AI agents your whole team can trust with real work.
TINA is a shared workspace where people and AI agents work in the same chat. Agents act only with your permission, in threads everyone can see, with a record of every action taken.
One platform. One person, a family, or a company of thousands.
TINA is an agentic AI platform delivered as a messaging app. AI agents appear as contacts. You talk to them the way you message anyone else, and behind the chat a permission system decides what each agent may do, for whom, and when a human must approve first. Only the settings change between an individual and an enterprise, never the software.
A workspace, not a chatbot
One to one, group, family, or team threads. Invite an agent, mention it, and it works in front of everyone with the context already in the room.
Connected to real systems
Accounting, email, calendars, CRM, and internal systems plug in through connectors. No code, and logins never leave the server-side vault.
Accountable by design
Every agent borrows the asking person’s access. Consequential actions pause for a human. Every step is written to a log that cannot be edited.
AI is built for one. Work is done by many.
Today’s assistants serve one person at a time. That is fine while the AI writes emails. It breaks the moment the AI does something real: pays a supplier, updates a customer record, approves a leave request. Someone has to answer for what it did.
The one question today’s tools cannot answer: under whose authority did the agent act?
One request, end to end.
Every instruction, typed in a thread or spoken to an agent, takes the same five steps. Nothing skips the check, and nothing consequential skips the human.
Ask
A user types a request in a thread, or mentions an agent in a group.
Plan
TINA works out what is needed, picks the right agent, and plans the steps.
Check
TINA checks what that person is allowed to do, tool by tool, action by action.
Approve
Anything important asks a human first. Who decided, and when, is recorded.
Do
The agent does the work in the connected system. Every step is logged.
The plan, the tool calls, and the results stream into the thread as they run. No black box, and no separate dashboard to go and check.
The agent is never more powerful than you.
Every agent executes under the identity and effective permissions of the person asking. In a group thread, five people can get five different results from the same agent, because it borrows each person’s access in turn, never everyone’s access combined.
Checked on every action
An agent can only do what the asking person is allowed to do, verified server side on every single action rather than once at the start.
Data is data, never instructions
Content coming back from a connected tool is treated as information to work with, not as commands to follow, which closes the obvious route to hijacking an agent.
Changes take effect immediately
Revoke an access and it applies at the agent’s next action, not at the next login, so a mistake can be corrected in seconds.
An append-only record
Every action an agent takes is written to a log that cannot be edited afterwards, searchable and exportable when a customer or an auditor asks.
Approval where it matters
Payments, permanent changes, and messages going outside the company pause for a named approver. Irreversible actions require approval by default.
What is not granted is invisible
An agent a person has not been granted does not appear to them, and cannot be reached by their other agents either.
An interface people already know how to use.
A messaging app on web, iPhone, and Android. The learning curve is close to zero because there is nothing new to learn.
Agent and people threads
One to one, group, family, or team. Mention an agent in a group and it works in front of everyone.
Approval cards inline
Approve or reject without leaving the conversation. The decision, the approver, and the timestamp are recorded.
Live run visibility
Plans, tool calls, and results appear as the agent works, with a clear note when something fails and why.
Mini apps in chat
Launch an app full screen from the thread, finish the task, and come back with the result attached to the conversation.
Notifications that matter
Push and email for approvals waiting, task outcomes, spend alerts, and app updates, with delivery status.
Usage in plain sight
A live view of AI credits used against your allocation, per agent and per task, with a top-up path instead of a hard cut-off.
A workforce you can shape.
When you need an agent for a specific job, the Skills and Agent Creator builds it through a guided conversation. You describe the job, it writes the instructions, picks the skills, and proposes the tools it needs. You grant or deny each one, so every agent is defined by what it is for and strictly limited to the tools it has been given.
Shared agents
An admin publishes an agent once and the whole team uses it, each under their own access.
Memory with retention rules
Agents carry context between conversations, governed by your organisation’s data-retention policy.
Model agnostic underneath
Lightweight models for routing, stronger models for planning, chosen per task and recorded per interaction. Never locked to one provider.
Say it once. It runs forever.
Written in plain language
- “Every weekday at 8am, summarise my unread messages and today’s calendar”
- Natural language in, a real schedule out, with timezone
- A run log showing outcome and credits used per run
- Pause, resume, edit, or delete at any time
- Every run executes under your own permissions, never broader
Playbooks with human gates
- An ordered sequence of agent steps and approval gates
- Triggered manually, on a schedule, or by an event
- Named approvers per gate, with a full run log
- Every run reproducible and auditable, step by step
- For the work that must never go rogue
For example: chase invoices overdue past 14 days. Drafting is automatic; sending needs a person.
Connect anything, write no code.
Add a system by URL and credentials through the Model Context Protocol. A curated catalogue covers the everyday tools, from office suites and calendars to accounting, CRM, messaging, and file storage, and any compliant server can be added on top.
Vaulted credentials
Logins are held server side and never exposed to the model or to a mini app.
Tool-level switches
Turn on read and leave write off. Permission is per tool, not per connector.
Reversibility classified
Every call is tagged safe or consequential, and consequential defaults to an approval gate.
Personal or shared
Connect your own calendar, or connect the company accounting system once for everyone.
Failures surface in the thread in plain language, with the retry history, not as a silent dead end.
A store that fits inside a chat.
Partners build mini apps and publish them to the marketplace. You browse, subscribe, and launch them without leaving the workspace: filing expense claims, booking travel, raising purchase orders, training your team, all in the thread.
Sandboxed runtime
App code has no direct network or data access, only the capabilities you grant.
Permissions shown before it runs
You see exactly what an app may do, then decide. Every capability it uses is metered and logged.
Secure checkout
Payments go through the platform payment service, with cards tokenised by a licensed provider.
Rewards built in
Apps can issue and redeem rewards credits against a ledger you can inspect.
An off switch per app
Any app can be suspended platform-wide, instantly, and retired without stranding its subscribers.
Reviewed and versioned
Every app is reviewed before publication and versioned after it, so what you subscribed to stays what you get.
Costs you can see, and caps you set.
Usage is visible while it happens, and every limit is enforced before the money moves.
AI credits, metered
Every request is costed and deducted against your allocation, visible per agent and per task, live in the app.
Limits you control
Monthly allocations, per-tenant spend caps, and rate limits enforced at the moment of the request, not discovered on the invoice.
Top-ups, not cut-offs
A heavy month means a top-up pack you choose to buy, never a surprise bill or a hard stop mid-task. Spend alerts warn you before a cap is reached.
Designed to Singapore’s agentic AI safety framework.
Singapore’s IMDA published a safety framework for AI agents in January 2026. TINA was designed to its four principles before it was published, because they describe the problem we set out to solve.
Know and limit the risks upfront
Every agent, connector, and app must be granted to a person before they, or their agent, can even see it.
Keep humans accountable
Payments, permanent changes, and messages going outside the organisation pause for a human. Who decided, and when, is recorded.
Build in technical safeguards
Rules and spend caps checked on every action, defence against hidden malicious instructions, mini apps fenced off, and an off switch per app.
Keep users informed and in control
Users see what each app may do before it runs, watch agents work in the thread, and can review the full activity log.
Note: the IMDA framework is voluntary guidance with no certificate to hold. The claim here is design alignment, principle by principle, not formal compliance or certification.
Put agents to work. Keep people in charge.
TINA gives your team AI agents that do real work in the systems you already use, under the permissions you already trust, with a record of everything they did.
Book a live demo → or write to enquiries@tangent9.com