An agent that finishes the task, not a chat box.
The AiServa AI Agent plans the work, searches, reads, drives a browser, writes files and drafts email, then checks what it did before it answers. It runs on your own AI server, or on a cloud provider only if you add your own key.

How a task actually runs.
The agent works in steps. It writes a plan, calls one tool, reads the result, and decides the next step, for up to 12 tool steps at the default Auto effort, or 6, 18 and 30 at Low, Medium and High. Then it must answer with no more tools.
A tool call is one line of plain text, so any model on any engine can use tools. Native tool markup from models such as DeepSeek and Qwen is understood too.
- 01
Plan as a Checklist
The agent keeps a live checklist of steps, each marked pending, in progress or done, so you can watch the work move.
- 02
Call One Tool at a Time
Search, read a page, drive the browser or search your knowledge bases. Each result is capped at 6,000 characters so one long page cannot crowd out the task.
- 03
Treat Results as Reference Data
Everything a tool returns is labelled reference data, not instructions. Text on a web page that says "ignore your rules" is read, never obeyed.
- 04
Only Claim What Happened
An honesty rule forbids the agent from saying it did something unless a tool result shows it. No invented "I have sent the email".
Built to finish, even when things fail.
Models time out, providers rate-limit and connections drop. The agent is engineered around each of these so a task does not quietly die halfway.
Retries, Then a Backup Model
A call that fails with 408, 409, 425, 429, 500, 502, 503, 504, 520 to 524 or 529, or with a network error or timeout, is retried twice with a backoff of 1 second then 3 seconds, and 2 seconds more on a rate limit. A half-streamed answer is cleared first, so you never see two answers glued together.
If retries fail, your Backup Model answers. It is deliberately not used when it would weaken privacy or quality:
- it is a cloud model behind a local Main Model and the turn carries organisation data;
- the turn has images and the backup cannot read them;
One Turn per Task
Only one answer runs per task. A double send within 15 seconds is refused. Each turn is capped at 16 to 38 model calls, depending on Effort, so it cannot loop forever.
Heartbeat and Recovery
A running turn writes a heartbeat every 30 seconds. If it crashes, it is marked interrupted and Answer Again picks it up.
Stop
is the only thing that ends an answer. A dropped connection does not; the answer keeps going, is saved and reattaches.
5x
automatic continuation when an answer is cut off at the length limit or mid-file, with repeated text removed.
32,768
tokens: the ceiling a thinking model is retried at if it spent its whole budget reasoning. Reasoning itself is never shown.
You decide how much it does on its own.
An agent that acts needs brakes. Each person picks a permission mode in the message box, and every question comes as a card in the task, with the choice to stop asking.
Plan Only
Looks things up and writes a plan. Nothing changes until you press Run This Plan.
Ask Every Time
Asks before every change and every action outside AiServa.
Accept Edits
Changes your own to-dos, calendar and scheduled tasks without asking; still asks before the web browser or an MCP server.
Auto
Works without asking, within what your organisation allows, with a Safety Check on actions you did not clearly ask for.
Answers That Stick
A question offers Allow Once, Allow for This Task, Always Allow or Deny. After Deny the agent never tries the same thing another way; it finishes the rest and says what was not done.
Rules and Spending Limits
Administrators allow, ask about or block any tool, add an instruction to every task, and set monthly and per-task spending limits for cloud models.
Emergency Stop
One switch pauses every action for everyone in the organisation, on the web, in scheduled tasks and in AiServa Desktop, until an administrator lifts it.
Sub-Agents for the Heavy Parts
For work that needs many searches or careful checking, the agent hands one part to a Researcher, an Analyst, a Reviewer or one of your organisation's own sub-agents. Each works with a fresh context and read-only tools, and only its report comes back.
The toolbox, with its real limits.
Every tool has a published cap. Limits are what keep an agent predictable, so we list them.
What the Browser Refuses
Card, CVV, one-time-code and file fields are never filled. A sign-in password is typed only if your settings allow it, and is masked everywhere. Private addresses such as localhost and .local are always refused, and plain lookups are sent to web search instead.
MCP Servers Too
Your organisation's MCP servers appear as tools as well. One set to Ask Before Every Use asks you first; scheduled tasks and API tasks use only those set to No Need to Ask. How MCP servers work.
Smart Routing: helpers for the hard parts.
Your Main Model does not have to be good at everything. With Smart Routing on, Helper Models take the jobs it cannot.
- Vision Helper
- Reads images and scans that the Main Model cannot see, and hands back the text.
