Autonomous work, under your command

One instruction in.
Verified work out.

CTROLL turns one approved instruction into a bounded plan, delegates it to specialist agents, has every result judged by an independent reviewer from a different provider — and hands you evidence instead of promises.

  • Controlled pilot
  • Provider-neutral
  • You hold final authority

The problem

Agents forget. Systems don’t.

You said it once, early, in message four. Two hundred messages later the constraint is gone — not refused, just quietly dropped. The work looks finished. It isn’t.

Every restart, retry, branch, compaction and provider switch is another chance to lose the thread. So you stop directing outcomes and start babysitting prompts, and the thing that was meant to give you leverage becomes another job.

CTROLL keeps intent as durable state, not model memory.

Every requirement is an ID with immutable original text, a change policy, a history and an explicit verdict. A worker cannot weaken it. A newer message cannot overwrite it. A later summary cannot forget it. When something must change, that change is a recorded decision with your name on it — not a paraphrase.

How it works

Six steps. No unbounded anything.

The whole loop is deliberately finite. Every stage has a limit that applies before execution, not as an apology afterwards.

Delegation: six signals converge into one organised network.
  1. 01

    Instruction

    You state the outcome, the constraints, the acceptance criteria and the budget. One instruction is enough — configuration is not the price of entry.

  2. 02

    Plan

    The orchestrator decomposes intent into a dependency-aware task graph and shows it to you. AUTO runs it; MANUAL waits for your approval. Same state, same controls.

  3. 03

    Delegate

    Each task goes to one specialist agent in an isolated workspace with a compiled contract: what to satisfy, what to preserve, what it may touch, and what it may never do.

  4. 04

    Review

    An independent agent from a different provider judges the result against the original requirements. A provider is structurally forbidden from reviewing its own work.

  5. 05

    Repair

    At most one repair cycle. If the second attempt still fails review, the mission stops and asks you — rather than burning budget discovering the same wall.

  6. 06

    Evidence

    Every requirement is mapped to an artifact and a verdict, with cost and owner time attached. “Done” is a claim the system has to prove.

The lineup

One orchestrator. Specialists on demand.

Not a robot army or a fixed headcount. CTROLL selects the bounded specialist functions the approved plan needs, while keeping one accountable chain of command.

The Orchestrator

Main-agent coordination

Owns the conversation, the plan, the delegation and the consolidated result. The only agent accountable to you.

The Builder

Code and product

Implements the smallest change that can produce decision-quality evidence.

The Analyst

Research and data

Tests assumptions independently and reports what the numbers will not support.

The Guardian

Security and policy

Holds the safety floor: permissions, secrets, approvals and destructive-action gates.

The Operator

Operations and automation

Runs the schedule, the retries, the pause and stop paths, and the recovery after failure.

The Creator

Design and content

Shapes what people actually see, inside the same evidence and approval rules.

The Scout

Research and discovery

Maps unknown ground before the mission commits budget to it.

Evidence

Other products show you a chat. We show you the receipt.

This is the record shape the control plane writes for every mission: the task graph, who reviewed whom, how many attempts it took, and which requirement each piece of work is answerable to. Run the demo below and yours looks like this.

demo passed

Demonstrate a bounded launch-readiness control flow

a4f19c2b07d3 · AUTO · PLAN R1
$0.00 · 0 provider calls

Bounded task graph

Primary implementation accepted · 2 reviews
2 ATTEMPTS
  • Attempt 1 rejected Planted demo defect detected. Resolve and resubmit evidence.
  • Attempt 2 accepted Independent review passed on resubmitted evidence.
Independent risk and continuity analysis accepted · 1 review
1 ATTEMPT
  • Attempt 1 accepted Independent evidence and unresolved risks returned.

The reviewer is never the implementer. The orchestrator refuses a verdict whose author matches the worker, so a self-review cannot be recorded as one.

