Agent identity • Scoped tools • Append-only audit

Build, deploy and
govern AI agents.

Give every agent an owner, a scope and a record. Build it, test it against real cases, publish it with its own revocable key — across Drive, Slack, Notion, Salesforce, Microsoft 365 and GitHub, under the permissions your team already has.

User 1User 2User 3User 4User 5User 6
Built for the teams who own the agents
Early access • No credit card to start
Google DriveSlackNotionSalesforceMicrosoft 365GitHub
iRABU — Agent Console published
SalesResearch-01 • Owner: VP Sales • 4 tools
You
publish this agent
You
iRABU
Published — 12/12 eval cases passed
Scope: Sales space • 4 tools • own key, revocable
You
run the Acme renewal brief
You
SalesResearch-01CITED
We promised Acme a custom SSO integration by Oct 15 and a dedicated Slack channel 【Q3 Deck — L4-L7】. Pricing locked at $24k/yr 【MSA — P2】.
Confidence 0.92
【Q3 Deck — L4】 【MSA — P2】 【Slack #acme — Aug 12】
Q3 Deck — Acme commitments
"Cut during Q3 planning? Actually promised SSO by Oct 15 + dedicated Slack channel for onboarding..." — Page 4, lines 4-7
Drive / AcmePriya • Aug 2
Requires approval — external send
Email renewal brief to AcmeAwaiting you
Illustrative run • An agent only reaches what its owner granted
Who it's for

Built for the people who have to answer for what the agent did.

The roles iRABU is built for
Platform • Ops • Security • Legal • Agent owners
No ratings, no logos, no borrowed credibility — we have not earned those yet. Illustrative faces, named roles, and what the product actually does. Real teams get named here when they opt in.
Identity, not anonymity
How it works • not a quote
Every agent has a name, an owner and a status. Not an anonymous API call you find out about later.
shipped todaylogged append-only
Scoped before shipped
How it works • not a quote
Declare the tools and the one space an agent may reach, before it is published. Keys are per-agent and revocable.
shipped todaylogged append-only
Inherits, never exceeds
How it works • not a quote
The permission story in plain English: an agent only ever reaches what its owner could already open.
shipped todaylogged append-only
No stock testimonials • No fake ratings until teams opt-in to be namedAn agent inherits its owner's access, never more
One connected layer

The systems your agents reach, in one place.

No migration. No new silo. Connect where work already happens — then decide, per agent, which of it they get.

Your stackBecomes →
Drive
Slack
Notion
Salesforce
M365
GitHub
iRABU layer
Permission-aware, isolated DB per org
Build
Name it, own it
Scope
Tools + one space
Deploy
Eval, then publish
Observe
Append-only log
Reachable viaIn-appREST API MCP for agents
Agents that show their work.

Traceable to a source, an owner and a record.

Every answer links to exact doc, page, line, owner. Click 【Q3 Deck — L4】 and see the source. Confidence score tells you how sure we are — 0.92 means we found it, 0.68 means you should double-check. And the log of what happened cannot be edited afterwards, by anyone.

Cited
Page-level links • Owner + date • Private by default
Append-only audit
Enforced in Postgres — our own backend can't rewrite it
Permission-aware
If you can't see the doc, neither can your agent
No fake social proof.
We don't show "Used by Linear, Stripe" unless they say we can. Early access waitlist open — you'll know when teams opt-in to be named.
"If you can't see the doc in Drive, neither can the agent you built." That's our permission story in plain English.
Use cases

The agents teams actually deploy.

Same identity model, same scoping, same audit trail. Different owner, different job, different blast radius.

Sales
Reads CRM and the deal room, drafts the brief. Sending anything out needs a human.
Read + draft
Product
Scoped to the product space. Finds the owner and the decision, with citations.
Read-only
Ops
Creates tasks, assigns roles, follows up. Writes inside the workspace, not outside it.
Write, scoped
Legal
Every answer links to page & line. The record of what it read cannot be edited after.
Auditable
Support
Summarises decisions across GitHub and Drive — only the spaces it was granted.
Least privilege

Build. Scope. Deploy. Observe.
The four things an agent needs before it touches your data.

One identity model, one audit trail, one isolated database per org. No separate products to buy.

Build
Agent builder
Give it a name, an owner, instructions and a job. Test it against real cases before anyone can use it.
Named, owned, versioned
Eval cases before publish
Re-test when config changes
Shares one permission model • One audit trail
Scope
Least privilege
Declare the tools it may call and the one space it may read, up front. Its key is its own, and revocable.
Per-agent tool list
Knowledge scoped to a space
Own key • revoke any time
Shares one permission model • One audit trail
Deploy
Lifecycle
Draft, testing, published, archived — a real lifecycle, plus approval gates on actions that leave your walls.
Draft → testing → published
Archive without deleting
External sends need a human
Shares one permission model • One audit trail
Observe
Audit trail
What it read, what it changed, who approved it — written to a log that nothing downstream can rewrite.
Append-only, enforced in Postgres
Even our backend can't edit it
Admin-gated reads
Shares one permission model • One audit trail
For developers

Already have agents? Bring them over MCP →

The same permission-aware API is exposed over MCP, so Claude or any compatible agent calls iRABU directly instead of clicking through a UI. Live today: irabu-mcp puts 43 tools behind one key that inherits the holder's access. In-app, REST and MCP are the same source of truth and the same ACLs — an agent you wrote elsewhere gets the same scoping as one you built here.

