Operator by Alcyone Systems

Your company's AI operator. On your hardware, under your rules.

A living AI employee appliance that executes plain-language tasks with governed tools, on-device company memory, scheduled routines and a signed audit trail.

  • Approvals before destructive actions.
  • Tamper-evident signed audit trail.
  • Company memory stays on-device.

Product view

Chat, routines, memory, approvals and audit in one appliance.

Operator accepts plain-language work and makes its governed execution visible to the people responsible for it.

Operator signed-in Chat view with its navigation for routines, memory, approvals, audit, setup and settings
Operator's signed-in Chat view.

How it works

Tell it. It does. It proves.

The task, tool execution and resulting evidence remain part of one governed workflow.

01

Tell it

Chat with Operator or hand it a task in plain language.

02

It does

Operator uses approved tools for files, HTTP, Tester runs and email triage. Destructive actions wait for a human yes.

03

It proves

Every tool call lands in a tamper-evident signed audit trail that a compliance team can verify.

Living AI employee appliance

Work, memory and routines stay on the device.

Operator combines an agent, company context and operational controls without moving the appliance boundary into a cloud service.

01

Company memory

Operator keeps company memory on-device so context remains with the appliance.

02

Scheduled routines

Cron-style agent tasks run with pre-approved tool lists.

03

Tool execution

Use files, HTTP, Tester and email triage through governed tool calls.

04

Enterprise sign-in

Local accounts, Microsoft Entra through OIDC and SAML 2.0 SSO use invite-only mapping.

05

Deployment choice

Run on Raspberry Pi 5-class hardware, mini PCs, Linux servers or Docker.

06

Sensory ingest

The camera and voice ingest API ships now. The Pi Tablet Bridge companion is on the roadmap.

Governed by design

The controls sit in the execution path.

Unlike cloud AI assistants and open-source agent frameworks, Operator is governed: approvals come before destructive actions, the signed audit trail can be verified, and data stays on hardware you own.

Governance before execution

Destructive actions stop at an approvals gate.

Operator can act with tools, but destructive actions wait for a human decision. The approval and the resulting tool call stay connected in the audit record.

Evidence after execution

A signed trail your compliance team can verify.

Every tool call is recorded in a tamper-evident signed audit trail. Governance is part of execution, not a separate activity added after the fact.

Hybrid brain

Local by default. Cloud only with recorded consent.

Choose the operating mode in Settings. The choice controls where model inference runs.

01

Sovereign mode

Fully local models run on the device, keeping model interaction inside hardware you own.

02

Consented cloud

With explicit recorded consent, select OpenAI, Azure OpenAI, GitHub Models or an OpenAI-compatible gateway in Settings.

03

Your data boundary

Data stays on hardware you own unless an administrator explicitly selects a cloud model. This is KVKK/GDPR-friendly deployment, not a certification claim.

Live demo

See the governed workflow.

The live demo is login-gated. Demo access is granted on request; credentials are never published.

Documentation

Install and administer Operator.

Start with installation, first run, configuration, SSO, routines and the Bridge API.

Read the Operator manual →

Operator 1.x

Own Operator 1.x. Add Care only if you need it.

€499 plus applicable taxes, once

Early adopter price for the first 10 licences. The later list price is €1,499. An optional Care plan is €299/year.

Self-serve Operator checkout will open after the app can consume and verify its signed licence and enforce the two-appliance activation limit.