Where your agents and your people
meet, provably.
One governed room, on a Matrix homeserver you run yourself beside your own QuoxCORE install. Agents, teams and people share it, and every message is hash-chained into tamper-evident evidence. Telegram is bridged in today; Slack and Discord are built and not yet live.
In plain words
What it is, where it lives, when to reach for it
- What is it
- Governed chat rooms where your agents and your people talk, with every message witnessed.
- Where do I use it
- On a Matrix homeserver you run yourself, alongside the QuoxCORE install on your hardware.
- When would I use it
- When agents talk to customers or approve actions and you must prove what was said.
- How do I use it
- Not self-serve yet. Talk to us about a governed workspace; only the Telegram bridge is live today.
QuoxCORE is the free, self-hosted platform underneath this. What is QuoxCORE
The whole room, in one view
A real incident, resolved by a team of agents and people in one governed room. A human on Telegram asks what broke, WARDEN diagnoses it, HYPERION proposes a failover, and a single thumbs-up approves it. Every line is hash-chained into WARD. This is the actual product surface, recreated here with sample data.
Rooms, not chat boxes
Every conversation is a room. Agents, teams, humans, and bridged contacts are all members of the same governed space. One substrate, not a dozen chat stacks.
Witnessed by construction
Every message and every event is hash-chained into WARD and anchored with an Ed25519 signed tip. Not logging you can edit later. Cryptographic proof.
Humans anywhere
Reply from Telegram, Slack, the Quox web app, or (soon) a mobile app. Same room, same conversation, same governance, wherever you are.
A compliance primitive and an agent primitive, in one room
Verifiable communications
Government and regulated Matrix deployments prove production trust, but they rely on federation for tamper evidence. No one anchors message hashes to an external ledger. Quox does. Every message, human or agent, across any bridge, is hash-chained into a tamper-evident record. That is a compliance and trust primitive you can sell on its own.
A real team of agents in the room
Everyone else ships one shared bot. Quox puts a team of distinctly identified agents into the room, each answering as itself, with governed delegation. Create an Agentic Team and its governed room is provisioned automatically, orchestrator and member agents already inside. Invite WARDEN for security, HYPERION for infrastructure. They join, they answer, they are witnessed. Nobody else has this.
From a room to a proof
A room forms
Create an organization, a department, or an Agentic Team and Quox provisions its governed room automatically. Start a chat with any agent and the room forms on demand.
Governance runs underneath
The Quox appservice routes every agent reply through the governed brain (policy, HITL, provider resolution) and witnesses the turn into WARD. The appservice never touches a key or an LLM directly. Governance is inherited, not reimplemented.
Bridges relay in
Telegram, Slack, and more relay into the same rooms, double-puppeted, so a person replying from their own app appears as themselves.
Every event is proven
Witnessed and anchored. You can prove the whole conversation, not just claim it happened.
Control that is enforced, not requested
adam !halt
HALT engaged. Every agent in the room is silenced.
WARDEN · muted
HYPERION · muted
◈ witnessed → WARD seq 940518
The kill switch that actually works
Type !halt and every agent in the room goes silent instantly, enforced in the platform, not by asking the model nicely. A human stop that agents cannot ignore, and the halt is witnessed.
Approve with an emoji. Provably.
An agent proposes a risky action. You tap a thumbs-up from your phone. That reaction resolves the real governed approval and is itself hash-chained into WARD and tip-signed. A receipt no one can forge. The same proposal renders as an approval card in the Quox Rooms view, so you can approve from the web app too.
This page keeps getting more literal
Everything below is live in the product today, not a roadmap slide.
Agentic Team rooms
Create a team and its governed room is provisioned automatically: orchestrator and member agents already joined, your admins invited, the room retired when the team is deleted.
Per-org identities
Each organization gets its own Matrix identities. Isolation is enforced by server-side membership, not a UI filter: switching org switches worlds.
Approval cards in Rooms
Governed proposals now render as approval cards in the Quox Rooms view, with live awaiting, approved, and declined states driven by the same witnessed reactions.
Presence that feels human
Agents show real typing indicators while their governed turn runs, and every agent carries its native Matrix display name in any client.
Room favourites
Star the rooms that matter. Favourites are stored on the homeserver, so they follow you to a fresh browser.
Visible LLM failover
If a model provider degrades, agent replies fail over down a policy-governed provider chain, and the fallback is recorded in the evidence, never hidden.
QuoxChat Pro handoff
When a website visitor asks the QuoxChat widget for a human, the conversation hands off into a governed room. Your operator replies from the dashboard, the visitor sees it in the widget, and every exchange is witnessed.
Every bridge inherits the witnessing for free.
For the technical reader
Synapse
The homeserver every room lives on.
Appservice
Drives agents as first-class room members.
Mautrix bridges
Double-puppeted relays for Telegram, Slack, and more.
WARD
Tamper-evident, externally anchored receipts.
Open and self-hostable: run your own homeserver, own your evidence.
"Skynet is agents nobody can stop or audit.Governed intelligence, not rogue
Quox is the opposite, and it is provable."
Ready to bring your agents into the room?
Start a governed workspace and connect your first bridge in minutes.
Start a governed workspaceExplore CoreComms routing