One brain owns the rules
One control plane holds the rulebooks, the contract, guardrails, approvals, audit and meters. A rulebook (an AOP) says what an agent may do, must never do and how it is tested. It is plain text your team owns.
Platform
Spine is built once and every agent inherits it. The rules live in one place, the work runs wherever it needs to and every tool call passes the same checks.
The shape
The brain sends each hand its rules with a version stamp. Each hand sends back a signed record of what it did. Change a rule once and every agent follows it.
One control plane holds the rulebooks, the contract, guardrails, approvals, audit and meters. A rulebook (an AOP) says what an agent may do, must never do and how it is tested. It is plain text your team owns.
The same engine is placed where each job runs: central for chat and office work, at the edge for live voice, batch for reports and a sandbox for proactive agents. Each hand enforces the rules locally.
Each app keeps its own tools and screens. Every tool call goes through one connector hub (MCP), allow listed per agent, so a new connector cannot widen what an agent can touch.
One database layer, walled per client with Postgres row level security. Agent memory sits behind the same walls, so one client never sees another.
How an action gets cleared
Every action asks one question first. The answer decides whether it runs now or waits for a person.
An agent wants to act
Is this action pre-approved and still under today's running total?
The check runs where the agent runs, so the answer never waits on the network.
Routine actions never wait.
Big ones always get a human.
Contract pinning
The engine can keep improving without breaking the agents you already trust.
Your phone gets a new system and your apps keep working. The engine keeps moving the same way and still honours the older contracts agents were built against.
Before an agent moves up, Spine checks that the engine can honour the contract it pins. If it cannot, the promotion is refused, not attempted.
Every supported contract version has its own tests. An engine change ships only when each of them still passes.
Record first, then act
If something fails halfway, the record already says what was about to happen. Nothing runs that the ledger cannot account for.
The intended action is written down before anything changes.
Only then does the action run, through the guarded doorway.
The record is synced to the tamper evident, hash chained ledger.
Fail closed
Autonomy ramp
An agent earns each step through evals. It moves up only when the tests say it is ready.
Built and tested away from customers. Nothing reaches a live system.
Runs beside the real work and proposes, while people still do the job.
Acts with a person in the loop who can approve, change or stop it.
Runs on its own inside its rulebook, with big actions still sent to a person.
Models and agents
Models and frameworks change fast. The rules, gates and ledger stay put, so you can switch without starting again.
Each tenant sets which models may run. Fallbacks take over when a model has a bad hour and a fuse per provider stops a failing one from dragging the rest down.
Open-weight models are supported. Voice AI runs on open-weight models on Google Cloud in Mumbai, so the voice data stays in region.
Our agents are built on Google ADK. The framework builds the agent. Spine decides what it may do and records what it did.
Agents built on other frameworks join through the same connectors and inherit the same rules, gates and ledger.
Say it in one sentence
Your procedures stay yours, in plain text and portable. We enforce them, record every action and never let an agent act outside them.
Flight operations writes the procedures and every cockpit follows them.
Go deeper
The runtime contract every agent step runs through.
Explore Governed ExecutionHow a named person decides the big actions.
Explore Approval GatesThe hash chained record. Try tampering with it.
Explore Audit LedgerWhere rulebooks are written, tested and launched.
Explore Agent StudioOne screen to see every agent and pause any of them.
Explore CockpitControls mapped with evidence collected from the platform.
Explore Compliance CenterWe will run one agent step, clear an action both ways and show the record it leaves.