Features
Everything between a sentence and a safe change
Somebody types a request in plain language. Something happens in software you depend on. These are the parts in between.
The whole design, in one line
The model proposes. It never executes.
Every call an agent suggests is independently re-checked against tool ownership, the argument schema, the acting person’s permissions and your policy before anything reaches your systems. That is what makes it safe to point at production rather than at a copy of it.
execution trace
refusedthe model proposed
delete_customer(customer_reference: 1)
- Tool resolved exists · owned by this workspace · enabled for this agent
- Arguments validated matches the schema the connector declared
- Permission checked viewer role — tool.execute not held
Refused before the connector was reached. An agent acts on somebody's behalf; it cannot lend them a capability they do not have.
What it looks like when a check fires
This call never reached the database. The model named a real tool with perfectly valid arguments — and the person who asked did not hold the permission it needs.
Traces record the calls that were stopped alongside the ones that ran. A history showing only successes would hide the single most useful thing about a run, which is the moment somebody was told no.
01 — Reach it
Getting Caterfli to the software you already run.
Universal connections
One connector interface covers MCP servers, REST APIs, OpenAPI documents, PostgreSQL and MySQL. Whatever the source, discovered capabilities are normalised into a single registry with input schemas, a risk level and an operation type.
- ✓ Auto-discovery of endpoints, tables and relationships
- ✓ Credentials envelope-encrypted, never in a prompt
- ✓ SSRF protection re-checked on every request
Wherever your team already talks
Web chat with live reasoning, or Telegram, Slack and WhatsApp so people can ask without opening a dashboard. Same runtime, same checks, a different door.
- ✓ A channel sender carries nobody’s permissions
- ✓ Allow-list starts empty, meaning nobody
- ✓ Requests signed and verified, replays refused
- ✓ A retried delivery is never answered twice
A toolkit that needs no connecting
Today’s date, date arithmetic, a sum worked out properly, a reference code — and sending email. The pure functions exist because a model cannot know the date, and because its arithmetic is confidently wrong.
- ✓ Email recipients allow-listed, empty by default
- ✓ A cap on recipients per message
- ✓ Sending needs approval unless you relax it
- ✓ Nothing to configure, nothing to expire
02 — Run it
Turning a connection into something that does work.
Agents drafted from your own system
Point Caterfli at a connection and it reads what is there, then produces an agent identity, written instructions, a tool selection and an approval policy for you to review before deploying.
- ✓ Deterministic — the same connection gives the same agent
- ✓ Destructive tools included but gated, not hidden
- ✓ Versioned, with rollback applied forward
Answers, not markup
Agents return structured results. The interface renders them as tables and charts and exports them as CSV, real Excel or PDF — so a model can never inject UI into something you are about to send a client.
- ✓ A model can never inject UI
- ✓ Saved questions run on a schedule
- ✓ Export is its own permission, and audited
Agents that hand work over
Each agent can become a tool the others call, so a generalist passes a billing question to the agent that knows billing rather than being handed every billing tool itself.
- ✓ A delegated run is a full run, with its own approvals
- ✓ It cannot reach through a colleague to something it could not reach itself
- ✓ Depth limited, and a loop cannot form
03 — Trust it
The reason this can point at production rather than a copy.
Policy and approval engines
Reads flow through. Deletes, bulk operations and anything high-risk stop and wait for a named human — in the dashboard, or from wherever the request came from.
- ✓ An approval covers one call, not a capability
- ✓ Bound to a fingerprint of the exact arguments
- ✓ Expires rather than going stale
Execution traces
Every run records its steps as they happen: what the model proposed, what was validated, what policy said, what ran and how long it took.
- ✓ Includes the calls that were refused
- ✓ Survives a crash mid-run
- ✓ Cost recorded per call in integer micro-cents
A record of every change
Every record your agents create, update or delete in your systems is written down: which record, which agent, who asked, and whether a person approved it. Reads are not changes, so they do not appear.
- ✓ Searchable by the record that changed
- ✓ Links back to the conversation it came from
- ✓ Failed attempts recorded too
- ✓ Kept for a period your plan sets
Usage you see before you hit it
Every plan includes an allowance of model tokens. What you have used and what is left is on the dashboard, and the chat screen says so before you type rather than after you wait.
- ✓ Owners emailed once when an allowance runs out
- ✓ Nothing is deleted when it does
- ✓ Upgrade mid-period and pay only the difference
Governance
The parts that matter once this stops being a demo
Five roles
Owner, admin, manager, member and viewer, with per-member grants and denials. Denials win.
Sign in your way
Password, Google or GitHub — and a second factor is never bypassed by any of them.
Hash-chained audit
Every consequential action, linked to the one before it, so a gap in the record is detectable.
Tenant isolation
Enforced by a global scope that fails closed. No tenant, no rows — not "no filter, all rows".
Retention by plan
The record of what changed is kept for 7 to 90 days depending on the plan, then removed automatically.
Credentials never in a prompt
Envelope-encrypted at rest, decrypted only to sign a request. The model names tools; the platform makes the calls.
Connect something and see what it drafts
The free plan is the same product at smaller limits, and there is a demo connection if you would rather not point it at your own systems yet.