An AI coworker you can actually let in.
Secure, capable and intelligent — in Microsoft Teams, on its own machine, reaching only what you switch on.
01 / Capability
It does the work.
Not a chat window that describes a task. Switched on, it pulls the numbers out of the systems that hold them, writes the script, runs it, and hands you the finished thing.
Analyse
“Pull the numbers out of the accounting system and tell me what changed.”
Gather
“Aggregate the site traffic and the search data into one weekly picture.”
Build
“Turn that into a chart that looks like it came from us.”
Watch
“Check the forms on the site still work, every Monday.”
Shapes of work, not a feature list. What any one coworker can do is what you have switched on for it.
02 / Context
It knows where things are.
Email, SharePoint and Teams to begin with. Then three thousand more services through Pipedream — each one a connection you make, name and can revoke. Never a key it helped itself to.
- Microsoft
- Teams
- Outlook
- SharePoint
- OneDrive
- Excel
- Gmail
- Google Drive
- Slack
- Notion
- Figma
- GitHub
- Dropbox
- WordPress
- Salesforce
- Zendesk
- 3,000+via Pipedream
Brand names and logos are the property of their respective owners and are shown to indicate connectivity only. They are not customers. “3,000+” is Pipedream’s own published figure.
It remembers
Its own notes, in its own database on its own machine — not a shared pool.
It learns the work
Tell it how a job is actually done here and it writes that down, in its own words, and reads it back the next time the job comes round.
Knowledge is not permission
What it learns can advise. It can never authorise — a build check fails if a decision path can read the knowledge store.
03 / Control
You decide what it touches.
Everything that reaches out of the coworker's own machine begins switched off. Inside its own machine it works at full speed, in a sandbox, from the first minute. You move it up one rung at a time, and your name is on the move.
Permission
off → shadow → propose → auto. A promotion climbs exactly one rung and is refused outright if no person is named. A demotion is any distance, instantly, by anyone.
Execution
Code runs in a kernel sandbox: read-only root, its own process namespace, capabilities dropped, no privilege escalation, cloud credentials stripped out of the process before it starts.
Input
Anything arriving from outside — a ticket note, an email, a web page — is tagged as untrusted data before the model reads it. What it reads can advise. It can never grant.
Start one this afternoon.
It arrives small: it can talk with you in Teams, look things up, and remember. Everything else you switch on with us, one rung at a time.
Burli is new. There are no customer logos to show you, no case studies and no numbers to quote. What we have is the code, and a page that tells you where it stops.