- Long Document Helper
- Splits a long document into parts of 40,000 characters, up to 8 parts, so about 320,000 characters can be worked through.
- Knowledge Helper
- Searches your knowledge bases, keeps only passages above a relevance floor and cites them by number.
Frameworks: LangChain and LangGraph, Optional
If your team standardises on LangChain or LangGraph, the agent can run on them instead of the built-in AiServa Agent Loop.
- A Framework Worker runs on your own AI server and listens on loopback port 8769 only.
- Its packages are hash-locked and it runs in its own environment.
- LangSmith and LangChain tracing and telemetry are forced off, and API-key variables are removed.
- LangGraph only decides the next step. It never sees keys, model text, tool results or files; AiServa runs every model call and tool with its own checks.
- If the worker is missing or fails, the turn continues on AiServa and the answer says so.
Memory that is yours, and refuses secrets.
Like memory in ChatGPT or Claude, the agent learns your preferences over time. Unlike a shared system prompt, your memory is private to you.

Six Layers, Nearest Last
- 01
Platform: up to 50 entries
- 02
Organisation: up to 100 entries
- 03
Department: up to 50 entries for each department
- 04
Project: up to 50 entries for each project and its members
- 05
Agent: up to 50 entries for AI Agent and Browser Controller
- 06
User: 200 memories of 300 characters: About You, Preference, Instruction, Work
A higher layer can switch off the layers below it.
Recall Without Guesswork
Up to 60 memories are all sent. Beyond that, the most relevant are chosen: pinned first, then instructions and preferences, matched by meaning with your own embedding model and by shared words, recency and use. A fact or piece of work can be shared with a colleague for up to 90 days.
Secrets Refused
Passwords, PINs, one-time codes, CVVs, card numbers, API keys and tokens are never saved.
Injection Guard
After reading outside content, an automatic save happens only if at least 60% of its words came from you, so a web page cannot plant a memory.
Summaries and Past Tasks
Each task keeps a 120-word summary, and up to 3 related past tasks are recalled. "Remember", "ingat", "jangan lupa" and "lupakan" all work.
You control it all: switch memory, auto-save or history off, and pin, edit, delete or delete everything. Only you can make it forget.
Around every task.
Agent Runs
Admins see where each run came from (User Portal, Client Portal, Scheduled Task, API, AiServa Desktop or Chrome Extension), its status, tool calls, questions, refusals, retries, tokens and cost, with 7-day totals. Only what the system did is logged; the words of a task are never shown.
Task Summary
A summary of the task beside it, written for you, with What AI Agent Did (steps, files, emails and questions, from AI Agent's own records), plus Done, Still Open and Next Steps. Its files are ready to save to a knowledge base, zip or email.
Web Browser Panel
A side panel with tabs and an address bar. An HTML file the agent writes opens there as a live preview, with a tab for the code, and pages open in a sandbox.
Commands
Type /name to run a saved prompt, with $ARGUMENTS filled from what you type after it. Personal, organisation and platform commands; /browse forces the browser.
Part of the working day, not a side window.
The same task screen holds the panels people open all day. Each one is opened from the toolbar, and the agent can read and change them when you ask.
To-Do Lists
Lists with steps, due dates and a Recently Deleted bin that keeps items for 30 days. Ask the agent to add, tick off or move a to-do, and it checks your list before it answers a question about your plans, deadlines or reminders. Reminders arrive in the Notification Center, and by email if you switch that on.
Calendar
Timed and all-day events that repeat daily, on weekdays, weekly, every two weeks, monthly or yearly, with same-organisation invites and Yes, Maybe or No replies. Day, Week, Month, Agenda and Year views, outside guests invited by email, calendars shared as Free/Busy, Details or Edit, and Find a Time across colleagues. Export to .ics, PDF, Excel or CSV, email a schedule or save it to a knowledge base. Use the built-in calendar, a connected one such as Google Calendar through an MCP connector, or both.
Voice Dictation
Speak a prompt instead of typing it. It is off until your administrator switches it on. The default Speech Reader transcribes on your own AI server, AiServa keeps no audio and nothing goes to a third party; the alternative uses the browser's own speech engine, which is Google's in Chrome and Apple's in Safari, and the settings page says so. With the Speech Reader the language is detected from what you say.
Quotations, Orders and Invoices
Describe the sale in plain words and the agent produces a quotation, sales order, invoice, purchase order, delivery order or credit note as a PDF on your letterhead. Document numbers and every total are worked out by the server, not the model, and next-step cards let you turn a quotation into an order in one tap.
