budgets, per-run cost caps, daily quotas, and a kill switch for runs that blow their ceiling.

Deployment

Self-hosted in your VPC. Bring your own model — Anthropic, OpenAI-compatible, or local. Air-gap friendly.

Every step visible while it runs.

Employees stream each tool call as a live, attributable feed — the same one your operators see in the console.

  • Roles for sales, finance, support, operations, marketing, and risk
  • Install from the catalog or author your own
  • Approval gates route high-risk actions to a human
Bahini · Sales agentLive

A typed SDK over the same governed API.

Everything the console does, your code does — same capability bounds, same audit trail. Dependency-free.

quickstart.ts@bahini/sdk
import { BahiniClient } from "@bahini/sdk";

const bahini = new BahiniClient({
  apiKey: process.env.BAHINI_API_KEY!,
});

const done = await bahini.runAgentAndWait("agent_123", {
  prompt: "Summarize last month's sales by division.",
});

console.log(done.run.status); // "COMPLETED"

Questions, answered plainly.

Self-hosted in your VPC. Bring your own model — Anthropic, OpenAI-compatible, or local. Air-gap friendly.

Put employees in front of your auditors, not your incident channel.