A team of specialists  ·  Waiting for your email  ·  Self-hosted

A full-stack tech team
that has read every line
of every project.

PostRequest AI Agents are a standing team of specialists on your own monitoring server. They answer from the current file, the live error and the real config — fetched, never remembered. They take work the way everyone already sends it, by email. And they never get tired of your follow-ups.

On duty every minute Every project at once Grounded in your real source Read-only, on your server
Why it is different

Total recall beats seniority

Ask an excellent developer about a project they last touched eight months ago and the first hour goes on remembering. Which file owns this? Why is this guarded twice? Nobody carries a codebase they have been away from.

These agents never left. Every answer starts from the actual file, the actual error, the actual schema — retrieved from the running system, not recalled. No misremembered refactor, no forgotten caller, no answer from how the code used to work.

And you can ask the same thing five ways, or fifty times over, at three in the morning. There is nobody to wear out.

  • No ramp-up — the context is fetched, not remembered
  • Every project at once, not the one someone still knows
  • Cites file and line, so you can check it in seconds
  • Never on holiday, never mid-sprint, never the only one who knows
  • Never impatient — no follow-up is the one too many
What they can see

Everything you already collect, finally joined up

PostRequest has been building the complete picture of your estate all along — every error and its diagnosis, every heartbeat, the schema, the DNS, the source of every client. Each part answered its own question well, and stopped at its own edge.

Monitoring told you that

Errors, heartbeats, lifecycle

Something broke, at this time, this many times, on this client. True and useful — and still a panel somebody has to think to go and look at.

Diagnosis told you why

Root cause, fix, confidence

One error read in depth against its own source. Excellent for that error — and it does not know a migration landed in the same minute.

MCP let you ask

The same seventeen tools

Your own AI client, reaching into the real system. Powerful — and only while you are sitting at it, asking.

The whole estate, read-only

The agents work from exactly that — the same seventeen read-only tools your MCP client uses. Nothing is uploaded, pasted or summarised for them. They fetch the current file when they need it, so the answer reflects the code that is deployed right now, not a snapshot from whenever somebody last explained the project.

The real answer to “checkout has been broken since the deploy” lives in the space between the panels — and nobody was ever going to open five of them at three in the morning. It is one installation throughout: same server, same licence, same key, same toolkit. Nothing new to host, integrate or sync.

  • Find, search and read the retrieved source of any client
  • Errors, existing AI diagnoses and the whole fault history
  • Heartbeats, lifecycle, database schema, DNS and sitemap
  • A diagnosis already computed is reused, not paid for twice
  • Never a write, a deploy or a command — the output is an email

The same toolkit powers AI diagnosis & MCP →

The comparison nobody else can make

They hold every project, so they can compare them

“Why does this work on the shop but not on the bank?” is an ordinary question on a real tech team — and an impossible one for a tool that only ever sees one project.

The agents hold every client you monitor, so the answer can come from somewhere the question was never asked: the site that already has the fix, the config that differs by one line. A person would have to have worked on all of them, and remember. They just look.

  • Two installations that should behave the same — find what actually differs
  • A fix found once, carried to every other client with the same pattern
  • “Is anyone else affected?” answered across the fleet, in one pass
  • Restrict an agent to one client and it stays there — the ceiling only narrows

The boundary is designed, not assumed. What a conversation may see only ever narrows — no handoff, tool call or instruction widens it. What it is about can grow to a second client inside that ceiling, because one question about two clients is still one question. An agent that can see only one of them says so, rather than quietly answering half.

The roster

Several specialists, not one chatbot

One all-purpose assistant gives you one voice and one standard of answer. PostRequest ships a team — each with its own brief, model tier and boundary, so a question reaches whoever owns it. These are the ones it starts with; the roster is yours to shape.

What differs between them is what they do with what they find — a fix, an error report, a plain answer, a severity. How closely they look is the same for all of them. A search hit is somewhere to look and not evidence, so the lines get opened. Code that calculates something is not proof anyone sees it, so it is followed through to the page. Only what is actually running counts, never an old copy in a backup folder. And a lookup that failed establishes nothing — what depended on it comes back as unknown, named, rather than reasoned around. That last one is the difference between an answer you can act on and one that merely sounds like it.

