Skip to main content

Bodega One Staff

Your AI team. Your machine. Your rules.

Hire AI staff members like you'd hire contractors. Give them a role, a budget, the rules they have to follow. They handle the work that fills your week.

Coming 2026

Coming 2026. No spam. No credit card.

Code is an IDE you drive. Staff is staff you supervise.

The agent in Bodega One Code helps you build software while you watch. Staff is for everything else: the inbox triage, the social account, the weekly report, the ops work that eats your week. Roles that run on their own, on a schedule, without you in the room.

Supervising means real controls, not a dashboard of vibes. Every staff member runs a loop type you choose, from ask-before-everything to plan-and-execute to fully autonomous. You pick how much rope each role gets, and the policy engine holds the other end.

Already built. Already running.

Staff shares its engine with Bodega One HQ, and the core is merged and tested today. This is what's real right now, not a mockup.

Policies enforced in code

Each staff member gets budgets, allowlists, deny lists, and confirm-first rules in plain YAML. The check runs before any tool call, outside the model. A failed rule means the action never happens.

Approvals that wait for you

When a rule says ask first, the agent pauses. Approve or deny from the dashboard or a push notification. The pause survives a restart, and approval links are signed and single-use.

Message your staff on Telegram and Slack

Prompt an agent, get its reply, and catch up on a run from a Telegram DM or a Slack thread, right where you already work. Two-way, and off by default until you turn it on. (Approving a held action still happens on the desktop for now.)

Budgets and spend ceilings

Cap what a single run can spend, and set a daily LLM-cost ceiling for the whole company. Both are enforced outside the model, so a runaway agent hits a wall instead of your card.

Sandboxed execution

Generated code runs in single-use, isolated containers with no network access. If the sandbox cannot start safely, the run is refused. Fail closed, every time.

A tamper-evident audit trail

Every action is recorded in a tamper-evident audit log. See exactly what your staff did, in order, and tell at a glance if any record was changed after the fact.

Skills they earn

Agents propose reusable skills from work that actually succeeded. Every skill is reviewed and human-approved before anyone can run it, and approved skills climb from personal to team to company. When a skill starts failing, the agent can draft a fix, but a human still approves it.

Your own tools, through MCP

Point a staff member at your own tools through MCP. Anything they send back is screened and policy-checked before the model can act on it, because outside tools are treated as untrusted by default.

Any model, per member

BYOLLM, per staff member. Run local models through Ollama, or Anthropic on your own key, with more providers landing. Assign a heavier model tier to the roles that need it.

What we don't claim.

Nobody can prevent prompt injection, including us. What we do instead: untrusted content from the web or email is tagged and screened before the model sees it, policies cap what any single action can do, and the sandbox and audit trail contain and record the rest. We publish our limits. That honesty is the feature.

Built for people who don't want their agents living in someone else's cloud.

Bodega One Staff runs on your machine. Your credentials sit in your local vault. Your prompts go to whichever LLM you pick. We never see any of it. Air-gap mode is one toggle.

The policies are not vibes. They're enforced in code, outside the LLM. If your rule says no spend over $50/day, the agent literally cannot spend $51. The check runs in our process, not in the model's head.

On the bench next.

In the order we plan to build it. No dates until they're real; follow the build log to watch it land.

  • Ready-made connectors

    First-party MCP connectors for Gmail, GitHub, Linear, Stripe, and X, so staff start useful. You can wire up your own MCP servers today.

  • Approve from chat

    Approve or deny a held action right from the Telegram or Slack reply, not just the desktop.

  • Standalone desktop app

    Staff runs inside the Bodega One HQ app today; a separate Staff-only install for Windows, macOS, and Linux is in early build.

  • CLI and SDK

    Script your staff, or build on top of them.

  • SIEM export

    Stream the audit trail to the tools your security team already watches.

Common questions.

  • How is Staff different from the agent in Bodega One Code?+

    Code is an IDE you drive; Staff is staff you supervise. The agent in Code helps you build software while you watch. Staff runs ongoing, non-coding roles like email triage, social, and ops under policies, approvals, and an audit trail, doing the work when you are not in the room.

  • Can I message my staff from Telegram or Slack?+

    Yes. Prompt an agent and get its reply in a Telegram DM or a Slack thread, right where you already work. It is two-way, and off until an operator turns it on. Approving a held action still happens on the desktop for now; approving straight from chat is next.

  • What happens when a rule needs my approval?+

    The agent pauses and waits. Approve or deny from the dashboard or a push notification. The pause survives a restart, and every approval link is signed and single-use, so nothing runs behind your back.

  • Can I plug in my own tools?+

    Yes, through MCP. Point a staff member at your own tools and everything they send back is screened and policy-checked before the model can act on it. Outside tools are untrusted by default.

  • Can Staff run on local models?+

    Yes. BYOLLM is the default. Run local models through Ollama or Anthropic on your own key today, with more providers on the way, and set a model tier per staff member. Air-gap mode covers work where nothing is allowed to leave the machine.

  • When does Bodega One Staff launch?+

    After Bodega One Code reaches full release. We do not announce dates until things are real. Join the waitlist on this page or the Discord and you will hear it first.

While you wait, the IDE is free.

Bodega One Code is in open beta right now, free for everyone, commercial use included. Same local-first DNA, same BYOLLM setup you'll use with Staff.

Download Code Free

We post updates here first. Catch the next drop:

Part of the Bodega One family.

Same hardened foundation as Bodega One Code (the IDE) and Bodega One HQ (the team operations platform). Built local-first.