Agents produce work
Agents inspect, edit, test, and propose through the tools a team already uses.
Tenant-scoped control for agent-produced applications
Agent harnesses coordinate sessions. Galatheus is the application control plane after the session: tenant identity, policy, audit, release intent, and local userspace execution for software produced by autonomous workers.
Codex, Claude Code, Omnigent, CI, local scripts, and custom workers produce proposed application changes.
Turns proposed work into scoped consequences: tickets, capabilities, policy verdicts, evidence, and AppIntent.
Customer-side execution owns source checkout, package materialization, secrets, app data, runtime, and status.
The world is filling with tools that help agents work. Galatheus focuses on the next boundary: what happens when that work becomes a real tenant application, with real secrets, data, runtime state, and consequences.
Agents inspect, edit, test, and propose through the tools a team already uses.
Work becomes tickets, approvals, runs, release evidence, and application intent before it changes a tenant system.
The customer-side userspace owns source checkout, package materialization, secrets, databases, runtime, and status reporting.
Galatheus does not need to be the chat UI, code editor, or model runtime. It is the boundary where autonomous work is converted into governed application operations.
A harnessed agent proposes code, content, configuration, data workflow, or operational work.
The kernel records the actor, workspace, ticket, capability, policy context, and evidence trail.
Human or automated review decides whether the proposed mutation can become release intent.
The runtime pulls source coordinates, builds, runs, owns app secrets and data, then reports status.
agent harness
-> proposed application change
Galatheus kernel
-> tenant context
-> capability check
-> policy verdict
-> ticket / run / evidence
-> release intent
customer userspace
-> source checkout
-> package materialization
-> local secrets and data
-> runtime convergence
-> status and audit
The kernel stays application-neutral. Userspaces do the operational work. That split lets agents create software without giving prompt text, tool arguments, or app config the authority to cross tenant boundaries.
Tenant identity, capability checks, policy decisions, durable tickets, evidence, AppIntent, and audit.
Outbound client connection, source checkout, package build, secrets, databases, app runtime, and status.
Codex, Claude Code, CI, local scripts, and custom workers propose and operate through scoped work records.
The output is not a chat transcript. It is a tenant-scoped application with release evidence and status.
When agents touch real applications, the important question is not which model wrote the diff. It is who authorized the consequence, what tenant boundary it belonged to, what evidence was produced, where it ran, and how it can be paused, revoked, or rolled back.
Built from systems experience
Galatheus is built around a simple boundary: agents can produce and operate software, but tenant context, authority, release intent, evidence, and runtime ownership need to be explicit.
The platform starts with the practical operating layer for that boundary: a hosted kernel for coordination and policy, plus customer-side userspaces for execution, source, secrets, and data.
Galatheus is early. The first users are teams that want agents to create or operate applications without losing tenant boundaries, auditability, and local runtime control.