Governed execution for people and agents

Give AI the data it needs.Control what it changes.

Onterix turns company knowledge and tools into reusable capabilities for people working through AI clients, autonomous agents, and applications. On every run, Onterix checks current authority, shapes the data released, constrains changes, and records the confirmed result.

Used by
People · agents · applications
Applied on
Every separate run

Renewal capability · v3.2

Same job. Separate authority.

00

Request

Maya Chen · person

Interface
Codex MCP
Trigger
On demand

Prepare the Acme renewal, advance the opportunity, and send the reviewed follow-up.

  1. 01

    Current authority

    Maya Chen · current Salesforce accessChecked at run time
  2. 02

    Released data

    4 of 5 fields released
    • Private note withheld
    • Contact tokenized
    • Call notes summarized
  3. 03

    Allowed change

    Stage 2 → 3 · reviewed emailBound to the request
  4. 04

    Confirmed result

    CRM confirmed · email acceptedProvider response retained
Evidence
otr_01JQ9F42
Capability
renewal.v3.2
Policy
release-14
Transform
renewal-7

Person via Codex run shown.

One capability, separate runs

Define the job once. Apply current controls on every run.

Package the approved context, instructions, tools, input and output contract, release rules, approval conditions, and expected result. Each caller starts a separate run under its own identity and current authority.

  1. 01

    Context

    Current company knowledge with source permissions, citations, freshness, and ownership intact.

  2. 02

    Method

    Reviewed instructions, tools, tests, inputs, outputs, and an accountable owner for one job.

  3. 03

    Controls

    Release rules, approved transformations, permitted changes, destinations, and approval conditions.

  4. 04

    Required result

    The expected outcome, provider confirmation, and evidence the run must retain.

Person via CodexAutonomous agentApplication or workflowSame versioned definition · separate authority on every run

Before data leaves

Control what leaves the source—not only who can reach it.

Onterix evaluates source authority, recipient, destination, purpose, and policy before release. Keep, remove, tokenize, minimize, or transform fields so the caller receives only the approved derivative.

Data retrieved

5 fields
Account
Acme Manufacturing
Treatment
keep
Renewal
Sep 30 · $1.2M
Treatment
keep
Contact email
[email protected]
Treatment
tokenize
Internal risk note
Executive escalation watch
Treatment
remove
Support severity
High
Treatment
keep
ONTERIX RUNTIMEData release control

Release check

Before release
Requester
Maya Chen · person
Recipient
Maya Chen · Codex session
Purpose
Renewal brief
Source access
Current
Custom transform
v12
Destination rules
v8
Release decisionTransform1 removed · 1 tokenized

Data released

4 fields
Account
Acme Manufacturing
Treatment
release
Renewal
Sep 30 · $1.2M
Treatment
release
Contact
contact_7A2F
Treatment
release
Support severity
High
Treatment
release
Release evidenceSource revision sf_842Transform tx_12Output hash 7d9a41c2otr_01JQ9F42

Built-in checks, existing DLP, and policy-approved custom transformations can participate in the same release decision.

Before and after execution

Approve the exact change. Follow the run through the result.

Constrain the target, fields, values, recipients, and destination. When approval is required, Onterix binds it to the exact request and retains the provider-confirmed result with the run evidence.

Exact change contract

Salesforce opportunity update

APR-208
Target
Acme opportunity · production
Proposed value
Stage 2 → Stage 3
Allowed fields
stage · next_step
Customer send
Reviewed follow-up only
Approved by
Maya Chen · this request
If the request changes
Supersede approval · review again
Approval applies to one exact mutationReady for execution
REQ-02418CUSTOMER RENEWAL · RUNTIME RECORD
Confirmed record
Requester
Maya Chen · person
Started in
Codex · MCP client
Capability
Customer renewal · v3.2

Requested work

01Request

“Prepare the Acme renewal brief, advance the opportunity from stage 2 to stage 3, and send the customer follow-up.”

  • Prepare a cited renewal brief
  • Advance the Salesforce opportunity from stage 2 to stage 3
  • Send the reviewed customer follow-up

Runtime controls

02Runtime controls
Source access
Maya Chen · current Salesforce permissions
Released data
4 of 5 fields · private note removed
Approved changes
Salesforce stage 2 → 3 · send reviewed email
Retry rule
Confirm provider state before another attempt

Confirmed result

03Result confirmed
Brief
Ready · four source citations
CRM
Updated · Salesforce confirmed
Email
Accepted · message ID retained
EVIDENCEotr_01JQ9F42Confirmed 2026-07-14 · 16:42:18Z

Who asked. What was allowed. What left. What changed. What was confirmed.

Start with one useful job

Useful on the first run. Reusable after that.

Start with a result the team already understands. Add sources, tools, and actions only when they improve that result.

01 · Revenue

Prepare and advance a renewal

See the workflow
Released data
Cited account brief · private notes removed
Allowed change
Forecast update · task · reviewed email
Confirmed result
CRM confirmed · email accepted
02 · Customer

Resolve an issue across systems

See the workflow
Released data
Assigned-team case summary
Allowed change
Account correction · customer response
Confirmed result
Account corrected · response delivered
03 · Legal + procurement

Move a vendor through every gate

See the workflow
Released data
Cited case file for assigned reviewers
Allowed change
Decision routing · approved updates
Confirmed result
Review completed · records updated
04 · Security

Complete a questionnaire from approved evidence

See the workflow
Released data
Cited answers · restricted fields removed
Allowed change
Exception review · package release
Confirmed result
Questionnaire approved · package delivered

Start with one capability

Turn one recurring job into a governed capability.

Connect a system, start with a template, and use the capability through an AI client, an autonomous agent, or an application.