How BitSafe Runs, Series Gateway
Company AI becomes useful when it can find the right context, complete permitted work, and leave a result that people can inspect.
That sounds simple. In practice, each part creates a design choice. Company state changes. Evidence sits across several sources. Some steps need judgment, while others should run as fixed rules. A useful system must move work without hiding who owns the decision.
BitSafe built around those choices rather than around one model or interface. Notion holds our shared company state and systems of record. NanoClaw handles bespoke computation, authorized cross-source retrieval, proactive work, and external execution. Deterministic workflows carry repeatable steps that do not need a language model to interpret them again.
As of 26 August 2026, our 22 standard workspace members work alongside 75 active Notion agents. The count matters less than the operating model that keeps the system legible as it grows.
This article is the gateway to that model. It explains how the pieces fit, then points to the deep dives for readers who want the architecture, governance, measurement, or cost detail.
Start with the system of record
AI cannot create dependable company state from scattered hints.
Notion is where BitSafe maintains the records people and agents need to share: projects, tasks, documents, meetings, customer context, ownership, and operating guidance. Relations preserve how those records connect. Status and verification signals help distinguish current guidance from working material or archived history.
This does not mean every piece of company knowledge belongs in one place. Conversations, code, public sources, and specialist systems keep their own roles. Notion holds the collaborative state that the company has chosen to make durable.
That distinction prevents two common failures. The first is asking an agent to infer an official answer from fragments. The second is letting a useful answer remain trapped in a chat after the work is done. When a decision should guide future work, it needs an owner and a durable home.
For BitSafe, the system of record comes before the agent. Better models can interpret ambiguity, but they should not become the organization’s method for resolving basic questions about truth or ownership.
Add an execution layer when the work justifies it
Some tasks fit cleanly inside the workspace. Others need current evidence from several authorized sources, custom code, a scheduled check, or an action in an external system.
NanoClaw handles that second class of work. It can assemble context for a defined task, perform specialized computation, run proactive checks, and use permitted tools outside Notion. Each run starts in a short-lived environment. Durable tasks, approved memory, and company records live outside that temporary execution.
The boundary is deliberate. NanoClaw does not replace Notion as the collaborative record. Notion does not need to absorb every external source or become the runtime for every custom process. Execution and record ownership can differ. NanoClaw may perform the work while the result belongs in a Notion project, document, or customer record.
A good handoff makes that return path visible. It carries the source evidence, result, intended destination, and remaining decision. The receiving system records what changed. If the work crosses an access boundary, the handoff preserves that boundary rather than copying private context into a broader destination.
Keep repeatable actions deterministic
Language models earn their place where interpretation matters. They are a costly and variable way to compare a timestamp, validate a required field, or transform a known format.
We separate judgment from execution. An agent can interpret evidence, classify an unusual case, or propose a next action. A deterministic workflow should perform predictable updates when the rule is already known.
This division improves reliability and cost control. Fixed steps can be tested against expected inputs. Failures are easier to reproduce. Model capacity stays focused on the part of the task that benefits from reasoning.
The operating rule is compact: agents decide where judgment is required, and workflows execute what can be specified in advance.
Use a decision framework, not a tool hierarchy
We no longer describe company AI as a ladder from chatbots to a single superior system. Current tools overlap, and the right choice depends on the job.
We route work through five questions:
Where should the final state live? If people need to review, maintain, or collaborate on the result, name the system of record first.
Does the task need judgment? Use an agent for ambiguity or synthesis. Use a deterministic workflow for a stable rule.
Which sources are required? Keep workspace-bounded work in Notion. Use NanoClaw when the job needs authorized cross-source context, bespoke computation, or external execution.
What is the consequence of the action? Routine permitted work can move within its scope. Destructive operations and other high-risk actions stop for explicit human approval. Other review gates depend on the workflow and audience.
How will we know it worked? Define the expected destination, completion signal, and evidence an operator needs if the handoff fails.
This framework avoids universal claims about autonomy or approval. The control should match the risk. The execution layer should match the work. The result should land where the company can use it.
Governance is part of the workflow
An agent fleet becomes difficult to manage when permissions, ownership, and instructions are treated as setup details.
Each governed workflow needs a narrow job, a responsible owner, and a defined set of sources and actions. Changes to important behavior should be reviewable. High-risk actions need approval rules enforced by the surrounding system, not left to polite prompt wording.
Observability completes the design. Operators need to see what triggered a run, which system owned the task, whether the intended action completed, and where the result landed. A failed handoff should be diagnosable without exposing confidential implementation detail.
Measurement also needs restraint. Activity does not prove value. We look at adoption, workflow maturity, reliability, and bounded cost as distinct signals. Business outcomes require separate evidence. When spend rises without a matching increase in completed work, cost becomes an operating signal that can expose poor routing, repeated retries, or a workflow that stopped making progress.
The goal is disciplined use, not a claim of absolute autonomy.
The infrastructure mindset, applied internally
BitSafe builds decentralized infrastructure for Canton Network. CBTC is the production proof. Decentralization Manager helps teams run applications across independent Canton nodes, using Decentralized Party as the underlying Canton model.
Our internal AI system follows the same broad instinct: build a dependable layer that other work can use. The analogy stops there. Company software has different trust boundaries and failure modes. What carries across is the focus on clear components, explicit control, and inspectable operation.
The durable asset is the operating context around the model. Company records, skills, tools, handoff rules, and review practices remain useful as models and interfaces change. That is the system we are documenting in this package.
Reading map
How BitSafe Runs on Notion
Before You Add AI Agents, Fix the Company They Need to Understand explains why shared operating context comes first.
How We Model a 22-Person Company in Notion covers the minimum useful data model.
Agents Decide. Workflows Execute. defines the boundary between judgment and deterministic action.
We Replaced Salesforce With Notion in Eight Weeks tells the CRM migration story.
How a 22-Person Team Keeps 75 AI Agents Governable explains ownership, permissions, and change control.
How BitSafe Runs on AI
We Built an AI Operating System, Not Another Chatbot makes the case for a custom execution layer and its boundaries.
Every Agent Starts Fresh. The System Still Remembers. explains ephemeral execution and durable state.
We Automated the Automator. Here’s What Still Needs a Human. covers proactive work, recovery, and human responsibility.
The Model Is Replaceable. The Context Is Not. examines the data, skills, and tools around the model.
What Working With a Company-Wide AI Agent Actually Feels Like describes the working relationship between people and the system.
Companion essays
When the Claude App Is Enough, and When It Isn’t offers a practical build-versus-buy threshold.
The Most Important Part of an AI Stack Is the Handoff defines execution ownership and the observable return path.
We Couldn’t Prove Our AI’s ROI. Here’s What We Measure Instead. separates adoption, reliability, cost, and outcomes.
The AI Bill Grew Faster Than the Work. Here’s What We Changed. explains attribution, routing, retry bounds, and spending controls.
Subscribe to the BitSafe newsletter for more field notes from the Canton ecosystem and how BitSafe operates.

