Skip to content

Elements is a canvas for pipelines and agents built from models, your documents, APIs and code. Rehearse a run to see exactly what it would send, put a person in the loop where it matters, and deploy it as an API on your own servers.

Create an account

Private beta. You need an invite code to sign up.

Support ticket triage10 steps · starts with a webhook triggerReady

A rehearsal of the real “Support ticket triage” template, recorded from the engine. Branch decisions, skipped steps and “would send” previews are the product's output. The model replies and fetched data are stand-ins, because this page has no provider keys. Open this template in the studio

Templates

Six templates cover the jobs people ask about most. Each one comes with the settings it needs and its own test cases, and all six run end to end in our test suite on every change, with stand-in model replies. If one stops working, the build fails.

Support

Support ticket triage

A ticket arrives by webhook. It is classified, urgent ones alert the team, a reply is drafted, and nothing is sent to the customer until a person approves it.

Starts
When another system calls it
Shape
10 steps, 2 decisions, 3 that act outside
Needs
A vault credential named 'llm'; A Slack incoming webhook (vault credential 'slack-webhook')

Sales

Lead qualification

A form submission arrives by webhook. It is scored against your ideal customer; strong leads go to sales in Slack and to your CRM, the rest are kept on a nurture list.

Starts
When another system calls it
Shape
8 steps, 1 decision, 3 that act outside
Needs
A vault credential named 'llm'; A Slack incoming webhook (vault credential 'slack-webhook'); Your CRM's inbound webhook URL in the CRM_WEBHOOK_URL variable

Operations

Invoice extraction

Turn the text of an invoice into structured fields. Extractions the model is unsure about, or that fail validation, go to a person before they are recorded.

Starts
Called as an API, or from the studio
Shape
7 steps, 2 decisions, 1 that act outside
Needs
A vault credential named 'llm'

Knowledge

Knowledge-base assistant

Answers questions from your own documents and says where each answer came from. An agent searches the knowledge base as many times as it needs; prompt-injection attempts are stopped first.

Starts
Called as an API, or from the studio
Shape
4 steps
Needs
A vault credential named 'llm'; A knowledge base (upload documents under Knowledge)

Reporting

Scheduled digest

Every weekday morning, fetch a page or feed, summarise what matters, and email it. If the source is down the run stops there instead of emailing an empty digest.

Starts
On a schedule
Shape
5 steps, 2 that act outside
Needs
A vault credential named 'llm'; A schedule (Schedules → New) pointing at this pipeline; Outgoing email configured for this installation

Research

Research agent

Give it a question. It reads public web pages, does the arithmetic with a calculator rather than in its head, and stops at a step and cost limit you set. Every step it took is kept as evidence.

Starts
Called as an API, or from the studio
Shape
5 steps, 1 decision
Needs
A vault credential named 'llm'

Testing and release

A workflow that emails customers or writes to your CRM is hard to test by running it. Follow one real template, support triage, through each safety tool. Every step, message and hash below is the engine's recorded output.

Rehearsal

Run the pipeline for real, except the steps that send, post or write outside it. Those report the exact message they would have sent, and the run carries on.

Fire drill

Each step that depends on an outside service is made to fail, once briefly and once completely. No provider is called, so a drill costs nothing.

Human approval

A step that stops the run until a person approves, edits or rejects. They decide in the inbox, or from an emailed link without an account.

Replay

Change one step and run again from there. Earlier steps keep the results they already produced, so you do not pay for them twice.

Shadow runs

Try a new version on real traffic. It runs beside the live one as a rehearsal, and callers only ever get the live answer. Then promote it or roll back.

Evidence receipts

An answer from a deployed pipeline can carry a signed receipt: which steps ran, which model, which path. Each step is chained to the one before; change anything and it no longer verifies.

Rehearsal

Run the pipeline for real, except the steps that send, post or write outside it. Those report the exact message they would have sent, and the run carries on.

Fire drill

Each step that depends on an outside service is made to fail, once briefly and once completely. No provider is called, so a drill costs nothing.

Human approval

A step that stops the run until a person approves, edits or rejects. They decide in the inbox, or from an emailed link without an account.

Replay

Change one step and run again from there. Earlier steps keep the results they already produced, so you do not pay for them twice.

