Access is by invitation only — every account is approved individually. To request access, email hello@xlooop.com.
Verifying access…
Connecting to your workspace. First load can take a few seconds while the API warms up.
← Back to sign-in
{{ authResultLabel }}
{{ authResultHead }}
{{ authResultDetail }}
{{ authResultFix }}
Retry sign-in
×
{{ authModalTitle }}
{{ authModalSub }}
GitHub
Google
or
Email address
We'll email you a 6-digit sign-in code — no password needed.
{{ authContinueLabel }} ▸
{{ authModeQ }} {{ authModeCta }}
Secured by Clerk
×
Check your email
Enter the 6-digit code we sent to {{ authMaskedEmail }}
Verify & continue ▸
Resend code · Use a different email
Secured by Clerk
✕ Close
{{ st.glyph }}{{ st.label }}· {{ st.sub }}
{{ onbIntroTitle }}
You're signed in as {{ onbAcct }}. In about two minutes we'll build a first-pass AI-readiness baseline from your answers and any public checks that actually run — so your workspace starts with traceable context, not a blank slate.
Company
{{ onbCompany }}
{{ onbDomain }}
{{ onbIntroCta }} →~2 minutes · you can close and resume any time
The public signals we'll check.
These are the sources Xlooop can check after a verified company and domain are available. This step lists them; it does not claim they have run. Completed checks show their server-recorded status and timestamp.
{{ s.glyph }}{{ s.name }}{{ s.meta }}
{{ onbSweepLabel }}
← BackContinue →
Your AI tools — and where your work lives.
Quick taps. The AI tools your team uses, plus the systems your information lives in — so we know what to connect and can add the right Connect tasks to your day-1 roadmap.
AI tools your team already uses
{{ t.name }}{{ t.sub }}{{ t.check }}
Where your work lives — we'll add a Connect task for each
{{ t.name }}{{ t.check }}
← BackContinue →
Four short questions.
These shape your baseline and the first actions we prioritise. Open-ended — answer in your own words, or skip and refine later.
What's the single biggest problem you'd want solved in the next 90 days?
Open-ended · give as much detail as helps · captures strategic intent
Roughly, what share of revenue comes from your top customer?
Accepts "I don't know" or a range
In the last 12 months, any cyber incidents, near-misses, or regulator contact you'd want us to know about?
Flagging early lets your reviewer act
{{ op.label }}
Over the next 12 months, are you trying to grow, sustain, or transition the business?
{{ op.label }}
← BackSee my baseline →
Your first-pass baseline.
Drafted from information you entered. Public-check status is shown separately; unavailable or unrun checks never count as evidence. This is a starting point, not a verdict.
Your identity is read from the signed-in account and workspace membership. Profile editing is hidden until it has a durable account contract.
{{ pfInitial }}
{{ pfFirst }} {{ pfLast }}
{{ pfEmail }}
{{ pfCompany }}
Access & authority
{{ ovMode }}· {{ accessStatusQualifier }}
{{ accessStatusAction }}
{{ spModeExplain }}
Workspace consent
Checking the workspace record...
◆Why these modes? Your authority is decided by four axes — see the full breakdown→
Looking for interface guidance (Guided · Contextual · Expert)? That’s a display preference, not a permission.
Identity axes · how production reads you
Membership role · entities/actor Role{{ axMembershipRole }}
Operating mode · OperatingMode{{ axModes }}
Authority · AppEntitlement{{ axEntitlement }}
Session · SessionMode{{ axSession }}
Platform role · PlatformRole{{ axPlatformRole }}
In production these come from your signed-in session & workspace membership — the switcher only previews a persona. §96 splits what the prototype used to fuse into one “role”.
Accessibility & notifications
◑Text density & light/dark live in your profile menu — one tap from the avatar, bottom-left.Open ↙
Notifications{{ n.label }}declared preference — delivery is production wiring
Access policy
Who can join and at what authority. Invitations are issued only from Members & access.
{{ workspaceDomain }}
Server verifies membership and assigns access.
External domains
Join as Client until approved — read-only, comments held from AI.
AI context & admissibility defaults
{{ a.glyph }} {{ a.label }}{{ a.desc }}
Only Operators promote content into AI context; every promotion is a governed feed line. The grounding summary on AI answers always shows used vs held-back.
Personalization & private learning
Xlooop learns explicit corrections, terminology, preferred skills, tools and response patterns for you. Your signals stay private unless you separately consent to a company promotion that an administrator approves.
Effective profile{{ spPersonalizationPrivacy }}
{{ spPersonalizationSummary }}
{{ spPersonalLearningReceipt }}
Audit & undo
How reversals and AI-on-behalf actions are recorded.
Production audit is append-only. Undo emits a compensating event and preserves the original. AI-on-behalf actions record principal plus instrument — {{ meName }} · via Xlooop — without exposing private platform governance.
