An assistant with your files attached knows what you wrote down. Chief knows your business. It reads 118 kinds of live record through your own permissions, changes 18 of them, and puts everything risky in a queue for a person.
Included on every plan, free included · not metered per message · no card required
kinds of business record it can read
it can change, under your permissions
tools it can call in one conversation
of your content used to train third-party models
These are counts of the running product, not estimates: the catalogue of records Chief can reach is a table in the database, and the number above is read from it. We publish no benchmark against other assistants because we have not run one, and a number nobody can check is worth nothing.
Every module in WorkBOS registers its records with Chief. That is why it can answer a question that crosses three of them without you joining anything up first.
drive files, approvals, automations, phone numbers, attendance devices, the audit trail, screen recordings, document templates, industry templates, connected MCP apps
invoices and their line items, bills and what was paid against them, journal entries AND the individual debits and credits inside them, manual entries, the chart of accounts, budgets, tax rates, bank statement lines, credit notes, payments, customer refunds
leads, deals, companies, contacts, activities, clients, proposals, estimate line items, specialist engagements and their reviews
job postings and which of them are published on the careers page, applications, interviews, offer letters, appraisals, payslips, leave, attendance
tasks, projects, portfolios, risks, time entries, ideas
marketing contacts and who agreed to hear from you, segments, email campaigns and how they did, forms, surveys, social posts, QR codes, text campaigns
members, teams, roles, permissions
tickets, replies, assignment
Of those, 18 can be changed by Chief and 11 can be created outright. The rest are read-only to it on purpose: an assistant that can edit your chart of accounts is not a feature, it is a liability.
No prompt engineering. These are the phrasings people use, because the tools were written around the questions rather than the other way round.
Chief reads your workspace live, through your own permissions, and it is not allowed to tell you a total it has not counted or say "there are none" without checking. Ask in your own words, including a vague half-memory of something you decided months ago. It also reads our own release notes, so it knows what is new in WorkBOS the day it ships.
Not a search result you then have to assemble. One question returns the whole situation: open and overdue work, who owns it, what is at risk, what is unpaid, what happened last.
Chief edits reversible fields directly as you: status, name, priority, due date, assignee, description. Money, deletes and approvals are deliberately not available to it. Anything risky becomes a proposal a human approves.
Ask Chief to keep an eye on a record or a whole area. An overdue watch does not send you another notification: it hands the work to the agent that covers that area, which proposes actions into the normal approve-first queue. You hear directly only when the agent could not deal with it.
Connect any app that offers an MCP server (Integrations, Connect an MCP app) and Chief can use its tools: it looks things up in that app straight away, and anything that would change the other app is filed for a person to approve first. Whatever the app answers is treated as outside information, never as an instruction. Rolling out gradually, from Pro upwards.
Corrections, preferences and durable facts are saved permanently, private to you or shared with the workspace. Teach Chief a report you keep asking for and it becomes a named skill an admin approves once and anyone can run.
A branded report you can open, print or send: project status, a client QBR, the pipeline, a finance summary, or what your agents have actually been worth.
Not a roadmap. Each of these is a tool it can call, an agent it can hand work to, or a record it can create.
Built, shipped and in use. These are being switched on workspace by workspace; until one reaches yours, it simply is not there yet, and Chief will tell you so.
Attach a picture or a PDF, or take a photo on your phone, and Chief reads it in that message. It says what it found and proposes the record, such as an expense claim with the amount, date and currency, and saves nothing until you say yes. Files are checked for viruses, read for that one message and deleted, and text inside a file can never give Chief an instruction.
"Do this and tell me when it is done", or "every weekday at 9, brief me on what is due today". A task runs as you, with your permissions, changes only what you asked it to change, and tells you when it has finished. The answer and every step it took are on the Chief tasks page.
A natural voice you can talk over, in English or Urdu, that stops the moment you speak. Everything about your work still goes through Chief with your own access, so it can do exactly what typing can and nothing more.
Switch off what Chief may do for the whole workspace (change records, drive the screen, talk, live voice, background work, outside apps, files) and see every step it took, with a CSV download. The switches are enforced on our servers, not just hidden on the screen.
Chief is the one you talk to. Behind it sit specialist agents with their own granted tools, their own autonomy level and their own spend ceiling, covering work, CRM, people, money and support. Ask Chief for something big and it decomposes the goal into steps and files them with the agent team for a person to approve. Nothing executes until somebody says yes, and every proposal is dry-run against your live data first so one that would fail never reaches your queue.
An assistant on your accounting is only worth having if you can say exactly what it is not allowed to do.
Every read and every write runs through your own row-level security and your own per-page permissions. Chief cannot see a record you cannot see, and it cannot change one you are not allowed to change. There is no elevated path and no service account behind it.
Money fields, deletions and approvals are not available to it at all. It can draft an email or a Slack message: where sending from WorkBOS is switched on for that app, the draft waits in the Outbox for an owner or admin to approve it, and otherwise you send it yourself. Nothing leaves your workspace from a chat window.
