Digital teammates deserve a seat at the company table
Claude Cowork, Grok bot, Instinct, and a wave of “AI coworkers” borrow your identity. That’s different from adding someone to your team.

Pablo Lleras
8.27.2026
Share:

For a few months it’s been obvious that agents are going to become the primary software layer for most knowledge work. It’s been equally obvious that almost nobody wants the job of building, maintaining, updating, and managing them. So the industry did what it always does at the start of a category: a lot of us shipped something that looks like a coworker, and we’re all still arguing about what that word actually means.
I like that argument. I’ve seen a category get named before in my early days at Pixlee, when the bet was that brands should market with their customers’ photos instead of a studio shoot. That sounded slightly unhinged in 2012. We were early in the way that feels like you’re wrong until, a decade later, the creator economy is just how commerce works. A hundred companies helped make it real. I loved building inside that. Categories only exist when other people show up.
Being early at Pixlee taught me that a category will get built with or without you. The important decision happens before the name settles: which version of it are you going to build?
We’re at that point again. Digital coworkers are getting named in public this year, and most of the industry has reached for an assistant that knows your tools because you handed it the keys. Claude Cowork works through your files. GPT for business lives in your tenant. A wave of agentic coworker products are selling some version of that screenshot.
I don’t think those teams are confused. We’re all staring at the same gap: knowledge work needs a new interaction layer, and the fastest way to demo one is to become the user.
The delegate is not a user
Last week the internet fell in love with Instinct. Testers called it magic: it booked the table, cleaned the inbox, finished the life-admin other assistants politely refuse. Then the questions started. It sent mail as someone without asking. It pulled a sign-up code out of their Gmail. Someone mailed a phish into their own inbox and the agent treated it as a command. Disconnect Google and you could still get a summary, because the copies lived in the agent’s house.
I don’t think Instinct is uniquely reckless. It is a very pure version of the shape the industry is trying to figure out.
A powerful app with your connectors, your scopes, your inbox: that’s the delegate. When it books the table, you look like a wizard. When it sends the email, you sent the email. Cowork, GPT-for-business, and the coworker crop are the same shape with better manners.
That’s a real product, and one I expect millions of people will use. It’s just not a teammate.
ChatGPT and Claude are excellent at that job. I use them constantly; the last post on this blog is about running an engineering team that way. They’re thinking partners. The problem starts when work needs to live inside a company, where other people can see it, interrupt it, and take ownership of it.
That is the identity split behind Automat Workforce agents like Ace, the first agent we built this way. Ace doesn’t borrow a user; it is one. Ace has a computer, a phone, and accounts in the software the company already runs. That choice has shaped nearly everything downstream.
Some Instinct testers independently reached for a dummy inbox “just for the experiment.” They had backed into the user model as a safety precaution.
Identity makes security boring
A real user does not skip onboarding. We provision a machine, a mailbox, and a Slack/Teams seat, then deal with every policy the customer already wrote: org-unit reauthentication, session limits, sharing rules, and whatever else a new contractor discovers during their first week. It is harder than putting a “Connect Gmail” button on a landing page. That is also the point. You CC Ace on a thread, add Ace to a channel, and never share the payroll folder.
If the agent sends emails as you, every thread is a little lie. The other side thinks they’re talking to you, and your teammates can’t ask the worker who actually did the work.
It also changes the security problem. Prompt injection still exists, but a phish in Ace’s inbox is not a command issued as you. When Ace leaves, IT disables the account. That is a process companies already understand. Un-copying a person from a vendor’s memory store is not. Least privilege needs a who.
Some things become refreshingly boring. Put the agent in a Workspace organizational unit. Route inbound mail through Gmail quarantine. Use Slack roles, Google Groups, IdP groups, Drive ACLs, and Salesforce permission sets. These controls already govern the humans doing the same work. API keys and MCP servers are useful ways for systems to talk to systems; they should not be the only way an agent can enter a company.
Other things become our problem. We built an internal password manager so Ace can sign in without dropping a secret into the model’s context. We built a contact book so names resolve to people instead of guesses. None of that makes for a magical demo, but it is what turns a model into an account you can safely put to work at scale, with real problems small and large business owners face every day.
You don’t have to pretend you’re the human
There is a more interesting product consequence too. Because Ace isn’t wearing someone else’s name, we can stop doing the uncanny-valley bit.
A delegate has to sound like you, text from your number, and hide in your inbox. Ace can have a recognizable voice, a phone line, and its own iMessage. It can have an employee handbook and a social ruleset for its role: how this company writes in Slack, who gets a call instead of a ping, what “done” means on this team. We get to design a new kind of colleague rather than an increasingly convincing impersonation.
That sounds cosmetic until you build it. With its own identity, every channel can tell the same truth: the message came from Ace, the reply goes back to Ace, and the record names Ace. We can teach it to write a formal email, keep a Slack update short, or make a phone call when something is urgent without ever hiding who did the work. Personality becomes part of the role instead of an imitation of the person who happened to connect the account.
Once Ace is a real actor, authorship stops being a label we add afterward. The system can distinguish what Ace drafted, sent, approved, or escalated because those actions originate from Ace’s account. You can give it a specific manager who approves consequential requests instead of sending every decision back to whichever person connected the integration.
It also lets two kinds of rules live beside each other without pretending they are the same. Social rules belong in the handbook: how direct to be, when to call, when to stay quiet, what channels can tolerate humour. Hard boundaries belong in the architecture: which data Ace can read, who can approve an action, which systems it can enter, what it can never send. One teaches Ace how to work here. The other makes sure good manners are never mistaken for permission.
Before it becomes obvious
"Creator” spent years sounding like a cringey made up word before it became a normal part of how marketing works. I think “digital teammate” is headed for the same fate. Eventually it will be boring. The interesting question won’t be whether a company has agents, but how it hires them, manages them, and decides what they are allowed to know.
By then, the distinction in this post may feel obvious. Claude and GPT can draft, analyze, and fight you on the design. Work that has to live on a team needs something else: a name on the org chart, an address other people can CC, and a seat IT can revoke.
We built Ace on that bet. Not as a better ChatGPT, but as something you can put on the team. If “digital teammate” becomes as ordinary as “creator,” the choice we made early will sound obvious: a teammate should have an identity of its own.






