Every source you already have, unified into one knowledge graph that knows who may see
what and what was true when. Ask anything in plain English; the answer comes back cited,
trimmed to your permissions before the model sees a token, and correct for the date you asked about.
Ask › Who owns billing integrations?Search or ask the brain…⌘KScoped to Leadership
Permission-aware memory for AI agents
Ask your company anything.
Who owns billing integrations?Ask
What changed in pricing this quarter?Who approved the SOC 2 policy?On-call for payments
Q. Who owns billing integrations?✓ Cited · permission-checked · as of 17 Jul 2026
DODana OkaforPlatform team · owner of record since the Q2 reorg
Dana Okafor owns billing integrations end-to-end on the Platform team, including the Stripe and Chargebee connectors and the on-call escalation for the service.[1] Ownership transferred during the Q2 platform reorg and is reflected in both the current engineering handbook and the pinned routing note in #billing.[2] One older PagerDuty rotation still lists a former owner — flagged as a contradiction rather than silently overwritten.
1Notion · Eng Handbook § Ownership2Slack · #billing pinned · Jul 14Scoped to leadership
Value / yr▲ 8.4%
$1.2M
▲ $94k vs last quarter
Freshness4 stale
94%
1,180 of 1,256 sources < 24h
Contradictions3 open
3
▲ 1 new this week
Questions / wk▲ 22%
1,204
▲ 214 agents + people
Knowledge graphOpen explorer →
DODana Okafordana@northwind.co
Actual product, July 2026. Sample data — plausible internal content, not a customer's.
Eight connectors over OAuth
You approve on their site. Two minutes.
Slack
Notion
GitHub
Google Workspace
Linear
AWS
GCP
Azure
…or describe any other tool
slashh stores the token encrypted and pulls the first batch straight away — then re-syncs on
its own cadence: cloud accounts every 6 hours, everything else every 2. Queued, rate-limited,
backed off when a credential breaks. Nobody clicks refresh.
Anything else? Describe it in plain English and slashh proposes the REST or MCP wiring for you to confirm.
The whole product in one interaction
Ask your company anything. Get an answer you can check.
Retrieval is trimmed to what you may see, the answer streams back with every asserted fact
bound to a source, and you can open any of them. Hover a citation chip to see the sentence it came from.
Live in this page — the same shape as the real answer, running from a small fixture
asked as dana@acme.com · finance, leadership·as_of today·retrieval trimmed before the model sees a token
Ask something else
One diagram, five stages
Eight systems in. One cited answer out.
Keep scrolling. The diagram builds itself as the notes explain each stage — the eight sources,
the edges pulling inward, the graph where every fact carries two clocks, the permission
membrane closing, and finally one question in and one cited answer out.
Stage 01 — sources
01 Sources
Eight systems, and no shared map between them
Slack, Notion, GitHub, Google Workspace, Linear, AWS, GCP and Azure. Each one holds part of every answer your company has already worked out; none of them holds the whole thing, and nothing can query across them. Anything not on the list: describe it in plain English and slashh proposes the REST or MCP wiring for you to confirm.
Slack
Notion
GitHub
Google Workspace
Linear
AWS
GCP
Azure
8 connectors over OAuth · you approve on their site · tokens stored encrypted
02 Edges
Everything pulls toward one place — and keeps pulling
You authorize once. After that a scheduler re-syncs every connection on its own cadence: cloud accounts every 6 hours, everything else every 2. Queued, rate-limited, backed off when a credential breaks. Nobody clicks refresh, and nothing quietly goes stale in the corner.
Re-syncs every 2h · cloud every 6h · self-updating by design
03 Graph
It becomes a graph, and every fact carries two clocks
Each document is read into one graph: the people, decisions and topics inside it, and how they connect. Every fact records when it was true and when we learned it — so “what did we know in March?” is a question with a correct, cited answer. Facts are invalidated, never deleted.
Bi-temporal · as_of on every read · superseded facts kept and flagged
04 Membrane
A permission membrane closes, and it fails closed
Retrieval is trimmed to owner-ACL ∩ granted-scopes before the model gets a single token. Anything outside it is not summarised, not hinted at, not counted — it is never retrieved. An agent inherits its human's ceiling: it can be given less, never more.
Fail-closed · trimmed before generation · deniedByAcl is logged, not leaked
05 Answer
A question goes in. A cited answer comes out.
Ask in plain English and the answer arrives with its provenance attached — every asserted fact carries a source you can open. If the answer leans on something since superseded, it is flagged with the current fact. Agents get exactly the same treatment over MCP, and every call lands in an append-only, hash-chained log.
Every answer cited · freshness guardrail · runs offline with no API key
The payoff
Eight systems went in. One answer came out, and you can check every clause of it.
That is the whole product in one sentence. The eight sources are never merged into a pile
of text — they become one graph where every fact knows who may read it and when it was
true, so a single question can cross Slack, Notion, GitHub, Google Workspace, Linear, AWS,
GCP and Azure at once and still come back with a citation per claim and nothing you were
not allowed to see.
