A connected toolbelt
Over a hundred tools — browsing, research queries, live market data for stocks, crypto and currencies, file workspaces, delegation — each one permission-gated.
A model that can only produce text is a writing aid. A model that can browse, read your files, query an archive and hand work to another persona is something closer to a colleague. The difference is the toolbelt — and whether you can control it.
What a persona can reach
The platform ships over a hundred tools. How many a persona may use depends on your plan, and the progression is deliberate rather than arbitrary: a tool lands on the tier that sells the module it belongs to. Manuscript tools are worth nothing without the manuscript editor, so they arrive together.
- Every plan — read, write and list files in a workspace, render markdown, draft and revise in Studio, and write, illustrate and chart newsroom articles.
- Standard adds your organisation's own metrics, dashboards and announcements.
- Pro adds live web browsing — fetch a page, read what is on it, follow its links — and the full manuscript toolset.
- Business adds browser automation (clicking, typing, capturing screenshots), research-archive queries, property and market data, and delegation: handing a task to another persona or to a whole team.
Every tool is permission-gated
This is the part that matters. Each tool has its own permission, checked at the moment of use — not suggested in an instruction the model may ignore. A persona reaches exactly what you have granted it and nothing else.
So a research persona can browse the web without being able to touch files. A drafting persona can write without being able to publish. An analysis persona can query an archive without being able to reach another team's work. When a persona attempts something it lacks, the attempt is refused and recorded rather than quietly succeeding.
Some tools are on no plan at all
A handful of capabilities belong to the people who operate the platform and are not sold at any price: running arbitrary code, querying the database directly, reading another organisation's workspace, messaging people outside your own team. That is not a limit you upgrade past.
It is also the point. Those are exactly the tools that would let one tenant's persona reach another tenant's data, so they are not purchasable — which is what makes everything above defensible.
The useful question about an autonomous agent is not what it can do. It is what it cannot do, and who decided.
Bring your own tools over MCP
The platform speaks the Model Context Protocol, so a tool server you run — an internal API, a data warehouse, your ticketing system — can be connected, and its tools then appear alongside the built-ins under the same permission model and the same audit trail. MCP connections are set up with us rather than self-served: tell us what you want to expose and we will wire it to your workspace.
Every call is on the record
Tool calls are logged with their arguments, their result and how long they took. When a routine produces something surprising, you can read what it looked at on the way there instead of inferring it.
Market data is fetched, not remembered. Quotes and price history for equities, crypto pairs and currencies are retrieved from the source at the moment of writing, with the as-of date attached. A model asked for a share price will produce one from training data; a model given a market tool produces the price.
Where this pays off
Anything touching your own systems. Any deployment where "the AI has access to that" needs a precise and defensible answer.