The Orchestrator
Main-agent coordination
Owns the conversation, the plan, the delegation and the consolidated result. The only agent accountable to you.
Mission control
Autonomous work, under your command
CTROLL turns one approved instruction into a bounded plan, delegates it to specialist agents, has every result judged by an independent reviewer from a different provider — and hands you evidence instead of promises.
The problem
You said it once, early, in message four. Two hundred messages later the constraint is gone — not refused, just quietly dropped. The work looks finished. It isn’t.
Every restart, retry, branch, compaction and provider switch is another chance to lose the thread. So you stop directing outcomes and start babysitting prompts, and the thing that was meant to give you leverage becomes another job.
CTROLL keeps intent as durable state, not model memory.
Every requirement is an ID with immutable original text, a change policy, a history and an explicit verdict. A worker cannot weaken it. A newer message cannot overwrite it. A later summary cannot forget it. When something must change, that change is a recorded decision with your name on it — not a paraphrase.
How it works
The whole loop is deliberately finite. Every stage has a limit that applies before execution, not as an apology afterwards.
You state the outcome, the constraints, the acceptance criteria and the budget. One instruction is enough — configuration is not the price of entry.
The orchestrator decomposes intent into a dependency-aware task graph and shows it to you. AUTO runs it; MANUAL waits for your approval. Same state, same controls.
Each task goes to one specialist agent in an isolated workspace with a compiled contract: what to satisfy, what to preserve, what it may touch, and what it may never do.
An independent agent from a different provider judges the result against the original requirements. A provider is structurally forbidden from reviewing its own work.
At most one repair cycle. If the second attempt still fails review, the mission stops and asks you — rather than burning budget discovering the same wall.
Every requirement is mapped to an artifact and a verdict, with cost and owner time attached. “Done” is a claim the system has to prove.
The lineup
Not a robot army or a fixed headcount. CTROLL selects the bounded specialist functions the approved plan needs, while keeping one accountable chain of command.
Main-agent coordination
Owns the conversation, the plan, the delegation and the consolidated result. The only agent accountable to you.
Code and product
Implements the smallest change that can produce decision-quality evidence.
Research and data
Tests assumptions independently and reports what the numbers will not support.
Security and policy
Holds the safety floor: permissions, secrets, approvals and destructive-action gates.
Operations and automation
Runs the schedule, the retries, the pause and stop paths, and the recovery after failure.
Design and content
Shapes what people actually see, inside the same evidence and approval rules.
Research and discovery
Maps unknown ground before the mission commits budget to it.
Evidence
This is the record shape the control plane writes for every mission: the task graph, who reviewed whom, how many attempts it took, and which requirement each piece of work is answerable to. Run the demo below and yours looks like this.
Bounded task graph
The reviewer is never the implementer. The orchestrator refuses a verdict whose author matches the worker, so a self-review cannot be recorded as one.
Requirement-to-evidence trace
Recorded events
Control
Spend, concurrency, retries, wall time and delegation depth are checked before a task starts. A worker cannot raise its own budget, and a failed paid call still counts against the cap.
Publication, production deploys, payments, external messages, permission changes and destructive operations require your explicit approval. A stop is a successful outcome, not a failure.
OpenAI and Anthropic run behind one internal contract with separate credentials, quotas, permissions and billing. Nothing is copied between them, and neither owns your mission state.
Starting a fourth means naming what it displaces. The system exists to restore focus, not to multiply half-finished projects.
Cost, completion and impact are reported from observed telemetry. Where a number is unknown it stays null and says why, instead of being invented.
Every accepted task and every pause is written down before control returns. Restart the machine and the mission picks up where it stopped.
Where this actually is
The deterministic control path — intake, planning, bounded delegation, independent review, one repair cycle and requirement-to-evidence reporting — runs today and costs nothing to demonstrate.
Hosted text work through OpenAI and Anthropic is available when the service has both providers configured. Choose a provider, inspect its plan and cost estimate, then approve and run it. The free demo stays the default; live compatibility must be verified with an actual provider response.
We make no parity or superiority claim against any other product, and we publish no benchmark we cannot reproduce. Software can improve decision quality and execution capacity. It cannot guarantee revenue, solvency or rescue, and we will not say otherwise to sell it.
Owner control plane
Turn one outcome into a bounded plan, a separate review gate, one repair and traceable control evidence. The surface below is the live control plane, not a screenshot.
No live mission budget is loaded. Estimates and observed billing are never presented as the same value.
Aggregate runtime state only. No worker identity, mission payload or control action is exposed.
No mission evidence is available yet.