Agent orchestration Runs our own fleet

One control plane for every agent we run.

Runners, identities, credentials, guardrails and schedules. Every agent we run, ours or a customer’s, lives here.

Why it exists

A fleet breaks quietly.

One agent is a script. Thirty agents, running across several companies, on schedules nobody is watching, is an operations problem — and the failures are silent ones. An expired token. A model that stopped answering. A job that has not run since Tuesday.

None of that announces itself. It sits between the moment a thing breaks and the moment somebody happens to notice, and that gap is where the trust in an agent fleet is actually lost.

Tartare is the one place all of it is held: who each agent is, what it is allowed to touch, what it costs, what it is supposed to do today, and whether any of that is still true.

Every agent we run, ours or a customer’s, lives here. What the control plane is for

How it works

An agent is a record, not a repository.

Which is what makes a fleet of them something you can operate rather than something you maintain.

  1. Runners

    One runner per workspace, each with its own database and its own secrets. A task spawns its agent as a real process with a scoped configuration, and its output streams back to one activity log.

  2. Identity

    An agent is a name, a system prompt, a model, a set of credential grants and a daily budget. Changing what an agent is means changing that record, not redeploying something.

  3. Credentials

    Resolved at the moment of the call from a per-workspace vault, scoped so an agent can only reach what its own entity holds. Nothing is handed out in the clear, and no workspace can read another’s.

  4. Budgets and approvals

    Spend is metered per agent and per day, and work can be gated behind a human before it runs. An agent that would cost more than it is allowed to stops instead of surprising somebody.

  5. Schedules

    Recurring work lives in a table, not in somebody’s memory or a laptop’s crontab. It runs whether or not anyone is at a desk.

  6. Health checks

    Cheap checks ping the upstreams continuously for no model cost. Deeper ones spawn a real agent on a small model to prove the whole pipeline still works end to end — the only check that catches a fleet that looks healthy and cannot actually do anything.

  7. Knowledge that compounds

    When an agent learns something durable, it proposes an edit to the knowledge its entity works from. A person approves it, and it lands as an ordinary reviewed change every agent then inherits.

One plane, several companies

The same control plane, kept deliberately apart.

Tartare runs agents for more than one company at once, and those companies do not share anything they should not. Each workspace gets its own runner, its own database and its own vault, so an agent working for one entity has no path to another’s data even by mistake.

What they do share is the engine. A guardrail added for one company is a guardrail every company has in the same release, which is the whole reason a team this small can operate a fleet this size.

Each entity’s knowledge — who its people are, how it writes, what it has decided — lives in its own repository that the runner keeps in step automatically. The agents are portable; the knowledge is not.

Running today

It is how this company operates.

Tartare is not a demonstration. Every agent Marbling runs is dispatched, credentialed, metered and supervised through it, and has been for as long as there have been agents here to run.

  • Shape

    Dashboard, runner, CLI

    An operator dashboard for people, a runner that does the work, and an agent-facing command line so an agent can dispatch to another agent.

  • Deployment

    One runner per company

    Separate hosts, separate databases, separate vaults. Isolation is the default rather than a configuration.

  • Standing work

    Scheduled, not remembered

    Recurring jobs and continuous health checks run on their own, and say something only when the answer changes.

The operator dashboards are for the people who run the fleet, and they stay behind a login. There is nothing here to sign into.