opengate

IIAgents

Routine work,done before you arrive.

The Monday reconciliation, already done.

An agent is a task someone runs by hand today, written down once: what it reads, when it runs, who owns it. By the time your team arrives, the result and the exceptions are waiting.

One run, on the record

What it read, what it prepared and who approved it, beside the definition of what it may touch.

Acts vs e-invoicesa name a colleague recognisesagent
owner: dana@financeDA
every Monday, 06:00schedule
last run: 41 read, 3 writtentoday, 06:41ok

Named, scheduled, attributable

Each agent has a name a colleague would recognise, a schedule, and an owner whose identity it runs under. The log names the owner, and the failure card reaches them.

triggerschedule or event
read1C sales, Drive/Finance
writeone sheet, one tab
approvalowner, before any write
ownermissing, so the agent does not exist yet

Defined before it runs

A trigger, a read scope, a write scope, an approval rule and an owner. If any of the five is missing, the agent does not exist yet.

One agent per department, one task to start.

Finance matches acts to e-invoices, sales flags deals with no next step, HR sees who has waited longest. Each agent reaches only what its department already may.

06:00read: acts, e-invoices, sales41 records for August1C
06:0238 matchedact to invoice, by number and sum
06:023 unmatchedAct No. 12, No. 15, No. 19to a person
06:41write: reconciliation sheet, tab Q3after the owner approvesDrive

Finance: acts against e-invoices

Every act of completed work matched to its invoice, and the ones without a match listed for a person.

read: deals, activities58 open dealsCRM
7 deals with no next stepNo. 214, 219, 231 and 4 more
2 past their close datemoved twice already
write: one comment per dealafter approval, in the CRM9 drafts

Sales: deal hygiene

Deals with no next step, no date or no owner, surfaced the day before the pipeline review.

read: applications, stagesthe register, this week
4 new this weekdata and AI 3, engineering 1
longest wait: 9 daysat stage interviewflag
write: nonea read-only agentread-only

People: candidate movement

Who applied, who moved stage, who has waited longest for an answer. Read from the register, written nowhere.

read: expenses, deals, timethree departments, one runcross-department
RKfiltered per readerthe lead sees all three totals
DAa figure a reader may not seefinance sees spend, never pipeline
write: one summary, to the ownerTelegram, first Friday

Strategy: spend against pipeline

The one agent that reads across departments, and the one where the permission check matters most. Each reader sees the total only over what they may see.

Nothing is written without a person.

The agent prepares the change and shows it in Telegram. The owner approves, and only then does it land. A write outside the declared scope is refused.

read: 1C salesinside the owner's permissions
read: Drive/Financeinside the owner's permissions
write: Reconciliation.xlsx, tab Q3one place, named exactly
write: anything elserefused before the connector

Two lists: read and write

Read scope is a subset of the owner's permissions. Write scope is narrower again, usually one place, named exactly.

06:02read half completed41 records1C, Drive
06:02attempted: update a 1C documentSale No. 4400
06:02refused before the connectorthe connector never saw itruntime
06:02DAcard to the ownerwhich write, why

A write outside scope does not happen

The runtime refuses it before the connector sees it. The read half completes, the write is dropped, and the owner gets a card saying which one.

+Act No. 12, 16 400 000 ₸, pair: e-invoice 4400row 1
+Act No. 15, 2 300 000 ₸, pair: e-invoice 4402row 2
+Act No. 19, 780 000 ₸, no pairrow 3
ApproveRejectexpires in 24h
06:41DAapproved in Telegram, 3 rows writtenwritten

Writes wait for a person

The agent prepares the change and shows it. The owner approves it where they already are, and only then does it land. An unapproved change expires.

It runs as its owner, never above.

An agent sees exactly what its owner sees. When the owner leaves, access revoked at the source stops the agent too.

DAowner reads 1C salesso the agent reads itagent reads
DAowner reads Drive/Financeso the agent reads itagent reads
DAowner cannot open the staffing tableso it does not exist for the agentagent cannot
a service account with wider accessno such setting

The same permissions as its owner

What the owner may open, the agent may read. What the owner cannot open does not exist for the agent, and no setting widens that.

