Features

Everything between a sentence and a safe change

Somebody types a request in plain language. Something happens in software you depend on. These are the parts in between.

The whole design, in one line

The model proposes. It never executes.

Every call an agent suggests is independently re-checked against tool ownership, the argument schema, the acting person’s permissions and your policy before anything reaches your systems. That is what makes it safe to point at production rather than at a copy of it.

execution trace

refused

the model proposed

delete_customer(customer_reference: 1)

  1. Tool resolved exists · owned by this workspace · enabled for this agent
  2. Arguments validated matches the schema the connector declared
  3. Permission checked viewer role — tool.execute not held

Refused before the connector was reached. An agent acts on somebody's behalf; it cannot lend them a capability they do not have.

What it looks like when a check fires

This call never reached the database. The model named a real tool with perfectly valid arguments — and the person who asked did not hold the permission it needs.

Traces record the calls that were stopped alongside the ones that ran. A history showing only successes would hide the single most useful thing about a run, which is the moment somebody was told no.

01 — Reach it

Getting Caterfli to the software you already run.

Universal connections

One connector interface covers MCP servers, REST APIs, OpenAPI documents, PostgreSQL and MySQL. Whatever the source, discovered capabilities are normalised into a single registry with input schemas, a risk level and an operation type.

  • ✓ Auto-discovery of endpoints, tables and relationships
  • ✓ Credentials envelope-encrypted, never in a prompt
  • ✓ SSRF protection re-checked on every request

Wherever your team already talks

Web chat with live reasoning, or Telegram, Slack and WhatsApp so people can ask without opening a dashboard. Same runtime, same checks, a different door.

  • ✓ A channel sender carries nobody’s permissions
  • ✓ Allow-list starts empty, meaning nobody
  • ✓ Requests signed and verified, replays refused
  • ✓ A retried delivery is never answered twice

A toolkit that needs no connecting

Today’s date, date arithmetic, a sum worked out properly, a reference code — and sending email. The pure functions exist because a model cannot know the date, and because its arithmetic is confidently wrong.

  • ✓ Email recipients allow-listed, empty by default
  • ✓ A cap on recipients per message
  • ✓ Sending needs approval unless you relax it
  • ✓ Nothing to configure, nothing to expire

02 — Run it

Turning a connection into something that does work.

Agents drafted from your own system

Point Caterfli at a connection and it reads what is there, then produces an agent identity, written instructions, a tool selection and an approval policy for you to review before deploying.

  • ✓ Deterministic — the same connection gives the same agent
  • ✓ Destructive tools included but gated, not hidden
  • ✓ Versioned, with rollback applied forward

Answers, not markup

Agents return structured results. The interface renders them as tables and charts and exports them as CSV, real Excel or PDF — so a model can never inject UI into something you are about to send a client.

  • ✓ A model can never inject UI
  • ✓ Saved questions run on a schedule
  • ✓ Export is its own permission, and audited

Agents that hand work over

Each agent can become a tool the others call, so a generalist passes a billing question to the agent that knows billing rather than being handed every billing tool itself.

  • ✓ A delegated run is a full run, with its own approvals
  • ✓ It cannot reach through a colleague to something it could not reach itself
  • ✓ Depth limited, and a loop cannot form

03 — Trust it

The reason this can point at production rather than a copy.

Policy and approval engines

Reads flow through. Deletes, bulk operations and anything high-risk stop and wait for a named human — in the dashboard, or from wherever the request came from.

  • ✓ An approval covers one call, not a capability
  • ✓ Bound to a fingerprint of the exact arguments
  • ✓ Expires rather than going stale

Execution traces

Every run records its steps as they happen: what the model proposed, what was validated, what policy said, what ran and how long it took.

  • ✓ Includes the calls that were refused
  • ✓ Survives a crash mid-run
  • ✓ Cost recorded per call in integer micro-cents

A record of every change

Every record your agents create, update or delete in your systems is written down: which record, which agent, who asked, and whether a person approved it. Reads are not changes, so they do not appear.

  • ✓ Searchable by the record that changed
  • ✓ Links back to the conversation it came from
  • ✓ Failed attempts recorded too
  • ✓ Kept for a period your plan sets

Usage you see before you hit it

Every plan includes an allowance of model tokens. What you have used and what is left is on the dashboard, and the chat screen says so before you type rather than after you wait.

  • ✓ Owners emailed once when an allowance runs out
  • ✓ Nothing is deleted when it does
  • ✓ Upgrade mid-period and pay only the difference

Governance

The parts that matter once this stops being a demo

Five roles

Owner, admin, manager, member and viewer, with per-member grants and denials. Denials win.

Sign in your way

Password, Google or GitHub — and a second factor is never bypassed by any of them.

Hash-chained audit

Every consequential action, linked to the one before it, so a gap in the record is detectable.

Tenant isolation

Enforced by a global scope that fails closed. No tenant, no rows — not "no filter, all rows".

Retention by plan

The record of what changed is kept for 7 to 90 days depending on the plan, then removed automatically.

Credentials never in a prompt

Envelope-encrypted at rest, decrypted only to sign a request. The model names tools; the platform makes the calls.

Connect something and see what it drafts

The free plan is the same product at smaller limits, and there is a demo connection if you would rather not point it at your own systems yet.