Live today • MCP spec compliant
Reachable via
In-app
Agent console
REST API
Keyed, per-agent
MCP
For Claude, etc.
irabu-mcp • Claude Codeirabu-mcp repo
# Install MCP server
npm i -g irabu-mcp
# claude_desktop_config.json
{
  "mcpServers": {
    "irabu": {
      "command": "irabu-mcp",
      "env": { "IRABU_API_KEY": "•••" }
    }
  }
}
permission-awarecitations included
Claude can now call: search, get_doc, list_sources — with same ACLs as chat.
Placeholder — irabu-mcp repo link will update soon
Trust is built in, not bolted on

Governance you can actually verify.

We won't claim certifications we haven't earned, or controls we haven't built. Here's what an agent is actually subject to today — and what's still roadmap, said plainly.

Agent Identity & Ownership
Every agent has a name, a human owner and a status. Nothing runs anonymously.
Shipped today
Scoped Tool Access
An agent is handed only the tools it was granted. The rest aren't withheld at call time — they're never offered.
Shipped today
Row-Level Security
Enforced at Postgres level. Policy fails = query fails. Not app-level filtering.
Shipped today
Permission-Aware Retrieval
An agent reaches only the space it was scoped to, under its owner's access. Never more than the human behind it.
Shipped today
Append-Only Audit Trail
A Postgres trigger blocks UPDATE and DELETE outright — which binds our own service role too, not just your users.
Shipped today
Approval Before External Send
An agent can only ever draft an outbound email. The send path is reachable from a human clicking Approve, and nowhere else.
Shipped today
Revocable Per-Agent Keys
Each agent gets its own hashed key with a last-used timestamp. Revoke one without touching the others.
Shipped today
Encrypted in Transit & at Rest
TLS everywhere, hashed API keys. No plaintext secrets in logs.
Shipped today
Your Own Database
Isolated DB per org. Your data doesn't share tables with other orgs. Stronger than shared-schema multi-tenant.
Shipped today
What we DON'T claim yet
No central policy engine — an agent's scope is set when you build it, not evaluated per action against org rules. Approval gates cover external email, not yet every action. Agents run under their owner's identity rather than their own. No SOC 2 audit, no SSO. All of that is roadmap, and we'll say so until it isn't.
Honest roadmap • No fake badges
Why this matters:Claiming "SOC 2 certified" when you're not voids contracts and attracts regulatory attention. The first enterprise buyer who asks for your report finds out in one email. Governance claims are worse — "policy-enforced" is the kind of thing a security review tests directly, and a control that turns out to be a setting nobody evaluates is how you lose the account and the reference. We'd rather show you the gap and the date.
iRABU.org • For Good

Sponsor schools & underserved groups to use iRABU for free.

Through irabu.org, you can sponsor schools, nonprofits, and underserved groups to use iRABU technology for free. Same permission-aware, cited answers — for classrooms that can't afford enterprise tools. Your sponsorship covers their isolated database, support, and training.

How it works
1
Choose
Pick a school, nonprofit, or classroom from our vetted list.
2
Sponsor
Cover their workspace — isolated DB, support, onboarding.
3
Impact
They get full iRABU free, you get hours saved + Q&A reports.
Tax-deductible via irabu.org • Same product, same security model.
Classroom using technology
Example classroom • illustrative Preview
Hours saved
—
reported once sponsored
Questions answered
—
cited, in classrooms
Sponsored
—
schools & orgs
Track impact as you sponsor: hours saved, questions answered, docs surfaced. No vanity metrics — only cited answers your sponsored classroom actually used.
Photos are illustrative • Real impact reports from sponsored workspaces
Live demo

Try it. 5 questions left in this demo.

No signup, no credit card. A scoped agent against sample data — same citations, confidence scores and source pills your own agents return in prod.

What to try
This demo agent is read-only. Anything that writes or leaves your walls goes through approval.
iRABU demo • permission-aware5 questions left
You
What did we promise Acme in Q3?
Y
iRABU
Custom SSO integration by Oct 15 + dedicated Slack channel. 【Q3 Deck — L4-L7】 Pricing locked at $24k/yr. 【MSA — P2】 Confidence: 0.92
Confidence shown • Sources clickable Row-level security enforced

Start free. Scale when the agents multiply.

No credit card. No fake enterprise badges. Pricing mirrors what we actually run — isolated DB per org, audit trail included on every plan.

Free
$0/ forever
1 user, 1 agent, 3 sources
Drive OR Slack OR Notion
1 published agent
Eval cases before publish
Audit trail + your own database
Start Building — Free
MOST POPULAR
Team
$20/ user / mo
Everything in Free, plus:
Unlimited agents + sources
Per-agent revocable keys
Approval gates on external sends
REST API + MCP for external agents
Row-level security enforced
Start 14-day trial
Isolated DB per org • No credit card
Enterprise • Roadmap
Talk to us
Honest about what's not built
VPC / private indexing
Custom retention + audit export
Central policy engine — On roadmap
SSO (SAML/OIDC) — Coming soon
SOC 2 — On roadmap, not claimed yet
Contact founders

Give your agents an owner, a scope and a record.

irabu.org is our nonprofit arm — sponsor schools & underserved groups. Same product. Honest roadmap: no central policy engine yet, approval gates cover external email rather than every action, no SOC 2, no SSO. We'll keep saying so until each one changes.