Copilot

Copilot is a persistent workspace inside Kravos.ai. It works alongside your dashboard and organization pages and helps

Copilot

Copilot is a persistent workspace inside Kravos.ai. It works alongside your dashboard and organization pages and helps you read and change platform state with the same permissions, confirmations, and tenant boundaries as the rest of the product.

Availability

Copilot availability is controlled by product and plan gates. The workspace, its navigation entry, and the /copilot route appear only when the product switch and the organization's allowCopilot entitlement are both enabled. If either gate is off, the rest of the dashboard continues to work normally.

What Copilot Can Do

Copilot uses the same first-party platform operations that back the dashboard and Platform MCP. It does not have a separate capability list.

  • Read platform state you already have access to, including agents, sources, media, conversations, skills, tools, MCP servers, credential and API key metadata, usage, and billing summaries.
  • Prepare changes to those records. Writes and destructive operations are prepared as previews and only run after you confirm them.
  • Author and manage skills, built-in tools, custom HTTP tools, and MCP integrations, including the separately confirmed test and activation steps those capabilities require.
  • Create and edit agents directly. A guided support journey is available for common support workflows, but general agent work is not limited to that journey.
  • Answer questions from your knowledge sources, conversation context, and the Kravos documentation.
  • Use scoped web research when an operator enables it for the organization.

Current access only

Copilot acts with your current role, permissions, and resource grants. It cannot read or change records outside your access, and it rechecks current access when a confirmed action runs or replays.

Answers And Citations

Copilot is designed to answer from retrieved evidence, and citations identify the source material it used. Use the citations to verify an answer yourself before acting on it. Citation coverage can be incomplete, so do not treat an answer as correct or complete without checking the cited evidence.

Confirmations

Writes and destructive operations are two-step:

  1. Copilot prepares a preview that shows what will change.
  2. You review and confirm. The proposed platform change is not applied until you confirm; the prepared action itself is recorded so it can be reviewed, replayed, or audited.

Confirmations are tied to the prepared action. Repeating the same decision returns the original receipt instead of running the change twice. Destructive operations also require the matching destructive permission.

Some capabilities keep their own confirmation boundaries. Creating or testing an MCP server or custom HTTP tool does not activate it; test the current configuration first, then confirm activation separately. See MCP Servers and Tools.

Billing

Model-backed Copilot turns are metered as Copilot usage and appear with your other usage and costs. Deterministic non-model operations do not incur model charges. Depending on your setup, model calls use hosted credits or your organization's provider credentials (BYOK). See Usage & Costs, Billing, and Provider Credentials And BYOK for the billing model, credit behavior, and provider ownership.

Privacy And Data Handling

Copilot conversations are tenant-scoped. When you use the secure handoff, the protected values you enter there — credentials, private configuration, signed upload URLs, and file bytes — stay out of model-visible data: they are not model input, tool results, receipts, transcripts, logs, or analytics. Protected values move through secure browser handoffs instead of the conversation.

Do not paste secrets, credentials, or private configuration into free-text messages. Free text you type is part of the conversation and is processed by the model; it is not a protected handoff value.

Retention, export, and deletion follow the organization's artifact and transcript policy. The initial release does not offer permanent thread deletion or raw file-byte export, and it does not apply an arbitrary retention duration.

Web Research

Web research lets Copilot look up current information outside your sources when an operator enables it for the organization. It is scoped to Kravos-related tasks and rejects unrelated use. Research results are cited like other retrieved evidence.

Files And Attachments

File support is conditional. It requires all of the following:

  • the product file switch,
  • the organization's allowCopilotFiles entitlement, and
  • server-verified artifact readiness.

When any of these is missing, Copilot hides file controls and continues to work for text and URL operations. Copilot does not treat a browser flag or a model claim as proof that files are ready.

Files use the shared artifact registry with opaque handles. Uploads are inspected before they become ready; if inspection is unavailable, the upload stays pending and retryable rather than becoming usable. Promoting a Copilot file into a Source or agent workspace is a separately confirmed action. See Sources and Media.

Protected Inputs And Credential Handoffs

Use the secure handoff for credentials and private configuration. Values entered there do not travel through the conversation; the transcript receives only safe metadata and an opaque reference. Do not paste secrets or private configuration into free-text messages. Protected outputs, such as a new key or an upload capability, appear once in an owner-scoped browser flow and are not recoverable from the transcript.

  • Source files, batch files, and bulk ZIP uploads use the protected file handoff described in Tools.
  • MCP credentials and OAuth use the handoff described in MCP Servers.
  • Custom HTTP tools use a reference-only secretRef; the secret is provisioned outside Kravos and is never stored by Copilot. See Tools.

Best Practices

  • review the preview before confirming a write or destructive operation
  • verify citations before acting on an answer
  • keep capabilities attached only to the agents that need them
  • never paste secrets or private configuration into free-text messages; use the secure handoff
  • treat file controls as available only when the file gates and readiness checks are satisfied

Tools

Built-in tools, custom HTTP tools, and the protected input boundary.

MCP Servers

Connect external systems and complete MCP credential handoffs.

Sources

Manage the knowledge Copilot retrieves and cites.

Skills

Reusable instructions Copilot can author and attach to an agent.

Billing

Plans, hosted credits, and organization-level billing settings.

Usage & Costs

Review Copilot and other workload usage and reported costs.

Last updated: September 2026