Platform · Build · The role

AI Employees

Every AI tool you've adopted waits to be prompted — and prompting is work, which is why the pipeline still belongs to a person. Real functions need an owner: someone who holds the queue, remembers yesterday, and can be delegated to and held accountable. Headcount-shaped work needs a headcount-shaped worker. An AI Employee is that worker — with a mandate, memory, a dialed autonomy scope, and an audit trail.

Hire your first employee See them in packs
At a glance
  • What it isan owner, not a tool
  • Delegate bychat · schedule · event
  • Its handsagents · tables · KBs · tools
  • Memoryshort · working · long-term
  • Autonomy4 scopes, 1→4
  • Writesauthorized at call time
  • Every actionlogged, config-pinned
IN A SOLUTION PACK

In a pack, the employee arrives hired: role, autonomy scope, and approval gates already set.

See Solution Packs →
app.turtlecoworker.com/employees/workspace
The AI Employee workspace: the conversation column with an in-flight delegated task, and the work rail showing live task progress, the task history, and the memory pane
The workspace: the conversation on the left, the employee's live state — tasks, progress, memory — on the right.
Why it's built this way

Tools wait to be prompted.
Work needs an owner.

A prompt-driven tool does exactly one unit of work, then forgets you. The pipeline — the watching, the chasing, the remembering, the reporting — stays with a person, because the tool can't hold anything. That's why AI adoption saves minutes without ever freeing a role.

An AI Employee is built to hold things: a standing mandate, a memory that persists, triggers that watch for work arriving, and a reporting habit. Delegation replaces prompting — and accountability comes with it, because every action it takes is scoped, gated and on the record.

Why teams switch

Most AI is a tool you operate task-by-task: you drive every step, and it forgets you the moment you close the tab. An AI Employee is delegated to: it owns its pipeline, plans its own work, remembers what it learns, and comes back to you for decisions — not directions.

What most AI tools give you
  • A chatbot that answers one message, then forgets everything
  • You babysit every step: it can't plan or run work on its own
  • It only reacts when you ask; it can't watch for events or run on a schedule
  • All-or-nothing trust: no dial between “suggest” and “do it”
What Turtle AI Coworker gives you
  • Autonomous multi-step work: it plans and executes in the background
  • Three ways in: chat to delegate, schedule a shift, or fire on events
  • Three-tier memory: it accrues institutional knowledge, not a cold start
  • Four autonomy scopes with a runtime floor under every one of them
Time to configure
~30 min
Give it a mandate, grant a few well-described resources, set its autonomy. No code.
Cost to run
Metered
You pay per task and conversation by usage, not a per-seat license.
Effort to operate
Runs itself
It works in the background, fires on schedules and events, and escalates only when it should.
How it works

One worker, three ways in, full accountability.

An AI Employee takes work from a chat, a schedule, or a live event, plans and runs it in the background across your resources, and stays inside guardrails the whole way.

Put it to work: three ways in
Chat
Delegate on demand

Message it like a colleague. It tells apart a quick question from real work: answering now, or planning a task and running it in the background.

Schedule
Shows up for its shift

Put it on a cron, timezone-aware. You approve the plan once; every scheduled run does exactly that reviewed job, never an improvisation.

Events
Watches your stack

Wire it to a tool or a webhook and the event wakes it up: a new lead, an inbound ticket, a closed deal. Guarded by dedupe, filters, debounce & rate limits.

Your AI Employee
plans its own work · runs in the background · asks when unsure
Classify intentPlan the workApprove?Work in backgroundRememberReport back
MemoryShort-termWorkingLong-termgets better the longer it works with you
Autonomy1 · Human-in-loop2 · Supervised3 · Bounded4 · Full
acts through: every grant permission-scoped
Governance · around every run
Write authorization enforced at the moment a tool is calledEvery task, tool call & trigger logged with inputs & outcomeSensitive values redacted before anything is storedNever claims a result a tool didn't confirm
Meet a few employees

Six coworkers you could hire this week.

Each is one autonomous employee, activated a different way: by chat, on a schedule, or by a live event, planning its own work and asking approval on anything risky.

The moment a new lead hits HubSpot, someone should enrich it, qualify it, and draft the first touch, before it goes cold. Nobody's watching the inbox at 2am; Ava is.

