The model at a glance
Organization and workspaces
Your organization is the account: it owns billing, the plan, and the member list. A workspace is an isolated environment inside it — production and staging, or one per team.
Org Owners and Admins are Admins in every workspace. Everyone else gets a workspace role — Admin, Developer, or Viewer — per workspace. See Workspace users.
Connections
A connection is a credential for one service — an AWS account, a Kubernetes cluster, a GitHub organization, a Datadog account. Agents can only see and act on what the workspace’s connections allow, so the connection’s permissions are the outer limit of what any agent can do.Agents
CloudThinker, the built-in assistant, takes every request. It spawns temporary subagents for parallel work and hands off to custom agents your team defines. See Agents.Guardrails
Two settings decide whether an agent’s write action runs on its own or waits for a person.
The mode applies to the whole workspace, including automations and subagents. See Auto Mode and Approval.
Context
Context is what agents know before you say anything. Each kind has a different source.Modules
The four modules — Resolve, Review, Optimize, and Cyber — each apply the same agents, guardrails, and context to one kind of signal: incidents, pull requests, cloud bills, and app security.Where results appear
Related
Agents
Learn how CloudThinker, subagents, and custom agents share the work
Modules
Compare what each module does and what it needs
Workspaces
Create and organize isolated environments
Quickstart
Put the model to work in about 10 minutes