Runtime for agent-built internal tools

The cloud for the tools your teams build.

Turn agent-built tools into governed internal software. Deploy from the same terminal or IDE where the code was created. Identity, permissions, secrets, network policy, and audit logs arrive with it.

CLIIDE agentCICloud agent
acss / sprint-tracker
agent connected
P

Deploy this sprint tracker for the engineering team. Keep it private and use our existing SSO.

Read package.json, auth.ts, acss.yaml

Ran npm test

Running acss deploy ./sprint-tracker

$

  • ✓ build complete
  • ✓ organization policy applied
  • ✓ live at sprint-tracker.internal.acme.com
Built where your agents work CursorClaude CodeCodexLemonCrowAny shellCI runners

One command, the whole handoff

The agent finishes the app.
acss finishes the infrastructure.

No ticket, bespoke pipeline, or second deployment surface. The same action that makes the tool live also makes it governable.

coding agenttask complete
A

The tracker is implemented and tests pass. I can deploy it now.

$acss deploy ./sprint-tracker
organization runtimeready
  • 01
    BuildPackaged and health-checked
    done
  • 02
    IdentityConnected to company SSO
    done
  • 03
    AccessRoles scoped to groups
    done
  • 04
    NetworkPrivate route created
    done
  • 05
    AuditEvents streaming to SIEM
    done

Governance as a reviewable change

Every security decision is explicit and inspectable.

Every control attached by acss is explicit, inspectable, and versioned alongside the service.

DEPLOY REVIEW

identity.policyapplied automatically
1identity: okta-sso
2provisioning: scim
3session: company-managed
4public_signup: false

Service inventory

Know every tool, owner, and boundary.

See what exists, who owns it, which agent built it, who can access it, where it runs, and whether it is live.

scroll · Services policy synced 42s ago
Service inventory Know every tool, owner, and boundary.

See what exists, who owns it, which agent built it, who can access it, where it runs, and whether it is live.

Service
Owner
Built by
Access
Network
Status
Tsprint-trackertool · 18 runs
eng-platform
CLI agent
engineering
VPC private
● Live
Asupport-triageagent · 94 runs
cx-systems
Claude Code
support-leads
EU region
● Live
Tinvoice-reviewtool · 31 runs
finance-ops
Cursor
finance
VPC private
● Live
Arelease-notesagent · 52 runs
devrel
Codex
company
Cloud private
● Paused

Built for the gap after generation

Coding agents can create the software. They still need somewhere responsible to put it.

01

Agent-native

Invoked from a terminal, editor agent, CI job, or remote coding environment. No separate builder UI required.

02

Private by default

Internal tools are not public links. Exposure is a deliberate policy change, not the default result of publishing.

03

Governed from first deploy

Ownership, access, auditability, and runtime boundaries attach before the service becomes available.

Design partner access

Give every coding agent a safe place to ship.

We are onboarding teams already using coding agents alongside Okta, Azure AD, Google Workspace, or internal SSO.

A founder will reply. No automated sales sequence.