amahub
Docs Sign in
NEW Self-hosted runners — agents now reach resources behind your VPN: run the sandbox inside your network, outbound-only, while control and audit stay in the cloud. READ THE DOCS → CLOUD PRIVATE LINK — COMING
amahub — the managed workspace for AI agents: real work inside your tools, under each person’s own access

Real AI adoption for people who don’t code.

Controlled. Safe. ROI on the record.
What changes
  • Every seat gets an agent in the tools you already run — claims, payroll, CS — under that person’s own access, nothing more.
  • Security keeps the keys: one gate, one log, hard dollar caps, instant stop — instead of invisible AI tabs.
  • ROI stops being a guess — hours returned and cost per task on one screen, to the cent, and every repeat becomes an automation.
2 minutes · no card · caps come already set
Saved last month, one team of 32
214 h
$12,840
of people's time given back · for $360 of agent time
illustrative team · hours counted as owner-asserted minutes saved × runs
1,240 tasks · 32 people picking up each other's work
One

Every seat gets AI.
You keep the keys.

AI power for everyone — not the engineers alone. Each person runs it on the tools they already use, under the access they already have. Adoption you can see and measure across the whole org — with central control in security's hands: one log, hard caps, instant stop.

SEALED RUNTIMESEALED RUNTIMESEALED RUNTIME CRMBILLINGHR ONE GATE YOUR TEAM
Two

Repeat work automates itself.
The hours come back weekly.

Automation comes with adoption — not as a separate project. As people do their repeated work in amahub, you see the repeats — and turn any of them into an autonomous agent that saves the hours and shows real AI impact. Every person gets this ability automatically.

"yesterday's follow-ups""yesterday's follow-ups""yesterday's follow-ups" FOLLOW-UP LIST every morning 09:00 → Slack THREE PEOPLEREPEAT SEENnobody types it again
For the three people who sign off
runtime for tech · control for the CISO · ROI for the COO
Runtime
For the CTO
  • · sandboxed, isolated workspace per user — Claude Code-grade agent abilities for non-technical staff
  • · 200+ MCP / API / skill connectors, allowlisted per group
  • · single egress gateway, default-deny outbound data controls
Control
For the CISO
  • · granular permissions and groups, following your Okta / Entra / SSO
  • · credential vault — secrets injected at call time, never readable by the agent
  • · SOC-grade trail logs — every data read/write, action and cent, per session
  • · kill switch mid-step: owner, admin, or automatic rule
Adoption & ROI
For the COO
  • · per-user and per-org spend caps — the budget is set before anyone runs anything
  • · repeated work detected across the org → promoted to shared automations
  • · hours returned and cost per task — ROI as a line item, to the cent
we send the brief · no call required
Works with Stripe Salesforce Slack Epic ADP BambooHR and 200+ more

amahub replaces none of it — it sits on top, under each person's own permissions.

agent time on us · no card · caps and safety rules come already set
running
The same week, made visible

Two Mondays, one team.

The left one is already happening. The right one takes a sign-in.

Monday, before
private AI tabprivate AI tabprivate AI tab ??? where did it go?what did it read?what did it cost? customer data · unlogged · uncapped · invisible
Monday, on amahub
runtime · own accessruntime · own accessruntime · own access ONEROOM shared · replayable ONE GATE every step logged · every cent capped
1,240 tasks logged 214 h returned · $360 agent time 3 repeats → buttons 0 data left the room
two minutes · work email only or book a walkthrough →

Put everyone in one place. Automation finds itself.

When every task runs in one shared place, repeated work surfaces on its own — the same ask, across desks. One click turns it into a shared process for the whole team.

Repetition found this month across 3 teams
"check invoices against Salesforce"
finance ops · 12 runs by 4 people
"verify coverage for tomorrow"
front office · daily, 21 runs
already a team process
"explain payroll register changes"
payroll ops · every cycle, 2 people
The admin view

One screen says who works, what it cost, what was stopped.

Spend against the cap, every connected system, every gate decision, and the teams that have not started yet — updated as tasks run, not assembled for a quarterly review.

