An assistant with your files attached knows what you wrote down. Chief knows your business. It reads 101 kinds of live record through your own permissions, changes 18 of them, and puts everything risky in a queue for a person.
Included on every plan, free included · not metered per message · no card required
kinds of business record it can read
it can change, under your permissions
tools it can call in one conversation
of your content used to train third-party models
These are counts of the running product, not estimates: the catalogue of records Chief can reach is a table in the database, and the number above is read from it. We publish no benchmark against other assistants because we have not run one, and a number nobody can check is worth nothing.
Every module in WorkBOS registers its records with Chief. That is why it can answer a question that crosses three of them without you joining anything up first.
drive files, approvals, automations, phone numbers, attendance devices, the audit trail, screen recordings, document templates
invoices, bills, journal entries, the chart of accounts, budgets, tax rates, bank statement lines, credit notes, payments
leads, deals, companies, contacts, activities, clients, proposals
job postings, applications, interviews, offer letters, appraisals, payslips, leave, attendance
tasks, projects, portfolios, risks, time entries, ideas
forms, surveys, social posts, QR codes, campaigns
members, teams, roles, permissions
tickets, replies, assignment
Of those, 18 can be changed by Chief and 11 can be created outright. The rest are read-only to it on purpose: an assistant that can edit your chart of accounts is not a feature, it is a liability.
No prompt engineering. These are the phrasings people use, because the tools were written around the questions rather than the other way round.
Chief reads your workspace live, through your own permissions, and it is not allowed to tell you a total it has not counted or say "there are none" without checking. Ask in your own words, including a vague half-memory of something you decided months ago.
Not a search result you then have to assemble. One question returns the whole situation: open and overdue work, who owns it, what is at risk, what is unpaid, what happened last.
Chief edits reversible fields directly as you: status, name, priority, due date, assignee, description. Money, deletes and approvals are deliberately not available to it. Anything risky becomes a proposal a human approves.
Ask Chief to keep an eye on a record or a whole area. An overdue watch does not send you another notification: it hands the work to the agent that covers that area, which proposes actions into the normal approve-first queue. You hear directly only when the agent could not deal with it.
Corrections, preferences and durable facts are saved permanently, private to you or shared with the workspace. Teach Chief a report you keep asking for and it becomes a named skill an admin approves once and anyone can run.
A branded report you can open, print or send: project status, a client QBR, the pipeline, a finance summary, or what your agents have actually been worth.
Not a roadmap. Each of these is a tool it can call, an agent it can hand work to, or a record it can create.
Chief is the one you talk to. Behind it sit specialist agents with their own granted tools, their own autonomy level and their own spend ceiling, covering work, CRM, people, money and support. Ask Chief for something big and it decomposes the goal into steps and files them with the agent team for a person to approve. Nothing executes until somebody says yes, and every proposal is dry-run against your live data first so one that would fail never reaches your queue.
An assistant on your accounting is only worth having if you can say exactly what it is not allowed to do.
Every read and every write runs through your own row-level security and your own per-page permissions. Chief cannot see a record you cannot see, and it cannot change one you are not allowed to change. There is no elevated path and no service account behind it.
Money fields, deletions and approvals are not available to it at all. It can draft an email or a Slack message, and that draft waits for an admin to approve it on the Connectors page. Nothing leaves your workspace from a chat window.
Chief is not permitted to say "there are none" or state a total unless it has actually run the count. If it has not looked, it says it has not looked. This is enforced in the prompt and in the tool contract, because a confident wrong number is worse than no answer.
It does not browse the web and it does not read your screen, so it is forbidden from saying it "looked at" a page. Where it cannot see, it tells you what it would need.
Content is sent to the configured AI provider only to produce the output you asked for. That commitment is published on our privacy page, and every AI provider we route to is named on our subprocessor list, which is the page to check rather than taking a marketing sentence for it.
A workspace can carry a daily AI budget in dollars. At the budget, the on-request helpers pause politely until the next day and everything that needs no AI keeps working. Agents carry their own caps on runs, tokens and dollars, per day or per month.
Pause all agents is one control, and the assistant connector for outside AI clients has its own workspace-wide write kill switch.
Proposals and actions are logged with who, what and when, and an executed action can be rolled back in one click. The append-only audit log itself is an Enterprise capability, and saying so is more useful to you than implying every plan has it.
The full detail is on security, privacy and the subprocessor list.
Every page like this one lists capabilities. This is the part you would otherwise find out in week three.
You cannot tell Chief in chat to "run this every morning". Recurring work is set up as an automation or an agent, deliberately, so that a standing job is something you configured rather than something a conversation created.
No amounts, no postings, no payment runs, no approvals. It will draft an invoice or a journal entry for a person to approve, and it will tell you which page to open. That line is in the tool definitions, not in a policy document.
It answers from your workspace and the product documentation. It is not a research assistant with your data attached.
Its creator, the person it escalates to, and workspace owners and admins can all see it. We would rather say that than let you discover it.
A general assistant with your files knows what you wrote down. Chief knows your ledger. It reads live records across 101 kinds of business object - invoices, journal entries, leave requests, deals, attendance, the audit trail - through your own permissions, and it can change 18 of them. The difference is not the model. It is that the answer comes from the system of record rather than from a copy of it, and that acting on the answer happens in the same place.
No. Our published privacy policy states we do not use your workspace content to train third-party AI models. Content is sent to the configured AI provider only to generate the output you asked for. Every provider we route to is named on our subprocessor page, and if you configure your own model endpoint, that provider processes your requests under your agreement with them and is not our subprocessor at all.
Chief is not a separate plan. It is included on every plan, free included, and it is not metered per message. What is capped is total AI spend: a workspace can carry a daily budget in dollars, and the Free plan carries a monthly cap on agent runs. If you would rather not depend on our provider at all, you can point the workspace at your own model endpoint.
It can change reversible fields on a record you are already allowed to change, such as a status or a due date, and it tells you it did. Everything else is a proposal that sits in an approval queue until a person accepts it, and every proposal is dry-run against your live data first so a suggestion that would fail is rejected before it reaches you. Executed actions roll back in one click.
Memories you save are scoped: a user memory is yours, a workspace memory is shared and is labelled as such when you save it. Watches are visible to their creator, whoever they escalate to, and owners and admins. We would rather state that plainly than let you assume otherwise.
It says so. Chief is not permitted to assert that something does not exist without having counted, or to claim it checked a page it cannot reach. The most common failure mode of an assistant on business data is a confident wrong total, so the design choice was to make that specific answer unavailable to it.
Yes. WorkBOS is itself an MCP server, so Claude, ChatGPT or Cursor can be pointed at it and read your workspace through the same row-level security and role rules a person gets, using a key the workspace issues and can revoke. It is included from Pro upwards and there is a workspace-wide kill switch for writes.
Yes. A workspace can configure its own model endpoint, in which case your requests go to your provider under your contract. The approval queue, the audit trail, the rollback and the spend ceilings are ours and work either way.
It cannot schedule itself from chat, it cannot move money, it cannot browse the internet, and it cannot send an email without a person approving the draft. Those are deliberate and they are listed on this page rather than discovered later.
Free for up to 5 seats. Chief is there on the first day, on your real data, with the same permissions you have.