Yours by design

Your agents, in your own environment.

Olano is not a shared tenancy with your data in it. Every deployment is an isolated environment, and everything an agent does is gated, logged and reversible.

Yours by design.

Every Olano system runs in its own isolated environment - your workspace, memory, files, connector secrets, and audit logs are never mixed with anyone else's, and everything is encrypted at rest and in transit. Your team governs what the system may do: approvals where judgment is required, a complete history of every action, and hard limits on what it can spend.

Isolated environment - your own dedicated deployment, never shared
Approval controls - human sign-off wherever judgment is required
Audit history - a complete, tamper-proof record of every action
Spending controls - hard caps on AI usage, agreed in advance

The gate

Read freely. Ask before acting.

Research needs no permission. Anything that leaves the deployment or spends money is a category you can hold behind a human.

EVERY ACTION IS CLASSIFIED BEFORE IT RUNS The agent decides mid-task, on any channel Category + trust level per agent Read-only research search, read, summarise Runs immediately no one is interrupted Outbound action send email · spend money write a file · use a secret Waits for you approve, edit or reject then it executes EVERY OUTCOME IS WRITTEN TO THE AUDIT LOG — HIGH-RISK OPERATIONS ASK A HUMAN AT EVERY TRUST LEVEL

Trust levels

Five settings, per agent.

Every agent carries a trust level describing how much autonomy it has been granted. A new agent starts at level 2.

  1. Level 0 · Observer

    Read-only. It can look and it can suggest, but it changes nothing.

  2. Level 1 · Assistant

    May write to its own memory and logs. Still touches nothing outside itself.

  3. Level 2 · Collaborator default for a new agent

    May create and edit workspace files and run commands through its configured environment.

  4. Level 3 · Autonomous

    Full workspace access, and auto-approves operations classified as low risk.

  5. Level 4 · Developer

    The widest setting, including local shell access. Intended for development, not for an agent facing customers.

High-risk operations require a human at every trust level. Level 4 does not mean “no approvals ever” — it widens what counts as routine, not what counts as dangerous. The full rules are in approvals and trust.

An environment that is yours

Every deployment is its own isolated instance - not a seat in a shared SaaS. You choose the region it runs in, and daily recovery snapshots are included.

Approval gates on anything outbound

Sending an email, spending money, writing a file, using a secret, delegating work: each is a category you can require a human to approve. Read-only research needs no gate.

An audit trail you can read

Every action is attributed to the human or agent that took it, on an append-only log. Agent-to-agent conversations are recorded and replayable - none of it is a black box.

Hard spending caps

Set the ceiling in advance, per agent and per deployment. Usage is metered and visible, so a runaway loop hits a wall rather than an invoice.

Your secrets stay secrets

Credentials live in a per-deployment vault, resolved per agent, and are never hydrated into a shared environment. Each agent sees only what it was given.

Private inference, if you need it

On a Private AI plan the models run on your own GPU with Ollama, so prompts and documents never leave the box. See approvals and trust.

Create your first agent.

Every plan includes approvals, audit history and spending caps - there is no security tier.