Radiant the gateway for your agents
One source of truth for every agent .
Radiant reads your systems without touching them, turns them into governed, versioned context, and serves it to people and agents through a CLI, an MCP and a gateway that checks permissions on every request.
- Read-only connectors min scopes
- Pinned to approved commits a3f9c21
- Permissions on every request identity
- Every delivery logged audit
- Changes by pull request approved
radiant sync Context on disk, verified, for people and scripts.
radiant mcp Your agents ask. The token never reaches them.
admins Who has access, what they got, what needs attention.
The problem
Every agent reads its own copy of the company. A stale wiki. A branch that moved. A token pasted into a prompt.
Then someone asks what the agent saw, who allowed it, and which version was true. Nobody knows.
See what every
agent gets.
One console for admins. The same answers, line by line, in the terminal.
Dashboard
Who has access, what is being used and what needs your attention.
Deliveries per day
Context and files served through the gateway, last 14 days.
Needs attention
Sorted by severity.
pull_requests:read is missing. Review connection Engineering
Exactly what a person or agent receives in this workspace. Changes are proposed as a PR to the governance repo and published once approved.
Context
Files pinned to an approved commit. Never a branch that moves.
Enforcement
What this workspace locks for every client.
Skills
From the approved catalog.
MCP servers
Granted by role.
Models
Allowed providers and accounts.
Users
Members, roles and invitations. Being in the company domain grants no workspace: roles are assigned explicitly.
| Person | Role | Workspaces | AI usage · 30 d | Last access |
|---|---|---|---|---|
| ARAna Ruiz | Admin | 3 | reporting | 12 min ago |
| DSDiego Salas | Editor | 2 | reporting | 2 h ago |
| MCMara Chen | Reader | 1 | no reports | yesterday |
| SMSofía Méndez | Operator | 3 | reporting | 3 d ago |
| LOLuis Ortega | Invitation pending | — | no activity | never |
Activity and audit
Who asked for what, through which door, against which policy. File contents and prompts are never stored.
| Time | Who | Via | Action | Policy | Result |
|---|---|---|---|---|---|
| 14:02 | ana@acme.com | CLI | sync · engineering | r42 | delivered |
| 14:01 | diego@acme.com | MCP | github_read_file · platform-api/AGENTS.md | r42 | delivered |
| 13:58 | mara@acme.com | MCP | github_read_file · infra/secrets.md | r42 | denied · not granted |
| 13:41 | diego@acme.com | CLI | refresh-plan · handbook | r42 | plan saved |
| 13:20 | ana@acme.com | CLI | invitation · luis@acme.com · reader | — | sent |
| 12:55 | mara@acme.com | MCP | github_list_issues · platform-api | r41→r42 | dropped · policy changed |
Console shown as a preview. Data is illustrative.
$ export R=https://radiant.acme.com$ radiant login --server $ROpen https://auth.acme.com/activate and enter the code QJXP-KWRTSession saved in the system keychain.$ radiant workspace use engineering --server $RWorkspace selected.$ radiant sync --server $R --out context.jsonConfiguration validated and saved.$ radiant tools list --server $R3 tools in engineering:github_read_file — reads an authorized file at its approved commitgithub_list_issues — issues of an authorized repogithub_project_items — items of an authorized Project
The CLI
Everything the console shows, the CLI shows first.
Built for terminals and for agents: --json output, stable exit codes, and a session that lives in the system keychain.
-
radiant loginSign in with your company account. -
radiant workspacePick what you work on. -
radiant syncGet the governed context, verified. -
radiant mcpPlug any MCP client into the gateway.
Built to be
trusted.
Control doesn't depend on the agent behaving. It lives in the gateway.
Ask
An agent asks through the CLI or MCP. The token stays in the keychain.
Identify
Is the session live? What can this person do today?
Match policy
Today's permissions, crossed with the approved policy.
Fetch
The exact approved commit. Verified, never the whole repo.
Check again
If anything changed meanwhile, the answer is dropped.
Log, then deliver
Who, what, against which version. Never a credential.
Read-only, everywhere.
Each connector declares its minimum scopes up front. Radiant never writes to your systems.
Pinned, not floating.
Agents get the approved version of each file. When it changes, you know exactly when and why.
Agents propose. People approve.
Updates arrive as a pull request with evidence. Nothing becomes official until a person signs off.
Part of Danil.
Start anywhere.
Radiant works with the agents you already use. It gets better with the rest of Danil.
Radiant
Context, skills, tools and permissions for every agent.
CLI · MCP · AuthTerminus
A desktop workbench for any AI agent. It plugs into Radiant through the MCP.
Download Terminus ↗Danil Agents
Agents for your customers, on every channel. Next: the same approved context.
Explore Danil Agents →Questions.
Does Radiant write to our systems?
No. Connectors are read-only and declare their scopes. Changes to what agents receive go through a pull request that a person approves.
Which systems connect today?
GitHub, Git, Cloudflare and AWS. Jira and Confluence are in testing. Tools like Figma stay where they are: each person keeps using their own account.
Which agents can use it?
Anything that speaks MCP or can run a command. We use it with Terminus, Claude Code and Codex through radiant mcp.
Do agents see our credentials?
No. The session lives in the system keychain and the CLI presents it for the agent. The agent never holds a token.
What does Radiant log?
Who asked for what, through which door, and against which policy version. Never file contents or prompts.
Cloud or on-premise?
Today's pilots run on infrastructure we operate. Whether Radiant ships as cloud, on-premise or both is still being decided with our pilot customers.
Give your agents
one truth.
We are onboarding a small group of pilot teams. See it on your own systems.
Radiant pilot