Open-source access control layer

Let AI act on your data. Not all of it.

Automata sits between AI agents, messengers, and databases. Give Claude, ChatGPT, or any agentic AI access to only the chats and tables you choose, with every boundary enforced before a tool can read or write.

Free and MIT licensed · Your infrastructure · Strictly scoped

Example: a user asks Claude to run the analysis client A requested on WhatsApp. Through Automata, Claude reads the client A chat and client A database table, while requests for a personal chat and another client's payment data are denied. Claude then returns the requested analysis document.

One control layer

One access layer. Two kinds of sensitive data.

Connect AI to the tools where conversations and operational data already live. Automata presents a common access layer while keeping the permission model specific to each connector.

Messengers

Grant access to named conversations, never an entire inbox by default.

  • WhatsApp
    Available
  • Telegram
    Available
  • iMessage
    Coming soon
  • SMS
    Coming soon

Databases

Expose only approved tables and separate read access from write access.

  • PostgreSQL
    Available
  • MySQL
    Coming soon
  • MongoDB
    Coming soon

Permissions, not promises

Chat allowlists and table scopes are checked in the control layer before a connector tool can touch the underlying resource.

One token, one connection

Each access token is bound to a single messenger or database connection, with only the read and write tools you explicitly grant.

Free and open source

Inspect the enforcement path, run it on infrastructure you control, and extend the connector layer under the MIT license.

Token scope

Enforced server-side

WhatsApp chats

send_message · search_messages

  • Design team

    WhatsApp group

    Read + write
  • Investor updates

    WhatsApp group

    Read
  • Family

    WhatsApp group

    Blocked

PostgreSQL tables

query · execute

  • public.orders

    PostgreSQL table

    Read
  • public.inventory

    PostgreSQL table

    Read + write
  • private.payroll

    PostgreSQL table

    Blocked

Out-of-scope call refused

private.payroll · permission_denied

Strict enforcement

The boundary is part of the tool, not the prompt.

Automata does not ask the model to behave. It checks the token, requested action, chat allowlist, and table scope before a tool executes. Requests outside that boundary are refused without exposing the protected data.

  • Allow specific chats and tables, not entire accounts
  • Separate read tools from send and write tools
  • Bind every connector token to exactly one connection
  • Reject out-of-scope requests before data is accessed
  • Revoke a token or permission at any time

Run it your way

Free, open source, and yours to inspect.

The control layer protecting your messages and data should not be a black box. Read the code, verify the checks, and deploy Automata wherever your security model requires.

Recommended

Railway

One-click deploy

Skip local setup entirely. Provision the full stack, including Postgres, Redis, and volumes, on Railway in a few minutes.

  • No local Docker required
  • Managed Postgres, Redis, and volumes
  • Add or remove connectors anytime
Deploy on Railway

Self-hosted

Free, forever

Run the Nuxt control plane and Postgres on your machine, VPS, or homelab. Add the WhatsApp or Telegram services only when you need those connectors.

  • MIT licensed source
  • Unlimited scoped connections
  • Credentials stay on your infrastructure
Open the repository

Hosted

Invite only, for now

Use the same connector and permission model without operating the services yourself. Tell us which messengers and databases you need.

  • Managed setup and updates
  • The same granular scopes
  • Direct access to the Automata team
Request hosted access

Your AI. Your connections. Your rules.

Put a strict control layer between AI and the data that matters.

Start today with WhatsApp, Telegram, and PostgreSQL. Self-host Automata for free, inspect every permission check, and keep control of where it runs.