Coordinator

The front desk

Reads everything sent to the general address, works out what is really being asked, and hands it to the right specialist — rather than half-answering it itself.

User support

Plain language, no jargon

Answers what a feature does and where to find it, in the words the reader uses. It reads the source to be right — and never lets a file name into the reply.

Technical support

For technical readers

How it works under the hood, how to configure it, why it behaves that way — grounded in the real config, separating what it verified from what it believes.

Security advisor

Strongest model, every tool

Injection, XSS, CSRF, access control, secret handling. Every finding must name the file and line and state the attack concretely — if it cannot, it says so instead of reporting a theoretical one.

Server administrator

The environment, not the code

PHP version and extensions, permissions, cron, TLS expiry, DNS, mail deliverability. It looks the environment up before answering and gives the exact record, with its TTL.

Software developer

Strongest model, every tool

The actual change: which file, which line, in the style of the code around it — plus what could break, and the test that proves it. It reads the callers before it writes a word.

UX designer

Walks the flow first

Where a flow makes people guess, backtrack or give up — judged by reading the real routes and templates, and by where the recorded errors show people actually failing.

UI designer

Consistency as correctness

Spacing, type, colour and the states a control must have. It finds your design system in the stylesheet first — what the product already does is the standard, not what it would choose.

Error analyst

The live monitoring data

What is failing now, how often, since when, and which release it started with — reading the diagnosis that already exists before it goes anywhere near the source.

Every one of them is editable. Rename them, rewrite the brief, change the model, narrow the toolset, restrict an agent to a single client — or add your own, and delete the ones you have no use for. What ships is a starting team, not a fixed one.

How a team beats an assistant

The handoff is the feature

Most questions are not one question. “Checkout is broken and the client is furious” is an error analysis, a code change, and a reply somebody non-technical can actually read — three different jobs, three different standards of answer.

An agent that cannot answer hands the work on, with a note on what the sender wants and what it has already established — so the next one does not start from zero. The sender sees one coherent reply; you see who did what.

  • Explicit boundaries — each agent is told what is not its job
  • “I looked and did not find it” is a handoff, never a reply
  • The specialist writes to the sender — no double replies
  • Cheap models for routing, the strongest ones for code and security
Literally, and figuratively

They speak your language

Write in German and the answer comes back in German. French, French. Not a per-sender setting somebody has to remember to change — a rule the reply is not allowed to argue with. Give an agent a voice of its own (“Schweizerdeutsch, per du”) and it carries the manner, not the language, the moment somebody writes in English.

The register lands too. Support answers your customer with no file name in sight. The developer sends the patch and the test to name. Same knowledge underneath — the answer sounds like the person who should have written it.

  • The sender's language, every time — including the sign-off
  • A one-line question gets a short answer — short in the words, never short of the answer
  • Each agent's tone is yours to write, in its own words
  • No jargon reaches an end user who did not use it first
What it does to your week

First-level tech, for the people who talk to clients

Your project managers, key account managers and support staff field the questions. Today most of them end the same way: forward it to a developer, wait, chase, relay the answer back. Three people and two days for something that was never hard.

Now they ask the team directly and get an expert answer in minutes, grounded in that client's actual code. No queue, no context to re-explain, nobody's afternoon interrupted. The client hears back the same morning, from the person they already deal with — and your developers keep only the questions that were worth their time.

  • A non-technical colleague gets several steps further before anyone is interrupted
  • Answers in plain language — the support agent never lets a file name into a reply
  • Anything that needs a change still reaches you — they are read-only, so the escalation is honest
  • Every answer sent is in the queue, so the tech team can read back what a client was told
And for the developers

A sparring partner that has already read the repo

Developers get the most out of it — not because the agents are better engineers, but because the slow part was never the thinking. It is finding out where the thing lives. Before you have been granted access to the right repository, the first answer is already in your inbox.

Ask the way you would ask the colleague who wrote it. Where is this called from. What changed between these two releases. Why is there a guard here. It answers with file, line, callers and the diagnosis that already exists — and it does not mind being asked again, differently, until you have it.

