Agent sprawl
Bring every agent into the light.
Register every shadow agent, give it an owner, and control who can find it. Nothing gets torn down, and teams stop building the same agent twice.
Distributed agents
When data can’t or shouldn’t move, send the agent to it. Your validated agents run on partner infrastructure and at your own sites. You control and audit all of them from one place.
Example animation. Your validated agents travel from your registry to the sites that hold the data: your headquarters, a partner’s data center, a partner cloud, a plant, a lab, and the edge. Each connects back out on port 443 and registers, gets an owner, and answers only what you grant. Tasks go out to the agents and results come back while the data stays where it is. Then an administrator takes the edge site’s agent offline, and the next task to it is rejected.
A global streaming service screens content before it goes live. The content sits with the partners and facilities that hold it. Hauling it to a central system and back costs time and money.
So the service sends its own validated screening agents to where the content lives. The content stays put. Only the task and the result cross the network, and the service controls and audits every one of those agents from one place.
The same shape shows up wherever data can’t or shouldn’t move: patient records in hospitals, trial data at research sites, telemetry on factory floors.
Deploy your validated agent on a partner’s infrastructure or at your own sites: any cloud, data center, or edge device.
The agent opens one outbound connection on port 443. The host opens no inbound ports and needs no public endpoint, static IP, or DNS change.
Every agent registers into your private registry under your organization. You decide who can call it, and you can revoke access or take it offline.
Every change to your agents and their access lands in one audit log, whichever site they run at.
Where the data lives
Connects out only →
Scoped access →
Controlled from one place
Where the data lives
Connects out only
Blocks
Your private agent network
Scoped access
Controlled from one place
You wrap your agent with the Blocks SDK or CLI, in Python or TypeScript, and it runs as an ordinary process on the host. It needs outbound HTTPS on port 443 to config.blocks.ai, api.blocks.ai, and *.pndsn.com, and nothing else: no NAT traversal, no port forwarding, no ingress rules.
Run more than one instance and Blocks routes work across the healthy ones, with retries and failover.
Bring every agent into the light.
Register every shadow agent, give it an owner, and control who can find it. Nothing gets torn down, and teams stop building the same agent twice.
Connect agents you don’t own.
Partners and portfolio companies bring their own agents onto your network, with access they scope and can revoke. Nobody has to standardize on your stack, and companies join and leave cleanly.