TINA  /  T9 Intelligent Agents  /  Product Overview
01 / 18
Product overview · 2026

AI agents your
whole team can
trust with real work.

TINA is a shared workspace where people and AI agents work in the same chat. Agents act only with your permission, in threads everyone can see, with a record of every action taken.

Agents as contacts Shared threads Mini app marketplace Permission scoped Human approvals
FA
Ops team
4 people · 2 agents
Priya@Finance Agent pull the overdue invoices over 30 days
Finance AgentFound 7, total S$18,420. I can send reminders from your Xero account.
Send them, but not to Acme, I am handling that one
Approval required
Send 6 payment reminders via Xero, acting as Marcus Lee.
ApproveReject
Approved
6 sent · logged · reversible
Tangent 9 Pte Ltd  /  Singapore
What TINA is

One platform. One person,
a family, or a company of thousands.

TINA is an agentic AI platform delivered as a messaging app. AI agents appear as contacts. You talk to them the way you message anyone else, and behind the chat a permission system decides what each agent may do, for whom, and when a human must approve first. Only the settings change between an individual and an enterprise, never the software.

01

A workspace, not a chatbot

One to one, group, family or team threads. Invite an agent, mention it, and it works in front of everyone with the context already in the room.

02

Connected to real systems

Accounting, email, calendars, CRM and internal systems plug in through MCP connectors. No code, and logins never leave the server-side vault.

03

Accountable by design

Every agent borrows the asking person's access. Consequential actions pause for a human. Every step is written to a log that cannot be edited.

The same platform serves a one-person business and a company of thousands. Only the settings change.
Why it exists

AI is built for one.
Work is done by many.

Today's assistants serve one person at a time. That is fine while the AI writes emails. It breaks the moment the AI does something real: pays a supplier, updates a customer record, approves a leave request. Someone has to answer for what it did.

01

Work is shared. AI is not.

A team coordinates constantly. But the AI sits in a private chat with one person while everyone else repeats the same context to their own.

02

Shared AI chats can only talk.

Group chats with an AI exist now. They answer questions. They cannot safely do work inside a company's systems with limits per person and approvals.

03

Safe AI shouldn't need an IT team.

The enterprise options assume an IT department, complex setup and one vendor's software everywhere. Most small businesses have none of that.

The one question today's tools cannot answer: under whose authority did the agent act?
How it works

One request, end to end

Every instruction, typed in a thread or spoken to an agent, takes the same five steps. Nothing skips the check, and nothing consequential skips the human.

01 ASK

Ask

A user types a request in a thread, or mentions an agent in a group.

02 PLAN

Plan

TINA works out what is needed, picks the right agent and plans the steps.

03 CHECK

Check

TINA checks what that person is allowed to do, tool by tool, action by action.

04 APPROVE

Approve

Anything important asks a human first. Who decided, and when, is recorded.

05 DO

Do

The agent does the work in the connected system. Every step is logged.

Watch it happen, live

The plan, the tool calls and the results stream into the thread as they run. No black box, no separate dashboard to go and check.

Approval required
Pay invoice INV-2214, S$4,120, from the company account.
ApproveReject
Approval policies are configurable per organisation and per connector. Irreversible actions default to requiring approval.
The core idea

The agent is never
more powerful than you

Every agent executes under the identity and effective permissions of the person asking. In a group thread, five people get five different results from the same agent, because it borrows each person's access in turn, never everyone's access combined.

Person

A named human in a named account, in your organisation.

Agent

Borrows only that person's granted agents, connectors and apps.

Safety checks

House rules, spend caps, restricted topics, injection defence.

Approval

Consequential actions pause for a named approver.

  • An agent can only do what the asking person is allowed to do, checked server side on every single action.
  • Data coming back from connected tools is treated as data, never as instructions.
  • Permission changes take effect on the agent's next tool call, not the next login.
  • Every action an agent takes is written to an append-only log that cannot be edited.
This is what makes it safe to let agents touch real systems.
Feature · The workspace

Agents as contacts

A messaging interface people already know how to use, on web, iPhone and Android. The learning curve is zero because there is nothing new to learn.

Agent and people threads

One to one, group, family or team. Mention an agent in a group and it works in front of everyone.

Approval cards inline

Approve or reject without leaving the conversation. The decision, the approver and the timestamp are recorded.

Live run visibility

Plans, tool calls and results appear as the agent works, with a clear note when something fails and why.

Mini apps in chat

Launch an app full screen from the thread, finish the task, come back with the result attached to the conversation.

Notifications that matter

Push and email for approvals waiting, task outcomes, spend alerts and app updates, with delivery status.

Wallet and rewards

Tokenised payment methods, purchase history, rewards credits earned in mini apps and redeemed at checkout.

