Skip to waitlist
OpenKernelJoin waitlist

Connect · Constrain · Audit

Give your agent a seat, not your account.

Connect GitHub, Notion, Linear and Slack once. Hand each agent or teammate its own seat with its own rules — this client’s pages but not that one’s, open PRs but never merge — and see every call it made.

Works with Claude · ChatGPT · OpenClaw · Cursor · Hermes · Grokbot · any MCP client

Demo as
1Connect

Maya creates a workspace per client and gives her agent a seat. Her prompt: Draft Friday’s status from the shared brief and project channel.

Switch workspaces to see the same connections through a different client's seat.

Workspace
Seats
Connections
2Constrain

Toggle a permission — Inspect shows what the seat now gets, Observe shows the call.

PermissionsNotion
Read shared pages
Update pages
Read context
Context
Acme voice / tone
Doc
Deliverable checklist
MD
Billing / cadence notes
PDF
3Audit

Inspect and observe every call it made, allowed or blocked, with the deciding rule.

Inspect
{
  "pages": ["Friday client brief", "Meeting notes"],
  "title": "Friday client brief",
  "pack": ["Acme voice / tone", "Deliverable checklist"],
  "workspace": "Acme Corp"
}
Observestreaming
09:41:02
read notion.pagesFriday client brief · Meeting notes
allowed
09:41:08
read pack: Acme voice / toneresource read allowed · pack travels with seat
allowed
09:41:16
update notion.pagerule: updates not allowed
blocked

Problem

A token isn’t a seat.

Providers hand you one connection. An agent needs a slice of it — and a different slice for each client, teammate, or bot.

Permissions in blocksthe actual scope menus

GitHub 2 scopes

Public repo readMetadata only — not enough for real agent work.
Full control of private repositoriesRead, write, merge, and delete. One block.

Notion 2 scopes

Read contentEvery page the integration can see.
Read and update contentEdit and create across the workspace. No field-level dial.

Slack 1 bot token

Bot with channel history + chat:writeEvery public channel it joins, send as the bot. There is no smaller useful key.

Google 1 scope

gmail.modifyRead, send, and delete, across the whole mailbox. Calendar is the same: read implies delete.

Permissions

The provider gives you a block.

No "open PRs but never merge". No "hide private pages". No "this seat, not that one". GitHub, Notion, Slack, and Google stop at the scope menu they chose. The agent gets the whole block — or nothing useful.

Context doesn't travel eitherevery thread, by hand
Acme voice / tone
pasted into this thread
every chat
Never mention other clients
still in the same project
every client
Globex architecture notes
dropped in CLAUDE.md
every seat
Don’t touch /infra
same dump as the rest
always visible

Context

Context doesn't travel either.

Voice, SOPs, “never mention other clients” — pasted into every thread, dumped in CLAUDE.md, visible to whoever’s in the project. Acme Corp’s brief sits one folder away from Umbrella Corp’s.

Solution

Connect once. Give every agent its own seat.

You hold the workspace credential. Each agent or person gets a seat — the tools, the context, and its own rules — never the account itself.

01 — Connect

Create a workspace

Create a workspace and connect GitHub, Notion, Linear, Slack. You keep the credentials. Seats never see them.

02 — Permissions

Say what's allowed

Read? Yes. Merge? No. Show private pages? No. Per action and per field, per connection, per seat — finer than the provider's own scopes.

03 — Context

Add the context

Voice, SOPs, architecture notes, "never mention other clients." Set once on the workspace, present in every seat you hand out — not pasted into every thread.

04 — Seats

{
  "mcpServers": {
    "openkernel-acme-corp": {
      "url": "https://mcp.opk.sh/seat/opk_live_••••a1c3"
    }
  }
}
Hand out seats

One MCP entry per person or agent. Each seat carries the workspace's tools and context with its own rules. Revoke one, only that one goes dark.

05 — Observe

You see every request, and every refusal.

Who, when, what it touched, what was hidden, whether it went through. Per seat, not per account.

09:41:02
agent · Acme Corp · read notion.pagesFriday client brief · meeting notes
allowed
09:41:16
agent · Acme Corp · update notion.pagerule: updates not allowed
blocked
09:43:10
agent · Acme Corp · send slack.message“Drafting Friday’s Acme status” → #acme-project
allowed
11:03:44
agent · Umbrella Corp · read notion.pagesUmbrella client brief · meeting notes
allowed

Scenarios

Two setups it was built for

Read them here, then try them yourself — both are in the demo console.

Maya

Maya

multi-client consultant

A wall between Acme Corp and Umbrella Corp

One workspace per client, one seat per workspace. Her agent drafts Friday's Acme status from the Acme brief and #acme-project — and has no tool that can reach Umbrella. Not a rule it has to obey; a tool that isn't there. Switch seats, and Acme is the one that's gone.

Felix

Felix

agentic engineer

One shop, two seats

Same GitHub, Linear and Slack, same architecture notes. Junior can update tickets and post in #eng, but can't merge or message customers. The coding agent can open PRs and link Linear, but can't merge or post in #releases. Revoke either one without touching the other.

FAQs

Questions people ask

GitHub, Notion, Linear, and Slack first. Google (Gmail, Calendar) is next — say so on the form if that's the one you need. After that, whatever design partners ask for, in the order they ask.

Tell me what your agent needs to reach — and what it must never touch.

Free while I onboard design partners. Pricing comes later, and you’ll have a say. Onboarding is by hand and the list is short.