§ Platform / Copilot
Everything you can do — except spend your money.
The Copilot is a working assistant inside the [Studio](/platform/studio/), not a chat window bolted onto it: it uses the same commands you do — search the catalog, compose workflows, edit a model layer by layer, launch and watch runs. Reading costs you nothing. Every change asks first, and shows you exactly what it would do. And money never moves: that last bar is architecture, not a setting.
Your controls, not a back door
In Scellis every action is a command before any button calls it. The interface presses those commands; the Copilot asks for the same ones. So anything you can click in the Studio, you can also just say — and a new capability arrives with its button and its assistant tool in the same change. The assistant cannot fall behind the product; there is nothing for it to fall behind on.
It reasons over the state you are looking at. Ask it to explain a workflow and it reads the graph; ask why a run slowed and it pulls the diagnostics; while a model trains it follows the same live stream your charts read, and narrates it. In Model View it edits architectures through the exact path the canvas uses — same validation, same diagnostics, same undo.
Reading is free; changing shows you the change first
| What it does | What it needs | What happens |
|---|---|---|
| Search & explain | nothing | Runs straight away — catalog, provenance, diagnostics, the live numbers of a run. |
| Compose & edit | your approval | Asks first — and the prompt shows the exact change. |
| Launch & steer runs | your approval | Budgets are stated up front; pause, resume, and watch work the same way. |
| Delete or overwrite | a separate confirmation | Confirms the concrete operation — never a paraphrase — and is rate-limited. |
| Buy, pay, bill | impossible | Never — the tools do not exist for it, and the server refuses it a second time. |
The level is enforced where it cannot be forged: on the server. The assistant's tool list only mirrors it.
Every command carries exactly one level of consent — nothing is unclassified. Reading runs without ceremony: search, browse, diagnostics, provenance, the live numbers of a run. A change asks first, and the prompt renders the concrete operation — the actual edit about to land, never a bare “allow?”. A destructive step confirms on its own, and is rate-limited. You approve the operation itself, never a paraphrase of it.
The rule is kept where it cannot be faked: on the server. Every request arrives with a caller the server works out for itself — you in the app, the Copilot, a script, an outside agent — and no client can claim to be someone else. The tool list the Copilot sees is only a mirror of what the server will accept. The full ladder, caller by caller, is on the API page.
No AI can ever spend your money here
This is a rule the platform cannot bend, not a preference you set. Purchases, payouts, billing changes, tips, refund requests, budget raises — everything that moves money — are simply never handed to the Copilot. The tools do not exist in its set, so there is nothing to trick it into calling. Behind that stands a second, independent layer: the server accepts a money-moving request only from a person clicking in the app, carrying a single-use code it issued for that one click.
The bad days are covered too. A Copilot that has read a poisoned instruction cannot buy. A leaked API key cannot buy. A script running without you cannot buy. An outside agent you connected cannot buy. Even a stolen session cannot quietly drain a payout — each money step demands its own fresh code. The same bar guards paid compute: the Copilot can set up free, volunteer device pooling all day, but entering any paid arrangement is a human gesture.
What remains is deliberately useful: the Copilot can browse the Marketplace, compare listings, recommend, and — if you say yes — install free content. It simply cannot check out. An assistant that structurally cannot spend is an assistant you can leave alone with your account.
What it reads is data, never orders
An assistant reads text it did not write all day long — descriptions, community notes, dataset cards, the results of its own tools. Scellis treats all of it as data, never instructions: the intent to act comes only from your turn. Context carries a note of where it came from, so the assistant can weigh what it reads. And a destructive or share-widening step proposed while untrusted content is on screen asks you item by item — never in a batch. The dialog is drawn outside the model's reach, so what you see is what will run.
The residual risk is printed rather than rounded to zero: inside the scopes you have already agreed to, an assistant that has been fed a poisoned instruction could still misuse read or write access. That risk is bounded — narrow scopes, loud attribution — and stated plainly in honest limits. Money, credentials, and unconsented egress stay barred no matter what the model reads.
And some gestures belong to the human hand by construction: entering credentials, approving an agent's access, arming a standing trigger, the browser's own file and sign-in dialogs. The Copilot cannot fake those moments — it prepares everything up to the boundary and hands you one clear step to finish. It prepares; you complete.
Every action signed, replayable, reversible
| Property | How it works |
|---|---|
| Attribution | Every change lands marked as the Copilot's — visible in history and in provenance. |
| Operations | Explicit and replayable, through the same queue as your own edits — a retry never doubles anything. |
| Undo | Per person — the Copilot takes back only its own steps, never yours or a colleague's. |
| Interruption | Stop a chain at any step; what was applied stays — and stays undoable. |
| Errors | A stable code with a severity and a suggested fix — never a raw stack trace thrown at you. |
What the Copilot changes are explicit operations, not side effects of a conversation. Each one goes through the same queue as your own edits — replayable, safe to retry — and lands marked as the Copilot's, visible in history and in provenance. In a live session, undo belongs to each person: your undo never reverts a colleague, and the Copilot takes back only its own steps.
A running chain of steps can be stopped at any point: what has already been applied stays, and stays undoable. When something fails, it fails in a shape you can act on — a stable code with a severity and a suggested fix, delivered as ordinary content rather than a hard-wired string — so the assistant can read its own error and propose the correction.
Starts instantly; runs on the key you choose
Talking to it works in your first sixty seconds: a small free allowance is included, so the assistant is not mute on arrival while you pick a provider. The steady state is yours: bring the key of whichever provider you prefer, or point it at a language model running on your own machine. Either way, the assistant's allowance is a hosted convenience — it is never a gate on computation, which stays unlimited and free on every plan.
Your key lives in the device's own credential store — encrypted on your device, never synced, never written into provenance, never visible to us. Every call to a provider counts as a network step the assistant has to declare, so consent can see it and a workspace policy can forbid it outright: a workspace set to no network refuses the assistant's outbound calls while your local compute carries on untouched. And the assistant is always labelled for what it is, on every surface it writes to.
One client of the interface, not a privilege
Nothing the Copilot does travels on private wires. One list of commands drives the interface, the command palette, and every programmatic client — so the assistant's reach is something you can check, not a feature list that quietly drifts. Scripting the same commands yourself is ordinary work: what the Copilot calls, your own script can call.
Outside agents are designed in as the third user of the same commands: a connection whose whole tool set is generated from that one list, with money commands left out at generation time and refused again at the door — two independent layers. That surface is specified end to end and being built now for early access. One interface, three hands — the one you click, the one you talk to, the ones you connect — same commands, same consent, same bars.