Admin · usage aug 1–15 · org-wide · live
spent
$412
of $900 monthly cap
tasks run
1,284
by 47 of 76 seats
hours returned
96h
across 9 processes
alerts open
3
2 acked · 0 critical
spend against cap46%
Systems in use
Salesforce412 callsall allowed
Epic118 callsall allowed
Stripe96 callsall allowed
filebin.example12 attemptsblocked
Not using it yet
Legal8 seats0 runs
Procurement6 seats2 runs
Internal audit4 seats0 runs
gate: 1,846 allowed · 12 blocked credential reads by agents: 0 6 policies active
The spec sheet — for the people who sign off

No gloss. What it is, in your language.

The full sheet
everything the strip above compresses — plus compliance & deploy
Runtime
  • · sandboxed workspace per user — full agent abilities for non-technical staff
  • · runner network physically offline — two exits only: egress gate and connector proxy
  • · 200+ connectors to CRM, helpdesk, billing, HRIS — allowlisted per group
  • · tasks keep running after the lid closes — schedules and triggers included
Access & policy
  • · permissions from your Okta / Entra SSO — the agent inherits the person's access, never more
  • · data classes cap what can go where — before anything runs
  • · dollar caps per user, per day, per org — strictest wins
  • · credential vault — secrets never enter the sandbox
  • · instant stop mid-step — owner, admin, or rule
Observability
  • · trail logs — every read, every action, every cent
  • · egress log — every allow / deny at the gate, kept forever
  • · six default policies — critical ones kill the session; alerts go to your CISO
  • · repetition detected org-wide — promoted to shared automations
  • · cost and hours returned per process — ROI as a line item
Compliance & deploy
  • · SOC 2 / ISO 27001 readiness mapped to these controls
  • · HIPAA plan; model traffic under BAA
  • · your cloud or ours — self-hosted runtime, vault and logs
  • · retention and auditor access built in
we send the brief · no call required Docs → Trust & security → or book a walkthrough →
From one sign-in to the whole org

Nothing to install. Nowhere near everything at once.

Step 1 · today
Sign in
Work email. Caps and safety rules come already set.
Step 2 · this week
Connect once
An admin links your systems. People see only what they already may.
Step 3 · week two
One team runs
Start where the repeats hurt most — finance ops, CS, payroll.
Step 4 · when ready
Everyone follows
Same rules, same log. Their runs become the next team's head start.
workspace ready in 2 minutes · no card, no call required
02 · Real work — safely, in one place

Control is the advantage.

Nobody files a ticket saying "I do this every Tuesday". When all the work runs in one place the repeat shows up by itself — the same ask, three desks, week after week. You see it before anyone mentions it, and one click makes it a shared process.

12 → 1 runs become one process
9 min → 40 s per follow-up list
$0.21 what the run cost
"yesterday's follow-ups" "yesterday's follow-ups" "yesterday's follow-ups" FOLLOW-UP LIST every morning 09:00 → Slack THE SAME ASK three desks, week after week REPEAT SEEN ONE SHARED PROCESS nobody types it again you don't wait for anyone to report it — the ledger shows the repeat

A real runtime for every person. Not a chat window.

for people who don't code engineer-grade power their own permissions, no more the whole team at once

Claims handlers, payroll clerks, analysts. No script, no model choice, no API key. They type the request; the runtime writes the code, runs it in its own sandbox, checks the result.

Plain language in
"check yesterday's claims against the policy file"

That is the whole instruction.

Nothing to set up
Admin connects the systems once.

The person sees only what they are allowed to use, already signed in.

Readable, not magic
Every step listed. Cost at the end.

A non-technical owner signs it off.

Learn from each other
Open a colleague's run, change the date, run it.

That is the entire onboarding.

Monday 09:12 — one person
"Yesterday's tickets where we promised a follow-up — draft the missing ones."

Dana in CS. Ticket texts and customer emails never left the runtime.

14steps logged $0.21
Same week — three people
The same ask, typed three times.

Everyone works in one place, so the workspace sees the repeat.

make it a process
Friday — nobody
09:00, in Slack, every morning.

