Companies
One estate per company, with its own connections, members and record. A second company is a second estate, never a shared one.
Control Plane
Atlas puts the control plane on your company map: the teams, projects and directives it serves on one side, the systems it is allowed to call on the other, and the record of every action underneath.
The plane at a glance
Agents on the left, connected systems on the right, the plane between them, governance beside it and the record underneath. This is the shape the console draws from a live estate.
Agents
Plane
Systems
| Time | Agent | Call | Outcome |
|---|---|---|---|
| 12:04:11 | Triage agent | Qualys · list_findings | Allowed |
| 12:04:13 | Triage agent | ServiceNow · create_incident | Escalated |
| 12:04:20 | Access reviewer | Okta · revoke_session | Denied |
| 12:05:02 | Evidence collector | Microsoft 365 · read_audit_log | Allowed |
What the plane holds
117 integrations are catalogued today. What a company can actually call depends on its connections, its members and its policy, and the plane keeps those three in one place.
One estate per company, with its own connections, members and record. A second company is a second estate, never a shared one.
Security, DevOps and IT work in the same plane with different scopes. A team sees the systems and agents it owns and nothing it does not.
Work is grouped by project, so a directive, the agents that carry it and the evidence they produce stay together.
A directive declares an outcome and the limits on reaching it. The plane plans the steps, runs the ones it is permitted and escalates the judgment calls instead of guessing past them.
Every catalogued integration exposes named tools. A connection determines the credentials, the permissions and the tools actually available, and the catalogue says which entries are available and which are planned.
Every call runs under a member's identity and scope. When two accounts of one system are connected, the plane fails closed rather than guessing which one a call means.
Allowed calls are listed per connection, and a deny-list floor holds under every policy. A denied call is a receipt in the record, not a silent skip.
Policy is written once and applied to agents, tools and models alike: what may be read, what may be changed, and what waits for a person's approval.
Models come from the configured provider catalogue with exact IDs, and each shows its source and whether it is available. A model listed is not a model proven on every tool path, and Atlas says which is which.
Agents are working nodes on the plane, not a list beside it. Each carries the state of its latest run and opens to the record behind it.
Every action is written to an append-only record: who asked, what was called, what answered and what was denied. Reopen it from Atlas or from your AI client.
How a directive runs
A member or an agent states the outcome and the limits, inside a project the plane knows.
The plane reads the member's scope per connection. An ambiguous connection stops the run before any call.
The steps are mapped onto the tools the connection allows, under the deny-list floor.
Permitted calls run. A judgment call is escalated to a person with the context attached, not guessed.
Each call, answer and denial lands on the append-only record with its receipt.
The result is a saved Atlas object: open it on the map, in the room, or from an external AI client over MCP.
Control Plane for AI
Atlas reads each provider through its administration or compliance API and renders it as a room beside the rest of the plane. What a room shows depends on the connection and the access the provider grants.
Usage and administration reads, rendered beside the tenant's other systems.
Compliance reads over Claude, Claude Code and Cowork usage.
Administration, analytics and cloud agent reads for engineering seats.
Agent usage and configuration reads from the CRM estate.
Organization, model and usage reads for the teams that build on open models.
Where it runs
Self-managed customers receive the artefacts, deploy them, allowlist egress per host and move versions on a release line. Each tier has a self-managed option.
| Tier | What it is | Self-managed option |
|---|---|---|
| Web | The Atlas console and every server route, including the MCP endpoint and the rooms. | One container from this repository. |
| Backend | The registry, the ledger, tickets, conversations and sessions. | Self-hosted or cloud database. |
| Credential broker | OAuth and API-key storage for the integrations. | Self-hosted or hosted broker. |
| Control plane | Kindo's MCP federation and REST API. | Kindo self-managed, reached over your network. |
| Model rail | Kindo's models, or a configured provider. | Kindo's rail keeps model traffic inside the plane. |
In Kindo's words
A control plane is not a thirtieth console. It sits above the systems you already run, takes an intent, and maps it onto the tools it is allowed to call. The operator declares an outcome. The plane plans the steps, executes the ones it is permitted, and escalates the judgment calls instead of guessing past them.Kindo Research, July 2026. The AI-native control plane for agentic execution and The evolution of AI interfaces.
Questions, answered
The Control Plane is the governed layer between the people and agents that declare work and the systems that do it. It resolves identity and scope, permits or denies each call, escalates judgment calls and writes every step to an append-only record. Atlas draws it on the company map beside the teams, projects and directives it serves.
No. It sits above the systems a company already runs and maps an intent onto the tools it is allowed to call. The console is how a team watches and governs the plane; conversation is one input into it.
The AI a company already uses is part of its estate. Atlas reads Microsoft 365 Copilot, Claude Enterprise, Cursor, Salesforce Agentforce and Hugging Face through their administration or compliance APIs and renders each as a room, so usage, policy and evidence sit beside the rest of the plane.
On your infrastructure or in a managed deployment. Self-managed customers receive the artefacts, deploy them, allowlist egress per host and move on a release line. The deployment guide lists every host a deployment reaches.
Start with one company, one team and one directive you can verify end to end.