Skip to main content

Coming 2026

Bodega One Staff

Your AI team. Your machine. Your rules.

Hire a roster of AI agents for the recurring work that fills your week, running on your own machine.

Coming 2026. No spam. No credit card.

Runs on your machineBYOLLMPolicy-gatedApproval-gatedDenied by defaultAudit-logged

Your own roster of AI workers, running on your own machine.

Bodega One Staff is a workforce you hire and run yourself. Pick roles from a template library, point each one at a model, including a fully local one with no API key, and set it loose on the recurring work that fills your week. Where Bodega One Code is an IDE you sit in and drive, Staff is the roster that runs the rest of the work on its own, on your hardware, with nothing leaving the machine by default.

And it works like a real team, not a row of isolated bots. A director agent can split a job across the right specialists, and when a decision needs weighing, your agents convene a boardroom, talk it through, and hand you minutes you can verify. When a job runs past what your current roster can do, Staff spots the gap and recommends the exact role to hire next, so the team grows to fit the work.

You set how much rope each agent gets, from asking before every step to running a job end to end while you are somewhere else. When one hits an action you flagged, it parks the job on disk and pings your phone; you answer from wherever you are and the run picks back up, even after a restart. And where most AI tools just log what an agent did after the fact, Staff stops it before it acts, checking every step against the policy you wrote.

A cloud agent cannot match this: cut its network and nothing is left, and your keys and data sit in its vault, not yours. Staff keeps your keys in your own OS keychain, runs air-gapped if you want, and lets you bring any of 25+ models, local or cloud. It is a workforce you own outright, not a seat you rent.

What supervising actually looks like.

Five questions people ask before they hand an ongoing role to an agent. Each one is answered by what runs today, not a roadmap slide.

Can the agents work together, not just one at a time?

A roster that runs itself

Your agents work as a team. A director splits a job across the right specialists, a boardroom convenes to weigh a real decision, and when a task runs past your current roster, Staff recommends the exact role to hire next.

  • A director agent splits work across specialists
  • A boardroom deliberates and hands you verifiable minutes
  • It spots a capability gap and recommends the role to hire

Can an agent run a role without me in the room?

Autonomy you set per member

Each member runs its ongoing role at the autonomy you dial in, from asking before every step, to planning then executing, to running fully on its own while you are somewhere else.

  • Ask-first, plan-and-execute, or fully autonomous, per member
  • Runs an ongoing role unattended, start to finish
  • You stay the supervisor, not the operator

How do I keep an autonomous agent in bounds?

Hard limits enforced in code, not prompts

Every member carries budgets, allowlists, and deny lists in plain YAML, checked before any tool runs. The limits live in the executor, not the system prompt, so the model cannot argue its way past them.

  • Checked before every tool call, outside the model
  • Fail-closed: a failed rule means the action never happens
  • A jailbreak in the prompt cannot lift a rule in the code

What happens when it needs my go-ahead?

A sign-off that waits for you

For the actions you flag, the member stops and waits for you instead of guessing. The held action survives an app or machine restart, and your yes authorizes that one exact call, once, and nothing more.

  • It pauses on the actions you flag, and waits
  • The hold outlives an app or machine restart
  • Your approval covers one exact action, one time

Where does the work run, and who sees my keys?

On your machine, keys in a local vault

Staff runs on your own hardware. Provider keys live in a local vault, encrypted at rest and wrapped by your OS keychain, and the shell tool is denied by default.

  • Your machine, your keys, nothing phoned home
  • AES-256 at rest, OS-keychain wrapped
  • Shell and run tools denied by default
  • A container and gVisor sandbox already runs on the server; the desktop is next

Everything else your staff can do

Built and running today. We're hardening it before the public launch.

01

Message on Telegram and WhatsApp

Two-way on Telegram and WhatsApp. Your staff pings you and you reply from your phone. Off until you switch it on.

  • Telegram and WhatsApp today, more coming
  • Reply from your phone, no desktop required
  • Off by default until an operator enables it
02

BYOLLM, per member

25+ provider presets: Anthropic, OpenAI-compatible endpoints, and Ollama running fully local. Pick a model per role.

  • 25+ provider presets
  • Anthropic, OpenAI-compatible, or fully local Ollama
  • A different model for every role
03

Budgets and spend ceilings

A per-run cap plus a daily company ceiling, enforced outside the model. A run stops at the limit.

  • A hard cap on every run
  • A daily ceiling for the whole company
  • Enforced outside the model, not a prompt
04

Run ceilings that always hold

A five-minute per-turn cap, plus iteration, timeout, and I/O limits armed on every loop.

