An environment that is yours
Every deployment is its own isolated instance - not a seat in a shared SaaS. You choose the region it runs in, and daily recovery snapshots are included.
Yours by design
Olano is not a shared tenancy with your data in it. Every deployment is an isolated environment, and everything an agent does is gated, logged and reversible.
Every Olano system runs in its own isolated environment - your workspace, memory, files, connector secrets, and audit logs are never mixed with anyone else's, and everything is encrypted at rest and in transit. Your team governs what the system may do: approvals where judgment is required, a complete history of every action, and hard limits on what it can spend.
The gate
Research needs no permission. Anything that leaves the deployment or spends money is a category you can hold behind a human.
Trust levels
Every agent carries a trust level describing how much autonomy it has been granted. A new agent starts at level 2.
Read-only. It can look and it can suggest, but it changes nothing.
May write to its own memory and logs. Still touches nothing outside itself.
May create and edit workspace files and run commands through its configured environment.
Full workspace access, and auto-approves operations classified as low risk.
The widest setting, including local shell access. Intended for development, not for an agent facing customers.
High-risk operations require a human at every trust level. Level 4 does not mean “no approvals ever” — it widens what counts as routine, not what counts as dangerous. The full rules are in approvals and trust.
Every deployment is its own isolated instance - not a seat in a shared SaaS. You choose the region it runs in, and daily recovery snapshots are included.
Sending an email, spending money, writing a file, using a secret, delegating work: each is a category you can require a human to approve. Read-only research needs no gate.
Every action is attributed to the human or agent that took it, on an append-only log. Agent-to-agent conversations are recorded and replayable - none of it is a black box.
Set the ceiling in advance, per agent and per deployment. Usage is metered and visible, so a runaway loop hits a wall rather than an invoice.
Credentials live in a per-deployment vault, resolved per agent, and are never hydrated into a shared environment. Each agent sees only what it was given.
On a Private AI plan the models run on your own GPU with Ollama, so prompts and documents never leave the box. See approvals and trust.
Every plan includes approvals, audit history and spending caps - there is no security tier.