What Estratos does
Everything below ships today. If it's on this page, it's in the product.
Folders
A tree, not a pile
Build folders that mirror how you work: clients, services, projects. Layers guide naming so the tree stays consistent as it grows.
Folder tree
- root
- camden-roasters
- meridian-dental
- proposals
- house-style
- year-end
- pennine-joinery
- brackenfield-care
- harlow-logistics
- thornbury-architects
meridian-dental › proposals
house-style
Inheritance
Rules flow down the tree
Ask for one folder and your agent reads everything above it too. A rule you set once at the top applies to every client below it, and a client can override it. Each block carries a priority, so the more specific one wins where they disagree.
What the agent reads
-
root priority 5house-style inherited
-
meridian-dental priority 8fixed-fees-only inherited
-
proposals priority 9two-partner-signoff you asked here
Nothing from a sibling client is ever included.
Provenance
Where it came from
Every proposal keeps the words that prompted it, quoted exactly, and the reason the agent thought it was worth saving. A reviewer can see whether you asked for it or the agent offered it, before deciding.
Meridian never accepts hourly rates. Fixed fees only, always.
Copied word for word by the agent.
The user corrected me on a lasting client preference, so it belongs in the client's folder.
Cross-cutting memories
Rules that follow the work
Some knowledge isn't about one client, it's about every client. Share it once and it applies wherever it belongs. Your proposal rules exist in exactly one place.
Written once · edited in one place
- camden-roasters applies
- meridian-dental applies
- pennine-joinery applies
- thornbury-architects applies
Review queue
Approval before it counts
People and agents propose. Admins see each change as a diff and approve, reject, or request changes. A rejection records why, and the person who proposed it sees the reason. Cross-cutting memories need an owner, because they touch everything.
-
house-style
meridian-dental · Aisha Bello
-
vat-signoff
pennine-joinery · Tom Reed
-
records-first
camden-roasters · Maya Patel
-
year-end-notes
thornbury-architects · Aisha Bello
meridian-dental › proposals
house-style
via ClaudeRoles
Three roles, clear lines
Basic users propose. Admins approve and organise. Owners guard org-wide rules, billing, and the danger zone.
-
B
Basic user
Proposes changes
Propose -
A
Admin
Approves and organises
Propose Approve Organise -
O
Owner
Guards org-wide rules
Approve shared Billing Danger zone
History
Change it back anytime
Every memory keeps its versions, with author and timestamp. Roll back a bad edit without losing the record that it happened. Archive what you don't need and restore it later, or let an owner delete it for good.
- v3 Maya Patel · today Current
- v2 Aisha Bello · 3 days ago Roll back
- v1 Maya Patel · last month
Deletes write a tombstone, never a hard delete.
Audit log
A log you can hand over
Logins, token grants, every agent call, every change and approval. Filter by actor, target, or request id. Memory content never appears in it.
- 14:22 Claude · agent retrieve root.meridian-dental.proposals
- 14:21 Maya Patel approve proposal_01j9…
- 14:07 Aisha Bello · via Claude propose memory_01j8…
- 13:58 Tom Reed token grant session_9f2…
- 13:41 Maya Patel sign in identity_a41…
Actions and ids only. Memory content never appears here.
Agent connections
Paste a URL, click approve
Install the Estratos plugin in Claude, Codex, or Copilot, or point any MCP client at your endpoint. First use opens an approval screen. OAuth discovery does the rest, so there are no client ids or API keys to paste.
1 · Paste one URL into your agent
No client id. No API key.
2 · Approve access to your account
Claude wants to connect
Memory access only · revoke anytime
Export
Markdown out, anytime
Export everything you can see, one subtree, or cross-cutting memories only. You get a ZIP of Markdown files with front matter: id, kind, path, version, updated.
Scope
- Everything
- One subtree
- Cross-cutting memories only
---
id:
kind:
path:
version:
updated:
---
Common questions
Can an agent save something without a person agreeing?
No. When you haven't asked, your agent suggests at the end of a task and saves nothing until you agree. Whether it then waits for a reviewer depends on your role and one workspace setting.
What happens when two memories contradict each other?
Each block carries a priority, and the more specific one wins where they conflict. If two blocks sit at the same priority, your agent surfaces the conflict instead of picking one.
Does an agent see everything, or only what it asked for?
Only the folder it asked for and the folders above it. Nothing from a sibling client, and nothing from a folder it didn't ask for.
How do we know where a memory came from?
Every proposal keeps the words that prompted it and the agent's reason for suggesting it. The version history then records each change, its author, and when it happened.
Which assistants can read our knowledge?
Any MCP client. Install the Estratos plugin in Claude, Codex, or Copilot, or point your own client at the endpoint. They all read the same approved memories.
Is our workspace isolated from other customers?
Yes. Isolation is enforced in the database by row-level security, not by application code. The audit log records actions and ids, never memory content.
See it with your knowledge.
Request access, connect an agent, and ask it something only your team would know.