  • A five-minute cap on every turn
  • Iteration and timeout limits on every loop
  • I/O limits armed by default
05

Analytics from real data

Spend and activity read straight from the audit and budget records. No estimates, no fabricated numbers.

  • Pulled straight from the audit and budget records
  • No estimates, no invented numbers
  • The same data the audit trail uses
06

Skills your staff earn

A member proposes a skill from work that succeeded, you approve it, and it is signed and shared across the roster at the scope you set.

  • Propose, approve, or reject from the desktop or the CLI
  • Cryptographically signed before it can run
  • Scoped to one member, a team, or the whole company
07

Drive it from the command line

A full CLI runs and chats, manages the roster, sets policy and spend caps, detects models, and queries the audit trail.

  • staff run, chat, agent, config, and models
  • Policy, secrets, and spend caps from the shell
  • Query and verify the audit trail

How does Staff run?

A desktop app

WINDOWS, MACOS, LINUX

A Staff-only desktop app with a real installer and first-run setup, branded Bodega One Staff. Point-and-click for the whole roster.

A full command line

SCRIPT IT, RUN IT HEADLESS

The same roster, policy, spend caps, model detection, and audit trail from the terminal. Wire it into your own scripts, or run it on a server.

Both ship together when Staff's beta opens, on the local-first core it was extracted from Bodega One HQ, so its policy, audit, and provider layers are the ones HQ already proved. The public launch follows Bodega One Code's full release; no dates until they are real.

On the bench next.

No dates until they're real. The build log is where progress shows up first.

  • The sandbox on the desktop

    Our container and gVisor sandbox already runs as the default on the self-hosted server. Wiring it into the desktop app, which runs in-process today, is what is next.

  • Connect your own MCP servers

    The MCP engine is built in; wiring up your own tool servers from the app is next.

  • Port your agents over ACP

    Export a staff member over the Agent Client Protocol and run it inside any app that speaks ACP.

  • Slack, Discord, and Matrix bridges

    Telegram and WhatsApp ship today. Slack is next, then Discord and Matrix.

  • Approve a held action from chat

    Approve or deny straight from a Telegram or WhatsApp reply. Today, approval happens on the desktop.

  • Ready-made connectors

    First-party MCP connectors for Gmail, GitHub, Linear, Stripe, and X, so a new staff member starts useful.

  • An SDK

    Build staff into your own scripts and tools, on top of the CLI that ships today.

  • Signed installers and auto-update

    Signed installers for the standalone app, with auto-update once it ships.

Common
questions

What people ask before they hand work to an agent.

  • How is Staff different from the agent inside Bodega One Code?+

    Code is an IDE you sit in and drive to build software. Staff is a roster of agents you supervise, each running an ongoing non-coding role on its own. Same company, different job: one builds, the other runs the work around it.

  • Can I message my staff from my phone?+

    Yes. The Telegram and WhatsApp bridges are two-way: a member can ping you and you can reply, and they are off until you turn them on. Slack, Discord, and Matrix are on the roadmap.

  • What happens when a rule needs my approval?+

    The member pauses and waits. You approve or deny from the desktop, and the held action survives an app or machine restart, so nothing gated ever runs behind your back.

  • Can I plug in my own tools?+

    MCP support is built into the engine, and connecting your own MCP servers from the app is coming, along with ACP so you can port a staff member into other apps that support it. Anything a tool sends back is fenced off as data, never instructions, and policy-checked before the model acts on it. Ready-made connectors for Gmail, GitHub, Linear, Stripe, and X are on the roadmap too.

  • Can Staff run on local models?+

    Yes. Bring your own LLM, including Ollama running fully local on your machine, or an OpenAI-compatible endpoint, or Anthropic on your own key. Pick a model per member.

  • Is my data ever sent to Bodega?+

    No. Staff runs on your machine and your provider keys sit in a local vault, encrypted at rest and wrapped by your OS keychain. Your work does not pass through us.

  • How does Staff relate to Bodega One HQ?+

    Same engine. Staff members are the agents; HQ is the team workspace they can clock into alongside your people. Staff was extracted from HQ, so they share their policy, audit, and provider core.

  • When does Staff launch?+

    It is in active development now, ahead of a public launch that follows Bodega One Code reaching full release. Join the waitlist and we will not invent a date before it is real.

While you wait, the IDE is free.

Bodega One Code is in open beta right now, free for everyone, commercial use included. Same local-first DNA, same BYOLLM setup you'll use with Staff.

Download Code Free

We post updates here first. Catch the next drop:

Part of the Bodega One family.

Same hardened foundation as Bodega One Code (the IDE) and Bodega One HQ (the team operations platform). Built local-first.