# GembaOS > GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC. Three languages, each written for its own market (not translated). Every page below also exists as Markdown at the same path with `.md`; `llms-full.txt` in each language directory holds that language in full. ## English > GembaOS is a zero-trust governance runtime for enterprise AI agents: policy-decided access, single-use clearance tokens bound to exact parameters, and accountable human approvals, running on-premises or in a private VPC. - [GembaOS — Put AI agents to work. Keep control.](https://gembaos.dev/en/): A governance runtime for enterprise AI agents. Policy-based access, single-use clearance tokens and accountable human approvals. On-premises or in your private VPC. - [FAQ](https://gembaos.dev/en/faq/): What enterprises ask before putting AI agents under GembaOS: SOPs, existing LangGraph or Dify agents, approval speed, data residency, tampering and the pilot. - [Glossary](https://gembaos.dev/en/glossary/): The fifteen terms GembaOS uses to govern AI agents, each defined once: work item, approval request, clearance token, signature chain, gap register and more. - [Design partner program](https://gembaos.dev/en/design-partner/): A six-week pilot of one real workflow under GembaOS: define the boundary, connect and verify, shadow mode, tiered release. Who it is for, what we bring, the terms. - [Privacy notice](https://gembaos.dev/en/privacy/): What the GembaOS website collects and what happens to it: no cookies, no tracking; contact-form entries stored on our own server and forwarded to our team by email. - [Changelog](https://gembaos.dev/en/changelog/): What changed in GembaOS, month by month, with the decision number and the date: engineering facts from the runtime's own decision record, redacted. v0.2. - [Security & deployment](https://gembaos.dev/en/security/): How GembaOS keeps AI agents inside a boundary you can inspect: your own infrastructure, gateway-held credentials, clearances bound to arguments, hash-chained audit. - [Keep your CRM, add the decision record](https://gembaos.dev/en/scenarios/crm/): A CRM-resident agent keeps updating cases; actions that leave the CRM get a human decision signed outside the vendor, executed once, written back as a comment. - [Cross-team work with responsibility attached](https://gembaos.dev/en/scenarios/cross-team/): Work moving between HR, IT and their agents keeps one record and one owner: a persistent work item, separation of duties, a batch signed once, executed row by row. - [Refunds under an approval limit](https://gembaos.dev/en/scenarios/refunds/): A customer-facing agent resolves refunds while the Delegation of Authority decides which cases pass automatically and which need finance sign-off, executed once. - [Production changes without a standing key](https://gembaos.dev/en/scenarios/it-ops/): An IT operations agent investigates incidents and drafts changes while every privileged action goes through change approval and executes once under a clearance. - [llms-full.txt](https://gembaos.dev/en/llms-full.txt): the whole English site as one Markdown file ## 日本語 > GembaOS は、AI エージェントを職務権限規程・稟議・監査のもとで運用するための実行基盤です。ポリシーによる権限判定、パラメータに紐づく一次性許可証、人の承認記録を、オンプレミスまたはプライベート VPC 上で提供します。 - [GembaOS — AI を現場へ。権限は、組織の手に。](https://gembaos.dev/ja/): GembaOS は、AI エージェントを職務権限規程・稟議・監査のもとで運用するための実行基盤です。ポリシーによる権限判定、パラメータに紐づく一次性許可証、人の承認記録を、オンプレミスまたはプライベート VPC 上で提供します。 - [よくあるご質問](https://gembaos.dev/ja/faq/): AI エージェントを GembaOS のもとで本番運用する前に寄せられるご質問への回答。