No automation team, no ticket to IT. A scheduled run keeps the same full trail as a manual one.

0manual asks

And every runtime sits inside one policy perimeter — vault, data classes, budgets, tripwires, stop:

ONE POLICY PERIMETER COMPANY SYSTEMS RUNTIME · CS RUNTIME · FINANCE RUNTIME · COMPLIANCE own permissions own permissions own permissions vault · data classes · budgets · tripwires · stop THE TEAM asks in plain words CRM HELPDESK BILLING ONE GATE one list to allow, one log to prove
The ask
The result
What the workspace did
What never left the workspace
workspace ready in 2 minutes · no card, no call required
03 · Full control — every action, every dollar

Five limits nobody can switch off.

Keys never leave the vault, a run reaches only the systems that person is already allowed to use, and every step and every cent is on the record. There is no checkbox for an admin to forget — so your auditor gets the same answer every time they ask.

the attempt hits the wall — the bounce is on the record
FACT 1
The vault

Credentials live in a vault the agent can never read. It can use a key to open a door; it cannot look at the key. There is no debug mode that changes this.

FACT 2
One door out

All internet traffic passes through a single supervised gate. Allowed destinations are listed in advance; everything else is refused and written down.

FACT 3
The ledger

Every action is recorded as it happens — the actual step, timestamped, not a summary written afterwards. Your auditors can read it. So can you.

FACT 4
The stop

Any task stops mid-step — its owner, an admin, or an automatic rule can cut it. Stop means the step in progress is cut, not politely finished.

FACT 5
Dollar caps

Spending limits per person and per company, set before anyone runs anything. A task that reaches its cap stops and says so. New workspaces start with conservative limits already configured.

You write the policy in plain words. We compile it into hard rules.

No policy language to learn. Write it the way you'd say it — and it unfolds into the real thing: credentials in the vault, approved app connections, allowlists at the gate.

"Support may read the helpdesk, never export attachments. Personal data never leaves." written by a person, in plain words COMPILES INTO OAUTH VAULTPAT TOKENSINTERNAL CONNECTORS SKILL REPOSITORIESGATE ALLOWLISTDATA-CLASS RULES client_id / secret, server-side onlyper user, injected at call time your wiki and tracker, wired insidevetted playbooks per team default-deny destinationspersonal data never leaves six enforcement points — none of them optional
Data has classes

Every connected system carries a label. Policy decides what each class may do — before anything runs.

THE GATE publicinternalcommercialpersonal may leave through the gate stays unless policy says never external never leaves. Period.
Six tripwires, always on

Deterministic rules watch every session. Critical ones don't alert — they cut the session mid-step, then a person decides.

blocked egress attemptalert
secret in outbound datastop session
access beyond grantstop session
sensitive data heading outstop session
unusually large transferalert
dangerous tool callalert
red square cuts the session mid-step — then a person decides
One approved doorway per app

Slack, Notion, the wiki — each runs under your company's own approved app. The admin signs off once, in the vendor's console.

NWD SlackNotionwikidrive ONE DOORWAY workspace personal laptop no doorway at all groups decide who gets which — Okta / Entra / Google SSO
For security teams

Live sessions on one screen. A map of where data went. An alert queue routed to Slack, a webhook, or a named admin. A dangerous session is cut automatically — then a person decides.

For auditors

SOC 2 and ISO 27001 readiness plans map point by point to the controls above — the product passes the audit, not a slide deck. A separate HIPAA plan covers health clients, with model traffic routed under a BAA.

workspace ready in 2 minutes · no card, no call required
04 · Auto-automation — one place makes repetition visible

What repeats, automates itself.

Every repeated task in the company is money leaking on a schedule. In one shared workspace it finally shows: save on everything that repeats — the best runs become buttons, the busiest patterns become the next automation — and you see the saving the moment it lands, not in a quarterly review.

SHADOW AI N people · zero shared memory ONE GATE ONE WORKSPACE repeated tasks get automated

Nobody adopts AI from a memo. They adopt it from the desk next to them.

