Outloop's vision for digital agencies

When you hire a new employee, you give them a computer.

Your AI agent is the new employee — and it also needs a computer.

Not another chat window that suggests ideas. A work environment where an agent uses approved tools and real client files, and carries a workflow to the end — for the right client.

A dedicated remote computer today; a company-owned machine later.

Last updated:

In short

An AI agent is becoming a worker, and a worker needs a workplace — not just a better model.

Give an AI agent an objective and it needs somewhere to do the work: files, instructions, approved tools, and access to real client systems. Outloop is the access and control layer for that environment. It decides which client, which account, and which action — and lets the agent work without ever seeing the raw credential.

01 — The shift

Not a chat. A digital employee.

A chat window answers a question and stops. You are still the one who opens the next tool, finds the right account, copies the number across, and decides what happens next.

An agent works differently. It receives an objective, plans the work, uses the information and tools it has been approved to use, and keeps going until it reaches a result — or until it hits a boundary that needs a human. It can analyse campaigns, prepare reports, work with files, check performance, and propose changes for approval.

That difference is not really about intelligence. The models are already good enough to be useful. The difference is whether the system is allowed to act inside real business systems — and whether anyone can say exactly what it was allowed to do.

Claude Cowork is like Claude Code for developers — but designed for people who are not programmers. It gives business teams a real agent workspace with files, instructions, tools, and workflows, not only a conversation inside a chat window. It is one good entry point, not the whole picture: models and agent environments will keep changing, and infrastructure should not depend on any single one.

02 — The workplace

The computer is not really about hardware.

When a company hires someone, the computer is not the point — what it carries is. The same is true here. A workplace for an AI worker means:

  • Files and client folders
  • Instructions and skills
  • Approved tools
  • Approved API access
  • Models for reasoning, image, video, and data
  • Permissions, audit, and approval gates

Recommended today

A dedicated remote computer

A machine that belongs to the work, not to a person's laptop between meetings. It is the practical starting point, and you can set one up today.

The longer-term direction

A dedicated computer inside the company

As machines get more capable, more of this work can run on hardware the company owns and controls. That is where we think it goes — it is a belief, not a product we sell.

A dedicated remote machine now; the same role moving in-house later.

Outloop does not supply or host either machine. It is the access and control layer that runs on whichever environment you choose.

03 — The operating model

A stack of tools, or one worker who can use them.

Today: a collection of separate tools

  • One tool for copy, another for images, another for video
  • One tool for campaign optimisation, one for reports
  • A separate interface for every marketing channel
  • Context and history scattered across all of them
  • A separate subscription and setup for each new need
  • A person acting as the integration layer between them

The new way: one worker with a work environment

  • A dedicated computer or work environment for the agent
  • A capable model that understands the objective and plans the work
  • A workspace that knows which client it belongs to
  • Approved access to the business systems that client uses
  • Different models for reasoning, images, video, and analysis
  • Humans setting the goals and approving the sensitive actions

The bottleneck is no longer how clever the model is. It is that a person is still standing in the middle of every workflow, holding the keys and remembering which account belongs to which client.

04 — What changes for software

SaaS does not disappear. Its role changes.

In the old model, a product was built around an interface a person had to learn and operate. That is still where most software value is captured today.

We think more systems will expose what they can do through APIs, MCP servers, connectors, actions, data services, and model endpoints — surfaces an agent can operate directly. The interface becomes less central. Access to the capability becomes more important.

Human interfaces keep mattering, particularly for configuration, oversight, exceptions, and approval. What moves is the routine execution: the part where someone opens ten screens to complete one task.

Scattered interfaces a person operates, becoming one stream of capability an agent can call.

The stack

Everyone is building the brain. Almost nobody is building the control layer.

An AI worker needs five things to do real client work. Four of them already exist and are improving fast. The fifth is the one that decides whether any of it is safe to run across more than one client.

  1. 01

    The model is the brain .

    It reasons, plans, writes, analyses. It changes fast — so nothing underneath it should depend on one model staying best.

  2. 02

    The computer is the workplace .

    Files, client folders, instructions, skills, approved tools. A dedicated environment the agent actually works inside.

  3. 03

    The API provides the capability .

    The stable execution surface. It is how work actually reaches Google Ads, Meta, GA4, a CRM, a Drive folder.

  4. 04

    MCP exposes tools to the agent .

    A useful way to present capabilities an agent can understand and call. It still runs on top of an execution surface.

  5. 05

    Outloop is the access and control layer .

    Which client, which workspace, which account or resource, which runtime, which action — and whether it can proceed without exposing the raw credential.

API is the engine. MCP is the connection layer for the agent.

What Outloop decides, on every request

  • Which client workspace is this?
  • Which approved access may be used?
  • Which account, property, folder, or resource is assigned?
  • Which runtime is making the request?
  • Which action is allowed, and which needs approval?
  • Can this proceed without exposing the raw credential?

Connecting an agent to a tool is not the same as deciding what it may do with that tool, for which client. That decision is the layer Outloop builds.

The whole picture

From a business goal to work done in a client's account.

Five parts, in order. The agent does the work — Outloop decides what it is allowed to touch on the way.

