Give every agent a clear identity, permission boundary, and line of accountability.
Agent Lab Platform brings identity, policy, approval, usage, budget, audit, and runtime environments into one control plane. Governance is present before an agent goes live, not added after.
Sam Lin: How many A-1200 air conditioners are left in the north warehouse?
Wants to call erp.inventory.lookup
{ "sku": "A-1200", "warehouse": "north" }
Runs with Sam Lin's ERP permissions
Approve
Deny
Monthly token budget 62% · near the cap, replies move to a cheaper model
Agent Lab Platform
A secure, governed, and auditable enterprise agent platform
The four products share workspace, identity, policy, approval, usage, and audit. Every agent follows the same enterprise rules from entry and decision to connection and execution.
Delegated identity: assistants act as the person asking
For every tool call, the platform computes an intersection: what this person can already do in the downstream system, what this assistant was granted, and what the tool itself allows. It runs only if all three agree. Your existing permissions are the rules.
Knowledge retrieval also runs as the asker, so documents they cannot see are never cited
A connector can be a shared organization connection or the member's own authorization
Permission is checked again right before execution, so removed members stop acting
Approval where work happens: tool calls pause for a person
By default, every tool call the model proposes waits for someone to approve it in the console or on a Slack card. Both use the same state machine. After approval the platform checks permission again before running, and a call that already ran is never run twice.
Business rules can require approval for certain tools, or forbid certain actions outright
When content screening escalates a turn, every tool call in it needs approval
Read-only tools an owner marks automatic can run unattended, and one switch turns that off
Budgets that hold: ceilings per workspace and per team
Every model call takes one path: check the budget, call the model, write the ledger. Near the ceiling, replies move to a cheaper model and tell the reader. Past it, requests are refused with a reason. If the member picked a model by name, the platform refuses the reply instead of silently switching models.
Monthly workspace budgets, rolling-window limits, and per-team ceilings
Each call records who, which assistant, which model, how many tokens, and why
The usage report answers "why was this reply so expensive"
Platform Security
What IT checks before go-live is already built in
Where data lives, who can sign in, and how to trace an incident are already set up when you roll the platform out.
Data and isolation
Runs on Google Cloud in Taiwan (asia-east1), with a tenant boundary per workspace
A workspace can have its own dedicated Cloud SQL database
Connector credentials sealed with AES-256-GCM, with short-lived grants per use
Enterprise SSO with SAML and OIDC, with directory groups mapped to workspace roles
Delegated identity, tool approvals, and token budgets with step-down in every workspace
Tool approvals, membership changes, and credential use are recorded, and owners can export them
Slack, Microsoft Teams, and LINE share one identity, budget, and audit trail
Cloud and on-prem
Runs where you need it: cloud, hybrid or on-premises
The same assistants, integrations and governance. Whether your data may leave your network decides where the platform runs.
Cloud
Runs on Google Cloud asia-east1 (Taiwan), with every workspace its own tenant boundary. No machines to prepare.
For teams that want to start this week and can keep data in a Taiwan cloud region
Hybrid: platform in the cloud, data on your network
Your ERP, warehouse and databases behind the firewall connect through a relay you run. The relay dials out, so no inbound firewall rule is needed; database credentials never leave your network, and every query is filtered to the asking person's own rows.
For companies whose core systems live in their own data center
On-premises: the whole platform in your environment
Agent Lab runs in your data center or private cloud, so assistants, knowledge and audit records stay inside your network. We plan the environment and sizing with you.
For finance, healthcare and public-sector teams whose data cannot leave the network