09:14owner's access revokedin Google Workspace, by the administrator
09:20next scheduled runno principal behind itrefused
09:20RKcard to the department leadthe agent waits for a new owner
10:05MTreassigned to a new ownerruns again on the next scheduleruns again

When the owner leaves, the agent stops

Access revoked at the source is access revoked here. A run with no principal behind it does not start, and the agent waits for a new owner.

When it fails, it stops and tells the owner.

A source times out, a record is malformed. The run retries a set number of times, stops whole, and sends the owner the step and the reason.

06:00attempt 1: 1C timed outread 1C sales, 30sretry
06:01attempt 2: 1C timed outafter a 60s pauseretry
06:03attempt 3: read completed41 recordsok
DAcard to the owner if all three failthe step, the reason, the time

Bounded retries, then a person

A failed step is retried a set number of times with a pause between. After that the run is marked failed and the owner gets a card with the step and the reason.

+row 1 written06:41
+row 2 written06:41
−row 3 failed: sheet locked by another user06:41
06:41rows 1, 2 rolled backthe sheet is as it wasrollback
06:41DAreported: 0 written, 1 failedto the owner

Half a write is never left behind

A change is applied whole or not at all. If the third of three rows fails, the first two are rolled back and the run reports zero written.

Inside 1C, Bitrix24 and Google Workspace.

An agent acts through the same connectors that feed the index, and writes only where a connector has a write path.

sales, actsread over ODataread
counterparties, item catalogueread over ODataread
a 1C documentprepared here, applied after approvalwrite

1C

Sales, acts, counterparties and the item catalogue read over OData. A change to a 1C document is prepared here and applied through the connector after approval.

Reconciliation.xlsx, tab Q3the usual write targetwrite
Driveread, per-file sharingread
Gmaila prepared email waits as a draftdraft

Google Workspace

Sheets are the usual write target: one sheet, one tab, named in the scope. Drive and Gmail are read, and a prepared email waits as a draft for a person to send.

deals, contacts, tasksread over RESTread
a comment on a dealinside scope, after approvalwrite
a stage changeinside scope, after approvalwrite

Bitrix24

Deals, contacts and tasks read over REST. A stage change or a comment on a deal is a write inside scope, applied after the owner approves it.

Every run is on the record.

What it read, what it wrote, as whom, and what it refused. One log for people and agents answers who touched what.

06:00DArun 2026-09-08 startedActs vs e-invoices, as dana@
06:01read: 41 records1C, Driveread
06:41wrote: 3 rowsReconciliation.xlsx, tab Q3written
06:41refused: 1 writea 1C document, out of scoperefused
06:41run ended41 read, 3 written, 1 refusedok

A run is a record

Start, end, records read, rows written, the owner it ran as and the refusals along the way. Nothing happens off the record.

filter: by agentActs vs e-invoices, 12 runs
filter: by persondana@, 41 questions, 12 runs
“Who read act No. 12 in September?”2 people, 1 agentfrom the log
exportevery row, people and agents alikeCSV

The same log as search and answers

One table, one identity model, one filter. A question about a document answers across people and agents alike.

Unattended, under the same rules.

An agent's model calls leave through the same gateway as a person's questions: your key, zero retention, no training, and spend counted against its name.

06:02agent callActs vs e-invoices, as dana@
06:02gatewayyour key, zero retention, no trainingenforced
06:02providerin the permitted region
a second path for an unattended run

One gateway for people and agents

The terms an agent runs under are the terms the gateway enforces, on every call, whoever made it. There is no second path for an unattended run.

Acts vs e-invoices12 runs this month4 100 ₸
Deal hygiene22 runs this month2 300 ₸
dana@, questions41 this month900 ₸
total, per tenantbeside the schedule, before the invoice7 300 ₸

Spend is attributed to the agent

Every call an agent makes is counted against its name and its owner. The cost of a process is a number beside its schedule, never a surprise on the invoice.

Start with one weekly task.

We build the first agent on your systems, under your permissions, and your people approve every write. Name the task somebody runs by hand every week.