PLATFORM / Internal Agents

Your employees already have agents. Give them guardrails.

Every copilot gets an owner, a permission set, and an audit trail — before it touches a real system.

Get a demoExplore the workflow ↓
01 / IDENTITY02 / POLICY03 / AUDIT
FABRIQ / RIPPLEIDENTITY · PERMISSIONS · VISIBILITY
Work freely. Within your role.FABRIQ / CONNECT
01 / THE CONTEXT

Agents for your people,
inside your boundaries.

Agents are already inside: drafting from Gmail, querying the CRM, touching databases. Nobody approved most of them — and nothing is watching.

AGENTDOINGTOOLOWNER
  • mail-draftDrafting repliesGmailno owner on record
  • crm-lookupLooking up accountsSalesforceno owner on record
  • digest-botSummarising channelsSlackno owner on record
  • workplace-agentReading team documentsGoogle Drivedana@acme · registered

Illustrative roster. A registered agent carries an owner, a permission set, and a record of everything it did.

02 / IN PRACTICE

Work freely. Within your role.

ONE EMPLOYEE · ONE DAY · ONE AGENTIllustrative · workplace-agent acting for Dana, Sales
  1. Dana signs in

    The agent starts under Dana’s own identity — her role, her teams, her connected tools. Nothing of its own.

  2. Google DriveRead team documentsAllowed

    The sales team’s folder is hers to open, so it is the agent’s to read. Allowed, and written to the trail with both names on it.

  3. GmailDraft a reply to a customerAllowed

    A draft in Dana’s own mailbox. The agent never holds her mail credential — it is attached on Fabriq’s side for the call.

  4. Google DriveRead another team’s private filesBlocked

    Dana is not in that team, so the agent acting for her is not either. Stopped before the call leaves Fabriq.

  5. SlackShare the deck outside the companyHeld

    A named human approver has to say yes first. Nothing leaves the workspace while the request waits.

  6. The day is on one trail

    One record for all of it: who asked, which agent acted, what it touched, and how each call came out.

Illustrative day · effective access = the agent’s grants ∩ Dana’s own permissions.

03 / WHAT CHANGES

Control, in the details.

01

Every agent tied to the employee who runs it.

Actions stay attributable; permissions inherit from the employee’s own role.

02

Fine-grained access controls per agent.

Per agent, per user, per action — the full permission model, enforced on every call.

03

A complete audit trail.

Who triggered it, what was accessed, and what happened — every time.

04

Policy enforced before actions execute.

Rule-breaking actions are blocked up front, not flagged afterwards.

05

Drop-in with your identity provider.

Okta, Azure AD, Google Workspace — no infrastructure redesign.

06

One switch to shut an agent off.

Disable an agent org-wide and its next call fails closed — no key rotation scramble.

02 / THE CONTROL LAYER

Every action checked
against policy.

Which agent, for which person, against which resource. Decided before anything runs.

ACTING ON BEHALF OF

Same agents. Different authority.
Select a cell to inspect the decision.

Swipe to explore all six tools →

AGENT × TOOLGmailSlackDriveGitHubDBDatabase$Payments
sales-agentfor dana@acme
support-botfor dana@acme
data-pipelinefor dana@acme
finance-agentfor dana@acme
research-agentfor dana@acme
ops-agentfor dana@acme
✓ Allowed

sales-agent → Gmail, acting for Dana. Both the agent grant and the user’s permission allow this tool.

● ALLOW × BLOCKEDIllustrative policies · effective access = agent grants ∩ user permissions
THREE LAYERS. ONE DECISION.

The boundary travels with the work.

Explore the context attached to every request.

What is this agent allowed to do?

workplace-agent has a defined purpose and a bounded set of tools.

QUESTIONS

A closer look.

How do agents get tied to employees?+

At registration — each agent binds to its owner, inherits their permissions, and every action it takes carries both identities.

Do employees have to switch tools?+

No — Fabriq drops in between the agents people already use and the systems those agents touch. Workflows stay; controls attach underneath.

Can risky actions require sign-off?+

Yes — grants go down to single actions, and sensitive ones can be held for human approval while everyday calls stay fast.

What happens when an employee leaves?+

Their agents lose access automatically, and the record of everything those agents did stays intact for review.

Which tools can employee agents reach?+

Whatever your organization connects through the hub — Microsoft 365, Google Workspace, Slack, and GitHub prebuilt, plus your own APIs, MCP servers, and Postgres behind guardrails.

YOUR NEXT CHAPTER

Give your agents
room to move.

See Fabriq in action
Integration HubCoding AgentsPermissions & Scopes