Blog

Build your agent anywhere. Run it governed.

Run AI agents governed across Claude, OpenAI, and Copilot Studio. Copyl's neutral layer: manifest import, sandbox, transcript—zero credentials.

Building an AI agent has become an afternoon’s work. You describe what you want in Claude, ChatGPT, Copilot Studio, or a framework like LangGraph, wire up a few tools, and it works — in the chat window, on your machine, under your login.

Then it stops. Not because the agent is bad, but because the road from “works in chat” to “runs for real, accountably, in my organization” runs through questions your build tool was never designed to answer. Who does this agent act as? What is it allowed to touch? Who sees what it did? What happens when it’s wrong?

Most working agents die right there — in a folder, as a prototype nobody dared to connect to anything real.

The layer nobody owns

Think of the agent stack as three layers.

Building is solved. Every major platform lets you create a capable agent in hours, and they keep getting better. This layer is crowded, excellent, and not the problem.

Identity and governance is being solved — inside each vendor’s own walls. Microsoft gives agents directory identities and conditional access. Salesforce gives them user records. Workday manages them alongside employees. If you live entirely inside one of those stacks, this is real progress.

Running agents from anywhere, governed, in one place — that layer is still open. Because every vendor governs its own. Your Microsoft stack governs Microsoft agents. Your Salesforce org governs Agentforce. But your organization’s actual agent population doesn’t respect those walls: someone on the marketing team built a research agent in Claude, an engineer has three running through OpenAI, and IT is evaluating Copilot Studio. Each platform sees only its own slice. Nobody sees — or governs — the whole.

And there’s a structural reason no model vendor will ever close that gap: Anthropic will never be the governance layer for OpenAI’s agents, and OpenAI will never govern Claude’s. A neutral layer can’t be owned by anyone with a model to sell.

That’s the layer Copyl is built for.

What this looks like in practice

Take an agent you’ve already built — wherever you built it — and give Copyl its definition: instructions, tools, examples. We accept an open JSON contract, the Agent Manifest, with shapes for Claude-style, OpenAI-style, MCP, and hand-written definitions.

From that manifest, Copyl creates the agent as a real member of your organization — with an identity, an owner, and a lifecycle — and runs it in a governed sandbox:

  • Zero credentials. You connect nothing. Every external tool the agent tries to call is stubbed — the call is captured and shown, never executed. Your systems are untouched.
  • A full transcript. You see exactly what the agent did, step by step, including every tool call it would have made.
  • Test results. If your manifest includes examples, the sandbox scores the run against them.
  • A mapping proposal. Copyl matches the agent’s tools against real connectors in your organization and proposes — without applying — what it would need to run for real.

First import to first governed run takes about a minute. The point of the design is that the risky decisions — real accounts, real permissions, real triggers — come after you’ve seen the agent work, not before. Seeing is free; connecting is deliberate.

From the sandbox, the path forward is graduation: scopes granted explicitly, sign-off, and an audit trail. That’s the operating model we’re building toward — agents as accountable members of the organization, not scripts running under somebody’s API key.

Why an open format

The manifest is a documented, public JSON contract — not a proprietary import wizard. That’s deliberate. A neutral layer earns neutrality by being open: any platform that can produce JSON can produce a manifest, today, without waiting for us to ship an adapter. The format reference, with complete copy-paste examples, lives at copyl.com/agent-manifest.

Two honest limitations, so you know exactly what you’re getting: the manifest is Copyl’s contract — if your platform exports a different shape, you reshape it (the reference shows how), and native export adapters are on the roadmap. And knowledge files listed in a manifest are stored for reference but not yet loaded into sandbox runs.

When you don’t need this

If your organization builds agents in exactly one vendor’s stack, connects them only to that vendor’s systems, and has no sovereignty requirements — use that vendor’s native governance. It’s good, it’s included, and adding a layer would be complexity without benefit.

The neutral layer earns its place when reality is messier: agents built in more than one place, agents that touch systems across vendor boundaries, a European organization that wants its agent governance independent of any US hyperscaler’s stack — or simply a team that hasn’t locked its platform choice yet and doesn’t want one afternoon’s tooling decision to become an architecture commitment.

That last case might be the most common one. You don’t have to pick a side to start running agents accountably. That’s the point.

Try it with an agent you already have

Grab the definition of an agent you’ve built — or copy the complete example from the manifest reference — and run it in a governed sandbox now:

Import your agent →

No credentials, no connections, no commitment. Just your agent, running where you can finally see it.


Copyl is an independent, Swedish operating layer for AI agents — built to govern and run agents regardless of where they were built.

Get in Touch

Book a demo, reach out for support, or explore partnership opportunities. We're here to help you build, integrate, and automate faster.

Send us a message

Fill out the form below and we'll get back to you within 24 hours.

Required fields are marked with *. Do not send passwords, card numbers, or other sensitive data through this form.