8 systems queriedone graph, one query
1 cited answerprovenance per claim
2 clocks per factvalid time · learned time
0 sources leakedtrimmed before the model
Every call loggedappend-only, hash-chained
Stage four, demonstrated
Same question. Two people. Two answers.
Watch the ACL gate sweep down the candidate rows: each one flips to permitted or withheld
before anything is generated. Hover or focus any row to see the rule that produced the
decision — including the ones that denied it.
one question · asked twice · nothing else changed
—
right-hand asker
vs
Being honest about this mockup: in the product, the right-hand asker sees the answer and a
withheld count — never the hatched rows. We are showing them here because the mechanism is the point.
A real denial returns nothing at all: no title, no snippet, no count of what lives behind it beyond the
single number the asker is told.
visibility is strictly nested:agent:brief-bot ⊆ Sam ⊂ Dana— an agent inherits its human's groups and holds a narrower scope grant, so both operations only ever narrow the set.
Four workflows
The jobs this was actually built for.
Four scenarios, drawn from the jobs the product is built for. Illustrated, not customers.
Priya Raman
Product engineer · day three
Three days in, half the words in her team's channel are codenames. Nobody writes a glossary for the language they already speak.
The brief assembles from what she actually touched, not from what she remembered to write down. Real capture of the slashh portal, July 2026. Sample data.
The point: a handover in an afternoon instead of three weeks of meetings.
Inside the product
Every claim on this page sits next to the screen that produces it.
Four real captures of the portal as it stands in July 2026. The data in them is
plausible demo content — sample names, sample figures — because the screens are ours and the
workspace is not yours yet.
01 · Command Center
Everything that moved while you were not looking.
One screen for the state of the brain: which connections synced and when, what
changed, what contradicts something else, and where the money is moving. Every tile is a
query into the same graph, so every number can be opened down to its sources.
Self-updating. The scheduler re-syncs on its own cadence — cloud accounts every 6 hours, everything else every 2. Nobody clicks refresh.
Broken credentials are visible, not silent. A connection that backs off says so on the front page.
Nothing here is a summary of something you may not read. The tiles obey the same fail-closed retrieval the answers do.
app.slashh.io/command-center
Ddana@
Command Center. Real capture, July 2026. Sample data.
02 · Graph explorer
One graph, not eight piles of text.
People, teams, services, decisions, documents and topics, with the edges the
documents themselves implied. Walk it when you do not yet know what to ask — the shape of
the neighbourhood usually tells you.
Every node is an entity profile — assembled from every source at once, not from one system's idea of a record.
Every edge carries its evidence. Click one and you get the thread, the commit or the page that produced it.
What you cannot see is not drawn. The graph you are shown is already the intersection of your ACLs and scopes.
app.slashh.io/graph
Ddana@
Graph explorer. Real capture, July 2026. Sample data.
03 · Value & ROI
We label the models as models.
There is a value screen, because somebody always has to justify the line item.
Every figure on it carries a provenance tag: real
means measured in your workspace, modelled
means derived from a published figure and an assumption we show you.
The honesty is the feature. A dashboard that cannot tell you which numbers it invented is not evidence.
The published starting point: knowledge workers spend roughly a day each week hunting for information that already exists. Your recovery is modelled from your own query volume.
Counts that are real are real: questions asked, sources returned, sources withheld, contradictions filed, calls logged.
app.slashh.io/value
Ddana@
Value & ROI — note the MODELLED / REAL tags. Real capture, July 2026. Sample data.
04 · Agents over MCP
The same brain, over one config block.
There is a desktop surface for people, and a stdio MCP server for their agents.
Both read the same graph through the same membrane: trimmed first, cited always, logged
either way. Thirteen tools are reachable over MCP.
Agents act on behalf of a human. Keys are hashed; every call is appended to a hash-chained log with the principal, the on-behalf-of and every ACL decision.
LangGraph and CrewAI adapters, or take the SDK straight: npm i @slashh/core.
Runs offline with no API key — deterministic embedder, extractive answers, still cited. Self-hostable and air-gappable on an MIT-licensed open core.
The desktop surface. Real capture, July 2026. Sample data.
Honest comparison
The “No”s are part of the pitch.
Every one of these categories is good at what it was built for. The fastest way to
see what that is, is to keep the honest answers in the table.
Capability
slashh
Enterprise search
Wiki
RAG bot
What it is
The company brain
An index of documents
Pages people maintain
A similarity index
Cites its source
Every answer
Links only
Manually
Sometimes
Knows who may see what
Fail-closed ACLs
Per-connector
Manual
Rarely
Knows what was true when
Bi-temporal
No
Page history
No
Flags contradictions
Built-in inbox
No
No
No
Keeps itself fresh
Self-evolving
Re-index
Humans
Re-embed
Open core → Pro → Enterprise → Cloud (metered). The core is MIT-licensed and self-hostable, so
the exit is always open. SOC 2 evidence room and control mapping with CSV export for auditors —
certification is on the roadmap, and we label roadmap items as roadmap.
Private preview
Connect one source. Ask the question you gave up on.
Open to a small cohort at a time, so we can wire your odd internal system
properly instead of shipping you a wrapper. Two minutes to connect, and the first answer
arrives cited.