Tasks You Can Tidy
Rename, pin, archive or delete a task from its menu, and bring archived ones back from Archived Tasks. Copy or edit any message you sent; editing rewinds the task to that point.
Scheduled Tasks
Say "every Monday at 8:00, summarise last week's approvals" and the agent sets it up. Each run happens as you, in a new task, daily, on weekdays, weekly, monthly, once, or when something happens such as an approval being decided. Scheduled tasks only read until you allow actions for them.
A Message Box That Keeps Up
Permission mode and Effort sit in the message box, next to the model. Paste a screenshot, photo or PDF anywhere on the page to attach it, and type / to run a command or a skill.
Keyboard Shortcuts
Option or Alt with Shift plus R, P, A or Backspace renames, pins, archives or deletes the open task, and arrow keys move through the list. Press Command or Control with a slash to see them all.
Tools are per person.
Each person has a Tools They Can Use list, set by role and adjustable per person. The agent only offers tools that person is allowed, and only tools that are actually set up and working.
AI Agent Questions
Is the AiServa AI Agent a chatbot?
No. A chatbot answers one message at a time. The AI Agent plans the task as a checklist, calls tools such as web search, a web page reader, a browser, knowledge search and file creation, reads the results and keeps going for up to 12 tool steps at the default effort until the task is done, then gives you the result.
Which models can run the agent?
Any chat model you connect: an open-weight model on your own AiServa server, such as Qwen, Gemma, gpt-oss, Llama, DeepSeek-R1 or Mistral, or a cloud model through your own API key. Tool calls are plain text, so the agent does not depend on a provider having native function calling.
What happens if the model or provider fails mid-answer?
The request is retried on common temporary errors such as 429, 500, 502, 503 and 504, with a short backoff. If it still fails, your Backup Model answers instead. A crashed turn is marked interrupted and can be answered again with one press.
Does closing the browser stop the answer?
No. Only the Stop button stops an answer. If your connection drops, the answer keeps running on the server, is saved, and the page picks it up again when you return.
Can the agent send email or buy things on its own?
Email is drafted as a card that you send yourself, unless you ask it to send to addresses you typed in that task. The Browser Controller never fills card or one-time-code fields, types a password only if you allow it, and asks Allow or Skip before any click that could buy, pay, send, submit or delete.
What does the agent remember about me?
Only what you or the agent save to your private Memory, up to 200 short memories, plus the shared memory your organisation, department or projects set for everyone in them. You can see, pin, edit and delete every personal memory. Passwords, card numbers, keys and tokens are refused and never saved.
Can admins read what people ask the agent?
No. Agent Runs records what the system did, such as retries, tool steps and timings, so admins can see reliability. It does not show the words of anyone's task.
Can the agent manage my to-dos and calendar?
Yes. The To-Do Lists and Calendar panels sit beside every task. Ask the agent to add, complete, book or move something and it does, and it checks both before answering a question about your day. The calendar can be the built-in one, a connected one such as Google Calendar through an MCP connector, or both.
Can I dictate to the AI Agent by voice?
Yes, once your administrator switches Voice Dictation on. The default Speech Reader transcribes on your own AI server and AiServa keeps no audio; the other option uses your browser's speech engine, which sends audio to Google in Chrome or Apple in Safari. It types a prompt for you; it does not transcribe recorded meetings.
Can I control what the agent does without asking?
Yes. Pick a permission mode in the message box: Plan Only (it looks things up and writes a plan, then changes nothing until you press Run This Plan), Ask Every Time, Accept Edits (changes your own to-dos, calendar and scheduled tasks, asks before the browser or an MCP server) or Auto. Questions offer Allow Once, Allow for This Task, Always Allow or Deny. Administrators can add Rules, Spending Limits and an Emergency Stop that pauses every action for everyone.
What if the agent needs details only I know?
It asks with one form instead of a string of questions: pick a customer, tick items and quantities with their prices, choose a date or type an email address. The task waits for your answer, up to 15 minutes, and carries on as soon as you press the button. It never asks for something you already said.
Does my data leave my server?
Work stays on your own AiServa server when you use a local model. Cloud providers are only used if your organisation adds its own key, and the Backup Model is never allowed to send a turn with organisation data to the cloud when your Main Model is local.
Give the agent a real task.
Create a workspace, connect your own AI server or cloud key, and hand the AI Agent a job your team repeats every week. Free for 14 days with every feature.