AI agents are becoming teammates. They read context, answer questions, summarize calls, write drafts, and turn messy conversations into work. That is useful only if the security model is honest about what an agent is.

An agent is not a search box. It is a participant.

Lydo is rolling out Enterprise MLS encrypted Spaces around that idea (in development, not yet GA): human members and every AI model the team connects (Claude, ChatGPT, Gemini, Grok, Mistral, DeepSeek, and any custom agent) operating inside one shared, governed workspace boundary, with access controlled by membership, policy, and explicit admin approval. There is no provider lock-in: bring your own keys and switch labs anytime. This is scoped for private enterprise rollouts where we work through security, agent, key-management, and deployment requirements with the customer.

The immediate audience is an enterprise department or pilot with a defined security boundary, not a claim that Lydo is already a full company-wide large-enterprise replacement. The same Space can hold multi-agent work, multi-provider choice, shared context, and agent-native notes while the rollout is scoped with the customer.

The old model: AI outside the room

Most collaboration tools bolt AI onto the side. Your team writes in one system. A model reads exported slices of that system through an API. The response comes back as if the AI was “in the workspace,” but the security model is really a handoff from one product to another.

That model can be fine for low-risk summarization. It is not enough for enterprise teams that want AI in sensitive channels, customer projects, legal work, healthcare operations, finance workflows, or regulated internal discussions.

The question is not just “can the AI answer?” The question is:

  • Who is allowed to read this Space?
  • Which agent identity is allowed to participate?
  • What content can that agent decrypt?
  • What external tools can that agent call?
  • What happens when a member or agent is removed?

What MLS changes

MLS, or Message Layer Security, is a modern group encryption protocol for secure collaboration. Instead of treating encryption as a simple one-to-one chat feature, MLS is built for groups: members join, leave, rotate keys, and continue collaborating as the membership changes.

In the Lydo Enterprise MLS architecture we’re rolling out (not yet GA), the encrypted content boundary is the Space itself. The normal Lydo service can route and store encrypted payloads, but the content is meant to be readable only by authorized participants in the MLS group.

That participant list can include:

  • Human members on approved devices.
  • Lydo’s built-in agent, Joby, when approved for that Space.
  • Every frontier and open-source model the enterprise connects (Claude, ChatGPT, Gemini, Grok, Mistral, DeepSeek, and any custom agent), approved and configured, with bring-your-own-keys and no provider lock-in.
  • Enterprise-controlled agent runtimes where required by the deployment.

The important shift: an approved AI agent is not scraping from outside the system. It is added as a first-class participant with its own identity and access boundary.

AI agents as first-class encrypted participants

For ordinary AI integrations, the usual pattern is “send context to the provider.” In the Enterprise MLS model we’re rolling out, the stricter pattern is “grant the approved model participant access to the encrypted Space boundary.”

That gives admins a cleaner model:

  • The agent must be explicitly approved for the Space.
  • The agent receives only the Space, channel, conversation, or tool scope it is allowed to access.
  • Removing the agent should remove future access, just like removing a human member.
  • Sensitive Spaces can block non-approved or non-MLS-capable agents.
  • External tool calls remain explicit integrations, not hidden side channels.

This is the security posture enterprise AI needs. The agent can help because it is in the room. It is constrained because it is governed like anything else in the room.

What stays inside the encrypted boundary

For the MLS encrypted Spaces we’re rolling out, the goal is straightforward: message and workspace content should stay encrypted to the authorized participant set. Lydo’s servers should not need plaintext message content to deliver, sync, or store the conversation.

That matters for:

  • Executive and board discussions.
  • Customer negotiations.
  • Legal and finance channels.
  • Incident response rooms.
  • Product strategy and confidential roadmap work.
  • Sensitive AI-assisted research and drafting.

When Joby or a connected model participates, it should operate from the same authorized content boundary as the humans, with every model sharing one Space knowledge base of channels, notes, and Vault, not a separate export per provider. Agent-native notes and drafts stay inside that governed context, with writes subject to approval. The agent sees what the enterprise allows it to see, not the entire company by default.

What does not magically disappear

Serious security copy should say the quiet part clearly: encryption is not a wand.

Metadata can still exist. Admin configuration, billing records, delivery state, abuse-prevention signals, audit events, and integration logs may still be processed outside the encrypted content body. If an admin authorizes an external tool or model provider, the data needed for that tool call may leave Lydo under that integration’s policy.

That is why any future enterprise MLS rollout must be paired with policy. Requirements a team may bring into custom scoping include:

  • Approved agent lists.
  • BYOK and key-management requirements.
  • DLP and audit expectations.
  • Regional hosting or data-residency requirements.
  • Subprocessor review.
  • Contractual controls for model providers and agent runtimes.

These are scoping requirements, not a claim that every control is generally available today. The intended boundary is encrypted content for authorized participants, explicit policy for agents, and no silent downgrade from “secure workspace” to “AI export pipeline.”

Why this matters now

The next wave of work software will not be just humans typing into chat. It will be humans and AI agents working together in shared spaces: planning, searching, drafting, scheduling, summarizing, filing, and following up.

If those agents are bolted on casually, enterprises will reject them for the right reasons. If they are governed as first-class participants, teams can use AI where the important work actually happens.

Lydo’s enterprise direction is built around that future:

  • Chat, calls, notes, boards, files, calendar, and contacts in one Space.
  • Joby built in and free in every Space.
  • Every frontier and open-source model (Claude, ChatGPT, Gemini, Grok, Mistral, DeepSeek, and any custom agent) working together on one shared Space knowledge base, with no provider lock-in through Enterprise BYOK.
  • One price per Space, never per seat, so the whole team joins free.
  • Enterprise MLS encrypted Spaces rolling out (not yet GA) for human members and the AI models the team connects.

FAQ

Is MLS the same as normal TLS?

No. TLS protects data in transit between clients and servers. MLS is a group encryption protocol designed for secure collaboration among changing groups of participants. Lydo’s Enterprise MLS Spaces (in development and rolling out, not yet GA) use that group model for workspace content.

Can AI agents participate in encrypted Spaces?

For the Enterprise MLS deployments we’re rolling out (not yet GA), the AI models a team connects are designed to be treated as first-class participants inside the encrypted boundary, with every model sharing one Space knowledge base. That means the agent is governed by membership and policy instead of being an unstructured export of workspace data.

Does this mean Lydo can never see any metadata?

No. Metadata, admin settings, billing, delivery state, abuse-prevention signals, audit events, and authorized integration activity can still exist. The MLS boundary is about encrypted content and participant access, not pretending operational metadata disappears.

Can an external AI provider still receive content?

Only if the enterprise authorizes that agent, provider, tool call, or runtime path. For sensitive Spaces, the Enterprise MLS model we’re rolling out (not yet GA) is designed so admins can require approved MLS-capable agents and block non-approved external providers.

Who should talk to Lydo about MLS encrypted Spaces?

Teams with sensitive collaboration needs: executive teams, healthcare operations, legal and finance groups, product strategy teams, regulated organizations, security teams, and enterprises that want AI agents in the workflow without turning every request into an uncontrolled data export.


Want AI agents inside a governed encrypted workspace? Talk to Lydo about Enterprise and we will scope the Space, agent, key-management, rollout timing, and deployment requirements with your team.