手順書の未整備、LangGraph・Dify との併用、稟議の速度、データの所在、パラメータ改ざん、6 週間の先行導入。 - [用語集](https://gembaos.dev/ja/glossary/): GembaOS が AI エージェントの統制に使う 15 の用語を一度だけ定義します。作業票、稟議書、一次性許可証、押印チェーン、職務権限規程、不足台帳、監査再生、正式回答など。 - [更新記録](https://gembaos.dev/ja/changelog/): GembaOS の変更を、決定番号と日付とともに月ごとに公開します。実行基盤自身の決定記録から、内部パス・人名・顧客名を除いた工学上の事実です。2026 年 9 月、v0.2。 - [個人情報の取扱い](https://gembaos.dev/ja/privacy/): GembaOS のウェブサイトが収集する情報と、その扱いについて。Cookie なし、追跡なし。お問い合わせフォームの入力内容は当社のサーバーに保存し、担当者へメールで通知します。Lux Mentis Limited、2026 年 9 月。 - [先行導入パートナー](https://gembaos.dev/ja/design-partner/): 貴社の実際の業務一つを GembaOS のもとで 6 週間かけて検証する先行導入プログラム。境界の定義、連携と検証、シャドーモード、段階導入。対象企業、当社が用意するもの、条件。ご相談は無料。 - [セキュリティと導入形態](https://gembaos.dev/ja/security/): GembaOS が AI エージェントを確かめられる境界の内側に置く仕組み。自社インフラ上の単一バイナリ、ゲートウェイが保持する認証情報、引数に紐づく許可証、ハッシュチェーンの監査記録。2026 年 9 月時点。 - [CRM はそのまま、決裁の記録だけ足す](https://gembaos.dev/ja/scenarios/crm/): CRM 内のエージェントに個案の更新を任せたまま、CRM の外へ出る操作(返金、赤伝、クローズ)にはベンダーの外で人が押印し、一度だけ実行し、決裁を個案へコメントとして書き戻す方法。導入前後の違い、手順、実機画面。 - [部門をまたいでも責任が残る一括処理](https://gembaos.dev/ja/scenarios/cross-team/): 人事と情シス、そのエージェントの間を動く仕事に、一枚の記録と一人の責任者を保つ方法。持続する作業票、職務分掌、一回の押印で行ごとの許可証により実行される一括処理。導入前後の違い、手順、実機画面。 - [本番変更を任せ、特権キーは渡さない](https://gembaos.dev/ja/scenarios/it-ops/): 情シスが AI エージェントに障害調査と変更案の起案を任せながら、特権操作はすべて変更承認を通し、許可証のもとで一回だけ実行する方法。導入前後の違い、手順、管理ゲート、実機画面。 - [会議の決定を承認済み議事録だけで動かす](https://gembaos.dev/ja/scenarios/meeting/): Teams の字幕を取り込み、SCRIBE が議事録を起案し、主催者が承認し、宿題が承認済み議事録だけを出典に作業票になる流れ。字幕に紛れ込んだ指示文は議事録に残らない。導入前後の違い、手順、実機画面。 - [決裁限度を守る返金対応](https://gembaos.dev/ja/scenarios/refunds/): 顧客対応のエージェントが返金・損害査定の申請を処理しながら、職務権限規程が自動判定と財務責任者の稟議を振り分け、許可証のもとで一回だけ決済する方法。導入前後の違い、手順、実機画面。 - [llms-full.txt](https://gembaos.dev/ja/llms-full.txt): the whole 日本語 site as one Markdown file ## 繁體中文(香港) > GembaOS 是企業 AI Agent 的治理執行平台:以政策判定權限、以綁定參數的單次放行令授權每一個動作、以可追責的簽署鏈記錄人的審批,部署於企業本地機房或私有 VPC。 - [GembaOS — AI Agent 返工,都要過審批。](https://gembaos.dev/zh-hk/): GembaOS 是企業 AI Agent 的治理執行平台:以政策判定權限、以綁定參數的單次放行令授權每一個動作、以可追責的簽署鏈記錄人的審批,部署於企業本地機房或私有 VPC。 - [常見問題](https://gembaos.dev/zh-hk/faq/): 企業在 GembaOS 之下讓 AI Agent 投入工作前最常提出的問題:SOP 未整理、沿用 LangGraph 或 Dify、審批會否拖慢、資料留在內網、參數篡改,以及六週試點。 - [詞彙表](https://gembaos.dev/zh-hk/glossary/): GembaOS 治理 AI Agent 所用的十五個詞,各只定義一次:工單、審批單、放行令、簽署鏈、授權表、代表執行、能力閘道、政策重放、影子重放、黃金測試、審計回放、缺口台賬、變更集、沙箱、正式回覆。 - [更新記錄](https://gembaos.dev/zh-hk/changelog/): GembaOS 每月的變更,附決策編號與日期:來自執行平台自身決策記錄的工程事實,已去除內部路徑、人名與客戶名稱。2026 年 9 月,v0.2。 - [Design Partner 計劃](https://gembaos.dev/zh-hk/design-partner/): 以貴司一個真實工作流程,在 GembaOS 之下進行六週試點:定義邊界、接入並驗證、影子模式觀察、按風險分檔放行。適合哪些企業、我們提供甚麼、貴司需要甚麼,以及條款。諮詢免費;試點範圍與費用另議。 - [私隱聲明](https://gembaos.dev/zh-hk/privacy/): GembaOS 網站收集甚麼、資料會怎樣處理:沒有 Cookie、沒有追蹤;聯絡表單的內容儲存於我們自己的伺服器,並以電郵通知團隊。Lux Mentis Limited,2026 年 9 月。 - [安全與合規](https://gembaos.dev/zh-hk/security/): GembaOS 如何把 AI Agent 留在看得見、查得到的邊界之內:貴司基建上的單一二進制檔案、閘道保管的憑證、綁定參數的放行令、雜湊鏈審計。截至 2026 年 9 月。 - [CRM 照用,補上決策記錄](https://gembaos.dev/zh-hk/scenarios/crm/): CRM 內置的 Agent 繼續更新個案,而離開 CRM 的動作(退款、折讓單、結案)則由人在供應商之外簽章、只執行一次,並以評論寫回個案。導入前後對比、步驟與實機畫面。 - [工作跨部門流轉,責任始終有據可查](https://gembaos.dev/zh-hk/scenarios/cross-team/): 在人事、IT 及其 Agent 之間流轉的工作,如何保持一份記錄和一位可追責的負責人:持續保存的工單、職責分離,以及簽章一次、逐行在各自放行令下執行的批次。導入前後對比、步驟與實機畫面。 - [交付生產變更,不交出無限權限](https://gembaos.dev/zh-hk/scenarios/it-ops/): IT 維運團隊如何讓 AI Agent 排障和草擬變更,同時每個特權動作都經過變更審批,並在放行令下只執行一次。導入前後對比、步驟、控制點與實機畫面。 - [回應客戶,守住審批額度](https://gembaos.dev/zh-hk/scenarios/refunds/): 面向客戶的 Agent 如何處理退款與理賠申請,由授權表決定哪些個案自動放行、哪些需要財務簽署,並在放行令下只執行一次付款。導入前後對比、步驟與實機畫面。 - [llms-full.txt](https://gembaos.dev/zh-hk/llms-full.txt): the whole 繁體中文(香港) site as one Markdown file