Crescendo Lab

Crescendo Agent Lab · Enterprise AI agent platform

AI agents that act for your people — never beyond them.

Whose identity it acts under, what it costs, who approved it — every step is on the record. Agent Lab is the governed agent workspace from Crescendo Lab.

Book a demo See how it works

Before you sign

The three questions IT asks first

Will the agent overreach?

If someone in the air-conditioner team can read the refrigerator team's reports through an assistant, that is a security incident. One retail chain's IT team put it plainly: they will not maintain a second set of access rules for AI.

Can we cap the token bill?

With usage-based AI, one misconfigured schedule turns into a surprise invoice. Buyers do not want another dashboard. They want a ceiling that actually stops the spend.

Can we trace who did what?

When an assistant changes an order, you need three answers: who asked, who approved, and whose identity it ran under. A platform that cannot answer will not pass an audit.

How it works

Governance built into the platform, not bolted on by consultants

These three mechanisms are in the platform's code. Every workspace has them from day one.

effective = user ∩ assistant ∩ tool User's own permission what they already see in ERP Assistant's capability which tools it was granted Tool's own permission what the credential allows Effective access

Delegated identity:
assistants act as the person asking

For every tool call, the platform computes an intersection: what this person can already do in the downstream system, what this assistant was granted, and what the tool itself allows. It runs only if all three agree. Your existing permissions are the rules.

  • Knowledge retrieval also runs as the asker, so documents they cannot see are never cited
  • A connector can be a shared organization connection or the member's own authorization
  • Permission is checked again right before execution, so removed members stop acting
Model proposes a tool call Three checks tool · rules · screening Waits for a person awaitingApproval Slack · #procurement Wants to call erp.inventory.lookup Runs with Sam Lin's permissions Approve Deny Runs and is recorded who asked · who approved · as whom The same card works in the console Read-only tools an owner marks as automatic can skip the wait

Approval where work happens:
tool calls pause for a person

By default every tool call the model proposes waits for someone to approve it — in the console or on a Slack card, one state machine behind both. After approval the platform checks permission again before running, and a call that already ran is never run twice.

  • Business rules can require approval for certain tools, or forbid certain actions outright
  • When content screening escalates a turn, every tool call in it needs approval
  • Read-only tools an owner marks automatic can run unattended, and one switch turns that off
Workspace monthly budget 62% 70% 90% Under 70% the model the member chose Claude Opus by default 70% to 90% steps down to a cheaper model and says so on the reply Past the ceiling refused with a reason never borrows next month Ledger · one row per model call 10:42 procurement · sam.lin · claude-opus · 3,120 tok · chat 10:43 procurement · sam.lin · claude-opus · 1,840 tok · tool 11:00 weekly-report · auto · claude-haiku · 22,400 tok · schedule 11:05 kb-index · system · claude-haiku · 8,900 tok · index

Budgets that hold:
ceilings per workspace and per team

Every model call takes one path: check the budget, call the model, write the ledger. Near the ceiling, replies move to a cheaper model and tell the reader. Past it, requests are refused with a reason. A reply where the member named a model is never silently swapped — it is refused instead.

  • Monthly workspace budgets, rolling-window limits, and per-team ceilings
  • Each call records who, which assistant, which model, how many tokens, and why
  • The usage report answers "why was this reply so expensive"

Build assistants

One workspace takes an assistant from draft to live

No code required. Each assistant has its own prompt versions, knowledge, skills, and tool bindings, and passes evaluations before it ships.

Agent Studio

Guided setup, prompt versions you can roll back, and evaluation runs. Only assistants that pass the publish gate reach members.

Knowledge base

Documents are indexed in the background and the most relevant sections are retrieved at answer time — with the asker's permissions, and with sources shown.

Skills library

Write down how a job is done once and attach it to many assistants. Import skill packs from GitHub, with versions and a view of who uses each one.

MCP connectors and tools

Connect your MCP servers or HTTP APIs, including OAuth. Credentials are sealed and each use gets a short-lived grant; you choose whose identity a tool acts as.

Schedules

Weekly reports and daily checks run on a schedule. Each run opens an ordinary conversation, under the same budgets and approvals as everything else.

Business rules

Write in plain language what an assistant must never do, must do first, or must hand to a person. Tool bans are enforced, not just suggested in a prompt.

Channels

One assistant, reached from where your people already work

The console is home. Slack and LINE are where colleagues spend the day. Every entry point shares one identity, budget, and audit trail.