Chief is not permitted to say "there are none" or state a total unless it has actually run the count. If it has not looked, it says it has not looked. This is enforced in the prompt and in the tool contract, because a confident wrong number is worse than no answer.
Chief knows the page you are on, the record you have open and the rows you ticked, so "this" and "these" work. It looks the record up itself through your own access, it never reads passwords, card or account numbers, and nothing about your screen is stored. One click turns it off.
It does not browse the web, so it is forbidden from saying it "looked at" a page or a site it cannot reach. Where it cannot see, it tells you what it would need.
Each step shows as it happens, with a Stop button. Stop halts it before the next step; anything already done stays done and is listed.
Content is sent to the configured AI provider only to produce the output you asked for. That commitment is published on our privacy page, and every AI provider we route to is named on our subprocessor list, which is the page to check rather than taking a marketing sentence for it.
A workspace can carry a daily AI budget in dollars. At the budget, the on-request helpers pause politely until the next day and everything that needs no AI keeps working. Agents carry their own caps on runs, tokens and dollars, per day or per month.
Pause all agents is one control, and the assistant connector for outside AI clients has its own workspace-wide write kill switch.
Proposals and actions are logged with who, what and when, and an executed action can be rolled back in one click. The append-only audit log itself is an Enterprise capability, and saying so is more useful to you than implying every plan has it. There, a change Chief made with its own tools shows "via Chief" beside the person’s name, signed by our servers and checked by the database, so nobody can pass their own edit off as Chief’s.
The full detail is on security, privacy and the subprocessor list.
Every page like this one lists capabilities. This is the part you would otherwise find out in week three.
Chief works when somebody asks. Anything that keeps running is something a person set up and can see and stop: a watch, an automation, an agent, or a routine on the Chief tasks page where background work has reached your workspace. Nothing keeps running because a conversation drifted there.
No amounts, no postings, no payment runs, no approvals. It will draft an invoice or a journal entry for a person to approve, and it will tell you which page to open. That line is in the tool definitions, not in a policy document.
It answers from your workspace and the product documentation. It is not a research assistant with your data attached.
Its creator, the person it escalates to, and workspace owners and admins can all see it. We would rather say that than let you discover it.
A general assistant with your files knows what you wrote down. Chief knows your ledger. It reads live records across 118 kinds of business object - invoices, journal entries, leave requests, deals, attendance, the audit trail - through your own permissions, and it can change 18 of them. The difference is not the model. It is that the answer comes from the system of record rather than from a copy of it, and that acting on the answer happens in the same place.
No. Our published privacy policy states we do not use your workspace content to train third-party AI models. Content is sent to the configured AI provider only to generate the output you asked for. Every provider we route to is named on our subprocessor page, and if you configure your own model endpoint, that provider processes your requests under your agreement with them and is not our subprocessor at all.
Chief is not a separate plan. It is included on every plan, free included, and it is not metered per message. AI use draws on your workspace’s AI credit, which every workspace is given a small amount of to start and which is shown on the Billing page; an empty balance does not pause anything today. A workspace can also carry a daily AI budget in dollars, and the Free plan carries a monthly cap on agent runs. If you would rather not depend on our provider at all, you can point the workspace at your own model endpoint.
It can change reversible fields on a record you are already allowed to change, such as a status or a due date, and it tells you it did. Everything else is a proposal that sits in an approval queue until a person accepts it, and every proposal is dry-run against your live data first so a suggestion that would fail is rejected before it reaches you. Executed actions roll back in one click.
Memories you save are scoped: a user memory is yours, a workspace memory is shared and is labelled as such when you save it. Watches are visible to their creator, whoever they escalate to, and owners and admins. We would rather state that plainly than let you assume otherwise.
It says so. Chief is not permitted to assert that something does not exist without having counted, or to claim it checked a page it cannot reach. The most common failure mode of an assistant on business data is a confident wrong total, so the design choice was to make that specific answer unavailable to it.
Yes. WorkBOS is itself an MCP server, so Claude, ChatGPT or Cursor can be pointed at it and read your workspace through the same row-level security and role rules a person gets, using a key the workspace issues and can revoke. It is included from Pro upwards and there is a workspace-wide kill switch for writes.
Yes. A workspace can configure its own model endpoint, in which case your requests go to your provider under your contract. The approval queue, the audit trail, the rollback and the spend ceilings are ours and work either way.
Yes to talking, today: press Talk in the Chief box and have a conversation, interrupting it whenever you like, in Chrome, Edge, Safari or Firefox. Live voice, a natural voice you can talk over, and reading the pictures and PDFs you attach, such as a receipt or an invoice, are being switched on workspace by workspace. From a file, Chief shows you what it read and saves nothing until you say yes.
Yes. Chief reads our own release notes, so you can ask it what is new, or whether WorkBOS can do something, and it answers from what has actually shipped, with the date. When a note says a feature is being switched on gradually, Chief says so too.
It does not act on its own initiative, it cannot move money, it cannot browse the internet, and it cannot send an email without a person approving the draft. Those are deliberate and they are listed on this page rather than discovered later.
Free for up to 5 seats. Chief is there on the first day, on your real data, with the same permissions you have.