Control Plane

One governed layer over every tool, team and agent.

Atlas puts the control plane on your company map: the teams, projects and directives it serves on one side, the systems it is allowed to call on the other, and the record of every action underneath.

Connect an AI client

The plane at a glance

Estate, plane, systems, record.

Agents on the left, connected systems on the right, the plane between them, governance beside it and the record underneath. This is the shape the console draws from a live estate.

Atlas / Control PlaneAcme Holdings / Security / SOC modernizationSchematic
RecordAppend-only
TimeAgentCallOutcome
12:04:11Triage agentQualys · list_findingsAllowed
12:04:13Triage agentServiceNow · create_incidentEscalated
12:04:20Access reviewerOkta · revoke_sessionDenied
12:05:02Evidence collectorMicrosoft 365 · read_audit_logAllowed
Illustrative estate. Names, counts and times are examples; your plane shows your own connections, members and record.

What the plane holds

Eleven things, one record.

117 integrations are catalogued today. What a company can actually call depends on its connections, its members and its policy, and the plane keeps those three in one place.

Companies

One estate per company, with its own connections, members and record. A second company is a second estate, never a shared one.

Teams

Security, DevOps and IT work in the same plane with different scopes. A team sees the systems and agents it owns and nothing it does not.

Projects

Work is grouped by project, so a directive, the agents that carry it and the evidence they produce stay together.

Directives

A directive declares an outcome and the limits on reaching it. The plane plans the steps, runs the ones it is permitted and escalates the judgment calls instead of guessing past them.

Tools

Every catalogued integration exposes named tools. A connection determines the credentials, the permissions and the tools actually available, and the catalogue says which entries are available and which are planned.

Access

Every call runs under a member's identity and scope. When two accounts of one system are connected, the plane fails closed rather than guessing which one a call means.

Permissions

Allowed calls are listed per connection, and a deny-list floor holds under every policy. A denied call is a receipt in the record, not a silent skip.

Governance

Policy is written once and applied to agents, tools and models alike: what may be read, what may be changed, and what waits for a person's approval.

Models

Models come from the configured provider catalogue with exact IDs, and each shows its source and whether it is available. A model listed is not a model proven on every tool path, and Atlas says which is which.

Agents

Agents are working nodes on the plane, not a list beside it. Each carries the state of its latest run and opens to the record behind it.

Evidence

Every action is written to an append-only record: who asked, what was called, what answered and what was denied. Reopen it from Atlas or from your AI client.

How a directive runs

From intent to a record you can reopen.

  1. Declare the intent

    A member or an agent states the outcome and the limits, inside a project the plane knows.

  2. Resolve identity and scope

    The plane reads the member's scope per connection. An ambiguous connection stops the run before any call.

  3. Plan against permitted tools

    The steps are mapped onto the tools the connection allows, under the deny-list floor.

  4. Run and escalate

    Permitted calls run. A judgment call is escalated to a person with the context attached, not guessed.

  5. Write the record

    Each call, answer and denial lands on the append-only record with its receipt.

  6. Reopen anywhere

    The result is a saved Atlas object: open it on the map, in the room, or from an external AI client over MCP.

Control Plane for AI

The AI your teams already use is part of the estate.

Atlas reads each provider through its administration or compliance API and renders it as a room beside the rest of the plane. What a room shows depends on the connection and the access the provider grants.

Microsoft 365 Copilot

Usage and administration reads, rendered beside the tenant's other systems.

Claude Enterprise

Compliance reads over Claude, Claude Code and Cowork usage.

Cursor

Administration, analytics and cloud agent reads for engineering seats.

Salesforce Agentforce

Agent usage and configuration reads from the CRM estate.

Hugging Face

Organization, model and usage reads for the teams that build on open models.

Where it runs

Inside your perimeter, on a release line.

Self-managed customers receive the artefacts, deploy them, allowlist egress per host and move versions on a release line. Each tier has a self-managed option.

TierWhat it isSelf-managed option
WebThe Atlas console and every server route, including the MCP endpoint and the rooms.One container from this repository.
BackendThe registry, the ledger, tickets, conversations and sessions.Self-hosted or cloud database.
Credential brokerOAuth and API-key storage for the integrations.Self-hosted or hosted broker.
Control planeKindo's MCP federation and REST API.Kindo self-managed, reached over your network.
Model railKindo's models, or a configured provider.Kindo's rail keeps model traffic inside the plane.

In Kindo's words

Not a black box that acts, but a governed operator that accounts for what it did.

A control plane is not a thirtieth console. It sits above the systems you already run, takes an intent, and maps it onto the tools it is allowed to call. The operator declares an outcome. The plane plans the steps, executes the ones it is permitted, and escalates the judgment calls instead of guessing past them.Kindo Research, July 2026. The AI-native control plane for agentic execution and The evolution of AI interfaces.

Questions, answered

Before you connect a plane.

What is the Control Plane?

The Control Plane is the governed layer between the people and agents that declare work and the systems that do it. It resolves identity and scope, permits or denies each call, escalates judgment calls and writes every step to an append-only record. Atlas draws it on the company map beside the teams, projects and directives it serves.

Is the Control Plane another console?

No. It sits above the systems a company already runs and maps an intent onto the tools it is allowed to call. The console is how a team watches and governs the plane; conversation is one input into it.

What does Control Plane for AI mean?

The AI a company already uses is part of its estate. Atlas reads Microsoft 365 Copilot, Claude Enterprise, Cursor, Salesforce Agentforce and Hugging Face through their administration or compliance APIs and renders each as a room, so usage, policy and evidence sit beside the rest of the plane.

Where does it run?

On your infrastructure or in a managed deployment. Self-managed customers receive the artefacts, deploy them, allowlist egress per host and move on a release line. The deployment guide lists every host a deployment reaches.

Put your plane on the map.

Start with one company, one team and one directive you can verify end to end.