Usage in plain sight

A live view of AI credits used against your allocation, per agent and per task, with a top-up path instead of a hard cut-off.

Sign in your way

Email and password through TINA ID Manager, single sign-on for organisations, or biometric unlock on mobile.

Team admin

Add members, set what each may use, and cap what your tenant spends, all from the same app.

Chat delivery under 500 ms P95. First token of a streamed agent response under 3 s P95.
Feature · Agents and skills

A workforce you can shape

Built-in agents cover the common ground from day one. When you need something specific, the Skills and Agent Creator builds it through a guided conversation. You describe the job, it writes the instructions, picks the skills and proposes the tools it needs. You grant or deny each one.

Tina, your concierge Research Agent Business Support Agent Ops Support Agent Finance Agent IT Helpdesk Agent Skills & Agent Creator
  • Purpose, instructions, skills, tools. Every agent is defined by what it is for and strictly limited to the tools it has been granted.
  • Shared agents. An admin publishes an agent once and the whole team uses it, each under their own access.
  • Memory with retention rules. Agents carry context between conversations, governed by your organisation's data-retention policy.
  • Profile photos and personalities. Agents look and feel like contacts, because that is how people delegate naturally.
  • Model agnostic underneath. Lightweight models for routing, stronger models for planning, chosen per task and recorded per interaction.
An agent a person has not been granted is invisible to them, and invisible to their agents.
Feature · Tasks and workflows

Say it once. It runs forever.

SCHEDULED TASKS

Written in plain language

"Every weekday at 8am, summarise my unread messages and today's calendar."

  • Natural language in, a real schedule out, with timezone.
  • A run log showing outcome and credits used per run.
  • Pause, resume, edit or delete at any time.
  • Every run executes under your own permissions, never broader.
WORKFLOWS

Playbooks with human gates

An ordered sequence of agent steps and approval gates, for the work that must never go rogue.

  • Triggered manually, on a schedule, or by an event.
  • Named approvers per gate, with a full lifecycle run log.
  • Every run is reproducible and auditable, step by step.
  • Example: chase invoices overdue past 14 days, drafting is automatic, sending needs a person.
Scheduling that runs under each person's own permissions, and workflows that stop for a named approver.
Feature · MCP connectors

Connect anything, write no code

Add a system by URL and credentials through the Model Context Protocol. A curated catalogue covers the everyday tools, and any compliant MCP server can be added on top.

Microsoft 365Google CalendarGmail XeroHubSpotWhatsApp Business DropboxAny MCP server

Vaulted credentials

Logins are held server side and never exposed to the model or to a mini app.

Tool level switches

Turn on read, leave write off. Permission is per tool, not per connector.

Reversibility classified

Every call is tagged safe or consequential. Consequential defaults to an approval gate.

Personal or shared

Connect your own calendar, or connect the company accounting system once for everyone.

Failures surface in the thread in plain language, with the retry history, not as a silent dead end.
Feature · Mini apps and the marketplace

A store that fits inside a chat

Partners build mini apps and publish them to the TINA marketplace. You browse, subscribe and launch them without leaving the workspace. Filing expense claims, booking business travel, raising purchase orders and training your team all happen in the thread.

  • Sandboxed runtime. App code has no direct network or data access, only the capabilities you grant.
  • Permissions shown before it runs. You see exactly what an app may do, then decide.
  • Secure checkout. Payments go through the platform payment service, cards tokenised by a licensed provider.
  • Rewards built in. Apps can issue and redeem rewards credits against a ledger you can inspect.
  • An off switch per app. Any app can be suspended platform-wide, instantly.
TRANSPARENCY BY DEFAULT

What a mini app can ask for

profile.readcheckout rewards.accruerewards.redeem storagenotifications ui.embedevents

Every capability an app uses is metered and logged. An app never gets more than the permissions it declared, and you saw, before it ran.

Every app is reviewed before publication and versioned after it, with a defined path for retiring an app without stranding its subscribers.
Feature · Cost control

Costs you can see,
and caps you set

Simple plans

A plan per tenant type, with a free trial to start, and upgrades or downgrades whenever you need them.

AI credits, metered

Every request is costed and deducted against your allocation, visible per agent and per task, live in the app.

Limits you control

Monthly credit allocations, per-tenant spend caps and rate limits, enforced at the moment of the request, not discovered on the invoice.

Top-ups, not cut-offs

Heavy months mean a top-up pack you choose to buy, never a surprise bill or a hard stop mid-task.

Wallet, done properly

Tokenised cards only. TINA never stores raw card data; card security stays with the licensed payment provider.

Rewards ledger

Earn, redeem, expire and reverse, each entry traced to its source and redeemable against purchases in the marketplace.

