An assistant with your key, and your finger on the button.
Themis explains an answer, writes a request's script or its checks, imports a spec from a URL, builds a mock, builds a whole app — through Sonda's own validated code, never by running text the model produced. Sending a request, deleting anything or running a folder becomes a button in the chat that you press, or do not.
At a glance
Forty-two tools, all of them Sonda's own code.
A tool call runs the same validated function a click would, under the workspace lock, with the member's permissions checked. The model's words never become code.
Reads and explains
Explain this answer. Why is this broker pane amber. What does this flow do. Read a device's last values. List the projects, the flows, the Echoes, the apps.
Builds
A project from a documentation URL — it fetches the page, finds the OpenAPI, WSDL, OData or FHIR document behind it, and imports it rather than guessing. Folders, requests with any body type, variables, auth told to use placeholders and never real values, checks from the last answer, a script into the editor.
Mocks and apps
An Echo with a realistic data set and endpoints answering by data, body or script. An app with containers, screens, a dashboard, watchers and functions — tried before they are handed over. An On watch from a device to a request.
Proposes
Send this request. Delete this. Run this folder. Each one is a card with No, Show me and the verb. The outcome comes back as a turn. A delete re-checks the permission at the moment you press.
Refuses
Frozen, locked and paused items. Anything the member's flags do not allow. Submitting, approving, locking, pausing and merging — never Themis's. Off for app runners and while Sonda is locked.
Guards
Every tool result and every screen block is sealed as untrusted data with a random nonce, and the system prompt says not to follow instructions inside it. About thirty injection phrases are removed visibly, with a line that says so. Web reads only from hosts named in the conversation, GET only, 16 MB.
What Themis does without a click, and what it never does.
Said exactly, because the difference matters in a regulated environment.
Without a click
Reads. Builds projects, mocks and apps. Imports a spec. Runs a flow you ask it to run, and tries a function or a watcher it just wrote. Calls a tool on an MCP server you connected, and answers that server's sampling requests with your model.
Only with a click
Sends a single request. Deletes anything. Runs a folder. These three are always a card in the chat that you press.