Tenant-scoped control for agent-produced applications

Govern the software your agents create.

Agent harnesses coordinate sessions. Galatheus is the application control plane after the session: tenant identity, policy, audit, release intent, and local userspace execution for software produced by autonomous workers.

Tenant context Every action belongs to one workspace boundary.
Capabilities Mutations require scoped authority, not prompt text.
Evidence Tickets, runs, approvals, and status are durable.
AppIntent Agent work becomes declared application state.
Userspace Execution, source, secrets, and data stay local.

Not another agent harness.

The world is filling with tools that help agents work. Galatheus focuses on the next boundary: what happens when that work becomes a real tenant application, with real secrets, data, runtime state, and consequences.

Harness layer

Agents produce work

Agents inspect, edit, test, and propose through the tools a team already uses.

Galatheus layer

Consequences are governed

Work becomes tickets, approvals, runs, release evidence, and application intent before it changes a tenant system.

Userspace layer

Applications run locally

The customer-side userspace owns source checkout, package materialization, secrets, databases, runtime, and status reporting.

The control loop after agent work.

Galatheus does not need to be the chat UI, code editor, or model runtime. It is the boundary where autonomous work is converted into governed application operations.

1

Agent session produces a change

A harnessed agent proposes code, content, configuration, data workflow, or operational work.

2

Galatheus binds the work to a tenant

The kernel records the actor, workspace, ticket, capability, policy context, and evidence trail.

3

Policy gates the consequence

Human or automated review decides whether the proposed mutation can become release intent.

4

Userspace reconciles locally

The runtime pulls source coordinates, builds, runs, owns app secrets and data, then reports status.

consequence-control-loop
agent harness
  -> proposed application change

Galatheus kernel
  -> tenant context
  -> capability check
  -> policy verdict
  -> ticket / run / evidence
  -> release intent

customer userspace
  -> source checkout
  -> package materialization
  -> local secrets and data
  -> runtime convergence
  -> status and audit

Central coordination. Local execution.

The kernel stays application-neutral. Userspaces do the operational work. That split lets agents create software without giving prompt text, tool arguments, or app config the authority to cross tenant boundaries.

  • The kernel owns identity, workspace context, policy, tickets, audit, and release intent.
  • Userspace owns source, packages, app secrets, app databases, runtime, and local status.
  • Agents can run through existing harnesses while Galatheus records consequences.
  • Application operations are replayable, inspectable, and revocable at the control-plane boundary.
Kernel

Authority and coordination

Tenant identity, capability checks, policy decisions, durable tickets, evidence, AppIntent, and audit.

Userspace

Runtime and data

Outbound client connection, source checkout, package build, secrets, databases, app runtime, and status.

Agents

Work production

Codex, Claude Code, CI, local scripts, and custom workers propose and operate through scoped work records.

Applications

Governed consequences

The output is not a chat transcript. It is a tenant-scoped application with release evidence and status.

Every autonomous change should leave a work record.

When agents touch real applications, the important question is not which model wrote the diff. It is who authorized the consequence, what tenant boundary it belonged to, what evidence was produced, where it ran, and how it can be paused, revoked, or rolled back.

Autonomous Work Record
agent-produced application change
Status
Ready
Tenant / Workspace Galatheus / marketing
Actor campaign-agent via approved harness
Authority scoped capability plus policy verdict
Evidence tests, review, source revision, deploy result
Intent declared application state and release target
Execution local userspace reported runtime status

Built from systems experience

Applications are becoming agent-produced systems.

Galatheus is built around a simple boundary: agents can produce and operate software, but tenant context, authority, release intent, evidence, and runtime ownership need to be explicit.

The platform starts with the practical operating layer for that boundary: a hosted kernel for coordination and policy, plus customer-side userspaces for execution, source, secrets, and data.

agent-produced applications tenant isolation control planes local execution audit and evidence

Request access.

Galatheus is early. The first users are teams that want agents to create or operate applications without losing tenant boundaries, auditability, and local runtime control.