AgentRoom
Blueprint V0.1 · in design
PepeR · personal agent

Not another chatbot.
It's your agent.

A single layer of intelligence and action across your whole digital life. You speak to it, it knows you, it connects to your services and works for you — within the permissions you define and leaving a record of everything it does.

  • Voicethe main interface
  • Any modelnot tied to just one
  • Bankread-only
Listening
you · 07:42

What do I have tomorrow? And check how much is left on my card.

pepe · 07:42

Tomorrow you have 3 meetings; the 10:00 one with Juan clashes with your focus block. Your card has 62% of its limit available. Shall I move the meeting with Juan to 15:00?

What happened behind it
  • Model Routersimple task → cheap model
  • Permission Enginecalendar.read ✓ · bank.read ✓
  • API ConnectorGoogle Calendar over OAuth
  • Credential Vaultbank session without exposing the password
  • Browser Agentbalance → structured result
  • Confirmationcalendar.move needs your “yes”
The problem

Today you are the integrator between ten applications.

Each service has its own interface, credentials, permissions and context. The agent sits on top of all of them and lets you ask for things the way you would say them out loud.

  • Gmail
  • WhatsApp
  • Calendar
  • Tasks
  • Drive
  • Bank
  • Card
  • Stores
  • Search
  • Sites with no API
  • “What important email came in last night?”
  • “Move the meeting with Juan.”
  • “Find the price of the shampoo and remind me to buy it tomorrow.”
  • “Check my messages and tell me if anything is urgent.”
How it works

One brain, many hands and a guard that does not negotiate.

The model interprets what you want. Everything else — permissions, secrets, execution and record — lives outside it.

Listening
  • Voice Layercaptures, transcribes and answers by voice
Reasoning
  • Agent Coreintent, context and coordination
  • Model Routerwhich model to use for each task
  • Memorywhat it knows about you
  • Permission Enginewhat is allowed and what is not
Execution
  • API Connectorwhen the service has an official API
  • Browser Agentisolated, when it does not
  • Schedulerworks without you asking
  • Audit Loga record of every action
Credential Vaultthe only place the keys live
The fundamental rule

The model ≠ your keys

It can say “I need to check the balance”. It can never ask for the password.

It receives a result, not a secret. That sentence is the entire security architecture in short, and it is what makes delegating defensible.

A bank query, step by step
  1. 01You ask how much you have in the bank
  2. 02The Permission Engine validates connector, action and policy
  3. 03The tool requests the session from the Credential Vault
  4. 04An isolated browser enters the bank site
  5. 05It returns a structured result, not a screen
  6. 06The model receives the figure. The key never entered its context
Permissions

You decide what it does alone, what it asks you about, and what it cannot touch.

Set once, for each connected service. After that you just talk.

Does it aloneAsks you firstCannot, full stop
Gmailread · search · summarizesend · reply—
Calendarreadcreate · move · cancel—
Bankbalance · transactions · credit used · billing—transfer · pay · invest · change payees

In the first version the bank is read-only. It moves no money, and that cell is empty on purpose.

Autonomy

You decide how much it does on its own.

Four levels, from less to more delegation. Every autonomous action goes through the same policies and is recorded.

  1. 1When you askacts only if you speak to it
  2. 2Scheduledruns tasks at a set time
  3. 3Proactivedetects and alerts you
  4. 4Autonomousexecutes what is authorized without asking each time
The other side of the counter

PepeR asks. AgentiR is who answers.

They are the two ends of the same conversation, which is why they live in the same house. When a person's agent looks for someone who can solve something, on the other side there has to be a company that understands the question, answers with real data and leaves a record.

For the personPepeR

Their agent. It asks, compares and resolves for them, with their permissions.

For the companyAgentiR

The infrastructure that makes it legible and operable when that agent arrives.

In PepeR, the model never sees the password. In AgentiR, payment data never enters the room. It is the same principle on both sides — whoever reasons does not touch the credentials — and it is no coincidence.

What this does not mean

  • AgentiR has no consumer app. We do not talk to the person who buys, nor compete with the assistant they already use. Our client is the company.
  • PepeR is not a requirement for anything. A company on AgentiR serves any properly identified agent, wherever it comes from. The front desk names by order of arrival and first place is not for sale.
  • They are not sold together. They are two products, with two customers and two pricing models.

Where it stands

PepeR is in design: the blueprint and the product definition exist, the service does not. It is not launched, which is why there is no price here. The model will be membership plus capacity — no artificial message caps, and a spending limit you set — and when it can be used it will have its own page.

Tell me when it is readyWrite to us and you are on the list.