Agents need context. Admins need control.
AI gets powerful when it has context. Lydo helps teams control which people and agents can access that context, what they can do with it, and how the work gets reviewed, so you can say yes to agents without giving up the keys.
Scoped agent access
Agents only work with the Space context they are allowed to see, set by admin policy and the tools a team explicitly connects.
Source visibility
Answers can point back to the files, notes, calls, boards, or channels they used, so AI work is inspectable, not a black box.
Human approvals
Sensitive actions can wait in an approval queue. A person reviews and signs off before an agent writes, routes, or ships anything.
BYOK
Business, Scale, and Enterprise Spaces can bring provider keys. You keep your provider relationship, control the spend, and switch labs anytime, with no lock-in.
Usage controls
Manage usage budgets, caps, and which models a Space can use, so cost and capability stay in the admin’s hands.
Enterprise scoping
Custom capacity, rollout, billing, security, and compliance requirements are scoped with your team instead of promised as a self-serve checkbox.
Some messages should really go away.
Tap Confidential on a message and its text, files, reactions, and AI traces are erased from your devices and our servers, or set messages to vanish on a timer. For teams that need a harder boundary, end-to-end encryption built on the open MLS standard is rolling out for confidential spaces and messages.
Straight about encryption
MLS end-to-end encryption is rolling out for eligible confidential surfaces; it is not on everywhere yet. When a Space turns Confidential Mode on, it also closes its outside connections, so MCP tools and the CLI are suspended until the Space re-authorizes them.
Stronger boundaries for larger teams.
Enterprise stays custom for organizations that need capacity, billing, rollout, security, or compliance requirements beyond the self-serve plans. Those requirements are reviewed with your team; SSO, SCIM, DLP, regional hosting, and a customer-facing audit-log product are not presented here as generally available features.
- Custom AI capacity
- Custom Space BYOK capacity
- Billing and deployment terms
- Security requirements review
- Compliance scoping
- Dedicated rollout support
Questions admins ask.
Can agents read everything by default?
No. Agent access is scoped by Space, admin policy, feature tier, and the integrations a team explicitly connects. Agents work with the context they are granted, not a free-for-all export.
Is Lydo end-to-end encrypted?
End-to-end encryption built on the open MLS standard is rolling out for confidential spaces and messages. It is not on for every surface yet; the page above describes what is available today and what is still rolling out.
What happens when someone leaves?
Admins can remove a member and revoke their access to the Space and its context immediately, so offboarding is a single action rather than a cleanup project.
Governed context for real AI work.
Give every agent the context to be useful, and every admin the control to trust it.