01Wakes on the event

A HubSpot “new deal” trigger fires Ava. The event carries the lead as context, guarded by dedupe and a “>$10k” filter.

02Plans and works

She enriches firmographics, scores fit against your ICP, and drafts a personalized email, planning the steps herself, in the background.

03Asks before sending

On Supervised autonomy she stages the send and the CRM write for approval; you approve once and it's logged.

<2 min
from lead-created to a drafted, qualified follow-up, day or night.
Anatomy of an employee

What it takes to own a function, not just run a task.

Eight properties that separate a worker you delegate to from a tool you operate — each one enforced, not promised.

01 · Ownership

A named worker that holds the pipeline.

Tools execute tasks; owners hold outcomes. An AI Employee has a name, a role and a written mandate — the standing instructions that define what it is responsible for, not just what it can do. Your team addresses it like a colleague, and every run, message and record carries its identity, so 'who did this' always has an answer.

  • Name, role and standing instructions: a mandate, not a prompt
  • Personal while you onboard it; Organization when it's ready
  • Its identity on every task, message and audit record it produces
The employee setup: name, role/title, and the standing-instructions field containing a written mandate with @mentioned resources
The mandate: what this worker owns, in writing
02 · Skills

Its hands: agents, tables, knowledge, tools — scoped.

Owning a pipeline takes reach, and reach is exactly what must be governed. An employee's capabilities are four resource groups granted explicitly: the agents it can hand work to, the tables it can read and write (four independent permissions each), the knowledge bases it can search, and the tools it can call. Nothing is implicit; the full inventory of what it can touch is one screen.

  • Agents · Tables · KBs · Tools, each granted per employee
  • Per-table R / C / U / D, Delete off by default
  • One screen answers the security review's first question: what can it reach?
The skills section: granted agents, tables with their R/C/U/D grids, knowledge bases and tools, each with a one-line usage description
The full inventory of its reach, on one screen
03 · Delegation

Three ways to hand it work: chat, schedule, event.

An owner doesn't wait to be prompted. Delegate by chat — one sentence becomes a planned, multi-step task it executes in the background. Put it on a schedule — a timezone-aware cron or a one-time run, and it shows up for its shift. Or wire it to events — an integration event or webhook fires it the moment the business does something, with dedupe, filters, debounce and rate limits deciding what actually wakes it.

  • Chat: delegate in a sentence; it plans the steps itself
  • Schedule: one-time or recurring cron, timezone-aware
  • Events: integration events and webhooks, guarded by dedupe · filter · debounce · rate-limit
The triggers view: a recurring cron trigger with its next-run preview and an integration event trigger showing its filter, debounce and rate-limit settings
Three doors in — every firing guarded and logged
04 · Memory

It remembers yesterday. That's the difference.

A tool that forgets you between sessions can't own anything. An employee runs on three memory tiers: short-term (the live conversation window), working (the context of the task in flight), and long-term (durable facts, preferences and standing instructions that persist across sessions and get retrieved by relevance). The worker you talk to in month three knows what happened in month one.

  • Short-term: the rolling conversation window
  • Working: the active task's context while it executes
  • Long-term: facts, preferences and instructions, retrieved by relevance
The memory pane: long-term memories listed by type (facts, preferences, instructions) with importance markers, alongside the active task's working memory
Three tiers: this conversation, this task, this job
05 · Autonomy

Four scopes, from ask-first to fully autonomous.

Trust in a new hire is earned in stages, and the platform makes the stages explicit. Each employee carries one of four autonomy scopes — Human in the Loop, Supervised, Bounded, Full — with hard caps on actions per task whatever the scope. Start conservative, widen as its record earns it, and narrow it back in one audited move.

  • 1 · Human in the Loop: every task waits for approval
  • 2 · Supervised: writes and deletes wait; reads run free
  • 3 · Bounded: internal work runs free; external actions wait
  • 4 · Full: autonomous execution, still logged and policy-governed
The autonomy control: the four scopes (Human in the Loop, Supervised, Bounded, Full) with the current one selected and the max-actions-per-task cap beside it
The dial: four scopes, hard caps underneath
06 · Runtime floor

Authorization is checked where the action happens.

Approving a plan is not the same as approving its side effects, so the platform separates them. Under every autonomy scope sits a runtime authorization floor: each write is checked at the moment the tool call executes, and an unapproved write does not run — even if a clever prompt or a misbehaving model put it in the plan. Approvals are single-use grants that expire; nothing accumulates quietly.

