Every card carries its goal, scope, attachments and rules. Finished work stays on the card — and any other card can pull it in as context. Each new task starts smarter.
Humans and AI together in kanban boards. Human in the loop, first.
Start with one cardContext on the card. Reviewable steps. One click to hand off.
Every card carries its goal, scope, attachments and rules. Finished work stays on the card — and any other card can pull it in as context. Each new task starts smarter.
Split a job into subtasks — some for the team, some for a research agent, some for a QA agent. One board, every step reviewed.
One click on Send to AI: Todokan packages the context, dispatches the agent, moves the card to Doing — every step visible, every step needs your approval.
Four states. One click to switch. Nothing the AI does crosses these lines.
The card doesn't exist as far as the agent knows. Title, body, and presence — all hidden. For salary, legal, family, anything private.
The AI can read it for context but cannot change a word. For style guides, brand docs, specs — reference material the agent should respect.
Work in progress. The agent has the pen right now and is executing the brief. Watch, comment, or wait. The result lands when it hands back.
Read and edit. Every change the AI makes is logged on the card. Default for everything not flagged otherwise.
Habitats are shared. Boards, cards, and AI access are not. Invite a teammate, hand them the marketing board, keep finance to yourself. The per-card rules above apply to every human and every agent.
Send an invite link. New members land in the same workspace — same boards, same agents, same context. No re-onboarding the AI for each colleague.
Grant access board-by-board, per member. Marketing board for marketing. Finance just for you. Same Habitat, tailored views — nothing leaks where it shouldn't.
Admins invite, remove, set defaults. Members work on what they were granted. No mystery permissions, no implicit access — every right is visible on the membership.
When a teammate sends a card to AI, the agent acts with their access — not the admin's, not yours. Protected stays invisible. Read-only stays untouched. The per-card rules from above hold for every member's AI dispatch.
One protocol for transport. An independent auditor watching. Anthropic's managed sandbox for execution. The activity log on the board. Each layer leaves a trace.
AI talks to data through one official protocol — Model Context Protocol. No webhooks. No DOM scraping. No backdoors. Every read and write is a typed call, recorded in the activity log.
A second AI agent on a separate MCP endpoint reviews every action the worker took. Different tool surface, different permissions. It catches drift, scope creep, and policy violations before anyone else.
AI work runs inside Anthropic's official Managed Agents sandbox. Data is processed for the task and never used to train a model — per Anthropic's commercial data policy. No fine-tuning, no retention beyond the session.
Every AI move — read, write, comment, status change — is written to the activity log. Exportable as JSON. Agent API keys can be revoked at any time.
MCP is the tunnel between them. Scroll to watch a task travel through it.