Know what your
agents did.Prove it.
Every agent gets a permission level. Every risky action needs approval first. Every decision gets logged, so you can show a client, an auditor or your future self exactly what happened.
None of our business. We never hold your keys, never read your content, never train on it.
“What did your AI do on my account?”
Maybe you run four companies. Or six clients. Or fifty. Your agents touch their data every day: drafting, sending, filing, deciding. Then a client asks what happened, and all you can hand them is a scroll of chat history that proves nothing.
Thornbury Ledger isn't a chatbot, a router or a platform. If a feature doesn't get more useful as you take on more clients, we don't build it.
The authority matrix, live.
This is what the product actually looks like, and how we run our own team of agents. Click any cell to change what that agent is allowed to do. Every change writes a tamper-evident, hash-chained record.
Click cycles: allow → gate → deny. Keyboard accessible.
| Agent · tier | Read client data | Draft outbound | Send externally | Move money | Change policy |
|---|
Demonstration hash chain, computed in your browser. Nothing on this page is transmitted anywhere.
We price by how many clients you run, not how big you are.
A context is anything with its own login, data and rules: one client, one company, one brand. Drag the slider and find where you land.
We never hold your provider keys. At any tier.
Not a policy we could quietly change: an architecture. Watch where the key actually goes.
Gmail, Slack, Notion, CRM: custodied by Composio. SOC 2 and ISO 27001 certified. Roughly 80% of the credential surface, transferred.
Custodied by your browser. Session-scoped, never written to our disk.
Nobody's. Managed is inference resale using Thornbury's own keys, not key custody.
Before the first paid customer: encryption at rest, per-tenant isolation at the query layer, a published data-handling page, a documented deletion path. Not SOC 2: that comes when a deal requires it, and we will say so plainly rather than imply otherwise.
One question kills most roadmap requests.
Does this get more useful as you take on more clients? If not, the answer is no, full stop, logged and returned with thanks. Try it with a feature you actually want.
Services now. Product next. In that order, on purpose.
The services we sell today aren't a placeholder while we build the product. They fund it and shape the roadmap: every paying customer helps write the spec.
Governance setup engagements, delivered with existing tools. Flat-fee projects. Available today: no product required.
Hosted Ledger, free and Pro tiers. Subscription. Month 5–12.
Thornbury-supplied inference, one invoice, per-client attribution. Month 9–24.
The audit format agencies hand their clients. Policy template library. 24 months out.
Honest timeline to usable alpha: 4–7 months, wide bars, planned against the top of that range. Built as a fork of LibreChat, we build the governance layer, not another platform. AGPL from the first commit.
The free tier isn't crippled. That's the point.
Full governance, free: the matrix, the gates, the decision records. We charge for extra depth and the managed version, never for the ability to prove what happened.
- Unlimited contexts, hosted
- BYOK, browser-held · BYO Composio key
- Full authority matrix, gates & records
- Community support only: public issues board, no email, no SLA. Stated plainly.
- Policy template library
- Per-context cost reporting
- Exportable audit records
- Email support
- Thornbury-supplied inference, one invoice
- Per-client cost attribution & chargeback
- Per-agent spend caps, overage alerts
- Where expansion revenue lives
- Self-hosted / VPC when a client demands it
- AGPL permits internal use with no publication obligation
- Built when a signed deal requires it, not before
A source-available AGPL self-host arrives around month 9–12, deliberately unmarketed: public repo, README, no support, no SLA. Self-hosting stays free: anyone offering Ledger as a service has to open their changes.
Governance Setup
Fourteen days or less. Corporate-card decision, no procurement.
Worth a call if: you're running three or more clients or companies, and at least one AI agent already touches client data.