Web console

Conversations, approvals, and settings, in English, Traditional Chinese, Simplified Chinese, Japanese, or Thai.

Slack

@mention the assistant in a channel and it answers; approval cards appear right in the thread. Admins decide which assistant serves which channel.

LINE group requests

What a manager asks for in a LINE group becomes a task on a shared board, with a daily digest and CSV export.

External AI clients

Agent Lab is also an MCP server. After OAuth consent, clients like Claude call the tools your workspace exposes as the member who connected them — never with more access than that member has.

Agent API

Each assistant has its own API key, so your systems can bring it into existing workflows under the same budgets and audit trail.

Microsoft Teams

@mention the assistant in a Teams channel and it answers, with approval cards right in the conversation. As with Slack, admins decide which assistant serves which channel.

Platform

What a workspace gets beyond assistants

Inside the same tenant boundary, a few building blocks companies actually use.

Site hosting

Upload a folder and get an address. Static sites publish directly; projects with a Dockerfile build and run in an isolated cluster. See Deploy

Dedicated Cloud SQL

A workspace can have its own PostgreSQL instance. The platform provisions it and manages its users; your code connects directly.

Usage and ledger

Every model call is one row, viewable by assistant, member, or source, so the monthly bill reconciles.

Audit export

Tool approvals, membership changes, and credential use are recorded, and owners can export the whole trail for audit or security review.

Many models, one gateway

Claude by default, with OpenAI-compatible models available. Whichever you choose, every call passes the same budget and metering gateway.

Workspace memory

Facts worth keeping are extracted after a conversation and read before documents next time, labeled separately in the reply. Curate or delete them in the console.

Our first customer is us

Franky runs on this platform

Franky is the AI coworker Crescendo Lab's staff @mention in Slack, and every answer cites a source. The identity, permissions, budgets, approvals, and audit behind it are Agent Lab — now a multi-tenant platform any company can open a workspace on.

Crescendo Lab · Franky internal adoption, last 30 days
Meet Franky

Security and deployment

What IT checks before go-live is already built in

Where data lives, who can sign in, and how to trace an incident are part of the platform, not settings added during rollout.

Data and isolation

  • Runs on Google Cloud in Taiwan (asia-east1), with a tenant boundary per workspace
  • A workspace can have its own dedicated Cloud SQL database
  • Connector credentials sealed with AES-256-GCM, with short-lived grants per use
  • On-premises systems connect through a relay, so data does not have to move to the cloud first

Identity and audit

  • Enterprise SSO with SAML and OIDC, with directory groups mapped to workspace roles
  • Delegated identity, tool approvals, and token budgets with step-down in every workspace
  • Tool approvals, membership changes, and credential use are recorded, and owners can export them
  • Slack, Microsoft Teams, and LINE share one identity, budget, and audit trail

Book a demo — bring your IT team

  • 45 minutes walking an approval and a budget through your own scenario
  • Straight answers on data residency, permissions, and cost control
  • If it fits, a workspace for your team the same week
Book a demo

Optional — helps us schedule faster

FAQ

Six questions procurement and IT ask most

How is Agent Lab related to Franky?
Franky is the AI coworker Crescendo Lab uses inside Slack, and it runs on Agent Lab. Agent Lab is the platform underneath it: the identity, permission, budget, approval, and audit machinery, packaged so any company can open its own workspace.
Where does our data live?
The platform runs on Google Cloud in Taiwan (asia-east1). Each workspace is its own tenant boundary, and a workspace can have a dedicated Cloud SQL database. Connector credentials are sealed with AES-256-GCM, and each use gets a short-lived grant held only in memory.
Can it connect to our ERP or internal systems?
Yes, through MCP connectors or HTTP tools, and on-premises systems connect through a relay so data does not have to move to the cloud first. The assistant uses the asking employee's own permissions in those systems, so IT never maintains a second set of access rules.
How is cost measured and controlled?
Every model call passes through one gateway that meters it, and the usage report shows each one. Workspaces and teams can have token ceilings; near the ceiling replies move to a cheaper model and say so, past it requests are refused. Plans and pricing are discussed in the demo.
How long does rollout take?
In the demo we walk an approval and a budget through your own scenario. If it fits, your team gets a workspace the same week and can start from Slack, Teams, or LINE.
Do you support enterprise SSO?
Yes. Members sign in with SAML or OIDC, or with an email link or Google account, and directory groups map to workspace roles so access follows your directory.