Skip to content

Platform

One brain owns the rules. Many hands do the work. One guarded doorway to the tools.

Spine is built once and every agent inherits it. The rules live in one place, the work runs wherever it needs to and every tool call passes the same checks.

The shape

Rules flow down. Records flow up.

The brain sends each hand its rules with a version stamp. Each hand sends back a signed record of what it did. Change a rule once and every agent follows it.

How Spine is shaped: one brain, many hands, one guarded doorwayAt the top sits the brain, the Spine control plane. It holds the rulebooks and the contract, guardrails and approvals, audit and meters and the fleet view. Rules flow down to the hands with a version stamp and signed records flow back up. The hands are the same engine placed where each job runs: chat and office work centrally, live voice at the edge, report building as batch and proactive agents in a sandbox. Every tool call passes through one guarded doorway, a connector hub using MCP that is allow listed per agent. Your own systems sit behind it. Underneath, memory is walled per client with database row level security.ONE BRAIN: THE CONTROL PLANERulebooks and contractGuardrails, approvalsAudit and metersFleet viewChange a rule once, every agent inherits itRules down, version stampedSigned records upMANY HANDS: ONE ENGINE, PLACED PER JOBChat and officeCentralLive voiceAt the edgeReport buildingBatchProactive agentsSandboxedOne guarded doorwayConnector hub (MCP), allow listed per agentCase systemPaymentsTelephonyMemory walled per client, row level security
Illustration. The tools shown are examples. Each app keeps its own tools and screens.
  • One brain owns the rules

    One control plane holds the rulebooks, the contract, guardrails, approvals, audit and meters. A rulebook (an AOP) says what an agent may do, must never do and how it is tested. It is plain text your team owns.

  • Many hands do the work

    The same engine is placed where each job runs: central for chat and office work, at the edge for live voice, batch for reports and a sandbox for proactive agents. Each hand enforces the rules locally.

  • One guarded doorway to the tools

    Each app keeps its own tools and screens. Every tool call goes through one connector hub (MCP), allow listed per agent, so a new connector cannot widen what an agent can touch.

  • Memory walled per client

    One database layer, walled per client with Postgres row level security. Agent memory sits behind the same walls, so one client never sees another.

How an action gets cleared

Routine actions never wait. Big ones always get a human.

Every action asks one question first. The answer decides whether it runs now or waits for a person.

An agent wants to act

Is this action pre-approved and still under today's running total?

The check runs where the agent runs, so the answer never waits on the network.

Yes

Clear it instantly.

  1. Do it now, on the spot.
  2. Write it to the record as it happens.

Routine actions never wait.

No

A named person decides.

  1. Pause the action and ask a named person.
  2. Keep the conversation flowing while they decide.
  3. Re-check the facts once they answer.
  4. Then act, with the decision on the record.

Big ones always get a human.

Contract pinning

Agents pin the contract, not the engine.

The engine can keep improving without breaking the agents you already trust.

  • Like apps after a phone update

    Your phone gets a new system and your apps keep working. The engine keeps moving the same way and still honours the older contracts agents were built against.

  • A gate that refuses a bad promotion

    Before an agent moves up, Spine checks that the engine can honour the contract it pins. If it cannot, the promotion is refused, not attempted.

  • A test suite per contract version

    Every supported contract version has its own tests. An engine change ships only when each of them still passes.

Record first, then act

No action without a record.

If something fails halfway, the record already says what was about to happen. Nothing runs that the ledger cannot account for.

  1. Write the record

    The intended action is written down before anything changes.

  2. Run the action

    Only then does the action run, through the guarded doorway.

  3. Seal it on the ledger

    The record is synced to the tamper evident, hash chained ledger.

Fail closed

When in doubt, stop. A missing setting blocks the action instead of skipping the check.

Autonomy ramp

Autonomy is earned, one step at a time.

An agent earns each step through evals. It moves up only when the tests say it is ready.

  1. Draft

    Built and tested away from customers. Nothing reaches a live system.

  2. Shadow

    Runs beside the real work and proposes, while people still do the job.

  3. Assisted

    Acts with a person in the loop who can approve, change or stop it.

  4. Production

    Runs on its own inside its rulebook, with big actions still sent to a person.

Models and agents

Choose the model. Keep the rules.

Models and frameworks change fast. The rules, gates and ledger stay put, so you can switch without starting again.

  • A model router with fuses

    Each tenant sets which models may run. Fallbacks take over when a model has a bad hour and a fuse per provider stops a failing one from dragging the rest down.

  • Open-weight models, in region

    Open-weight models are supported. Voice AI runs on open-weight models on Google Cloud in Mumbai, so the voice data stays in region.

  • Built on Google ADK, governed by Spine

    Our agents are built on Google ADK. The framework builds the agent. Spine decides what it may do and records what it did.

  • Framework agnostic through connectors

    Agents built on other frameworks join through the same connectors and inherit the same rules, gates and ledger.

Say it in one sentence

Two ways to explain it.

  • To a client

    Your procedures stay yours, in plain text and portable. We enforce them, record every action and never let an agent act outside them.

  • To anyone

    Flight operations writes the procedures and every cockpit follows them.

Go deeper

Each part, in detail.

See the whole shape on a real agent.

We will run one agent step, clear an action both ways and show the record it leaves.