  • Writes gated at execution time, not on the honor system
  • Single-use grants: one approval releases one action, then expires in 24h
  • The full model, documented: governance and approvals
A task paused at the runtime floor: the held write with its sanitized payload, the reason it was held, and approve/deny controls
A write, held at the floor until a human releases it
07 · Escalation

It knows what it shouldn't decide.

The difference between automation and an owner is knowing where the edge is. When an employee hits something outside its mandate — a dispute, a judgment call, a write above its scope — the task pauses and asks a human, with the full context attached. You answer in chat; the task resumes where it stopped. Nothing is guessed through, and nothing is silently dropped.

  • Human-input requests pause the task and keep its state
  • The ask arrives with context: what it was doing, what it needs
  • Answer in chat; the task resumes, not restarts
A task waiting on human input: the employee's question with the task context attached, and the task status shown as waiting
The edge of the mandate: it stops and asks
08 · Reporting

It reports to you — every morning, and on demand.

An owner accounts for the pipeline without being asked twice. Every task the employee runs is logged step by step, every tool call lands in the audit trail pinned to the config version it ran under, and a daily summary rolls up what it did, what it finished and what's stuck. Ask 'how's it going?' in chat at any hour and it answers from its live task state.

  • Daily summaries: yesterday's work, rolled up per employee
  • Every task and tool call logged and sanitized, config-pinned
  • Ask it for status in chat; it answers from live state, not vibes
The daily summary view: an employee's morning roll-up showing tasks completed, items pending approval, and exceptions raised
The morning report: what moved, what's waiting, what's stuck
One role, worked

An AR coordinator that owns the receivables pipeline.

A scenario: a finance team hires an AI Employee to own collections — a few hundred open invoices at any time, on Bounded autonomy. Here is the role as the system runs it: not a script that fires, an owner that holds the pipeline.

Own
The mandate is standing, not per-task
Its instructions define the role once: keep receivables current, follow the dunning sequence in the collections KB, never contact a disputed account, escalate anything over the threshold. Its reach is scoped to match — the Invoices table (Read + Update, Delete off), the email tool, the collections knowledge base.
Watch
The pipeline wakes it — nobody prompts it
A table trigger fires when an invoice row turns overdue; a morning cron sweeps the aging buckets in the team's timezone. Dedupe and filters keep noise from becoming runs. Every firing is logged with its payload before any work starts.
Chase
It works the queue in the background
For each overdue invoice it plans the steps itself: check payment status, pick the right dunning stage, draft the chase email in the team's voice. On Bounded autonomy the internal work runs free — but every outbound email is an external action, so each send waits at the approval gate for a single-use grant, checked at the moment of the call by the runtime authorization floor.
Escalate
Disputes go to a human, with the file attached
A customer replies disputing the charge. That's outside the mandate — the employee pauses the thread's task, files the dispute, and asks its manager in chat with the invoice history attached. The human decides; the task resumes with the answer. Long-term memory keeps the account's story for next time.
Report
Each morning, the pipeline accounts for itself
The daily summary rolls up the shift: invoices chased, payments confirmed, disputes escalated, sends still waiting for approval. Underneath it, every task, step and tool call sits in the audit trail — sanitized, and pinned to the config version the employee ran under.
The AR coordinator's live state: overdue-invoice tasks in progress, two drafted chase emails held at the approval gate, and one escalated dispute waiting on a human
The pipeline, held: work moving, sends gated, one question for a human
What you can build

If a person would own the function, hire an employee.

AR / collections coordinator

Owns the receivables pipeline: watches invoices, chases overdue payments, escalates disputes, reports each morning.

Support coworker

Answers on web and Slack, searches your docs, opens and updates tickets. Every write is held for review.

Ops coordinator

Runs a nightly reconciliation on a cron, flags exceptions, and drafts the fix for a human to approve.

Sales assistant

Enriches inbound leads, drafts follow-ups, and writes qualified ones to the CRM on your say-so.

Compliance analyst

Triages incoming items against policy KBs, remembers prior rulings, and never commits a write unattended.

HR helpdesk

Answers benefits and policy questions from the handbook KB across a public link, escalating edge cases.

