A coworker that works where your work is

An AI coworker on your computer.No one gets the keys on day one.

Medellis Coworker starts by watching: it reads, plans and drafts — and does nothing you haven’t approved. It runs on your own machine — we never see your files, prompts or output. Promote it when it’s earned the call, demote it the moment it hasn’t.

Version 0.1.9 · macOS 13+ on Apple silicon · Windows 10/11 x64 · Early access

Windows early access is not code-signed yet. Microsoft Defender SmartScreen may ask you to confirm before running the installer.

Executive Assistant · this computerTue 09:14
09:14:22READinbox — 41 unreadauto
09:14:26DRAFTre: Thursday renewal callauto
09:14:31SENDpriya@northwind.coheld
09:16:02SENDapproved by yousent
09:16:09WRITE~/clients/northwind/brief.mdheld
09:16:44SHELLgit push origin mainheld
3 actions taken · 3 waiting on you · the whole record on your disk

It was never whether the agent could do it.

It’s what it did at 2am, on whose behalf, with which account — and whether you can show someone afterwards.

Most agents hand you one switch: watch every step, or let it run. That isn’t how you’d onboard a person, and it’s a strange way to onboard software that can send mail as you.

You hand it work. It hands back finished work.

Not chat — deliverables. Real asks, and what comes back:

“Triage my inbox”

A sorted inbox with the replies that matter drafted — each one held for your approval.

“Prepare the customer brief”

A finished document, pulled together from your files, mail, and notes — not an outline for you to fill in.

“Untangle Thursday”

Conflicts found, reschedules proposed — your calendar moves only after you say go.

“Where’s the release?”

Status pulled across GitHub, Slack, and your tracker — with the receipts, in one answer.

“Size up these five vendors”

It searches, reads the sites, and hands back a comparison memo with its sources — not ten tabs for you to skim.

“Watch the pipeline for me”

A standing task, every weekday at eight: deals that moved, mail unanswered, the digest filed. Anything outbound still waits for you.

Three levels of trust. Set per coworker.

Autonomy is earned, and it’s enforced by the engine, not the prompt. The same ask at each level — pick one:

Level 1 · Where every coworker starts

Proposes everything. Touches nothing.

It reads, plans, and drafts what it would do — while writes, sends and commands are blocked outright, not merely gated. You learn how it thinks before it can act on how it thinks.

You: send Priya the renewal briefRead 3 files and 11 emails. Plan shown.Reply drafted in the session, for your eyes.Nothing sent. Nothing written to disk.

A full pair of hands, not a chat window

Everything here ships in the app today — and every bit of it sits under the same clearance ladder.

Reads the live web

Built-in web search and page reading, no API key to configure — research, comparisons, and pulling sources work out of the box.

Terminal and files

Runs commands, edits files, builds and checks its own work — and every command shows up in the ledger before it runs.

Standing work

Schedules like “every weekday at eight”, or wait-until-something-changes. While you’re away, approvals queue in your inbox instead of timing out.

Remembers what you tell it

Durable notes and preferences, kept on your disk and carried into every session. Say it once, not every morning.

Learns your procedures

Write a routine down once — how you brief, how you file, how you ship — and it becomes a skill the coworker pulls up when the task calls for it.

Answers in Slack

@-mention it in a thread and it works the task from your desk and replies in that thread — allowed to speak there and nowhere else.

Every action leaves a receipt.

Not a transcript — a log. Which coworker acted, in which session. What ran, with secrets redacted before anything is written. What was held, what you approved, and when.

Proposal to done

Each step lands as it happens — proposed, held, approved, ran. Not a summary written after the fact.

Attributable

Every line ties to the coworker, the session, and the approval that released it — including which standing rule, if one did.

Yours

A durable log on your own disk, next to the work. Read it, query it, keep it — it leaves your machine only if you send it.

Three steps, then it gets on with it

1

Install and sign in

One app on your Mac or Windows PC. Signing in with Medellis Cloud is what ties your licence to you — the work itself happens locally either way.

2

Connect what it needs

Gmail, Google Calendar, Drive and Outlook connect in one click. Everything else takes a pasted token, and always will if that’s what you prefer.

3

Give it a task

Ask in plain English. It plans, does the work, and stops at anything that writes, sends or runs — until you say go.

Control you can check, not claims you have to take on faith

The agent runs on your computer

Not a browser tab pointed at our datacentre. Your files are read where they live, and they stay there.

We never store your connector tokens

Connecting Gmail hands the token straight to your device. Our servers pass it along and keep nothing — there is no table for it.

It works offline

Sign in once. After that a dropped connection means “reconnecting”, not “locked out of your own machine”.

No lock-in — that’s the exit clause

Stop paying us and the coworker keeps working: the engine is open source and already on your machine, and the record is a file you own. What lapses is ours — branding, licence, support. We’d rather earn the renewal.

It plugs into the tools you already run

Thirty-four services today, five more on the way — mail, calendars, chat, code, CRMs, docs, files, books, analytics. Mail, calendar and Drive connect in one click; the rest take a token you paste, and always will if that’s what you prefer. Every one of them answers to the same clearance ladder and writes to the same record.

Gmailone clickGoogle Calendarone clickOutlookone clickGoogle Driveone clickSlackGitHubNotionWhatsAppTelegramEmail (IMAP)HubSpotAttioQuickBooksJiraConfluenceLinearGitLabmonday.comAsanaClickUpZendeskDiscordStripeDropboxBoxDocusignCanvaFigmaClosePostHogMixpanelAmplitudeApollo.ioHunterSalesforcesoonDatadogsoonPagerDutysoonClaysoonDescriptsoon

Plus anything that speaks MCP — point the app at your own tool servers and they join the same ladder.

Ship it under your own name.

Coworker deploys white-label through the Medellis studio: your brand, your workflows, and a licence sealed with your name — seats, term, and how far anyone may promote a coworker, enforced on every desk.

Every desk still runs local and offline — the policy travels, the data doesn’t. A fleet console, one record and one policy across the team, is next on the roadmap. Fixed implementation, then a platform fee.

Talk about a rollout

The questions you’d email us anyway

Which AI model does it use?

Your choice. Bring your own key for the major model providers, or run fully local. Your data goes to the provider you picked — or nowhere, if you keep it local.

What actually leaves my machine?

Only what you approve, plus the calls to the model you chose. Connector tokens are handed straight to your device — our servers keep nothing.

What does it cost?

Early access is free. Team rollouts are a conversation — tell us what you need.

Can it run under our company’s brand?

Yes. Coworker deploys white-label through the Medellis studio — your brand, your workflows, a fixed implementation plus a platform fee.

Start it in shadow. Decide later.

Free to try. Nothing goes out without your say-so.