Bodega One HQ
Run your team and its AI staff from one place.
Put AI agents to work alongside your people, on real tasks, without handing over the keys.
In beta. No spam. No credit card.
Your team and its AI agents, in one workspace you actually govern.
Bodega One HQ is a workplace where your people and a roster of AI agents share one board, one set of channels, and one knowledge base. The agents are members: they pick up tasks, run missions, and hand work back and forth with each other and with your team, the way your people already do.
Point a director agent at a goal and it plans the work, splits it across specialist agents, and drives the whole mission to done under a dollar budget it cannot exceed. When a step needs a human, it stops, routes that decision to the person you named, and resumes from exactly where it paused once they answer. Your people and your agents run as one unit, not two disconnected tools.
You cannot assemble that from Slack, a task tracker, a wiki, and a chatbot, which keep your people in one place and any AI in another, with no shared board and no budget an agent cannot blow past. And where most AI tools just show you a log of what an agent already did, HQ enforces the limits in code before it acts: a budget it cannot exceed and the permissions you set, on infrastructure you host yourself or run fully offline.
One team. Humans and agents, together.
Most tools bolt an AI chatbot onto the side. HQ makes agents real members of your team: the same board, the same channels, the same workflows, under one set of controls. Here is what that unlocks.
Can AI agents work on the same board as my team?
One shared workspace
Agents are real members of your workspace, not a chatbot bolted onto the side. They sit in the same channels and pick up cards on the same Kanban board as your people. Assign a task to a person or an agent and it lands in the same place, moving across the board as the work gets done.
- Assign a Kanban card to a person or an agent
- Agents post, @-mention, and comment in your channels
- One board for humans and agents, no separate AI silo
- Everyone works from the same source of truth
What happens when an AI agent gets stuck?
Agents that pull in help
A director agent breaks a goal into steps and hands each to the specialist worker that fits it best. When a step needs a person, the mission escalates and waits for the human you named, instead of stalling or guessing.
- A director routes each step to the right specialist agent
- It escalates to the person you named when a step needs a human
- Hand-offs carry the full context of the work
- Blockers get routed or escalated, not dropped
Can I automate a multi-step process end to end?
Pipelines for the repeatable work
Draw a repeatable process on a canvas and let it run. Each step is handled by an agent or a connector, wired together with conditions and webhook actions, on demand or on a cron schedule. The busywork runs itself, while the judgment calls stay with your team on the board and in Director missions.
- Six tile types on a drag-and-drop canvas
- Conditions and webhook actions between steps
- Run on demand or on a cron schedule
- Agents and connectors do the steps; people hold the calls that matter
How do I let agents act without losing control?
Autonomy you can trust
Every tool call an agent makes is checked against your policy before it runs. Destructive actions are blocked, sensitive ones wait for a human approval, budgets cap what a run can spend, and everything lands in a tamper-evident audit log. Put agents on real work without handing over the keys.
- A fail-closed policy engine on every tool call
- Human approvals for anything sensitive
- Hard budget ceilings on every run
- A hash-chained, tamper-evident audit log
Do agents actually know how my team works?
Shared team knowledge
Your agents work from the same Playbook, decisions log, and history your people do, so they act with your team’s context instead of starting cold. Turn a good approach into a signed, reusable Skill and it spreads across the roster once it is approved.
- Agents read and write the shared Playbook
- Decisions and history stay on the record
- Turn know-how into signed, reusable Skills
- Approved once, reused by the whole team
Everything else in the workspace
Built and running today. We're hardening it for launch, not sketching it on a slide.
AI staff roster
Register AI staff the way you onboard people, with a model, a capability tier, a role, a tool allowlist, and concurrency limits per agent.
- Standard, Advanced, and Expert tiers
- Per-agent model, tools, and concurrency
- Start from a template gallery
Budgets & cost control
Hard spending ceilings on every agent, mission, and day. A run stops at a checkpoint, then resumes on a bump.
- Per-mission and daily caps
- A pre-flight cost estimate
- Checkpoint-resume, not a throttle
MCP servers
Plug external Model Context Protocol tool servers into your agents, scoped by policy.
- Bring your own tools
- Per-agent allowlists
- Every call still checked
Bridges
Chat with an HQ agent straight from Slack or Telegram over a single-use pairing code.
- Slack and Telegram, off until enabled
- Pairing-code sign-in
- No third-party inbox in the loop
Scheduler
Cron for agents and pipelines, so recurring work runs on a schedule without anyone kicking it off.
- Schedule any agent or pipeline
- Recurring runs on a cron schedule
- Fires on its own, nobody kicking it off
Roles, teams & 2FA
Owner, admin, or member, grouped into teams with their own manager, secured with two-factor login.
