tachikoma
Tachikoma lets AI agents work across all your systems, so everything they produce inherits the access rules of the data it came from. A report built from restricted data only opens for people who could already read that data.
Sits on top of what you already have — no migration.
Keep your agents, your models, your tools — and your vendors' agents. One registry for all of them; Tachikoma sits underneath and governs what their outputs are allowed to reveal.
Data-driven firms need agents to work across scattered sources. Tachikoma reads the access rules of every source and carries them into whatever the agent produces — answers, reports, summaries, files.
A Monday-morning scenario: two vendor copilots and one internal agent build the board pack. Watch your access rules — not the vendors' — travel with the file, all the way to who can open it. Click a step to trace it.
Every team, agent, and system becomes a node in one permission-aware graph. Agents get real accounts, scoped networks, and borrowed secrets — so what they read is always attributable to a source and a rule.
Agents get Unix accounts and scoped addresses — access is decided in the OS, not in a prompt.
Secrets are borrowed, never read. Every retrieval is tagged with the rule that allowed it.
New agents and new outputs inherit the strictest rule of everything they touched.
Agents don't get API keys — they get job descriptions. Reads are scoped, outputs carry their sources' rules, sensitive deliveries route to a human, and every decision lands on an immutable trail.
Deploy where your data already lives, and answer the auditor's real question: for this output, which sources went into it — and was every recipient allowed to see them?
Currently in partnership conversations with major banking groups in Asia, on regulated production-grade use cases.
Runs entirely inside your infrastructure, next to the data it governs. No vendor lock-in.
On incident day: who read what, produced what, and for whom — replayable end to end.
Drafts inherit deal-room walls — no client data crosses into the wrong desk.
Every answer is bounded by the recipient's clearance level, inside your perimeter.
Summaries built on patient data stay bounded to that patient's care team.
Adjusters see summaries scoped to their own book — never another policyholder's file.
Lumen runs multi-agent investigations on Tachikoma. Planner, retrieval, and legal agents work across scattered sources, cite their evidence, and return a recommendation that carries the access rules of every document it read.
A report built from restricted data only opens for people who could already read that data. Open source, self-hosted, no migration.
Lumen — Investigation dashboard