  • Spend alerts notify you before a cap is reached, with a clear view of who and what is using the credits.
  • Idempotent payments with ledger reconciliation, so a retry never charges twice.
No surprise bills. Usage is visible while it happens, and every limit is enforced before the money moves.
Feature · Control and governance

Four dimensions of permission

Access is granted across four resource types, to a person, a group or a role. Anything not granted is invisible, both to the user and to any agent acting for them.

Agents

Which AI workers this person may talk to and delegate to.

MCP connectors

Which systems, and which tools inside them, are reachable.

Mini apps

Which marketplace apps may be installed and launched.

Functions

Which feature-level actions, such as purchasing or inviting, are allowed.

Groups, roles and directory sync

Build groups by hand, or inherit them from Entra ID and Active Directory. Effective permission is the union of direct and group-derived roles.

Audit that holds up

Append-only records of every agent run, tool call, permission change and admin action, searchable and exportable.

Your data is isolated at the data layer with row-level security, with a dedicated database option for enterprises that want it.
How it is built

One platform, five layers

What people see
The TINA app on web, iPhone and Android, with admin views for teams and families
Connections
Secure doorways through which apps and mini apps talk to the platform
The AI brain
Plans tasks, picks agents, enforces rules and spend caps, pauses for approvals, logs everything
Business engine
Subscriptions, payments via a licensed provider, rewards, the app marketplace
Doing the work
Secure links into your existing systems, and a fenced-off space where mini apps run safely

Any model

Commercial APIs or private models, switchable per organisation and per task.

Any cloud

Containerised and portable, so deployment is never tied to one provider.

99.9% target

Graceful degradation when a model or connector is down, with a public status page.

Built to scale

Grows with you from one seat to thousands without a migration.

Never locked to one AI model. When a better or cheaper model appears, TINA switches underneath without changing how anything works.
Governance and safety

Designed to Singapore's
agentic AI safety framework

In January 2026 Singapore's IMDA launched the first safety framework for AI agents. TINA was designed to its four principles before it was published.

Know and limit the risks upfront

Every agent, connector and app must be granted to a person before they, or their agent, can even see it.

Keep humans accountable

Payments, permanent changes and outside messages pause for a human. Who decided, and when, is recorded.

Build in technical safeguards

Rules and spend caps checked on every action, defence against hidden malicious instructions, mini apps fenced off, an off switch per app.

Keep users informed and in control

Users see what each app may do before it runs, watch agents work in the thread, and can review the full activity log.

PDPA baselineISO/IEC 27001 aligned ISO/IEC 42001 readinessMAS TRM alignment PCI scope at the payment providerWCAG 2.1 AA target
The IMDA framework is voluntary guidance with no certificate to hold. The claim is design alignment, principle by principle, not formal compliance.
The case for TINA

Why teams
choose TINA

Shared context, not repeated context

The agent is in the room with the team. Nobody re-explains the same thing to their own private assistant.

Enterprise-grade permissions, built in

Every agent, function and mini app is permission-controlled to enterprise standard, switched on from day one, no IT department required.

Works with the tools you already use

A mix of Xero, Google, WhatsApp and whatever else. No requirement to standardise on one vendor's stack.

Interface people already know

If someone can use WhatsApp, they can use TINA. Adoption does not depend on training.

Costs that cannot run away

Metered AI credits, tenant-level spend caps and top-ups instead of surprise bills.

An audit trail that holds up

Every agent action, approval and permission change in an append-only log, searchable and exportable when a customer or auditor asks.

Automation with a human gate

Scheduled tasks and workflows run on their own, under each person's own permissions, and stop for a named approver at the steps that matter.

Never locked to one model

Swap to a better or cheaper model, or run a private one, without changing how anything works.

An ecosystem, not a feature list

Every partner app in the marketplace makes TINA more useful the day you install it.

Safety, adoption and cost control, switched on from day one.
Plans

The same platform,
sized to fit you

Small business

Per seat, with optional single sign-on, groups and roles, shared org connectors and workflows with approval gates.

Enterprise

Dedicated database option, directory sync, advanced administration, premium SLA and custom credit allocations.

Non-profit

An organisation tenant at concessionary pricing, with eligibility verification.

The same platform underneath every plan. Grow from a small team to an enterprise without migrating anything.

Put agents to work.
Keep people
in charge.

TINA gives your team AI agents that do real work in the systems you already use, under the permissions you already trust, with a record of everything they did. See it working on your own tools in a live demo.

TINA  /  T9 Intelligent Agents  /  Tangent 9 Pte Ltd
hankiong@tangent9.com  /  +65 8868 1386  /  tangent9.com
Arrow keys, or swipe