Loading customer audit…
The customer audit trail is unavailable for this workspace role. No local substitute is shown.
Connect Claude Code, Codex, or another MCP host through one connector named xcp-gateway. Customer sessions start with xcp_session_start; revoking a token is immediate and audited.
xcp-gateway · customer profile
{{ spApiGatewaySummary }}
{{ spApiReadinessDetail }}
{{ spApiTokenError }}
Copy this token now. It is shown once and cannot be retrieved again.
{{ spApiGeneratedToken }}
Loading connector tokens…
Only workspace owners and operators can view connector tokens. The server decides — this panel never infers authority from the interface.
The token list could not be loaded. Reopen Settings to retry.
No connector tokens yet. Connect xcp-gateway at {{ spApiGatewaySummary }}, then call xcp_session_start. Browser consent creates it.
{{ tk.label }}{{ tk.roleLabel }}
{{ tk.meta }}
{{ tk.pill }}Revoke
Every mint and revoke writes an audit record. Tokens carry issuance-derived authority: they can report and propose, never sign off or approve.
Members & access{{ spMemberCount }} in workspace+ Invite member
This is the single invitation authority. Company-domain accounts join via SSO as Operator; external emails join as Client until approved, with a receipt for every change.
Each source carries a scope level — L1 index-only, L2 read, L3 operate — and a freshness state. Connect opens the same governed source flow used across the app.
Xlooop is the product — these are the engines it routes to. Cloud credentials are submitted once over TLS to encrypted tenant storage; secret values are never returned or retained in browser storage. Private runtimes connect through an authenticated customer relay. Admins set the workspace default; you can override it for your own sessions.
◆
Provider state, effective selection, model discovery and validation come from the live backend. Credentials are write-only: entered for one governed save, encrypted server-side, cleared from memory, and never returned or stored in browser storage.
Active runtime
Workspace default
{{ rtDefaultName }} · {{ rtDefaultProvider }}
{{ rtDefaultCaps }}
{{ g.sect }}
{{ m.label }}
{{ m.meta }}
{{ m.check }}
Your session
{{ rtActiveName }} · {{ rtOverrideNote }}
Reset to default
{{ rtActionReceipt }}
⛨
Runtime is governed by workspace policy
{{ rtPolicySummary }} · Provider setup and policy are managed by owners and operators.
AI context & source permissions decide what can be sent. Runtime policy decides where it can be processed. Policy mutation remains unavailable until it has durable storage, authorization, versioning, and audit receipts.
Cloud providers
{{ p.name }}
{{ p.models }}
{{ p.statusLabel }}{{ p.actionLabel }}
Enter a credential once. Xlooop transmits it directly to the encrypted tenant vault; this field is cleared after the receipted save and is never read back.
Private runtimes execute through the authenticated customer relay; the cloud service does not fetch arbitrary private URLs directly.
{{ p.rs }} {{ p.discoveredModels }}
Changing the workspace default is an operator-gated, audited action — production records the model_id, provider, and who changed it. Personal overrides apply only to your own sessions, within workspace policy — they can't widen what the workspace allows. Model choice carries the same locality meaning as a source: Local (no data leaves) · First-party · External.
Export{{ spExportButtonLabel }}
{{ spEntitlementLabel }}
{{ spEntitlementMeta }}
{{ spEntitlementPill }}
{{ d.label }}
{{ d.meta }}
{{ d.pill }}
{{ spExportStatusGlyph }}
{{ spExportStatusDetail }}
Submitting creates an approval request. No data is exported until the request is approved and executed; the application reports the durable request ID.
Onboarding & context
Your AI-readiness baseline is built from your saved answers and separately labelled server-run public checks. Unrun checks never count as evidence; review or update it any time.
{{ onbCompany }}{{ onbStatusLabel }}
Last updated {{ onbUpdated }} · {{ onbDomain }}
Review onboarding baseline
Your saved answers
AI tools in use{{ onbToolSummary }}
Where work lives{{ onbLiveSummary }}
Biggest 90-day problem{{ onbQ1Summary }}
Top-customer share{{ onbQ2Summary }}
Cyber / regulator flag{{ onbQ3Summary }}
12-month direction{{ onbDir }}
Answers are yours to edit. Finish saves them to your workspace and returns a durable receipt; closing before Finish leaves the saved baseline unchanged. Public checks show their live, stale, restricted, or unavailable state explicitly.
Authority — what you can do, and why
Your authenticated workspace session supplies the role, session, and permission policy shown here. An explicit denial always wins, and every governed action is checked again by the backend when you submit it.
◆
A permissive role label alone never grants write authority. You also need to be in Operator mode with an entitlement that allows the action — and any explicit denial always wins.