Shadow runs

Try a new version on real traffic. It runs beside the live one as a rehearsal, and callers only ever get the live answer. Then promote it or roll back.

Evidence receipts

An answer from a deployed pipeline can carry a signed receipt: which steps ran, which model, which path. Each step is chained to the one before; change anything and it no longer verifies.

Tests and a deploy gate. Save inputs with what must be true of the result. The triage template ships with “A billing problem with a deadline is urgent and waits for approval”. A test can check 12 kinds of things, and a deploy is refused if any test fails.

Branching

A decision step reads the input and picks a branch: a condition, a switch on a value, or a router that looks for keywords. Only that branch runs. The others are marked skipped, so you can see afterwards which path a run took and why.

incoming ticket · illustrative

I was charged twice this month.

  1. BillingLook up order · Draft reply · ApprovalRefund reply drafted, waiting for approvalskipped
  2. Account helpSearch help docs · AnswerAnswered from the help docs, with sourcesskipped
  3. CancellationCheck plan · Post to SlackHand-off posted to the retention channelskipped
  4. Bug reportExtract details · Create issueIssue opened with the request detailsskipped

After the first run

Run a pipeline over a list of inputs and fix single cells by hand. See what a change would do to last week's runs before you deploy it. Trace a sentence of an answer to the passage behind it. When a deployment keeps failing at one step, get a repair that was already tried on the failed calls.

InputClassifyDraft reply
I was charged twice this monthbillingRefund opened for the duplicate charge.
Invoice shows the wrong addressaccountUpdated the billing address on the invoice.
How do I reset my password?accountUse “Forgot password” on the sign-in page.
Export fails with an errorbugThanks, the team is looking into the export.

Four inputs run through the same pipeline, one row each.One cell edited by hand. Only the reply for that row ran again.

Before anything goes live

See what it will send.

Then decide if it should.

Rehearse any pipeline, put a person in front of what matters, and keep a record of every run.

Steps

A test fails the build if a step is listed in the palette without code behind it. The four GPU steps are off unless the server has a GPU: an administrator turns them on with one setting.

Integrations12
Processing12
Flow Control10
Analysis9
AI Models8
Data7
I/O7
Agents5

Real branching

Email Inbox, Human Approval, IF / Condition, Only New Items, RSS Feed, Smart Router, Switch, Validator choose a path and only that path runs. Skipped steps are shown as skipped, on the canvas and in the run record. Independent branches run at the same time.

Agents with limits

An agent step picks tools one at a time: web requests, your knowledge base, a calculator, sandboxed Python, your other pipelines, or any MCP server. It stops at the step and cost limit you set, and every step it took is kept.

Integrations

Discord, GitHub, Google Sheets (add rows), Google Sheets (read), Notion, Send Email, Send Email (your mailbox), Slack, Telegram, plus any HTTP API. Webhook URLs are checked against the service they claim to be, so a step cannot be pointed at your internal network.

MCP in both directions

Agents can use tools from remote MCP servers, and every pipeline you deploy is also exposed as an MCP tool, so other assistants can call it with the same scoped API key.

Retrieval

Write a set of questions with known good answers once. Score each retrieval strategy on precision, recall, nDCG and faithfulness, and compare runs before you switch. The RAG step ships with 9 strategies, from basic to corrective and fusion.

evaluation · support-golden-v2 · 42 cases · k=5
StrategyPrecision@5Recall@5nDCG@5Faithfulness
basic0.710.640.690.81
multi_query0.780.740.770.84
hyde0.750.700.740.82
rerankingbest0.860.790.880.90
fusion0.830.810.850.87
corrective0.800.760.820.89
⚠ regression caught: fusion · ndcg@5 -0.03 vs run_2026-06-30Illustrative scores: real metric keys from the evaluation engine

Documents

Upload any of 16 formats, watch it parse and split, and choose how it is chunked: 8 strategies, from fixed token windows to parent-child and code-aware. Collections are versioned, so an evaluation always compares like with like.

ingestion · resumable job
  1. 1Uploadbilling-guide.pdf · 2.4 MB
  2. 2Parseparser: docling
  3. 3Chunkstrategy: parent_child · 400 tok
  4. 4Embedtext-embedding-3-small
  5. 5Collectionbilling-v3 · version 3
q3-policy-pack.zip64% · resumable
chunk preview

Team plans are billed per active seat with usage-based execution credits. Unused credits roll over for one billing cycle. Enterprise contracts can pool credits across workspaces…

chunk 12 · p.4 · parent_child
billing-v3v3
18 documents · text-embedding-3-small
tokenrecursiveparagraphsentence_windowsemanticmarkdown_headersparent_childcode

By the numbers

Every figure on this page is read from the product itself when the site is built, so it changes when the product does.

