Schedule meetings
Topic, time, duration, agenda and the agents who should attend — planned, ad hoc or urgent.
the agency® ControlCenter
The native app for iPhone, iPad and Mac. You see what your office is doing, talk to your agents and release — or stop. Decisions happen server-side; the app never invents success.
ControlCenter is software and is licensed. The Apple devices it runs on are not part of the offer: you source them yourself — or we source them for you and bill them separately at Apple’s published list prices, excluding setup.
Control room
System state, data freshness, active and waiting agents, available offices — plus the safety actions you need when it matters. Every role sees exactly what it is responsible for.
Onboarding
You get a personally delivered, signed link. Open it, sign in with Apple, done. The device identity sits protected in the keychain; a second device pairs via a short-lived code. Live only becomes visible once TLS, user, device and role check out.
Operation
Topic, time, duration, agenda and the agents who should attend — planned, ad hoc or urgent.
You describe goal, context and priority. The team lead turns that into bounded work packages.
You see the specific revision, where it came from and who released it — not just the end product.
On the Mac in separate windows, spread across screens, restored on next launch.
Camera and microphone stay off by default. A short connection drop does not destroy your working view — on a real role or device violation the app closes immediately.
Safety
Operational pause — the working context stays intact.
Safety interruption of a scope. Immediate, visible, logged.
Deliberate continuation — only after the cause has been checked.
Read-only output
That sounds like a limitation and is in fact what makes a result mean anything. Released files reach you as a network drive in Finder — the only process that can write there is the publisher.
If the output folder were writable, any file could be altered after the fact — and the entire release chain before it would be worthless. That is why delivery is one-way: what arrives with you is bit-identical to the revision that security, research & data and the team lead released. Without that one-way street there would be no dependable proof, only a claim.
Corrections are of course possible — as a new task and a new revision. A released state is never silently overwritten.
Traceability
The decisive question in agentic work is not “was it fast?” but “can we reconstruct later how this result came about?”. For that the system ties every step to a business operation and writes it into an append-only, hash-chained audit trail.
Entries are appended, never edited. Hash chaining makes later tampering detectable instead of invisible.
Raw tokens, passwords and private keys have no place in the audit trail — a log that contains credentials is itself a risk.
This is a technically traceable chain of evidence, not a certification and not a legal opinion. What counts as proof in your context is something we clarify per project.
Security architecture
The app shows intent; decisions happen server-side. Every relevant mutation needs a matching server receipt.
Gateway, worker, credential broker, audit writer, publisher and support hold separate identities and only the rights they need.
Row-level security in PostgreSQL, dedicated organisation and office keys, separate data paths. Knowing an ID opens nothing.
Size, type, MIME, magic bytes, archive structure, malware, secrets, macros, links and prompt injection — before any expert work.
A missing role, expired release, uncheckable content or unclear provider path leads to a controlled stop, not a generous fallback.
Support sessions are bound to ticket, purpose, person, device and expiry, read-only by default and fully audited. No general SSH or root credentials.
Connection profiles, agent configurations, presentation packages, files and manifests are signed or hash-bound. Changes create versions.
External providers are permitted only when data class, region, contract and technical processing match. A local inference lane is foreseen for highly sensitive cases.
Device identity and private key sit protected in the Apple keychain. On a real role or device violation the app closes immediately.
An Austrian server location strengthens sovereignty over platform, tenant, audit and file data. It does not follow that every model computation happens in Austria — each provider path is approved and evidenced separately.
Individual design
Our specialist in human-centred interaction design (Master of Arts, Intermedia) shapes the look and feel of your ControlCenter app to your wishes, informed by the latest research in human-computer interaction.
She works with our surface generator: rooms, desks, materials and lighting moods exist as individually exchangeable building blocks. That way the human-centred interaction of your app is composed to your brief — not picked from a catalogue.
The surfaces and your very own click path, so you feel at home from the first moment you work with the members of your personal agent office.
Cleanly separated in technical terms: the presentation package is checked for structure, signature and certification before activation. Design never changes permissions, security boundaries or runtime behaviour.
Team lead
Research & Data
Content
Design
Development
Analytics Two of many possible lines — same desks, different materiality and lighting. Yours emerges in conversation.