Permissions are returned by the server for this account and workspace. A role label alone does not grant a write. If the permission response is missing or invalid, Xlooop keeps governed actions unavailable and makes no change.
ActionDecision & reason
{{ r.label }} {{ r.tag }}
{{ r.why }}
{{ r.mark }}{{ r.decisionLabel }}
This view explains the current session; it does not grant permission. The backend remains authoritative, and a denied or unavailable action makes no change.
What each role can do · ✔ allowed · ○ read only · — blocked with reason · your column highlighted
CapabilityOwnerOperatorViewerClient
{{ r.cap }} · {{ r.note }}{{ x.mark }}
Capability map · what the prototype claims vs what actually backs it
Every governed capability, mapped to the construct behind it. This is a view over reconciled truth — the §136 connector reconciliation and the permission helpers read from the real repo — not a second registry. Confidence is honest about this seat's limits: Verified = confirmed from source; Modeled = the prototype behaves correctly but the backend route was not confirmed here.
{{ s.glyph }}{{ s.n }} {{ s.label }}
{{ g.fam }} · {{ g.n }}
{{ c.cap }}
{{ c.surface }} · {{ c.backend }}
{{ c.proof }}
{{ c.glyph }} {{ c.lvlLabel }}
Closing the Modeled rows to Verified is precisely the remaining backend-execution work — it needs a repo + CI seat, not more prototype. The Verified rows trace to permissions.ts / connector-registry.ts. See Implementation Plan §139. This is the capability lens; for the actor lens — why you personally can or can’t act — see Authority →.
Xlooop
Service unavailable
The service connection could not be verified. No workspace data or conversational fallback has been loaded.
Next UI preview · FSD migration build (?ui=next)
Shared with you
{{ sharedScope.name }}
{{ sharedScope.by }}
{{ sharedScope.line }}
You can review and propose — approvals stay with the owner’s team. The wider workspace, other projects, and settings aren’t part of this shared view.
A persona bundles the backend axes: membership Role, its mode entitlement, and session kind. Owner & Operator are operator-entitled; Viewer & Client are watch-only.
ⓘ Preview only. In production your role comes from your signed-in session & workspace membership — not this switcher.
Hi {{ accountName }} — what should we start from today?
Your goal: {{ onboardGoal }}. Pick a starting move — I’ll ground everything in your connected sources and keep each step on the record.
×
{{ st.glyph }}{{ st.label }}
using /abe-research-to-webpageintent create a webpage for the owner builder TAS
Rendering review-and-approve widget
I rendered the intake widget and checked it against the verified-facts memory. Here's where things stand — the genuine gaps are ABE's commercial details, which are login-gated.
This request · {{ digestTotal }} eventsView all in rail →
{{ needsLine }}
{{ r.expandChev }}
{{ r.title }}
{{ r.metaType }} · {{ r.metaState }}
Review →
{{ r.body }}
Open in rail →
Nothing in this view — all clear.
Your queue (right) is the one place to act — each row opens there with its full lineage.
You haven't proposed anything yet — write below and it lands on the record, {{ collabPosture.admWord }}.
{{ railEmptyMsg }}
Clear filters
{{ toastMsg }}Undo
◌Client view · redacted
Showing {{ clientRedaction.shown }} item(s) as a client sees them · {{ clientRedaction.hidden }} internal item(s) hidden. Names appear as roles; receipts, evidence internals, lineage and decisions are withheld — the projection runs through client-view.
Request lineage · shared pipeline — a block on any event stops readiness
{{ graphSpineSummary }}
Read left → right: from what you asked for through what we assembled and verified, to your sign-off and the build. Click any stage for its artefacts; hover to see who did it.
×
{{ n.label }}
Serves intent{{ lineageServesLabel }}↗
{{ lineageStageLabel }} · artefactslinked · versioned · not copied
{{ a.icon }}
{{ a.name }}{{ a.ver }}
{{ a.src }} · {{ a.time }}
Restore?ConfirmCancel↺Restore
Queryable · rollback-able · fully audited — each row is a node in the temporal graph.
Recommended
{{ recText }}
{{ railSettledLabel }}
Connect a source
1 · Choose a connector
{{ c.glyph }}{{ c.label }}{{ c.badge }}
Free plan connects up to 3 sources · GitLab & OneDrive sit on the paid plan · Gmail & Outlook read metadata only.
2 · Access level · you can change this anytime
{{ l.label }}{{ l.tag }}
{{ l.desc }}
3 · Use it in
⬢{{ connectProjName }}scope▾
{{ o.name }}{{ o.check }}
◈{{ connectLensName }}lens▾
{{ o.name }}{{ o.check }}
{{ connectSummary }}
⬢
Frame a new project
Name it, set the goal, bring in what it should know.
1 · Name your project
2 · What's the goal? · optional, but it orients the AI