70

kinds of step for the canvas, in 8 groups

IntegrationsAgents
9of 9

steps that send, post or write outside the pipeline, and every one of them stops at a rehearsal

12

kinds of check a pipeline test can make before a deploy is allowed

6

ready-made use cases; the line shows how many steps each one has (4 to 10)

Security

Secrets never enter a pipeline graph, workspaces never share state, and every deployed endpoint needs a key you can scope and revoke.

Credentials stay server-side

Provider keys live in an encrypted vault. Steps hold a reference like vault:llm, never the key itself, so an exported pipeline contains no secrets.

AES-256-GCM at rest

Workspaces are isolated

Pipelines, collections, credentials and run history belong to one workspace. Retrieval in one workspace cannot reach another workspace's documents.

Checked on every request

Scoped API keys

Deployment keys are shown once, stored hashed, rate-limited per key, limited to the endpoints you choose, and can be revoked at any time.

SHA-256 hashed

Self-hosting

Runs you start in the studio stream step by step from the FastAPI engine. Queued runs and document ingestion go through RabbitMQ to workers, with Redis carrying progress and MongoDB holding state.

runtime topology
PATH A · interactive
StudioFastAPI engineSSE stream/execute/stream
PATH B · queued
API/execute/async · ingestionRabbitMQholds the jobWorkers
  • FastAPIAPI + in-process execution engine
  • MongoDB + GridFSpipelines, versions, resumable batches
  • ChromaDBworkspace-scoped vector retrieval
  • Redisprogress events, rate limits, sessions
  • RabbitMQasync execution & ingestion job queue

What exactly does a rehearsal do?

It runs the pipeline for real, including model and knowledge-base calls, except for steps that change something outside it: sending email, posting to Slack, Discord or Telegram, writing to Notion or GitHub, HTTP requests other than GET, and writes to the data store. Those steps report what they would have done and pass their input on. Model calls in a rehearsal cost what they normally cost.

What do I need to self-host Elements?

Docker. The repository includes a production compose file that starts the API, a queue worker, the web app, MongoDB, Redis, RabbitMQ, ChromaDB, a reverse proxy that obtains TLS certificates, daily backups, and monitoring (Prometheus, Grafana, Loki). One script generates the secrets and another deploys and smoke-tests the stack.

Do I bring my own model API keys?

Yes. You connect your own provider keys (OpenAI, Anthropic, Gemini, Groq, OpenRouter, and embedding providers). Keys are stored encrypted in a vault. Steps refer to them by name; saved, shared and deployed pipelines never contain the key itself, and it is decrypted only at the moment a step runs.

How do agents differ from a normal pipeline?

A pipeline follows the path you drew. An agent step decides for itself which tool to use next, within limits you set: a maximum number of steps and an optional cost limit. It can use web requests, your knowledge base, a calculator, sandboxed Python, your other deployed pipelines, and tools from remote MCP servers. Every step it took is recorded with the run.

How mature is it?

It is a private beta: registration needs an invite code and things will change. What is on this page works today and is covered by automated tests. Things we have not verified are not claimed here; for example, provider calls in our test suite use stand-in replies, and the Google Sheets step can read but not write.

Where does my data live?

On your infrastructure. Documents, collections, pipelines, credentials and run history stay in the databases you run. Model calls go directly from your deployment to the providers you configure. Evidence receipts contain fingerprints of content, never the content.

Am I locked in?

Pipelines are stored as JSON graphs with version history, and you can export your account data at any time. Deployed endpoints are plain REST with API-key authentication, and are also available over the Model Context Protocol, so callers do not depend on an Elements SDK.

Try it on one of your own workflows.

Free during the private beta. Bring an invite code and your own model keys, and keep your data on your own servers.