Skip to content

Radiant the gateway for your agents

One source of truth for every agent .

Radiant reads your systems without touching them, turns them into governed, versioned context, and serves it to people and agents through a CLI, an MCP and a gateway that checks permissions on every request.

Book a demo Join the pilot For CTOs, platform and IT teams.
Your systems 01 · connect
GitHub read
Git read
Cloudflare read
AWS read
Jira testing
Confluence testing
Radiant 02 · govern
Governed context policy r42
  • Read-only connectors min scopes
  • Pinned to approved commits a3f9c21
  • Permissions on every request identity
  • Every delivery logged audit
  • Changes by pull request approved
People and agents 03 · serve
CLI radiant sync

Context on disk, verified, for people and scripts.

MCP radiant mcp

Your agents ask. The token never reaches them.

Terminus Claude Code Codex
Console admins

Who has access, what they got, what needs attention.

The problem

Every agent reads its own copy of the company. A stale wiki. A branch that moved. A token pasted into a prompt.

Then someone asks what the agent saw, who allowed it, and which version was true. Nobody knows.

See what every
agent gets.

One console for admins. The same answers, line by line, in the terminal.

Preview · illustrative data
Acme/Dashboard All workspaces ▾

Dashboard

Who has access, what is being used and what needs your attention.

People with access
12
1 invitation pending
Workspaces
3
All pinned to approved commits
MCP calls · 7 days
1,284
9 denied by policy
Policy by PR
r42
Approved in PR #117

Deliveries per day

Context and files served through the gateway, last 14 days.

Sep 20Sep 27Oct 3

Needs attention

Sorted by severity.

High The GitHub App can't read pull requests: pull_requests:read is missing. Review connection
Medium 2 governance proposals are waiting for review. See proposals
Low Luis Ortega hasn't accepted his invitation. See user

Engineering

Exactly what a person or agent receives in this workspace. Changes are proposed as a PR to the governance repo and published once approved.

View activity ↗Propose change

Context

Files pinned to an approved commit. Never a branch that moves.

platform-apiAGENTS.md · docs/
a3f9c21
infraREADME.md · runbooks/
e41b7a0
handbookpolicies/ · onboarding.md
90c3d12

Enforcement

What this workspace locks for every client.

ModeManaged
Locked skillsmodels
NetworkTailnet required

Skills

From the approved catalog.

code-reviewb72e1f0
release-notesb72e1f0
incident-runbookb72e1f0

MCP servers

Granted by role.

Radiant gateway3 tools · read
public
docs-searchdeclared · read
tailnet

Models

Allowed providers and accounts.

Anthropic · ClaudeOrganization account
default
OpenAI · CodexPersonal account
allowed

Users

Members, roles and invitations. Being in the company domain grants no workspace: roles are assigned explicitly.

RolesInvite
Person Role Workspaces AI usage · 30 d Last access
ARAna Ruiz Admin 3 reporting 12 min ago
DSDiego Salas Editor 2 reporting 2 h ago
MCMara Chen Reader 1 no reports yesterday
SMSofía Méndez Operator 3 reporting 3 d ago
LOLuis Ortega Invitation pending — no activity never

Activity and audit

Who asked for what, through which door, against which policy. File contents and prompts are never stored.

Last 30 days
Time Who Via Action Policy Result
14:02 ana@acme.com CLI sync · engineering r42 delivered
14:01 diego@acme.com MCP github_read_file · platform-api/AGENTS.md r42 delivered
13:58 mara@acme.com MCP github_read_file · infra/secrets.md r42 denied · not granted
13:41 diego@acme.com CLI refresh-plan · handbook r42 plan saved
13:20 ana@acme.com CLI invitation · luis@acme.com · reader — sent
12:55 mara@acme.com MCP github_list_issues · platform-api r41→r42 dropped · policy changed

Console shown as a preview. Data is illustrative.

$ export R=https://radiant.acme.com
$ radiant login --server $R
Open https://auth.acme.com/activate and enter the code QJXP-KWRT
Session saved in the system keychain.
$ radiant workspace use engineering --server $R
Workspace selected.
$ radiant sync --server $R --out context.json
Configuration validated and saved.
$ radiant tools list --server $R
3 tools in engineering:
github_read_file — reads an authorized file at its approved commit
github_list_issues — issues of an authorized repo
github_project_items — items of an authorized Project

The CLI

Everything the console shows, the CLI shows first.

Built for terminals and for agents: --json output, stable exit codes, and a session that lives in the system keychain.

  • radiant login Sign in with your company account.
  • radiant workspace Pick what you work on.
  • radiant sync Get the governed context, verified.
  • radiant mcp Plug any MCP client into the gateway.

Built to be
trusted.

Control doesn't depend on the agent behaving. It lives in the gateway.

Every request, checked twice. This runs in full each time someone asks.
01

Ask

An agent asks through the CLI or MCP. The token stays in the keychain.

02

Identify

Is the session live? What can this person do today?

03

Match policy

Today's permissions, crossed with the approved policy.

04

Fetch

The exact approved commit. Verified, never the whole repo.

05

Check again

If anything changed meanwhile, the answer is dropped.

06

Log, then deliver

Who, what, against which version. Never a credential.

waiting Watch a request go through.
01

Read-only, everywhere.

Each connector declares its minimum scopes up front. Radiant never writes to your systems.

github read
cloudflare read
aws read
02

Pinned, not floating.

Agents get the approved version of each file. When it changes, you know exactly when and why.

platform-api a3f9c21
infra e41b7a0
handbook 90c3d12
03

Agents propose. People approve.

Updates arrive as a pull request with evidence. Nothing becomes official until a person signs off.

radiant refresh-plan evidence
pull request #118 review
policy r43 published

Part of Danil.
Start anywhere.

Radiant works with the agents you already use. It gets better with the rest of Danil.

Questions.

Does Radiant write to our systems?

No. Connectors are read-only and declare their scopes. Changes to what agents receive go through a pull request that a person approves.

Which systems connect today?

GitHub, Git, Cloudflare and AWS. Jira and Confluence are in testing. Tools like Figma stay where they are: each person keeps using their own account.

Which agents can use it?

Anything that speaks MCP or can run a command. We use it with Terminus, Claude Code and Codex through radiant mcp.

Do agents see our credentials?

No. The session lives in the system keychain and the CLI presents it for the agent. The agent never holds a token.

What does Radiant log?

Who asked for what, through which door, and against which policy version. Never file contents or prompts.

Cloud or on-premise?

Today's pilots run on infrastructure we operate. Whether Radiant ships as cloud, on-premise or both is still being decided with our pilot customers.

Give your agents
one truth.

We are onboarding a small group of pilot teams. See it on your own systems.

Radiant pilot

Join the pilot

How many people use AI agents? (optional)

Which agents do you use? (optional)

Which systems do you want to connect? (optional)

Where would you run it? (optional)

By submitting you agree to our privacy notice.

Book a demo

Tell us a bit about your team and we’ll find a time to show you Danil.

What are you interested in?

Company size (optional)

By submitting you agree to our privacy notice.

Join the waitlist

In-house AI model: your models, your compute. We’ll let you know when it opens.

What are you looking for? (optional)

By submitting you agree to our privacy notice.