Permission-bounded tool runs
Only approved tools run. Calls stay inside the scope you set for that AI employee—rejected at runtime when they step outside.
Built-in
AgentX is the engine + common tool pack inside AgentOS X (not a separate product). AI employees use approved tools inside the scope you set; every tool run is attributable to a named AI employee. Each run returns a structured record—who ran which tool and what happened—not a chat transcript. You supply third-party credentials; AIAGENTNET does not bake your CRM or mail keys into the platform.
On the stack
Built into AgentOS X (not a SKU): tools, bounds, receipts.
What this product owns
Focus on this product
Open connections
Ecosystem ports around the stack. Full contracts live on the docs site.
Open docsFocus
Step 01 of 03
AI employees act with named ID inside OS bounds.
Step 02 of 03
Approved connectors fire under permission.
Step 03 of 03
Every run leaves an audit trail toward data.
Replace, for the irreplaceable.
Run approved tools, get a receipt every time
AgentX is the engine + common tool pack inside AgentOS X (not a separate product). AI employees use approved tools inside the scope you set; every tool run is attributable to a named AI employee. Each run returns a structured record—who ran which tool and what happened—not a chat transcript. You supply third-party credentials; AIAGENTNET does not bake your CRM or mail keys into the platform.
Part of AgentOS X—not sold as AIAGENTNET X. Protocol details (identity, connectors, public API) live on the docs site. Credentials stay yours.Capabilities
Only approved tools run. Calls stay inside the scope you set for that AI employee—rejected at runtime when they step outside.
You can see which AI employee ran a tool; your own product credentials stay separate at the third party.
Discover and reuse tool-style connectors. Build to publish; Use to attach credentials and run—open ecosystem, not a closed plugin island.
Every run leaves JSON evidence: agent identity, tool name, outcome. Audit and handoff use the receipt—not a free-form chat log.
How it works
Identity and permission scope are set before tools open.
Pick approved connectors; document which credentials your organization must provide.
The runtime shows which AI employee is calling; connectors can log that for safety.
Pass/fail, tool list and agent id ship back for review and audit.
Who it is for
CRM, mail, docs, internal APIs—without anonymous automation.
Publish connectors that accept named AI callers and grow the open market.
Every run must answer who called, which tool, what happened.
What you get
Trust is part of the product. Audit and permissions, deployment boundary and data handling are built in. Read the trust brief or talk to sales.