Forward-deployed operators + self-hosted agents·design partners open

Don't onboard a hire. Onboard an agent that fills the role.

You've already scoped the headcount and its budget. We fill that open requisition with a FillDesk agent — trained on your live workflow by two senior operators, supervised by a forward-deployed engineer, running on infrastructure you control.

Meet the agent — freeSee how it worksA live, guided video consultation. No card.
Pulls up the slides
FillDesk agent · online
Meet the agent

Ask it anything about FillDesk. It walks you through the brief — and pulls up the right slide as you talk.

Talk with the agent
Livevoice or text~2 min
Trained on your role
Operators with decades from
What you get

A virtual employee, not a task bot.

You define the role. We embed, learn it by hand, and stand up an agent that operates where your team works and delivers how they trust — with a senior engineer accountable for the outcome.

Fills a role, not a task

Task automation is brittle and static. A role is a moving target. We map the judgment, exceptions and institutional knowledge by hand — then the agent owns the whole job, end to end.

✓ accepts work✓ delivers output⤴ escalates edge cases✎ remembers

Works where your team works

Responds on Slack and email, picks up tickets, and joins meetings for context. No new interface to learn.

A forward-deployed engineer

A senior FDE is attached to every account — steering the agent, refining the harness, and accountable when an edge case appears.

Runs on your infrastructure

Hosted or self-hosted. You retain every VM and container the agent uses — and all the knowledge it relies on.

Learns and remembers — and you keep it

A Zettelkasten second-brain accumulates institutional knowledge from every task. It lives inside your environment, fully extractable, so the knowledge stays with you when the role evolves.

✎ edge cases✎ approval logic✎ house voice✎ exceptions

Bring your own models

Any model your InfoSec policy permits — major cloud or fully local. No lock-in to a single frontier vendor.

AgentBox isolation

Each agent runs in an isolated, checkpointed VM. Git credentials never leave the host — built by co-founder Marco. agent-box.sh ↗

Anchored to the role cost

One benchmark: the headcount you've already approved. A fraction of its loaded cost — no recruiting, no ramp, no attrition.

How it works

A virtual employee that sits between the work and your tools.

Work arrives through the channels your team already uses. The agent applies your workflow, escalates the judgment calls to its FDE, writes what it learns to memory — and only then acts in your systems. Six layers, all on infrastructure you control.

Ingress · where work comes from
Slackthreads · DMs
Emailinbound
Ticket queuesJira · Linear
Video callscontext
FillDesk — the virtual employee
Workflow & judgment
Trained onyour live workflow
Routine taskautonomous
Edge caseFDE steers
Forward-deployed engineer
Attached1 per account
Every cyclerefines harness
Second-brain memory
Storezettelkasten
Locationyour env
Runtime · where it executes
OpenClaw harnessmodel-agnostic
AgentBox VMisolated · checkpointed
Your modelscloud or local
Tools & deliverablesPRs · docs · replies
Human overwatch · interactive

Autonomous on the routine. Supervised on the judgment calls.

Most of the role runs hands-off. When something crosses a threshold you set — a payment, a deletion, an ambiguous SLA — the agent pauses and the forward-deployed engineer steps in. Toggle the two modes to see how it behaves.

Routine work — hands-off

Inside the role's defined scope, the agent just does the job. Tests, triage, drafts, scheduling, summaries — picked up from your channels and delivered back in the format your team already uses.

Run tests & report resultsauto
Triage tickets, open PRsauto
Draft replies to known contactsauto
Anything outside scopeFDE
FA
FillDesk Agent · QA
acme · production policy
running autonomously
Channels & tools

Open from everywhere your team already works.

The agent accepts work through the channels your team trusts and delivers back through accepted endpoints — committing code, opening PRs, and setting expectations like a good colleague.

#

Slack

Picks up work from threads and channels; replies like a teammate.

ingress + delivery

Email

Triages the inbox, drafts replies, owns follow-ups end to end.

ingress + delivery
JL

Tickets

Pulls from Jira & Linear, delivers a reviewable output.

ingress

Video calls

Joins meetings for context — and can be spoken with by voice.

context

GitHub

Commits code, opens pull requests, never holds your credentials.

delivery
G

Google Workspace

Produces docs, sheets, and calendar work in your suite.

delivery

AWS · GCP · Azure

Runs in your cloud, your region, your account.

infra

Custom skills

Tuned loops for ticket severity, house voice, and role specifics.

bespoke
Your infra · your knowledge

Built for teams who get asked hard questions by InfoSec.