  • Which file, which line, which callers — read from the source, not recalled
  • The context of a ticket assembled before you have finished reading it
  • Picking up an unfamiliar project measured in questions, not weeks
  • A second opinion at 23:00 that is neither guessing nor asleep
  • A lookup that failed is told to you, not reasoned around
No new tool to learn

It works because it is just email

Nobody has to be onboarded, given a login, or persuaded to open another app. They write to an address, the way they already do.

1

Connect a mailbox

IMAP or POP3 in, SMTP out — spoken directly, with no mail library and no third-party relay. Test the connection before you save; the password is stored encrypted and never returned to the browser.

2

Somebody writes in

A client, a colleague, a forwarded ticket, an alert from another system. The coordinator reads it — attachments included — and hands it to the specialist who owns it.

3

The answer comes back

A normal reply, in the same thread, from your own address. Every step, tool call, handoff and cost is recorded in the dashboard queue for you to read back.

Mail is collected every minute, and each pass is deliberately bounded — a few messages read, a few conversation steps taken. One long investigation spreads across passes instead of holding the queue up behind it.

Not a one-to-one assistant

CC a colleague, and they are in the conversation

An assistant answers whoever typed. A team answers the thread. Copy two colleagues in and all three get the reply — and any of them can answer, and be answered, with no account, no invitation and no login.

It behaves like a mailing list right up until it matters. A copied-in colleague is authorised for that conversation and no other, because a registered user vouched for them — and their mail still has to pass the same sender checks as anyone's. Being vouched for is not the same as being believed.

  • Everyone on the thread gets the answer — up to fifteen people
  • Drop the copies on a reply and the next answer goes to you alone
  • A guest is let into one conversation, never into the mailbox — and every reply to them copies whoever vouched
  • Vouching does not pass on — and “as I mentioned last week” is only ever said to somebody who was there
Hardened by default

An inbox is an untrusted input

The moment an AI reads mail from strangers, the mail becomes an attack surface. PostRequest treats it as one — before the message reaches a model, and again after.

Strangers are held, not answered

Mail from an address you have not approved is quarantined and waits for an explicit allow or block. Approve a sender and everything they already sent is processed — nothing is silently dropped.

DKIM is verified, not assumed

A From: header is a claim, not an identity. The signature is checked before a sender is believed, so an allow-list cannot be walked through by forging an approved address.

Prompt injection is scored

Every message is scanned for instruction overrides, system-prompt extraction, forged conversation turns, persona resets, exfiltration to an address or URL, credential hunting, hidden HTML, remote images and encoded payloads.

Hostile mail runs with nothing

A suspect message keeps a reduced toolset. A hostile one has every tool withdrawn and is answered from the conversation alone — so the attempt is named in the transcript rather than met with silence.

Scoped to the client at hand

A conversation reaches only the clients it is allowed to reach. An agent answering about one site cannot go browsing another customer's errors or source on the way.

Deliverability checked both ways

SPF, DKIM and DMARC are checked for the address you answer from, each reported pass or fail with the exact record to add — so your replies land in an inbox instead of a spam folder.

You stay in charge

Nothing happens that you cannot read back

Every conversation appears in the dashboard queue with its state, the agent handling it and what it cost. Open one and you get the full transcript: each step, each tool call, each handoff, each refusal — so an answer that went wrong can be read rather than guessed at.

Spend is capped, not merely reported. Set a maximum number of steps a day and a daily USD ceiling; reaching one pauses the work, tells the sender once that there will be a delay, and resumes by itself when the budget resets. Nobody is left waiting on a reply that was quietly dropped.

  • Daily step limit and daily cost cap — either can be unlimited
  • Per-feature spend reported over four spans in Settings
  • Your own key, on the LLM of your choice — you pay the provider directly
  • Disable any agent, or the whole team, at any moment

And none of it leaves your server. The agents run on your own installation, against your own API key — no SaaS in between, no third-party telemetry. Credentials, conversations, transcripts and attachments are all encrypted at rest. With no key configured, the page is not even shown.

Get in touch

Put the team on your inbox

Leave your email and we'll reach out to get you set up — agents, AI diagnosis, MCP and all. No account, no obligation.

We'll send one email to confirm the address is yours — nothing reaches us until you click it. No spam, never shared.