Your agents do the work. You hold the line.
Works with Claude, Codex, Cursor and any MCP client.
Specify Work is the record your agents work against: what they did, what they were stopped from doing, and what you decided. Memory is opening first; Security and Briefings follow (opening in stages).
PreflightMode, scope and cost, checked before the job runs.
The planned path from command to record.
Memory opens first; Security and Briefings follow. This planned workflow requires the Guard adapter and enabled client coverage. Open a step to explore it.
With an installed Guard adapter and enabled Security access, supported client hooks or a proxy will submit covered calls for a policy check. Commands outside that integration are not intercepted.
- Shell commands, file edits and MCP tool calls
- Each call is tagged with who ran it and from which client
- The check runs on the person’s machine, not on a server
The planned gate will check a covered call against your policy. Rules can allow, mark or deny a matching command. Publishing a policy and installing client coverage are separate steps.
- Rules make the decision, not a model
- Test a new rule against your recent calls before it applies
- Turn a starter policy to deny when you are ready
In the planned workflow, a denied command will stop with a reason. The decision will be recorded; how the agent continues depends on its client integration.
- The person sees the reason in their own client
- A retry is denied again until an admin grants an exception
- Every denial is written to the record
The planned decision record will link the covered call to its client and policy outcome. Memory captures explicitly submitted records, not every action in an external session.
- Explicitly saved context can be reused in a later session
- Facts an agent learns stay unconfirmed until a person confirms them
- Private records still require authorization; membership alone is not access
The planned exception workflow will let an authorized admin review a denied command and grant or decline a scoped exception. Approval authorizes a defined action; it does not prove that action ran.
- An exception is bound to the action and authority it was issued for
- It is written to the record with the admin’s reason
- The person is told either way
Briefings is being built to turn selected records into a page or podcast with source links. Generation and delivery are not available as a complete service yet.
- Choose who it is for and how long it should be
- Claims the record cannot back are marked
- Anything sent to other people is reviewed first
Memory. The whole thread, on the record.
Memory opens first. Keep selected facts, decisions and files with their sources and history. Capture is explicit; access follows each record.
Explicitly saved notes
Release 24.3
Plan · in memory
release-plan.md
- Survey incidents since 24.2done
- Verify checkout on the release branchdone
- Write the release briefdone
- Deploy 24.3 to productionawaiting review
- Sources
- 3
- Last verified
- 09:41 · A. Lind
- Owner
- M. Reyes
Security. A command gate for the rules you name.
Security is planned to check covered commands on the machine, record the policy decision and support scoped exceptions. Enforcement needs a separately installed Guard adapter; signing in does not install it.
Denied and escalated
What ran
Escalation · for D. Marsh
Deploy 24.3 to production
- Denied
- 09:44 · Production changes · logged
- Requested by
- M. Reyes · plan step 4 · still working
- Evidence
- verify log 09:41 · 212 tests passed · brief reviewed
- Retries since
- None
The decision lands on the approved log with this evidence. A retry passes only after that.
Briefings. A briefing on anything, from the team’s memory.
Planned for Briefings; not available yet. Ask for a page or a podcast on a release, a week or a single decision. It is written from the record, each claim tied to its source, in the form your team likes to take it in. If a source changes after review, the claim is held until someone re-verifies it.
Briefing · asked by M. Reyes
Release 24.3, for leadership
1The askBrief leadership on release 24.3. Five minutes, spoken. Lead with what shipped.
- 0:00What shipped in 24.31
- 1:05The deploy that was denied, then allowed3
- 2:20Checkout on the release branch2
- 3:30What is next12
Specify Convert. Five file workflows to explore.
Explore examples for Markdown PDFs, resumes, background removal, image conversion and CSV charts. Convert is not open yet; these examples do not process or export your files.

OriginalCutoutAgents that remember, stay in bounds and keep you briefed.
Memory
It keeps the record.
On its ownEvery session starts from zero. What the last one learned is gone.
With Specify WorkMemory opens first, with explicitly saved facts, decisions and sources. People and agents can reuse the records they have access to in the next session.
Explore Memory →Security
It holds the line on the commands you name.
On its ownNothing stands between an agent and a command it should never run.
With Specify WorkSecurity is planned to check named commands against your policy and record denials and exceptions. Enforcement requires the Guard adapter and enabled coverage for your client.
Explore Security →Briefings
It briefs you from that record.
On its ownIt can summarise its own session. It can’t tell you where the team stands.
With Specify WorkBriefings is being built to turn selected records into pages and podcasts, with source access and review before delivery. Generation and delivery are not available as a complete service yet.
Explore Briefings →
Put your agent work on the record.
Specify is where agent operations become something you can stand behind.
Create your account