Persistent AI operator · for fleets you own

An agent that actually does the work on the machines you own.

Enroll a machine once, grant power with an explicit consent screen, then chat with a persistent agent that runs any command as root, edits system files, drives the GUI, and types vaulted passwords — from a mobile-responsive web UI. No per-action nagging. No “I can’t do that.”

  • Live today — control-plane + model-proxy
  • Agents on macOS + Windows
  • Edge brain · cloud custodian
OpenRouterAnthropicOpenAIxAI GrokSelf-hosted open-weightsOpenRouterAnthropicOpenAIxAI GrokSelf-hosted open-weights
provider-agnostic · no vendor lock
How it works

Enroll, consent, chat — then it operates.

Four steps to a machine that runs itself under your command. In-scope full-power work runs offline, with zero per-action prompts.

  1. 01

    Enroll a machine

    Redeem a short-code on the machine you own. One outbound tunnel comes up — no inbound ports, no local API key. The machine registers to your fleet.

  2. 02

    Grant power, once

    An explicit power-tier consent screen records durable, DB-immutable consent inside the enroll transaction. Consent-on-install, not consent-on-use.

  3. 03

    Chat with the operator

    Open the machine in a mobile-responsive session. Tell it what you want in plain language: "find why nginx keeps dying and fix it."

  4. 04

    It does the work

    The edge brain runs the loop locally as root — inspects logs, edits config, restarts services — streaming live tool cards back. In-scope work auto-approves with zero prompts.

Capabilities

Full power, made accountable.

Built for expert operators running real fleets — not a chatbot that hedges, but an operator that executes and records everything it does.

Persistent edge execution

The agent brain runs as an always-on daemon on each enrolled machine. It survives reboots (resumes from an on-disk journal), tolerates network partitions, and executes tool calls locally — zero WAN round-trip per action.

Does the work — doesn’t refuse

Authorization lives at the consent and audit boundary, not in per-action model gates. Run any command as root, edit system files, type a vaulted password. No confirmation theater, no "I can’t do that."

Provider-agnostic brain

One provider interface behind a cloud model-proxy: OpenRouter, Anthropic direct, OpenAI, xAI Grok, and self-hosted open-weights. Swap models per task. No vendor lock — the open-weights path is the real hedge.

JIT encrypted secrets

When a step needs a credential it doesn’t have, the agent requests it — it never stalls or refuses. You provide it once over an encrypted channel; it’s sealed with own-KMS envelope encryption and injected at the tool boundary. Never in chat, model context, or logs.

Consent + audit spine

DB-immutable consent records, a tamper-evident append-only audit trail, Merkle-chained on-machine WAL, and emailed consent receipts on every grant and revocation. Every tool exec and decision is recorded.

Mobile-first control

A cloud custodian owns identity, fleet, consent, and audit; the UI is a mobile-first web app. Watch the live screen on the left, drive the agent on the right — from your phone, same-origin, reconnect-safe.

Architecture

Edge brain. Cloud custodian.

The agentic loop runs on the enrolled machine and executes tools directly against the real filesystem as root. The cloud is the custodian — never the executor.

  • Runs on your machine. A tiny static Go daemon, supervised, reboot-durable, executing locally.
  • Cloud holds metadata only. Identity, fleet, immutable consent, audit, and the model key — not your bytes.
  • One outbound tunnel. No inbound ports. Model inference is the only egress, out through the tunnel to the proxy.
  • Chat & screen never touch the control plane. They ride a dedicated gateway; the cloud only mints the token.
Read the design story
Provider-agnostic

Bring any model. Keep the keys off every machine.

One Provider interface behind a cloud model-proxy holds all keys, normalizes streaming and tool-use, and handles refusal→fallback and per-tenant metering. The edge speaks one wire format; you choose the brain.

OpenRouterAnthropicOpenAIxAI GrokSelf-hosted open-weights Self-hosted open-weights is the real vendor-lock hedge.
Security & trust

No-prompt power is only safe if it’s accountable.

The law: consent-on-install, full power, no artificial caps — security = authenticated + authorized + audited + revocable. The machine is the sandbox by design; the spine is the control surface.

Authorized-fleet only

Operates solely on machines you enroll with recorded operator consent. Not built to reach systems you don’t control.

Consent-on-install

An explicit disclosure screen writes a transactional, DB-immutable consent record — captured once, made durable, never a per-action nag.

Tamper-evident audit

Dual trail: a Merkle-chained on-machine WAL (durable before return) plus a cloud append-only audit ledger. Secrets never touch audit detail.

Fail-closed veto

A rare out-of-scope action blocks one tool goroutine and issues a synchronous up-call. Pending, timeout, or partition all map to deny.

Revocable, honestly

Terminal device revoke, an immediate in-flight abort-run kill, and epoch-anti-rollback grant withdrawal — with the latencies stated plainly.

Own-KMS vault

Per-tenant DEK envelope encryption under a rotatable master key held in Secret Manager. A stolen machine disk yields no standing secrets.

Get started

Put an operator on your fleet.

Enrollment is a single command on a machine you own — one outbound tunnel, no inbound ports, no local key. Early access is invite-based while we onboard operators.

enroll · your machine
# on the machine you own + authorize
curl -fsSL https://goodagent.cloud/enroll | sudo sh
# → opens the power-tier consent screen, records durable consent,
#   brings up one outbound tunnel, joins your fleet.

Authorized-machine use only. Enrollment records operator consent before any power is granted.

Pricing

Simple while we’re early.

GoodAgent is an early but real product. Pricing lands as we onboard the first fleets — for now, get in touch and we’ll set you up.

Operator

Inviteearly access

For a single operator running a personal fleet.

  • Enroll your own machines
  • Persistent edge agent + mobile UI
  • Consent + audit spine
  • Bring-your-own model keys
Request access

Enterprise

Customself-host option

Regulated fleets, self-hosted open-weights, custom custody.

  • Everything in Fleet
  • Self-hosted model backend
  • Custom KMS & data residency
  • DPA, consent receipts, review support
Talk to us