Built to be checked.

Handing work to Jori means handing it your repositories, your issues, your threads, and your inbox. That access comes with controls you can see and receipts you can audit.

Every tool has a mode

Allowed, ask first, or blocked: you set what Jori can do on its own, per action, per account.

Some tools read, some act. Reading is how Jori stays useful; acting is where you set the terms. Modes live in the console, and a change takes effect on the next run.

Answering where it's asked stays on, so Jori can always report back in the thread that called it. Everything else is yours to set.

Permissionsa few of the modes you set

Search threads

Search your Gmail threads.

Allowed

Create draft

Save a Gmail draft without sending.

Allowed

Send email

Send a new email from your Gmail account.

Ask first

Create calendar event

Add an event to your Google Calendar.

Allowed

Create pull request

Create a GitHub pull request.

Ask first

Search web

Search the public web.

Blocked

Ask first means ask you

Set a tool to ask first and Jori requests before acting. Nothing runs until you approve it.

Every request carries a code. Approve it from the console, or reply where the work is: type approve YD4UEFNV in the thread and the action runs. Deny it, or let it expire, and it never does. Jori doesn't retry on its own.

Unattended runs can never use ask-first tools. Anything you gate waits for a run with you in it.

Approval requested#eng · Slack

Comment on the certification issue

  • On: COP-73 · Tip-pooling certification
  • Asking Jonas which two signatures are missing
  • Posted as you

Every run keeps receipts

What Jori read, what it did, what it asked: timestamped, on every run.

Runs live in the console: what triggered them, which tools they used, what they produced, and what they asked along the way. When Jori splits work into subtasks, each one links back to the run that started it.

Receipts aren't a report Jori writes about itself. They're the record of what actually ran.

Run receiptsRelease readiness · today
  1. Started on schedule

    Schedule
    Weekday mornings
    0s
    07:58
  2. Read pull requests

    GitHub
    copperline/payroll, 9 open
    4s
    07:58
  3. Read issues

    Linear
    Copperline and Platform, 14 issues
    6s
    07:59
  4. Updated the app

    Release readiness
    2 blocking, 11 ready, 1 in review
    2s
    07:59
  5. Posted the change

    Slack
    #eng, what changed since yesterday
    1s
    08:00

It acts as you, never past you

Jori works with the accounts you connect, with the access you grant. Nothing else.

Your accounts, your identity
Jori acts through the accounts you connect, as you. Disconnect an integration and its access ends with it.
Personal and organization
Work that touches your own tools stays scoped to you. Organization work is visible to the whole team, so nothing shared happens out of sight.
Subtasks inherit less, never more
Jori can split a job into subtasks. A subtask can never hold access its parent lacks.

Some things are structural

Not settings, and not promises. The way it's built.

Unattended runs can't use ask-first tools
Scheduled and event runs never touch a tool you've gated. Anything that needs your sign-off waits for a run with you in it.
The web is off until you turn it on
Web search and fetch are granted per playbook and per automation, never assumed.
What Jori reads is evidence, not instructions
Text inside emails, pages, and tickets can't redirect Jori, grant permission, or change the task. Only you can.
Share links are view-only and mortal
App links carry their secret in the URL fragment, so it stays out of server logs. They expire on a clock you choose, and you can revoke them anytime.

Where your data goes, and doesn't

Short list, plain words.

Access you grant
Jori reads through the OAuth grants you approve, integration by integration. Revoke a grant and the access is gone.
A short list of subprocessors
Never used for training
Your data is never used to train models.
GDPR
Jori is built to operate in line with GDPR. Data processing agreements are available from launch.
Audits
Independent security audits are planned. We'll publish the results when they're done.

Opening to a few teams at a time.

Set the modes, watch the receipts, expand from there. Tell us what you'd hand over first.

We'll only email you when there's room for your team.