Software can finally do the work. AI agents write code, read documents, file reports, and ship changes on their own. What stands between that capability and your actual business is no longer intelligence. It is trust. Operator is the layer that makes autonomous work something you can hand your business to, by keeping you in command of it.
The supervision gap.
A modern coding agent can refactor a service, run the tests, and push to production without a human touching the keyboard. That is thrilling right until the moment it runs rm -rf, emails the wrong client, or deploys on a Friday afternoon.
The usual answers are both bad. Watch it the whole time and you have hired someone expensive to babysit a robot, and you automated nothing. Walk away and you are trusting a black box with your database, your money, and your name.
There is a third option. Let the agent run, but keep a human on the one decision that matters. Should this happen? And make that decision answerable from anywhere.
Autonomy you can supervise is autonomy you can trust. That single idea is the reason Operator exists.
Four convictions.
Everything in the product falls out of a small set of beliefs about what supervised autonomy has to guarantee.
- 01
Any agent, on your own compute.
Operator ships no model of its own. It runs the agent you already use, whether Claude Code, Codex, Gemini, Grok, OpenCode, Pi, or Computer Use, as a real, supervised worker on your Mac or your own cloud. Your API keys are sealed to your machine and injected only at spawn. The relay never sees them. Neither do we.
- 02
Approvals from anywhere.
When a worker reaches something risky (a deploy, a delete, a spend, an outbound message) it pauses and asks. The request lands on your Mac, iPhone, and Apple Watch at once. The agent keeps its momentum; you keep the veto.
- 03
Nothing off the record.
Every command, approval, and auto-rejection is written to a tamper-evident, hash-chained log: who ran what, when, on which machine, and what you decided. Autonomy without a paper trail is a liability; here the work has a memory you can audit.
- 04
Your content stays yours.
Operator is a control plane, not a content grab. It governs how work runs; it never mines what is inside your files. Documents, code, and keys stay on your machines.
The shape of it.
Three apps that pair once and work as one, and a growing catalog of real work you can hand them.
The engine
Runs your workers in on-device sandboxes and holds your keys sealed. Where the work happens.
The control
Launch work, watch the live timeline, approve the risky moments. The remote for your fleet.
The pulse
A yes or no on your wrist, plus fleet vitals, without reaching for a device.
Solutions: real jobs, ready to run.
You never start from a blank terminal. A Solution bundles the recipe, skills, connectors, and policy for one job, whether PR review, invoice processing, a research briefing, or a listing writer, so you install it once and hand your fleet real work.



Automations: put the work on a clock.
Connect the tools your team already runs on, then fire a worker on a schedule, an incoming email, or a webhook. An invoice lands and gets filed; a pull request opens and gets reviewed; a nightly report writes itself, and it still pauses for you the moment it turns risky.
Document Intelligence.
Drop in a contract, an invoice, or a manual and Operator reads it into structured, searchable knowledge. Every value it pulls is cited to the exact page. Tap a number and it highlights where it came from, so you trust the extraction instead of taking it on faith. Then ask questions of your documents in plain language and get grounded, cited answers back.
One screen for the whole operation.
A worker becomes a fleet. Dozens of agents (different tools, different projects) running at once, under one operator, on one timeline.
Autonomy you can trust.
Free for seven days, no card. Download the Mac app, get it on your iPhone, pair once, and start a worker. You will feel the difference the first time one pauses and asks.
← Back to Read