Kogei
AGENT ORCHESTRATOR · RUNS ON HARDWARE YOU OWN

Put agents to work on data you can’t send away.

Kogei is an agent orchestrator that runs on hardware you own. Deterministic steps produce every number. Agents interpret them — never the other way around.

computed
inferred
01 · WHAT IT DOES

The work it does today: scheduled reports and checks.

On a schedule, it reads from your systems, computes the result, has a local model interpret it, and delivers the report inside your network.

  1. Trigger
  2. Collect
  3. Compute
  4. Interpret
  5. Deliver
  6. Seal

v1 is read-only. No write actions, no desktop RPA.

02 · THE LINE

Everyone builds agents. Kogei makes you say which part you trust one with.

Deterministic step

Computes. Can produce numbers. Golden-tested. Same input, same output.

table → table

Agent

Decides its own steps, uses tools. Cannot produce numbers. Budgeted. Traced.

budget: 12 steps · 90 s

A third type sits between them: a workflow call — a published, signed pipeline. An agent can hold one in its toolbox and decide when to run it; the pipeline still runs deterministically. Your security team approves the list once; agents compose freely after that.

03 · THE GROUNDING GATE

Every number in the report is checked against the arithmetic.

This is the one mechanism that keeps “no number comes from the model” true when anyone can compose anything.

1 · what the pipeline computed
Invoices matched1,284,097
Discrepancies11
Value at risk₺ 48,900
2 · what the agent wrote

“Eleven discrepancies remain, mostly in the Ankara ledger, worth about ₺52,000 — all raised after the cut-off.”

3 · what the gate did

pass 11 is in the deterministic output.

return ₺52,000 is not. The sentence goes back.

If it comes back wrong again, the report ships without that comment.

04 · ESCALATION

Deterministic by default. An agent only when the pipeline gets stuck.

Running an agent loop on every job is slow, expensive and unnecessary. Good operations teams do not work that way, and neither does Kogei.

reconciliation runs → finds a discrepancy → cannot classify it → escalates to a research agent → agent reads ledgers, notes, external sources → returns a finding → the deterministic pipeline finishes the report

The dashed branch is not the normal path. It is labelled on exception on the canvas, and it is the only way an agent enters a run.

05 · WHERE IT RUNS

It runs on a box you own.

Single node, arm64.

The model runs in the same box as the engine. No inference leaves the appliance.

One command to install.

Signed, offline updates. Backup and restore included.

Read-only into your systems.

PostgreSQL, MySQL, SFTP, HTTP, and a generic ODBC escape hatch.

one marked opening — every outbound step

Your data stays in your network unless you connect an agent to the internet. When you do, that agent is marked, and every request it makes — target, full text, timestamp — is written to the audit log. One switch turns outbound access off for the whole box.

06 · ON THE RECORD

On the record.

Every run freezes its plan.

Configuration you change tomorrow does not rewrite what happened today. The plan a run executed is stored with the run.

Hash-chained audit log.

Every read, every model call, every outbound request — target, full text, timestamp — appended and chained. Tampering breaks the chain.

Signed templates, visible forks.

Install, upgrade, roll back. The moment you edit a template’s graph the agent is forked, and it carries that mark wherever it appears.

The raw evidence is already being recorded.

The report as delivered, the run’s trace, the frozen configuration it ran under, and source evidence — query text, timestamp, row count, hash, data profile. Packaging it into a signed auditor bundle is not built yet.

07 · LIMITS

What Kogei doesn’t do.

Not yet, and in some cases not ever — and the list now says which is which. You will find both halves in the contract too.

Not built yet.

On the roadmap, and absent today. We are not attaching a date to any of it: a line on a roadmap is not a working feature, and this page only claims what already runs.

  • Chat on top of a report
  • Email, Teams or Slack delivery
  • LDAP and SSO
  • Multi-node, high availability
  • Cell-level lineage

Ruled out by design.

These are not late; they are declined. Kogei reads, computes and reports — it does not write back to the systems it reads from, and that one restraint is what the audit log, the egress record and every claim on the security page rest on. Desktop RPA would move the boundary onto a screen where no log can see it. Multi-tenancy would put your evidence on a box you don’t own alone.

  • Write actions of any kind
  • Desktop RPA
  • Multi-tenancy

A local model’s agentic loop is measurably more fragile than a frontier model’s — tool selection, format adherence, knowing when to stop. That is why every agent step is budgeted and traced, not something we discovered afterwards.

Made to be checked.

Request a demo

Thirty minutes. We run a real report end to end on our box, and you follow one number from the report back to the row it came from — through the frozen plan, the audit log and the seal.

No slides.