The agentic workbench

One workbench builds your agents, runs them on your work, and deploys them anywhere.

Create agents and workflows, put them to work on your own documents, and deploy the same method wherever the work lives — your machine, the cloud, an enterprise's environment, or your own website. Across every deployment, the method and the data stay protected on both sides.

How it works

GaugeDesk runs one loop: you build a method, put it to work on real documents, and deploy it without rebuilding it.

Build agents and workflows

Define an agent — its instructions, skills, and tools — and compose agents into workflows with WhippleScript. Everything lives in your own library, versioned like software and refined in an edit chat until it does the job.

Work on your documents

Place an agent on a project and give it a task. Each run works in an isolated sandbox and hands you a diff to keep or discard, and the agent remembers context across a chat, so you never re-prime it.

Deploy it anywhere

Take the same method off your desk without rebuilding it — to the cloud, into a client's environment, or onto your own website. Governance is added as you go, never re-architected.

Deploy anywhere

A method that works on your desk should work everywhere else without a rewrite. GaugeDesk runs the same agent across four surfaces; you add reach and governance only as you need them.

On your machine

Your desk is the default. Available

The desktop workbench keeps orchestration and storage on your own machine. Nothing is hosted by us to get started, and every other surface is opt-in.

In the cloud

Reach clients who can't install anything. In development

A hosted relay and compute run your agents for people who never touch a desktop build — isolated per tenant and metered by engagement.

Inside an enterprise

Deliver within a client's boundary. Available

Federate into an organization's environment under its own identity and audit — OIDC and SAML sign-in, append-only logs, SIEM export. The method runs there without your source leaving your custody.

On your own site

Embed an agent as a panel on a web page. In development

Drop a GaugeDesk agent into your own site for end-users. Each session is isolated, restricted to origins you allow, and capped by a budget you set.

The federated network

Deploying across parties means two machines that don't trust each other have to cooperate. GaugeDesk connects them through a relay that carries the work without ever reading it — so the expert and the client both stay in place and neither hands the other a copy.

Each side keeps custody

The expert's library stays on the expert's machine; the client's data stays on the client's. To collaborate, neither is copied to the other — they are joined by handle across the network.

The relay is blind

Between the two, a relay routes opaque, encrypted bytes. It moves the traffic and cannot read the payload — a property the system machine-checks, not one it merely promises.

Every crossing is on the record

A cross-party action needs both a source willing to release and a target willing to admit. Each crossing is signed and logged, so the network is auditable end to end.

This is what lets the network grow past two parties: any authority can join, expose a bounded view of its work, and let another's method act on it under rules both sides can audit. Read how the boundary is enforced in the architecture & security reference.

Two sides, one boundary

An expert has a method worth paying for; a client has data too private to hand over. Rather than one side shipping to the other and hoping, GaugeDesk runs the method against the data inside a boundary neither can cross. The two have opposite fears, and the same boundary answers both.

For experts

Your method never leaks

Package your agent and deploy it onto a client's work. It runs read-only at their side — your instructions, skills, and prompts are never exported or revealed. Build once, deploy repeatedly, keep your edge.

For clients

Your data never leaks

Let an outside expert's agent work your private context without it escaping. Data is admitted by handle, never read or exported without an explicit rule, and fail-closed by default. Every access is on the record.

Why GaugeDesk

One substrate carries a personal project all the way to a governed, cross-party deployment — governance is added, never re-architected.

Agentic workbench

Point an agent at your files, give it a task, review the diff. It remembers context across turns within a chat — no re-priming.

A versioned library

Agents and workflows are stored, versioned, and reused like software — deploy one repeatedly on new work without shipping your source or touching theirs.

🛡

Strict protection

Method and data are protected resources. Nothing is read, exported, or revealed without explicit admission. Fail-closed by default.

Your own model

Agent reasoning uses the LLM provider you configure, under your own credentials — so the model relationship stays your subprocessor, not ours.

Audit & rollback

Every run is a commit plus an admitted event. Full history, reversible changes, integrity you can verify.

Progressive governance

The same architecture spans solo work, team collaboration, and governed deployments across machines and parties.

Confidentiality is the whole product, so we show our work.

Read how the boundary is enforced — the invariants, the audit trail, and the threat model, each grounded in the source and machine-checked.

Security & architecture

Start on your own machine.

Free desktop builds for macOS, Windows, and Linux.

Download GaugeDesk