  1. 01

    Business goal

    A person defines the objective, the boundaries, and what needs approval.

  2. 02

    AI employee on a dedicated computer

    Dedicated remote computer

    Recommended today

    Local computer at the agency

    Longer-term

  3. 03

    The agent plans and executes

    It reads the instructions, checks the client files, and carries out the work.

    • Claude Cowork logo
    • Claude Code logo

    …or another approved agent runtime.

  4. Outloop logo 04

    Outloop controls the access

    Which client, which account, which action — and no raw credential is exposed.

    • Right client workspace
    • Right account or resource
    • Approval where it matters

    secret_exposed: false

  5. 05

    The client systems

    Advertising, analytics, CRM, files and media, and other approved business APIs.

    • Google Ads
    • Meta Ads
    • Merchant Center
    • Google Drive
    • Airtable
    • Gmail

The model thinks.

The computer runs the work.

The API does the action.

Outloop routes and approves it.

Product names and logos are shown for workflow context and are trademarks of their respective owners. Their appearance does not imply any partnership with or endorsement of Outloop.

The honest line

What runs today, and what is still a belief.

A manifesto is only worth reading if you can tell which parts are already true. So here is the line, drawn in public.

Shipped and running

today
  • Approved API access, reused across workspaces

    live

    Connect a service once, then grant it to the client workspaces that should have it — instead of rebuilding the setup for every workflow.

  • The agent never sees the raw credential

    live

    Secrets stay in the OS keychain and are read host-side at request time. The agent gets a redacted result, never the value.

  • Workspace bound to the right client account

    live

    A workspace is bound to the specific account, property, or folder it is allowed to touch.

  • Wrong-client access blocked by policy

    live

    A request for a client this workspace is not bound to is denied before any backend call is made.

  • Redacted local audit of every attempt

    live

    Allowed and denied requests are both written to a local, redacted audit log.

  • File and media work through approved access

    live

    Drive, Shared Drives, and approved media roots — within the scope that has been proven. Blocked actions stay blocked.

Where we think this goes

not shipped
  • A dedicated local computer inside the company

    vision

    Today a dedicated remote computer is the recommended starting point. As machines get more capable, more of this work can move to a computer the company owns and controls. Outloop does not supply or host that machine.

  • Moving a workspace between agent platforms

    vision

    Carrying safe instructions, skills, and workspace context between agent platforms without moving raw secrets. Prepared direction, not a current capability — and never a claim that memory, skills, or runtime config move today.

  • Choosing the right model per task

    vision

    An agent selecting approved models for reasoning, image, video, and analysis. A belief about where this goes, not a shipped router.

Nothing in this column is sold, priced, or promised on a date. It is written down so you can hold us to the difference.

05 — How the control layer works

The belief, reduced to one request.

Everything above comes down to what happens when an agent asks to do something on a client's behalf.

One request, end to end

  1. 01

    Agent request

    The agent asks for an approved action or alias — not a raw key.

  2. 02

    Policy & tenant check

    Outloop checks project, tenant identity, and runtime policy before anything runs.

  3. 03

    Local broker

    On approval, the local broker uses the credential on the wire to perform the call.

  4. 04

    Redacted result

    The agent receives a sanitized, non-secret result. Raw values never enter its context.

  5. 05

    Audit log

    Every attempt is written to a redacted local audit — decision, tenant, service.

The agent never sees the credential. A wrong-tenant request is denied at the policy check, before any backend call.

What the agency gets

The point of all this is capacity.

Security is how it stays safe. Capacity is why an agency does it at all.

  • More execution capacity across clients and channels
  • Less manual work and fewer switches between tools
  • More workflows per client without rebuilding setup
  • Clear separation between clients and permissions
  • Less dependence on the one person who knows every account
  • Human approval kept where the action is sensitive

None of this removes the human. It removes the manual handoff, and keeps review where the work is sensitive.

The one-pager

Take the whole argument with you.

The complete vision on a single page — the AI employee and its computer, today versus the new way, how it works, and what an agency gets. Useful for a partner meeting or a leadership conversation.

Download the AI Workforce Vision

PDF · 237 KB · no form

Preview of the Outloop AI Workforce Vision one-pager
Adam Argaman, Founder and CEO of Outloop

Why I'm building this

We ran an agency. The agent was never the problem.

Every workflow we built worked beautifully in a demo and then stalled in the same place: the moment it needed access to a real client's systems. Someone had to stop, find a key, paste it somewhere, and remember which account belonged to which client.

We were not missing a smarter model. We were missing the layer that decides what an agent is allowed to do, for whom — so the work can continue without a person handing over credentials, and without the wrong client's account ever being touched.

That layer is what we build. The rest of this page is where we think it leads.

Adam Argaman

Founder & CEO, Outloop

The vision

One person will manage one AI worker. Then a team of them.

Each one working from a dedicated environment, with approved access to the models, APIs, and business systems it needs — and clear separation between clients. Humans set the objectives, the boundaries, and the approvals.

The model is the brain. The computer is the workplace. Outloop is the access layer.

Live product with guided onboarding · Keys stay local · Cancel anytime

Questions

The AI Agency Manifesto — FAQ