OpenKernel uses analytics cookies to see which parts of this page people read. Nothing is shared with advertisers.

Skip to waitlist
OpenKernelJoin waitlist

Connect · Constrain · Audit

Give your agent a seat, not your account.

Connect GitHub, Notion, Linear and Slack once. Hand a seat to each agent — yours, a teammate’s, a contractor’s — with its own rules: this client’s pages but not that one’s, open PRs but never merge. See every call it made. Pull the seat, they’re out.

Works with Claude · Cursor · ChatGPT · any MCP client

Demo as
1Connect

Maya creates a workspace per client and gives her agent a seat. Her prompt: Draft Friday’s status from the shared brief and project channel.

Switch workspaces to see the same connections through a different client's seat.

Workspace
Seats
Connections
2Constrain

Toggle a permission — Inspect shows what the seat now gets, Observe shows the call.

PermissionsNotion
Read shared pages
Update pages
Read context
Context
Acme voice / tone
Doc
Deliverable checklist
MD
Billing / cadence notes
PDF
3Audit

Inspect is what the seat received. Observe is every call it made, allowed or blocked, with the deciding rule.

Inspect
{
  "pages": ["Friday client brief", "Meeting notes"],
  "title": "Friday client brief",
  "pack": ["Acme voice / tone", "Deliverable checklist"],
  "workspace": "Acme Corp"
}
Observestreaming
09:41:02
read notion.pagesFriday client brief · Meeting notes
allowed
09:41:08
read pack: Acme voice / toneresource read allowed · pack travels with seat
allowed
09:41:16
update notion.pagerule: updates not allowed
blocked

Problem

A token isn’t a seat.

Providers hand you one connection, and it’s always yours. An agent needs a slice of it. A contractor’s agent needs a smaller slice, for six weeks. There is no scope menu for either.

Permissions in blocksthe actual scope menus

GitHub 2 scopes

Public repo readMetadata only — not enough for real agent work.
Full control of private repositoriesRead, write, merge, and delete. One block.

Notion 2 scopes

Read contentEvery page the integration can see.
Read and update contentEdit and create across the workspace. No field-level dial.

Slack 1 bot token

Bot with channel history + chat:writeEvery public channel it joins, send as the bot. There is no smaller useful key.

Google 1 scope

gmail.modifyRead, send, and delete, across the whole mailbox. Calendar is the same: read implies delete.

Permissions

The provider gives you a block.

No "open PRs but never merge". No "hide private pages". No "this seat, not that one". GitHub, Notion, Slack, and Google stop at the scope menu they chose. The agent gets the whole block — or nothing useful.

Context

Voice, SOPs, “never mention other clients” — pasted into every thread, dumped in CLAUDE.md, visible to whoever’s in the project. Acme Corp’s brief sits one folder away from Umbrella Corp’s.

Acme voice / tone
pasted into this thread
every chat
Never mention other clients
still in the same project
every client
Globex architecture notes
dropped in CLAUDE.md
every seat
Don’t touch /infra
same dump as the rest
always visible

Solution

Connect once. Give every agent its own seat.

You hold the workspace credential. Each agent or person gets a seat — the tools, the context, and its own rules — never the account itself.

01 — Connect

Create a workspace

Create a workspace and connect GitHub, Notion, Linear, Slack. You keep the credentials. Seats never see them.

02 — Permissions

Say what's allowed

Read? Yes. Merge? No. Show private pages? No. Per action and per field, per connection, per seat — finer than the provider's own scopes.

03 — Context

Add the context

Voice, SOPs, architecture notes, "never mention other clients." Set once on the workspace, present in every seat you hand out — not pasted into every thread.

04 — Seats

{
  "mcpServers": {
    "openkernel-acme-corp": {
      "url": "https://mcp.opk.sh/seat/opk_live_••••a1c3"
    }
  }
}
Hand out seats

One MCP entry per person or agent — including people who don't work for you. The seat carries the workspace's tools and context with its own rules; the seat holder never sees the account, the token, or the other seats. Revoke one, only that one goes dark.

05 — Observe

You see every request, and every refusal.

Who, when, what it touched, what was hidden, whether it went through. Per seat, not per account.

09:41:02
agent · Acme Corp · read notion.pagesFriday client brief · meeting notes
allowed
09:41:16
agent · Acme Corp · update notion.pagerule: updates not allowed
blocked
09:43:10
agent · Acme Corp · send slack.message“Drafting Friday’s Acme status” → #acme-project
allowed
11:03:44
agent · Umbrella Corp · read notion.pagesUmbrella client brief · meeting notes
allowed

Scenarios

Two setups it was built for

Maya’s is in the demo console. Priya’s is the same connectors, handed to someone who doesn’t work for her.

Maya

Maya

consultant · other people’s systems

A wall between Acme Corp and Umbrella Corp

One workspace per client, one seat per workspace. Her agent drafts Friday's Acme status from the Acme brief and #acme-project — and has no tool that can reach Umbrella. Not a rule it has to obey; a tool that isn't there. Switch seats, and Acme is the one that's gone.

Priya

Priya

agency owner · contractor's agent

A seat for someone who doesn't work here

Her freelance developer runs his own Claude. Priya gives it a seat on the client workspace: the client repo and #client-project, open PRs but no merge, none of #internal, none of the other clients. Priya sees every call he makes. The contract ends, the seat is revoked, and his Claude has nothing.

FAQs

Questions people ask

Yes. That's the point. A seat is a URL and a key; the holder pastes it into their own Claude, Cursor or any MCP client. They get the tools and rules you set, nothing else, and you see everything they do. Revoke it and their client just stops.

Tell me what your agent needs to reach, what it must never touch — and whose agent you’d hand a seat to.

Free while I onboard design partners. Pricing comes later, and you’ll have a say. Onboarding is by hand and the list is short.