Skip to main content

Retool launches the first centralized agent harness

Today, we’re announcing early access to a new centralized agent harness which gives every employee an agent to work with in Slack, Teams, and Google Chat, while maintaining company-wide control over the tools, data, and models those agents can use.

Local agents are extremely powerful. Today, all engineers at Retool use Codex, Claude Code, and Cursor to write code, run tests, install programs, and use the terminal. Because these agents are run locally, they can do this against a real dev environment and automate many coding tasks. And since it lives in a development sandbox, it’s safe: it can test code to check if it broke anything and revert the changes to try again if it needs to.

The rest of the company doesn’t have that sandbox. Give an agent access to live business systems, and its mistakes have real consequences. Agents can revert bad code, but they can’t revert an email sent to the wrong customer.

Using agents across a company means controlling what they can do before they do it.

As more people put agents to work, local-first agent harnesses show their strain. One agent on one computer works fine, even great. But what happens when you have to manage a thousand agents running on a thousand computers?

Enterprises need better tools and controls to guide, set limits, and control than what local agent harness platforms can offer.

We think business agents should be managed on central company infrastructure.

The enterprise agent harness

The core idea is straightforward: put a shared policy and execution layer between agents and company systems. Tool calls pass through a single gateway you control, so permissions and policies can be applied consistently and activity can be traced back to the agent that performed it.

Retool already handles much of the unglamorous work this requires: connecting to the systems companies run on, mapping who’s allowed to touch what, and keeping a record of what happened. We’ve built our agent harness on that foundation and expanded the system.

Manage every agent on shared company infrastructure

The harness runs centrally and can be deployed on-prem to your own VPC, giving you full control over the environment and its data ingress and egress.

Give every person their own agent (or multiple), each with its own virtualized filesystem, memory, and accumulated context. Preconfigure every agent with skills and scheduled jobs, and customize the onboarding flow to fit your business. From there, your users can delegate access to tools and data within the limits you set centrally.

Configure which frontier models or open source models different users can use. Dynamically route models based on the quality they need and the cost that makes sense for their work. The agent infrastructure should always give you the best and cheapest option available on the market.

Turn what works into a shared company capability

Every file, skill, and piece of code is stored in centrally hosted permissioned folders that map to your existing identity groups. This means that whenever someone works out a good way to do something, you can promote it once and make it available to the right team. Each team can build on that work instead of starting from scratch.

Delegate local authority over the agent’s skills and abilities to the early adopters of AI that are close to the teams and departments. Allow them to evangelize best practices and surface efficiency and productivity metrics to them.

Control what agents can do

Tool calls pass through a gateway you control. Policies can inspect the arguments passed to a tool, so permission to use a tool doesn’t have to mean permission to use it in any way the agent chooses.

These limits are enforced outside the model. If an agent misunderstands a request or encounters a malicious instruction, its tool calls still have to pass the policy checks. You don’t have to rely on the agent remembering a rule in its prompt.

We’ve made deliberate choices about access: no employee laptop access, no browser automation, and no desktop control. Agents run in a centrally hosted sandbox and reach business systems through governed tools. The sandbox contains their local work; the tool policies govern the actions they take outside it.

Get visibility into actions and costs

Agents are modeled as their own actor and given a virtual service account with its own set of policies that exist separately from the user model.

They are also separate actors in the audit log—you can distinguish what someone did directly from what their agent did with delegated access. As more work gets handed to agents, you need to know who acted, not just whose account was involved.

Actions, inputs, and outputs are logged by person, model, and job. You can trace token spend to the work it funded, investigate an expensive run, and decide whether the result was worth the cost.

Let everyone work with agents where work happens

People can work with their agents directly in Slack, Google Chat, and Teams. They can ask for work in the tools they already use, without moving to a separate desktop app.

Agents can also run on a schedule. Describe a recurring task in a sentence and turn it into an automation, without filing a ticket. A useful one-off task can become something that runs every week.

Join the waitlist

We’ve been running this internally at Retool for the last 4 months. Every new hire who joins uses this by default and we can’t imagine working at Retool without it.

On top of our own usage, we’re happy that the product has been used by scrappy startups all the way to some of the largest companies in the F500. We’re now beginning to roll out access to the next hundred customers over the next few weeks.

If you’re interested in learning more, join the waitlist here!

Author

Published

Category

Product