Korux

Korux

The Governed AI Workforce OS

Build and safely run agentic AI for everyday workflows — no technology background required. Stay focused on your business; Korux handles confirmed workflows, AI agent guardrails, and human approval.

Request a 7-day trial — we'll email an invite link. After you set a password, sign in anytime at try.korux.ai.

See the problem

Agents can draft the outbound email. Korux makes sure a human still holds the send.

A real early-build walkthrough: natural language → confirmed Spec → Governor pause → approve or reject. This is the gap Korux is built to close.

  1. 01Staff ready

    Staff ready

    Virtual staff with abilities and flows — ready to run work you define.

  2. 02Describe it

    Describe it

    Write the job in everyday words. Korux proposes a Spec you can review.

  3. 03Confirm Spec

    Confirm Spec

    Internal steps can auto-run. External writes wait on require_human.

  4. 04Governor pauses

    Governor pauses

    Before the side effect fires, the action lands in Hub for a person.

  5. 05You decide

    You decide

    Approve, reject, or edit. The brake sits before send — not after.

Product preview from an early build — UI may change.

A new kind of need

A platform for the new work of AI agents — easy to build, safe to run

Korux is built for a need that is becoming common: virtual staff that can research, draft, and take real-world actions — while people stay in command. Our aim is simple: anyone should be able to build and safely use AI agents to take over repetitive daily workflows, without a technology background — staying focused on their business and process. That means natural language → confirmed workflow, runtime governance on external side effects, and human-in-the-loop as a first-class path — designed into one platform, not bolted on later.

NL → workflow

Describe the job in natural language, get a Workflow Spec you can review, then confirm before anything runs. Authoring should feel conversational — execution should stay explicit.

Governor on side effects

When an agent is about to email, publish, write to CRM, or otherwise leave your boundary, runtime rules can pause the action. Governance travels with the capability, not as an afterthought.

Human-in-the-loop first

Approvals are a product surface: approve, reject, edit, or always-allow similar — with a designated Approver who does not need the whole vault.

Identity, secrets, and trail

Agents have roles and scoped credentials. Keys stay out of the model. Intercepts and runs stay readable so you can answer what happened and who decided.

What we're building

Autonomy with governance — trustworthy scale for a one-person company

The product value we are designing for is trustworthy scale: many agents under explicit command, with border control on data and side effects — so people who know the work can automate it safely. Below is how the platform is meant to support that.

Governor

A dedicated Governor that watches agents where it matters — on external side effects.

When an action looks risky or crosses an Internal → External boundary, Korux can pause the workflow and route the decision to a human instead of hoping a post-mortem catches it. Policies can encode rate limits, amount thresholds, forbidden actions, and connector-level rules so governance travels with the capability — not as a spreadsheet you remember later.

  • Intercept before send, publish, mutate, or trade
  • Pause + notify instead of silent failure
  • Per-connector governor packs alongside manifests

Human-in-the-loop

Approvals are a first-class surface — not a buried webhook.

High-risk actions land in an approval experience where you can approve, reject, or always-allow similar cases (and revoke later). Invite an Approver who can decide gated actions without needing full admin access or vault credentials. Your AI workforce can move; the final say stays with a person you trust.

  • Approve / reject pending actions from a dashboard
  • Always-allow similar with explicit revoke
  • Approver role without Vault access

Per-agent Secret Vault

Credentials are scoped to the agent that needs them — and kept out of the model.

An email agent gets mail credentials; a trading agent gets broker credentials; nothing more. Secrets are injected at the tool / proxy boundary so LLMs never see raw keys in context. That is how you run many agents without turning every prompt into a credential leak.

  • Per-agent credential isolation
  • Inject at tool boundary, not into prompts
  • Least-privilege by default for each role

Virtual staff & workflows

Hire agents with roles and tools, then wire them into governed pipelines.

Define marketing, research, support, or ops agents with system prompts and bound capabilities. Author workflows visually, or propose a Workflow Spec from natural language and confirm it before it runs. Schedule and monitor triggers keep work moving — while Governor still sits on external writes.

  • Agent builder with prompt + tool binding
  • NL → Spec → confirm before execute
  • Runs history for debugging and review

Connectors with rules built in

Capabilities ship as packages: what they do, how risky they are, and when a human must gate.

The open korux-repertoire catalog covers mail, IMAP, web research, social publish, CRM notes, ads mutate, analytics reads, and more. Each package carries a manifest and governor rules — for example, outbound email that requires human confirmation before send. Governance is co-shipped with the connector, not bolted on after an incident.

  • Risk metadata and I/O boundary in the manifest
  • governor.json rules such as require_human
  • First-party catalog you can read on GitHub today

Audit & visibility

Trustworthy scale needs a readable trail — not a black box.

Intercept logs, run history, and step-level audit envelopes help you answer what ran, what was blocked, and who decided. Usage visibility keeps token burn observable. Frame it as operational accountability for builders and operators — clear enough for a non-engineer Approver to follow the story of a gated action.

  • Governor intercept log and risk alerts
  • Step-level execution accountability
  • Usage visibility for LLM spend

A concrete moment

Agent drafts an external email. Governor intercepts — before it sends.

This is the difference between “AI that can do anything” and AI you can actually run near a company mailbox. In the open mail capability pack, outbound send can require human confirmation by default when the action writes externally. Speed without steering is not automation — it is liability.

  1. 01

    Agent prepares the outbound action

    A research or executor agent drafts an external email — recipient, subject, body — as part of a governed workflow, not a free-form chat with your company mailbox.

  2. 02

    Governor intercepts on external write

    Because the action writes outside your boundary, the mail capability’s governor rules can pause execution. The side effect does not fire yet. The workflow waits on a human decision.

