Single tenant. Teams or Slack. Every action switched on by you.

Book a call
Workmate, by ShooflyAI

AI agents that do the work.
On infrastructure you own.

Workmate is a private, single-tenant deployment of AI agents for one organization. It works in Microsoft Teams or Slack, connects to the systems you already run, and every action it can take is switched on by you.

Single tenant
Teams, Slack, WhatsApp
Off until you enable them
The Situation

Legal said no to general AI. The work is still waiting.

Most mid-market companies are in the same place. Staff already use consumer AI on their own accounts. IT runs on Microsoft or Google. Legal has blocked anything that sends company data to a vendor it has not reviewed. There is a list of use cases, and none of them are running.

CONSTRAINT 1
The data cannot leave.
Client records, financials and contracts stay inside your environment. A tool that copies them to someone else's server is a non-starter, however good it is.
CONSTRAINT 2
Access control is not action control.
Your identity platform decides what an agent can see. Nothing in it decides what the agent is allowed to do once it can see it.
CONSTRAINT 3
Rented tools keep what they learn.
Every prompt, document and correction you feed a subscription builds an asset for the vendor. When the price changes or the vendor changes, you start again.
What Workmate Is

Agents with one job each, on a runtime you control.

A Workmate deployment is four things, and you own all four. The base deployment covers up to four agents and four connectors on one channel. More is scoped in the Blueprint.

Agents
One job each.
Inbox triage, document routing, weekly reporting, follow-up drafting, a morning briefing. Each agent has one job, one owner on your side, and a defined set of tools it can reach.
Connectors
Into the systems you already run.
Microsoft 365 or Google Workspace, your CRM, accounting, storage and forms. Built per deployment, read-only first, write access only where you enable it.
Channel
Where your team already works.
Microsoft Teams or Slack for office teams. WhatsApp for field teams. Access is locked to the people you name. Messages from anyone else are ignored.
Controls
Capability, approval, record.
What each agent may do, who approves it, and a record of what it did. These are part of the runtime, not a dashboard bolted on afterwards.
Built Into The Runtime

See. Record. Refuse.

An overlay can log an action. Only the runtime can refuse it. Three controls come with every deployment, switched on from day one.

CAPABILITY
Off until you enable it.
Every outbound action is disabled at the code level. Sending an email, posting to a channel, changing a record: each one is a specific capability you turn on, for a specific agent.
APPROVAL
The agent drafts. A person approves.
Anything that leaves your environment routes to the owner you name, in the channel they already use. Nothing goes out until they say so.
RECORD
Every action, written down.
Who asked, what was read, what was done. It lands in a log and in the morning briefing, so the record is something people actually see.

Single tenant is the deployment model, not an upgrade tier. Your deployment runs on hardware you own or a server provisioned only for you. Model calls go to hosted providers under your own accounts, on terms that bar them from training on your data. No other client's data touches any part of it.

Stated Plainly

What is running today. What is not.

Enterprise buyers ask the same questions in every security review. Here are the answers before you ask.

RUNNING TODAY
In production, single tenant.
Deployments on client-owned hardware and dedicated servers. Teams, Slack and WhatsApp channels. Capability gating and approval routing in the runtime. Morning briefings and per-agent memory. A documented threat model. A 72-hour breach notice in the agreement.
NOT YET BUILT
We will not sell you these.
SOC 2 certification. A third-party penetration test. Local, open-weight inference inside your network. A central console across many deployments. Platform-level spend caps. If your procurement requires one of these today, we will say so on the first call.
DISCLOSED
Who can reach your deployment.
ShooflyAI engineers hold administrative access to your deployment for support and iteration. That access is named in the agreement, key-only, and revocable by you. It is written down, not hidden.
The Process

Blueprint. Pilot. Scale.

01
Step 1
Operating Blueprint.
A paid, company-wide assessment. We map the business function, the systems it touches, the controls your legal and IT teams need, and the order to build in. You get a written plan and a go-live date we will stand behind. $6,000, credited in full if you proceed.
02
Step 2
Pilot.
One function, one or two agents, deployed in your environment with the controls on from day one. Your owners approve the first actions. We tune against the KPIs named in the Blueprint.
03
Step 3
Scale.
Add agents and connectors across departments on a flat monthly. ShooflyAI manages the deployment, iterates it, and reports against the numbers you already track.

We do not promise a go-live date before the Blueprint. We put one in writing after it.

Commercials

Priced per organization. Owned by you.

One deployment fee for the build, then a flat monthly for operations. Scoped to your organization after the Blueprint. Not per seat, not per token.

Honest About Fit

Workmate is not for everyone.

A private deployment only works when someone inside owns it. If any of these apply, we are not the right fit yet.

If nobody inside will own it.

Every agent needs an owner who approves its first actions and reviews the record. Without that person, the controls have nobody to route to.

If procurement requires SOC 2 today.

We do not hold it yet and we will not pretend otherwise. If a certification is a hard gate for you this quarter, we are not the right fit yet.

If you want a chatbot.

Workmate does work inside your systems. If what you need is question and answer over a set of documents, that is a smaller build, and we will tell you so.

FAQ

Questions from every security review.

What is a Workmate deployment?

A private, single-tenant deployment of AI agents for one organization. It runs on hardware you own or a server provisioned only for you, works in Microsoft Teams or Slack, connects to the systems you already run, and every outbound action is switched off until you enable it.

Where does it run and where does the data go?

On your hardware or a server provisioned only for your deployment. Model calls go to hosted providers under your own accounts, on terms that bar them from training on your data. No other client shares any part of your deployment.

What can an agent do without asking?

Read and summarize what you have connected it to. Anything that changes a record, sends a message, or publishes is off at the code level until you enable that specific capability, and most clients keep an approval step in front of it.

Which channels and systems does it connect to?

Microsoft Teams and Slack are the primary channels, with WhatsApp for field teams. Connectors are built per deployment for the systems you run: Microsoft 365 or Google Workspace, your CRM, accounting, storage and forms. The base deployment covers up to four agents and four connectors. More is scoped in the Blueprint.

Do we own it?

Yes. The code, the data and the configuration are yours outright, on infrastructure you control. If you stop working with ShooflyAI, the deployment keeps running. Monthly operations are a service you can cancel, not a license that switches the system off.

Are you SOC 2 certified? Are you HIPAA compliant?

Not yet on SOC 2, and we have not commissioned a third-party penetration test. What exists today: a documented threat model, single-tenant isolation, capability gating and approval routing in the runtime, and a 72-hour breach notice in our agreement. If your procurement requires SOC 2 today, we will tell you so on the first call. Health data engagements are scoped case by case under a BAA.

What does it cost?

A deployment fee for the build, then a flat monthly for operations, support and iteration. Priced per organization after the Operating Blueprint, not per seat and not per token. The Blueprint is $6,000 and is credited in full if you proceed.

Get Started

Start with the Blueprint.

One company-wide assessment that maps the function, the systems, the controls and the order to build in. Credited in full if you proceed. Bring your IT and legal leads to the first call.

or email jonathan@shooflyai.com