Calendar
On the benchThere is no native calendar. The agent emits an allowlist-validated scheduling link; it does not hold events, check availability, or sync with Google or Outlook.
read the whole entryAn agent with no mailbox, no memory, no permissions and no way to move is a demo. AgentBag is the carry-on: eleven packed modules an agent can actually use, and a published ledger saying exactly which of them are real.
Every control in the bag sits on the same path. This is that path: a question arriving from outside, and everything that has to agree before an answer goes back.
01A request arrives
An email, a guest question, a text, or another agent asking on someone's behalf.
02It crosses a tenant boundary
The subdomain is the isolation boundary, so the request resolves to one workspace, one database, and one question of whether it is even in scope.
03A trust decision resolves
For agent-to-agent traffic the edge is authorised before anything executes, and the caller token is minted for that hop alone.
04Access narrows the corpus
Policy filters what is retrievable before generation, so a document you cannot open cannot be paraphrased at you.
05The agent consults its bag
Retrieval over your own material, documents, and whatever tools it has been given; each call priced as it happens.
06A reply leaves, and the trail stays
Tasks, delegation edges, decisions and artifacts persist as rows you can replay, and the spend is already accounted for.
Open any module and you keep your place: every module page shows which step of this path it belongs to, and links straight back to the card you left.
acme.agentbag.ai is a tenant, not a folder. Isolation, routing and access resolution all hang off that boundary, which is why it is the first thing you pick rather than a setting you find later.
https://yourteam.agentbag.aiEvery workspace gets its own.
Every platform in this category claims every feature, so nobody believes any of them. Here is our whole capability ledger, including the module that is currently only a deep link.
There is no native calendar. The agent emits an allowlist-validated scheduling link; it does not hold events, check availability, or sync with Google or Outlook.
read the whole entryA ledger only means something if it costs us something. Ours says Package lets you export and move agents but has no marketplace, Phone does voice but not phone calls, Memory is retrieval and not persistent memory, and Calendar is a validated link to your existing booking tool. Those four sentences are the reason to trust the other seven entries.
Read the full ledgerA candidate has an agent. A recruiter has an agent. Neither side wants to hand over everything just to find out whether there is a fit. Today the choice is the whole CV or nothing.
Hiring is one of only two relationships compiled into the platform's agent network, and the consent and disclosure kernel around it ships on by default. It is not a vertical we picked for a landing page; it is the edge the trust layer was built against.
See the exchange, step by step01A recruiter's agent asks a candidate's agent whether they have shipped production Rust.
The request resolves a trust decision on that specific edge before it reaches a model. Unauthorised, and it never executes.
02The candidate's agent answers yes, with two examples, and nothing else.
Disclosure is tiered, not binary: the decision permits an answer at reduced disclosure instead of choosing between full access and refusal.
03The recruiter's agent tries a second question about current compensation.
Access policy narrowed the retrievable corpus before generation, so the material simply is not there to paraphrase. Nothing has to be redacted after the fact.
No signup, no email gate, no "book a demo". This agent answers only from the published ledger and cites the module every answer came from. When the ledger does not cover your question, it says so. Which is the same rule the product runs on.
Answers are retrieved from the published module ledger on this page. No model call, no cost, no cold start. See the agent surface
I answer only from the published module ledger, and I cite which module the answer came from. If the ledger does not cover it, I will say so instead of guessing.
Individually boring. That is the point: infrastructure is only interesting as a set.
Per-document permissions that filter answers, not just pages.
Policy resolution is cached per session for speed; a permission change propagates on cache invalidation rather than instantly on every in-flight request.
A folder tree the agent reads, and a config file it obeys.
Extraction covers PDFs, spreadsheets and transcripts. Exotic binary formats are not parsed.
A durable ledger of what agents did, and why.
The in-process event bus is a single-node emitter, not a distributed broker. The durable cross-agent record is a separate Postgres task ledger.
Your agent has its own inbox, not a share of yours.
Inbound arrives by webhook from an email provider. We do not run our own MX or SMTP servers.
Both ends of the protocol: server and client.
Custom remote-MCP connectors authenticate with a static bearer token today. Full OAuth 2.1 for third-party MCP servers is planned, not shipped.
Grounded retrieval over your own material, with receipts.
This is retrieval, not persistent agent memory. Vector grounding is deployed; hybrid scoring combines vector similarity, keyword match and graph centrality.
Export, share and install agents as portable archives.
Export, import, handoff links and showcase all work. There is no marketplace, no package versioning, and no signed packages.
Knowing what a question is about before answering it.
Tagging plus a tiered scope classifier. Tags are derived from material and connectors; there is no authored ontology hierarchy yet.
Which agent may talk to which, and what it may say.
Decisions and scoped tokens are enforced on the agent-to-agent paths. The explainability surface ("why was this blocked") is thinner than the enforcement.
Voice in and out, and SMS. Not phone calls.
Speech-to-text and text-to-speech are live. SMS is built but flag-gated off and needs a carrier account. There is no inbound or outbound telephone calling.
Scheduling by validated deep link: for now.
There is no native calendar. The agent emits an allowlist-validated scheduling link; it does not hold events, check availability, or sync with Google or Outlook.
The first reader of a B2B site in 2026 is usually a model someone sent ahead. Every other site in this category makes it screenshot the DOM and guess. This one registers typed tools on navigator.modelContext via WebMCP, and serves the same tools over JSON-RPC at /api/mcp for everything else.
Which is the product's whole argument, demonstrated by the brochure: giving a capability a typed, authorised, callable surface beats hoping a model figures it out.
See the live tool consolelist_bag_modulesreadget_bag_modulereadsearch_bagreadcheck_workspace_addressreadanswer_faqreadget_pricing_statusreadjoin_waitlistwritehttps://yourteam.agentbag.aiEvery workspace gets its own.