The payoff
3
ways to delegate: chat a sentence, schedule a shift, or let events fire it.
3
memory tiers — short-term, working, long-term — so it gets better the longer it works.
4
autonomy scopes, Human in the Loop to Full, reversible in one audited move.
100%
of tasks, tool calls and trigger firings logged, with writes authorized at call time.
From the live catalog

Built on AI Employees.

All templates
Incident Command And Change Operations Coordinator
AI Employee · Operations

Operations AI employee for service operations, incident triage, stakeholder updates, postmortem preparation, and change risk review. Includes three relational tables, AI-enriched columns, two operations knowledge bases, and four specialist embedded agents.

4 agents3 tables2 KBs
Official · ~25 min
Nova
AI Employee · Marketing

AI Marketing Content Manager

12 agents6 tables3 KBs
Official · ~20 min
Raj Coordinator
AI Employee · Sales

Sales operations AI employee for pipeline reviews, prospect research, lead qualification, email drafting, and handoff coordination. Includes embedded deals/prospects tables, a sales playbook KB, and three specialized agents.

3 agents2 tables1 KB
Official · ~20 min
Maya Employee
AI Employee · Support

Sales Operations Assistant for the B2B sales team. Manages pipeline tracking, prospect research, email drafting, and deal follow-ups. Has access to the Deals and Prospects tables, Sales Playbook knowledge base, and specialized agents for research, email writing, and lead qualification.

3 agents2 tables1 KB
Official · ~12 min
AI Care Coordination Assistant
AI Employee · Healthcare

An always-on care-coordination assistant that supports patient intake and triage, scheduling, insurance eligibility and prior-auth, clinical documentation and coding, referrals, patient education, and denial appeals: always as drafts, suggestions, and guidance for a licensed clinician or staff to approve.

10 agents4 tables3 KBs
Official
AI Claims and Underwriting Assistant
AI Employee · Insurance

An always-on insurance operations assistant that handles FNOL intake, claims triage, coverage verification, fraud and subrogation screening, underwriting risk summaries, renewals, claimant communications, and settlement drafting: always as drafts and recommendations for a licensed adjuster or underwriter to approve.

10 agents4 tables3 KBs
Official
Questions

The details, up front.

How is an AI Employee different from an agent or a team?
Scope of responsibility. A Sequential Agent runs one procedure you invoke; a team answers one conversation. An AI Employee owns a function: it holds standing instructions, watches for the work to arrive via schedules and events, plans multi-step tasks itself, remembers across sessions, and reports on the pipeline it carries. Hire an employee when the job description would otherwise be a person's.
What exactly are the four autonomy scopes?
Scope 1, Human in the Loop: every task waits for approval before it runs. Scope 2, Supervised: tasks with a write or delete step wait; pure reads run free. Scope 3, Bounded: internal work — tables, knowledge, agent calls — runs free, while external integration actions wait for approval. Scope 4, Full: unrestricted autonomous execution, still logged, budgeted and policy-governed. One scope per employee, changeable — and audited — in one move.
If we approve a plan, can it still do something we didn't approve?
No. Plan approval and action authorization are separate floors. Underneath every scope, each write is checked at the moment the tool call executes — the runtime authorization floor — so a step that was never authorized does not run, even if it appears in an approved plan. Approvals are single-use grants that expire in 24 hours unused. The governance page documents the full model.
Does it remember anything between conversations?
Yes — that's the point of hiring rather than prompting. Three tiers: a short-term conversation window, working memory for the task in flight, and long-term memory holding durable facts, preferences and standing instructions, retrieved by relevance when they matter. Long-term memories are visible and editable, so what it 'knows' is inspectable, not mystical.
Can it work without anyone asking?
Yes, two ways. Put it on a schedule — a timezone-aware recurring cron or a one-time run — and it shows up for its shift. Or wire it to events: an integration event or any webhook fires it the moment something happens in your stack, with dedupe, filters, debounce and rate limits deciding what actually wakes it. Every firing is logged with its payload and outcome.
What does oversight look like day to day?
Lighter than managing the work yourself. Held writes arrive in the approvals queue with the reason attached; escalations arrive as questions in chat with context; a daily summary rolls up what each employee did. Behind that, every task, step and tool call is in the audit trail, sanitized and pinned to the exact configuration it ran under.
Next rung on the ladder

Skip the climb: install the whole system.

Solution Packs