Essential Deck is the AI Workplace. Chat with your data, ship live dashboards and reports, stand up monitoring and automations, and build the internal app your team keeps asking for — all built by asking, on infrastructure you host, with every access decision on the record.
- Ask questions of your own data.
- Describe a dashboard, get a live one.
- Set an instruction once, let it keep working.
- Ship an internal app without waiting on IT.
- Approve what goes live.
- Mask what shouldn't be seen.
- Audit every prompt.
What stays inside your network — and what has to ask permission
Your databases, your documents, and any AI running on your own servers stay inside your network. Anything that would go to an outside provider passes one checkpoint you control — and only if you've allowed it.
Your network
InsideEverything here is rated for how sensitive it is, and none of it is reachable from outside your network.
Outside
Public internetOnly what you've allowed ever leaves — and every time it does, it is recorded.
Sending anything to an outside provider is a decision someone makes and signs off on — never a default. You can rule it out entirely for your most sensitive data, and that rule holds even against a setup someone configured earlier.
Ask a question. Get an answer you're allowed to have.
The same question asked by two people can return two different answers — each correct for who's asking. That is the whole product in one screen.
| Account | Days late | Value |
|---|---|---|
| •••••••• | 12 | 48,200 |
| •••••• | 9 | 31,500 |
| ••••••••• | 6 | 27,900 |
Nobody set that up for this particular question. You decide once that customer names are sensitive, and every dashboard, report, scheduled check, and answer that touches them follows the rule from then on — including ones built months later by someone who never knew the rule existed.
Two systems. One set of rules underneath.
Intelligence systems answer questions and keep watch. Business systems are the ones your teams build and maintain themselves. Both run inside the same clearances, approvals, and audit trail — nothing gets a quieter path through.
Intelligence systems
Agents, Dashboards, Reports, Trackers, and Automations — the AI that works with your data.
Agents
A named AI scoped to one job — its own instructions, its own model, its own data.
Dashboards & Reports
Describe what you need and get one back that stays live, refreshed for whoever opens it.
Trackers & Automations
Standing checks and a recurring AI worker, both confirmed before they're ever left unattended.
Business systems
App Builder, Wiki, and the Process knowledge base — the tools teams keep for themselves.
App Builder
The internal app your team keeps asking for, reviewed before it touches a real database.
Wiki
One governed home for company knowledge — closed by default, not open to anyone signed in.
Process knowledge base
Map how work actually happens, and find what's worth automating.
What your governance team gets
The controls that make it possible to say yes, applied the same way across both systems.
People see only what they should
People reach what their group and clearance allow. Viewing a Wiki Space or a Process needs its own explicit grant, closed by default rather than open to anyone signed in.
A real approval workflow
Anything that reaches your data or a model provider goes through review before it goes live, by named approvers set per group in advance, and stays on the record afterwards.
Sensitive columns never reach the model
Masked data is replaced before it ever leaves your database. A column nobody has classified yet is treated as sensitive by default.
A complete record
Who asked what, which data was reached, what it cost, and what an administrator changed — each kept and searchable, with an organisation-wide view across every group.
Cost and quota
Daily, weekly, and monthly limits per person, applied automatically. Running costs are tracked and summarised by month, not reconstructed from provider invoices.
Secrets encrypted at rest
Database credentials and provider keys are encrypted where they're stored and hidden in the interface — not simply restricted to administrators.
Nothing that reaches data goes live without a paper trail
Everything that could reach your data goes through the same review before it is switched on, so "who approved this, and when" is something you look up rather than investigate.
That covers every route to your data — a new database connection, a new AI provider, a person's access, or a rule about how either may be used. None of it goes live on one person's say-so.
Bring your own model — and actually mean it
Most tools that claim to work with any model mean any model that imitates one vendor. This works with the major families directly.
The major model families, directly
OpenAI, Anthropic, and Gemini models are each supported in their own right, alongside anything you run yourself. Switching a group from one to another is a configuration change, not an integration project.
You choose what each model is used for
Reasoning, image reading, and live search are enabled per model by your administrators, so a group gets the capabilities you've decided it should have — and none you haven't.
New models without waiting on us
When a provider ships something new or unusual, your administrators can accommodate it themselves — no support ticket, no waiting for our next release.
And the databases you already have
MySQL, Postgres, ClickHouse, Snowflake, BigQuery, Databricks, DuckDB and more — connected where they already live, with no migration and no copy of your data anywhere else.
Run everything on your own hardware if you need to. A model hosted inside your network is a first-class option here, not a compatibility mode.
Where this sits next to what you're probably already evaluating
What each does differently — not what's wrong with it. Both are good products built for a different situation.
A hosted enterprise AI platform
ChatGPT Enterprise and similar
- Runs on hardware you control, rather than someone else's.
- Answers from your live databases, rather than from files you upload and keep re-uploading.
- No seat floor. Deployable for one group, not only an enterprise-wide rollout.
- Any model behind it, including a local one, rather than one vendor's.
A lakehouse-native AI layer
Databricks Genie / AI BI and similar
- No migration. Queries the databases you already have, rather than requiring the data to land in a proprietary lakehouse first.
- Approval records and audit trails are things it produces for you, not log files someone has to assemble into evidence.
- Any model, including one you host yourself, rather than the platform's own.
- Teams can record and update information here. A reporting tool only reads it.
See your team's AI workplace, built around your data and your approval rules
Tell us a bit about your team and we'll set up a walkthrough against your own use cases — the groups you'd scope, the data sources you'd connect, and the approval policy you'd actually run.
Not ready to talk yet? The security overview is the place most technical evaluators start.