01
build anywhere
Use the agent your team already uses.
Build in Claude, Cursor, LemonCrow, or any other environment that writes code. acss does not dictate how the tool is made.
Governed runtime for agent-built internal tools
Turn agent-built tools into governed internal software. Deploy in one command, with SSO, role-based access, secrets, network policy, and audit logs built in.
deploy from a terminal or agent shell
$
Why acss
Teams are already generating approval flows, data viewers, dashboards, and one-off scripts. Without a shared runtime, those tools become invisible infrastructure: duplicate apps, scattered credentials, unclear owners, and no reliable answer to who can access what.
acss turns every small tool into a known, owned, access-controlled service — without sending the builder through a ticket queue or asking the platform team to invent another deployment path.
How it works
No bespoke pipeline. No new console to learn. No public URL by accident.
01
build anywhere
Build in Claude, Cursor, LemonCrow, or any other environment that writes code. acss does not dictate how the tool is made.
02
deploy once
acss deploy ./tool packages the app and gives it an internal address. The same action works from a human terminal or an agent shell.
03
govern automatically
Identity, scoped roles, network policy, secrets, ownership, and audit logging attach before the tool goes live.
“Small software should be as easy to share with your colleagues as a Google Doc — and as governable as everything else your company runs.”Pete Koomen, on why we're building acss
Built for platform and security teams
App builders optimize for getting something online. acss optimizes for running it inside a company.
Security is not an add-on
Every deploy starts with the controls your platform team would otherwise have to assemble by hand.
sso / scim
Authenticate through Okta, Azure AD, or Google Workspace. Joiners and leavers follow the directory you already manage.
rbac
Every tool starts with viewer, editor, and owner roles — granted to people or groups, not whoever has the link.
audit log
Deploys, permission changes, and access events become a durable trace that can be exported to your SIEM.
network
Run in our cloud, your VPC, or fully on-prem and air-gapped. Public exposure is an explicit decision, never the default.
policy as code
Attach organization-wide rules for residency, approved integrations, retention, and networking to every tool automatically.
secrets
Inject credentials for internal systems at runtime. They never need to live in the repository or an agent's prompt history.
Design partner program
We're onboarding a small group of companies already running Okta, Azure AD, Google Workspace, or an internal SSO. Tell us where agent-built tools are showing up in your organization.