Requirement-to-evidence trace

BR-012 evidencepassed
BR-022 evidencepassed
BR-042 evidencepassed
BR-062 evidencepassed
ARC-022 evidencepassed
GOV-032 evidencepassed

Recorded events

job submitted plan created dispatch started task started task reviewed rework requested task started task reviewed job finalized

Control

The limits are the product.

Bounded autonomy

Spend, concurrency, retries, wall time and delegation depth are checked before a task starts. A worker cannot raise its own budget, and a failed paid call still counts against the cap.

You hold final authority

Publication, production deploys, payments, external messages, permission changes and destructive operations require your explicit approval. A stop is a successful outcome, not a failure.

Provider-neutral by design

OpenAI and Anthropic run behind one internal contract with separate credentials, quotas, permissions and billing. Nothing is copied between them, and neither owns your mission state.

Three active priorities. No more.

Starting a fourth means naming what it displaces. The system exists to restore focus, not to multiply half-finished projects.

Evidence before claims

Cost, completion and impact are reported from observed telemetry. Where a number is unknown it stays null and says why, instead of being invented.

Resumable by construction

Every accepted task and every pause is written down before control returns. Restart the machine and the mission picks up where it stopped.

Where this actually is

A controlled pilot, described honestly.

The deterministic control path — intake, planning, bounded delegation, independent review, one repair cycle and requirement-to-evidence reporting — runs today and costs nothing to demonstrate.

Hosted text work through OpenAI and Anthropic is available when the service has both providers configured. Choose a provider, inspect its plan and cost estimate, then approve and run it. The free demo stays the default; live compatibility must be verified with an actual provider response.

We make no parity or superiority claim against any other product, and we publish no benchmark we cannot reproduce. Software can improve decision quality and execution capacity. It cannot guarantee revenue, solvency or rescue, and we will not say otherwise to sell it.

Owner control plane

Command the agents.
Keep control.

Turn one outcome into a bounded plan, a separate review gate, one repair and traceable control evidence. The surface below is the live control plane, not a screenshot.

DEMO DEFAULT SCOPE — SIGN IN FOR LIVE STATUS
TEAM ACCESS

Activate invitation

Paste the invitation token you received directly from your workspace owner. It is used once and is never placed in the URL or stored by this page.

Ready for an invitation token.

STEP 01

Verify invitation

Paste manually. CTROLL does not read activation tokens from links, browser storage or logs.
WORKSPACE CONTROL

Account

REPEATING MISSIONS

Schedules

CODING AGENT

Repository control

Inspect repository policy and saved workflow status. Owners can prepare a code job using a configured repository preset. Execution needs a separate approval; publishing needs its own approval.

PRODUCTION / READ ONLY

Release readiness

Evidence summary only. This panel cannot approve, deploy, restore, roll back or execute commands.

OPERATIONS / LOCAL POLICY

Alerts

Redacted operational aggregates only. Delivery is local to this control plane.

AUDIT / REDACTED VIEW

Activity

0 EVENTS

Bounded operational history. Mission IDs, task IDs, instructions, prompts, outputs and error details are never displayed here.

    RUNTIME / READ ONLY

    Worker operations

    Redacted aggregate status only. Worker identities, mission content, payloads, errors and lease tokens are never shown here.

    STATE
    NOT LOADED
    • Open operations to read the current redacted readiness gates.
    STATUS
    NOT LOADED
    STATUS
    NOT LOADED

    No recovery decision is available until the durable status snapshot is loaded.

    STATUS
    NOT LOADED
    MISSION DETAIL

    Detail

    NAVIGATION ONLY

    Command palette

    Move between workspace views and open read-only panels. Execution controls are never available here.

    0 commands
    DESKTOP CONTROL

    Keyboard shortcuts

    G M
    Mission view
    G A
    Agent view
    G E
    Evidence view
    N
    Focus new mission
    /
    Search loaded missions
    Ctrl K
    Open navigation commands
    R
    Refresh control state
    ?
    Open this guide
    Esc
    Close an open panel

    Shortcuts are inactive while typing in a field.