People fear AI — for their jobs, for the data, for looking stupid. Training doesn't fix that. What works is learn by example: one strong person figures it out first, and everyone can open their real runs and see exactly how. Give that person visibility, and adoption spreads on its own.

Remote teams too No desk next to you needed — open a colleague's run and see exactly how they solved it, from anywhere.
THE FIRST ONE RUNS ARE VISIBLE THE REST LEARN BY EXAMPLE
01
Shared memory

A good run becomes a button — "Make it a process" turns one success into a team process. Sessions are shared, so people learn from real examples. Six months in, you hold a library of proven processes no competitor starts with.

02
Usage in one place

Who uses it, which teams get value, what it costs — by day, by model, by person, by group, every task to the cent. Shadow AI can never give you this data.

03
The improvement loop

Failed, stopped and unusually expensive sessions are a map of bottlenecks. One person improves a process; the whole team gets the new version. Tried, shared, improved, standard.

04
What to automate next

Usage data answers the planning question: where people spend the most agent time is where the next big saving sits.

05
Results are shared, not exported

A finished report is published inside the workspace under a name — "weekly-report". A colleague's task picks it up and builds on it: people and AI coworkers pass work to each other without a single file leaving the walls.

Shared in this workspace
Invoice mismatch check
finance ops · shared by K. Osei
run 41 times · avg $0.12
Missed follow-up sweep
customer success · shared by T. Okafor
run 28 times · avg $0.21
PEP file completeness
compliance · shared by M. Reyes
run 9 times · avg $0.30
New-hire checklist audit
people ops · shared by J. Lindqvist
run 12 times · avg $0.09
Every shared run keeps its full ledger. Anyone reusing it sees exactly what it will touch before pressing go.
Usage — August total $412.80 · avg task $0.14 · 13% more efficient than last month
finance ops$182.40
customer success$121.10
compliance$64.90
people ops$44.40
workspace ready in 2 minutes · no card, no call required
05 · Pricing

Pay for safe, controlled AI at scale. And see the cost of every task.

Trial
Free
Agent time on us. No card required. Conservative caps come preconfigured. Every task shows its live cost as it runs — to the cent.
Team
$29
per seat / month · bring your own model key
Model usage is billed by your provider at cost — no markup. Includes the vault, the gate, the full audit ledger and the shared run library.
Enterprise
Custom
priced per workspace
Self-hosted option: runtime, vault and logs in your VPC; model traffic under your own provider agreement. SSO, retention policies, auditor access. For regulated estates that keep everything in-house.
Or book a 20-min walkthrough →
Most everyday tasks cost cents; heavier scheduled processes run $1–3. The exact number is on every run, to the cent.
Access

Two minutes to your first task.

My work email is and we have people whose routine work needs automating.

work email only · no card · our optimisers reply within 24 hours
Rather talk it through first? Book a 20-min walkthrough → · live product, no slides
Prefer talking?

Love Wispr Flow? Leave us a voice note instead.

Forty seconds, any language. We send the recording exactly as you said it — no transcription, nothing in between. A person here listens to every one and replies within 24 hours.

  • What happened that made you look for something like this?
  • Nobody there really knows AI yet — or the tools are just too complicated?
  • How many people would actually use it?
  • Is this about keeping data safe, or getting work off people's plates?
0:00
up to 2 minutes · we'll need your work email above
Setup

Or set it up from the Claude you already use.

amahub is itself an MCP server. Connect it to Claude — desktop, web or the terminal — and configure the workspace by asking: connect the tools, put people in teams, grant access, set the spend caps.

Sign in with your own account, approve it on one consent screen. No key to paste and nothing to copy into a config file. Every change it makes is written to the audit ledger with your name on it, and you can revoke the connection from the admin page at any time.

One connector, then plain English
https://api.amahub.io/mcp/admin
you → connect Zendesk, give support access to it,
you → and cap them at $5 a day
✓ Zendesk enabled — each person approves it with
  their own account, so the agent sees exactly
  the tickets they can
✓ support (3 people) granted
✓ $5 per person / day · $40 workspace