Isolated VMs, models you choose, knowledge that never leaves your environment, and deployment options that fit your threat model.

Yours by default

Every FillDesk deployment is built so that the work, the runtime, and the knowledge stay under your control.

Isolated, checkpointed VMs
Each agent runs in its own AgentBox sandbox and can spawn more to parallelize heavy work.
Credentials never leave the host
Git and tool credentials stay on your hardware; every push requires explicit permission.
Extractable memory
The second-brain is emitted inside the agent's own environment — fully extractable by you.
Senior accountability
An FDE is in the room for every edge case — not a support-ticket queue.
Deployment options

Pick the infra that fits your compliance story.

  • Hosted — we run it, you retain every VM and container.
  • Self-hosted — the whole solution in your environment.
  • On-prem / air-gapped — for the strictest threat models.
  • Bring your own models — any cloud provider or fully local.
No vendor lock-inYou own the VMsYou keep the memory
The engagement

From first role to compounding advantage.

We deliberately keep pricing flexible at this stage — anchored to the role cost you've already approved, shaped together as a design partner. The work moves through three phases.

1EMBED & DELIVER

One month, on-site

~4 weeks · forward-deployed

We shadow the work, map every decision and exception by hand, train the agent on your live workflow, and get the job done alongside your team.

  • Integrate into existing infrastructure
  • Ingest the company memory
  • Train on the specific task
3ADAPT & COMPOUND

Each role makes the next faster

compounding · across deployments

Learnings from AgentBox and the FillDesk memory system transfer across every deployment, so each engagement stands up the next one stronger and faster.

  • Keeps pace as the role shifts
  • Knowledge stays with you
  • No enterprise price tag from another market
"You cannot take a person out of the loop until you understand why they were in it."
The FillDesk thesis
The team

You're hiring decades, not a headcount.

Instead of one junior employee, you onboard two operators with four-and-a-half decades of combined experience — plus the agent.

HY

Han-Shen Yuan

Product & Operating

25+ years as a product and engineering executive (CPTO / CTO). The FillDesk thesis came from his recent work vetting CTOs and watching clients stall on do-it-all agent SaaS that missed the human-as-middleware nuance.

Upwork — led engineering through IPO
eBay & Netflix — mobile at global scale
CPTO — Outdoorsy, Recharge
MD

Marco D'Alia

Infrastructure & Agents

20+ years as a founder and founding engineer. Creator of AgentBox, the isolated-VM agent runtime FillDesk is built on — the person who built the foundation is in the room.

AgentBox — creator (agent-box.sh)
Upwork — Software Manager
Waldos.ai — Firecracker micro-VMs
FAQ

Questions teams ask us before the first role.

What does the first month look like?
A forward-deployed engagement on a single approved role. We embed on-site for about four weeks, shadow the work, map every decision and exception by hand, integrate the agent into your existing infrastructure, and ingest your company memory — while getting the job done alongside your team.
Which roles do you start with?
Junior, high-volume roles with a clear path and a countable result: QA / black-box testing, closed-path development (ticket → fix → PR), Tier-2 customer support, and Admin / Executive Assistant work. We deliberately start where the outcome is measurable from day one.
Can I test the agent for free?
The FillDesk agent isn't a self-serve product you can try in a sandbox — it's trained on your specific role during the embed. What you can do for free is a guided video consultation with our agent (the "Meet the agent" button), and explore agent-box.sh — the open agent-orchestration tool co-founder Marco built, which FillDesk runs on.
Where does our data and knowledge live?
On infrastructure you control — hosted or self-hosted. You retain every VM and container the agent uses, and the second-brain memory is emitted inside the agent's own environment, fully extractable by you. The knowledge stays with you when the role evolves.
What exactly does the forward-deployed engineer do?
The FDE is attached to your account and steers the agent across its full task load. Every cycle they refine the harness, workflow and memory; when an edge case appears they're in the room to fix it; and as the role shifts they reshape the agent to match. This is the difference between a tool you operate and an outcome we're accountable for.
How is pricing structured?
There's no published price — it's a white-glove consulting engagement plus the agent. The only benchmark that matters is the role cost you've already approved; we fill it for a fraction of that loaded cost. As a design partner you help shape a structure that fits how startups actually buy.

Point us at a role you've already defined.

We'll fill that open requisition with a FillDesk agent, train it on your live workflow alongside your team, and get the job done — while you keep everything it learns.