One capability
An assistant that has to be let in, like anybody else.
Most assistants read your messages on somebody else's server. An InTouch agent holds keys of its own and joins the room as a member, so the company running the service still cannot read a word of it.

A seat at the table
The usual way to give an assistant access to a conversation is to hand it the plaintext on a server. That is how the assistants built into the big work chat tools do it, and it is why the platform can read everything they read. InTouch does the other thing. The agent is given keys and a place in the group, and it decrypts its own copy on its own machine. The server carries the same sealed traffic it always carried.
Who is in the room
The membership of one Space, set up for a mortgage application. Five members, and one of them is software.
- The borrower
- HoldsOwn keys · verified
- MaySend · upload · sign
- The broker
- HoldsOwn keys · verified
- MaySend · upload
- The solicitor
- HoldsOwn keys · verified
- MaySend · upload · sign
- A compliance officer
- HoldsOwn keys · verified
- MaySend · approve
- A drafting agentAgent
- HoldsOwn keys · verified
- MaySend · draft · ask for approval
Every row holds the same kind of keys, and every row is visible to everyone else in the room. The last one is labelled, because a participant nobody can see is not one anybody agreed to.
Checking it is the same job
An agent holds an Ed25519 key and an CRYSTALS-Dilithium key, the same pair a person holds, and it has its own entry in the transparency log. Read its safety number and compare it with the one your app shows, exactly as you would with a colleague. An agent cannot be added to a Space quietly: membership changes are signed, and the whole room sees them.


It can recommend. A person signs.
An agent can draft a contract, complete a structured message, chase a missing document or produce an approval card. Putting a signature on that card is a human action. The work stops there and waits, and the agent has no way round it, because the permission to sign was never granted to it.
What it can read
An agent reads what the room reads. That is the point of putting it in the room, and it is worth being plain about: this is not a way of getting help from an assistant that sees nothing. What changes is who else sees it. Nobody else does, including us, and that is a property of the keys rather than a line in a policy.
- Only the rooms you put it in
- An agent belongs to one organisation and to the Spaces it has been added to. There is no view across Spaces and no global access underneath. Add it to a room and it reads that room. Add it to nothing and it reads nothing.
- Everything it does is written down
- Every tool an agent calls is recorded inside the Space with the time and the agent that called it. The arguments are redacted, so the record says what was done without repeating what it was done to.
Whose intelligence
InTouch does not supply the model. An agent connects through the Model Context Protocol, the open standard for wiring a model up to tools, so an organisation can run whichever model it has already chosen and change it later without touching the encryption. What we provide is the identity, the membership and the channel.
MCP · Ed25519 request signing · per-agent rate limits · agent accounts only
Taking it out again
Deactivate an agent and it is refused at the door on its next request. Remove it from a Space and the keys move on without it, so everything sent from that moment is unreadable to it. It is the same removal a person gets, and what happens next is arithmetic.
How a Space worksA member can be checked. A service cannot.
Everything on this page falls out of one decision: an agent is a member of the group instead of a service standing outside it. Membership is what makes it visible, checkable and removable.