  3. 03

    You decide in Message Hub

    Approve as-is, approve with edits (to / subject / body), always allow similar, or reject. The brake sits before Internal → External — not after the message is already gone.

The same pattern applies beyond email: social publish, CRM writes, ads mutations, and other external side effects can carry governor rules in the capability package — so the brake is defined with the tool, not reinvented for every workflow.

Who it is for

Built first for one-person companies — and the humans who approve risk

Korux is aimed first at the founder-operator who wants virtual staff, with clear roles for people who build and people who decide. Larger multi-department topologies are on the roadmap; they are not the first cut we plan to ship.

Solopreneurs & founder-operators

Run a one-person company with virtual staff — research, outreach, ops — without treating autonomy as an all-or-nothing liability.

Small teams with a trusted Approver

Invite a Collaborator to build, and an Approver to gate high-stakes actions, without handing over the entire vault.

Builders who care about side effects

If your agents will touch email, CRM, social, ads, or paper trading, you need identity, secrets, and governor packs — not just another prompt chain.

Why the name

A chorus under command

Korux takes its sound from chorus — many voices, each with a part, becoming music only when they share one score. We imagine every founder conducting an AI agent team the same way: roles that specialize, a workflow that keeps time, and a human who still holds the baton.

That idea meets an older Eastern saying often rendered as “the more, the better” — Han Xin's answer that forces grow stronger under clear command. On Korux, more agents should mean more work done. The Governor and human approval are how “more” becomes “better,” not chaos.

Build in the open

Capability catalog on GitHub. Requirements in Discussions.

You can already read how connectors declare risk and human gates in korux-repertoire— mail, research, social, CRM, ads, and more. If you have strong opinions about where brakes should sit, bring them to GitHub Discussions: Announcements for official updates, Ideas for features, Governance for approval boundaries, and Q&A for concepts.

Request a 7-day trial on this page (we email an invite). Discussions are for shaping the product in public. Use both — they serve different jobs.

Guides

Dig deeper into the ideas behind Korux

What is agentic AI?

How agentic AI differs from chatbots — and why control planes, guardrails, and human approval are rising with it.

Agent control plane for solopreneurs

What the trending phrase means — and the control jobs founders need before “enterprise fleet” scale.

Human-in-the-loop AI agents

When agents should pause for approval — and how HITL becomes a product path, not a policy sentence.

AI agent governance

Runtime rules before external side effects: boundaries, secrets, approvals, and readable trails.

FAQ

Korux in plain terms

Short answers on agentic AI, agent control planes, AI agent guardrails, human-in-the-loop approvals, and who Korux is for — written for people and for search.

What is Korux?

Korux is a platform to build and safely run agentic AI workflows for everyday work. It combines natural language to confirmed workflow, per-agent secrets, AI agent governance on external side effects, and human-in-the-loop approvals in one product.

What is agentic AI?

Agentic AI refers to AI systems that can pursue a goal across multiple steps — planning, using tools, and taking actions — rather than only generating a one-shot chat reply. Korux focuses on governed agentic workflows: agents can prepare work quickly, while high-stakes external actions wait for a human decision.

What are human-in-the-loop AI agents?

Human-in-the-loop AI agents can research, draft, and prepare actions, but pause at high-stakes moments for a person to approve, edit, or reject — especially before external side effects like sending email, publishing, or writing to CRM. Korux treats this approval path as a first-class product surface, not an afterthought.

What is AI agent governance?

AI agent governance means runtime rules that control what agents are allowed to do when they act in the world. In Korux, a Governor can intercept risky or external actions, pause the workflow, and route the decision to a human, with connector-level policies and a readable audit trail.

What is an agent control plane?

An agent control plane is the operational layer people search for when agent fleets grow: inventory, policy enforcement, and audit of what agents may do. Korux approaches the same need for founder-operators — Governor rules, human approval, scoped secrets, and readable runs — so agentic autonomy stays under clear command. Read more at https://korux.ai/agent-control-plane.

What are AI agent guardrails?

AI agent guardrails are runtime controls that allow, deny, or require human approval before a tool action executes. In Korux, connector-level governor packs and Internal → External boundaries act as practical guardrails — enforced in the product path, not only as prompt instructions.

How does natural language to workflow work in Korux?

You describe the job in everyday language. Korux proposes a Workflow Spec you can review, then you confirm before anything runs. Authoring stays conversational; execution stays explicit and governed.

Where does the name Korux come from?

Korux takes its sound from chorus — many voices, each with a part, becoming music only when they share one score. The idea is that anyone can assemble an AI agent team like a choir: specialized roles, a shared workflow, and one human conductor.

What does “the more, the better” have to do with Korux?

It nods to an Eastern saying (duō duō yì shàn) linked to Han Xin: forces grow stronger under clear command. On Korux, more AI agents should mean more work done — with the Governor and human approval as the command that keeps scale trustworthy.

Who is Korux for?

Korux is aimed first at solopreneurs and founder-operators who want virtual staff, plus small teams with a trusted Approver. It is for people who want AI agent workflow automation without a deep technology background — staying focused on business process while keeping control of side effects.

What does the Governor do?

The Governor watches agents on external side effects. When an action looks risky or crosses an Internal → External boundary, Korux can pause the workflow and route the decision to a human — with policies for rate limits, thresholds, forbidden actions, and connector-level rules.

Is Korux available today?

Yes — request a 7-day trial with your email on korux.ai. We'll send an invite link so you can create a password; after that, sign in anytime via Try Korux at try.korux.ai. Capability packages and governance patterns are also visible in the open korux-repertoire catalog on GitHub.

Want agents with brakes?

Request a 7-day trial with your email — we'll send an invite link. Prefer to influence defaults first? Tell us which actions should never run unsupervised in Discussions.

Join the conversation on GitHub →