What is an AI agent?
A plain-English guide for owners who already use ChatGPT or Claude and keep hearing about AI agents, operators and agent teams. We call ours an operator. This page covers what it does, what it doesn’t, and where it stops.
How an AI agent differs from ChatGPT
Most people use ChatGPT or Claude as a chat. You ask, it answers, and you take the answer away and do the work yourself. An operator does the work, and three things change.
- It acts. It can run commands, edit files, push commits and send messages, on your own machine.
- It remembers. It keeps a written memory of decisions and context in plain files, so a new session picks up what the last one settled. You can read those files and correct them.
- It runs several jobs at once. A lead orchestrator reads your messages, passes each piece of work to the specialist agent suited to it, and reports back. Several specialists can work at once. That is what people mean by an AI agent team.
You run it from your phone. You send a request on Telegram, and the report comes back there.
What an AI agent can do, and what it can’t
It does the kinds of work it has been configured for, inside limits you set.
- Its specialists are set up for the work your business does, with the routing written down where you can read it.
- In the demo on this site, one working session checks a domain’s email set-up and puts two records live with a check, fixes a website’s privacy and terms pages, finds a hole in a sign-up form, and starts five more jobs that don’t need the owner.
What it can’t do
- Answer while your machine is off. It runs on your machine, so a machine that’s shut down or asleep can’t answer, and it won’t bring itself back unattended.
- Be downloaded like an app. There’s no one-click install and no graphical setup.
- Be right every time. It acts on what you tell it, and it can make mistakes. That’s why the safety gate exists.
Is an AI agent safe? Where it stops
It acts on your behalf, so its limits go in before it is given any real work.
- The safety gate. Every shell command and every file edit passes through it before it runs. A force push to your main branch is refused, and no approval overrides it. A recursive delete or a dropped database table waits until you approve that exact command. Everything else runs, and each action is recorded in an audit log.
- Going live. Before installation we agree which accounts it can touch and what it must never do. In the demo, fixes are made on a draft and go live only when the owner says go.
- Passwords. It doesn’t type them. In the demo, a sign-in asks for a password, and it stops there.
- Who can reach it. Only the Telegram accounts you approve.
- Where the protection ends. The gate is a check inside Claude Code rather than operating-system enforcement, and it hasn’t had an independent security audit. A process started outside Claude Code isn’t checked.
Where your data lives
It isn’t hosted anywhere. It runs on your machine, under your own Claude plan.
The operator can only be reached from Telegram accounts you approve. Beyond that, your information sits in five places.
- On your machine: conversation history, the audit log, the memory and the operator’s rules.
- Kept out of your GitHub backup: the audit log, secrets files and the Telegram bot token.
- With Anthropic: the work Claude does, under your own plan and Anthropic’s terms.
- Through Telegram’s servers: the messages between you and the operator.
- In a private GitHub repository: memory and project files, when they’re pushed there.
How to set up an AI agent for your business
With Chancelry it’s a service, not software you subscribe to. We install the system, configure it for your business and support it afterwards.
- Consultation. We learn how your business runs and whether this suits it. Either side can stop here.
- Scope. We agree what the operator will handle, which machine it lives on, which accounts it can touch, and what it must never do.
- Installation. On your machine. The safety gate goes in before the operator is given anything real.
- Configuration. Specialists, routing, memory and rules, written for your business.
- Handover. You run it from Telegram while we watch it work.
- Support. We stay responsible for it. When something breaks, it gets fixed, and we add a check for that fault.
What do I need before we start? A Mac that can stay on, a paid Claude plan, a Telegram account, and enough comfort with a terminal to follow what’s being set up.
Who it’s for
- Owners and operators who already delegate, and want more of the work handled from their phone, inside limits they set.
- People comfortable in a terminal, who want to see how the thing they rely on works.
- Anyone with a Mac that can stay on, a paid Claude plan and a Telegram account.
Who it isn’t for
- Beginners, or anyone looking for an app to download. There’s no one-click install and no graphical setup.
- Anyone who needs it answering while their own machine is switched off.
- Regulated environments that require an independently audited stack.
Start with a conversation
Tell us how your business runs and what you’d hand over first. If Chancelry suits it, we’ll say so. If it doesn’t, we’ll say that too.