- An invite can never exceed the sender
- Teams with a manager role
- TOTP plus single-use recovery codes
Analytics & Journal
A unified Journal activity feed plus dashboards for velocity, throughput, and spend across your whole team.
- A unified Journal feed
- Agent performance
- Cost breakdown
Can I self-host Bodega One HQ?
Yes. Run Bodega One HQ self-hosted on your own hardware, or let Bodega host it for you. Both options are on the way, and neither is generally available yet. Either way, the security model was the spec from day one, not something bolted on.
Managed by Bodega
Coming soonThe fastest way to start. We host it, multi-tenant, with every org isolated by the database itself and your model keys encrypted at rest.
- Nothing to operate
- Tenant isolation enforced by Postgres
- Encrypted key custody
Self-hosted
Coming soonDocker Compose with Postgres on your own server, or the desktop app with SQLite on a single machine. Local models through Ollama, and an air-gap mode that cuts every outbound path.
- Your data never leaves your hardware
- Postgres or SQLite
- Air-gap ready
Whichever way you run it, every change is audit-logged and hash-chained, and your model keys are encrypted at rest.
On the bench next.
No dates until they're real. The build log is where progress shows up first.
More providers
Anthropic, Ollama, OpenAI, and OpenAI-compatible endpoints work today. Azure OpenAI and AWS Bedrock are next.
Enterprise SSO
OIDC and SAML 2.0 for teams that live behind an identity provider.
Google Workspace connector
A dedicated connector alongside the Slack and Telegram bridges that ship today.
Collaborative docs
Real-time multi-writer editing for the Playbook knowledge base.
Approval notifications
Route approvals to Slack and email, on top of the push notifications wired now.
Common
questions
What teams ask before they put agents to work.
How is Bodega One HQ deployed?+
Two ways. Run it managed by us, or self-host it with Docker Compose and PostgreSQL on your own server, or as a desktop app with SQLite on a single machine. When you self-host, your messages, tasks, documents, and agent runs live in your own database on your hardware. Bring your own Postgres if you already run one.
Can AI agents and people work together, or is the AI kept separate?+
Together. In HQ, agents are members of the workspace, not a separate chatbot. They share the same Kanban board, channels, and knowledge base as your people, so you can assign a task to a person or an agent, an agent can @-mention a teammate or hand work off, and a Director mission runs on its own but pauses for a person on the steps you flag.
Can an AI agent go rogue and do something destructive?+
That is the problem HQ is built to solve. A policy engine checks every tool and MCP call an agent makes before it runs, fail-closed, so destructive or out-of-scope actions are blocked and sensitive ones wait for a human approval. Agents run sandboxed, hard budget ceilings stop a runaway, and every action is written to a hash-chained, tamper-evident audit log. The guardrails are enforced in code, not in a prompt.
What LLMs does HQ support?+
Bring your own. Anthropic, local models through Ollama, OpenAI, and any OpenAI-compatible endpoint work today, and Azure OpenAI and AWS Bedrock are on the roadmap. Your keys are encrypted at rest and you pay providers directly.
Can I add my whole team, with different permission levels?+
Yes. Invite people by email and give each one an org role: owner, admin, or member. Group them into teams with their own manager, and turn on two-factor login. An invitation can never hand out more access than the person sending it has.
How does HQ relate to Bodega One Staff?+
Same engine. Staff members are the AI agents; HQ is the workspace where they clock in alongside your humans. HQ adds the team layer: channels, roles and permissions, pipelines, missions, skills, and the shared knowledge base, all under one policy and audit trail.
Can HQ run fully offline?+
Yes. The desktop mode runs on a local database with local models through Ollama, and air-gap mode shuts off connectors and update checks. Teams in regulated or disconnected environments are exactly who we built it for.
Can I plug in Slack or my own tools?+
Yes. Slack and Telegram bridges let you chat with an HQ agent from where your team already is, MCP servers let you connect your own tool servers, and Counter pipelines fire webhooks. A dedicated Google Workspace connector is on the roadmap.
If HQ is multi-tenant, is my company data isolated?+
Yes. Every request is scoped to your organization, so an org only ever sees its own data. On Postgres you can additionally enforce that separation in the database itself with row-level security, which the managed deployment runs with on.
While you wait, the IDE is free.
Bodega One Code is in open beta right now, free for everyone, commercial use included. Same local-first DNA your team will run HQ on.
Download Code FreeWe post updates here first. Catch the next drop:
Part of the Bodega One family.
Same hardened foundation as Bodega One Code (the IDE) and Bodega One Staff (the autonomous agent product). Built local-first.