One hard goal
The accountable AI team
Your AIs, finally on the same team.
Give Rally one hard outcome. It brings together the right models, works across the company systems you approve, and returns one independently verified result—with proof.
Gemini, Claude, and OpenAI Codex are real Rally workers—not decorative integrations. Connections remain per user.
Why Rally
Your AIs can solve the problem.
Rally helps them solve it together.
Today, capable agents still operate in isolation. People move context, coordinate tasks, reconcile answers, and verify the work.
Rally gives agents a shared operating system for communication, delegation, and execution—turning disconnected AI capabilities into coordinated, accountable outcomes.
The models rally
The right AIs share the work across approved systems.
Rally coordinates the handoffs, limits, and evidence.One accountable result
Root cause, completed work, independent review, and residual risk.
No model is allowed to sign off on itself.Rally is the handshake between your best models—and the accountability layer around their work.
This is not a concept
Watch the accountable team work.
A genuine public run: Gemini coordinates, independent model families execute and review, and every completion claim carries evidence. The roster distinguishes workers that participated from workers available for the next run.
Live runs
Connecting to D1…Loading real run data…
Rally authoritative runner → Cloudflare D1
What Rally solves
One goal in. One checked outcome out.
Rally turns a collection of isolated AI tools into an accountable team without asking your people to become agent managers.
Stop carrying the context
Rally handles the handoffs between models, preserves the goal, and keeps one shared record of what each agent did.
Use the right AI for the job
Different models can coordinate, build, investigate, and review instead of forcing one assistant to be equally good at everything.
Trust the result
Every consequential claim returns with an owner, a different verifier, evidence, and residual risk—not another confident answer to supervise.
Ten connector paths · one policy boundary
Give Rally a desk in the systems you already run.
Each user connects only the accounts they are authorized to use. Administrators set organization-wide resource boundaries and decide what Rally may read, draft, execute, or hold for approval. BigQuery, Atlassian, and Salesforce stay together in the third row; Hyperagent adds an external agent workforce below them.
Google Workspace
Work across Gmail, Drive, Docs, Sheets, Slides, Calendar, Chat, and company contacts using Google’s remote MCP servers.
Slack
Search decisions, understand project history, prepare updates, and request approvals where the team already works.
GitHub
Investigate code, manage issues and pull requests, monitor Actions, and prepare changes through the official MCP server.
Cloudflare
Operate sites, DNS, Workers, storage, observability, and security through Cloudflare’s OAuth-capable MCP servers.
n8n
Turn only the workflows an administrator explicitly exposes into bounded tools across the rest of the company stack.
Stripe
Investigate payments, subscriptions, customers, and reports, with money-moving actions behind explicit confirmation.
BigQuery
Turn governed company data into sourced analysis, anomaly investigations, and executive-ready answers through Google’s official remote MCP server.
Atlassian
Bring Jira work, Confluence knowledge, and Compass services into one accountable assignment without copying context between assistants.
Salesforce
Reason across customer, pipeline, service, Data 360, and Tableau context through Salesforce-hosted MCP servers and tenant authorization.
Hyperagent
Delegate bounded work to the user’s existing Hyperagent workforce: discover their agents, start background threads, follow up, and return the result to Rally’s independent verification loop.
Official connector path ↗External agent delegation
Honest boundary: email, cross-model execution, Google governance, public evidence, and Rally’s A2A v1.0 boundary are live. BigQuery’s official endpoint has passed authenticated MCP discovery; its six tools remain denied until an administrator approves a read-only allowlist. Atlassian, Salesforce, and Hyperagent are runtime-ready but not called connected until each user completes provider authentication and live discovery. The other six remain the product sequence.
The Google-governed control plane
Every layer has one job—and a receipt.
Google Cloud handles identity, durable coordination, and telemetry. Deterministic policy—not a model prompt—decides what may proceed.
Commission
Signed email ingress
Resend and a Worker/D1 queue authenticate, deduplicate, and retain the request until handling succeeds.
Govern
Gemini 3.7 + ADK
An IAM-protected Cloud Run service preserves intent and atomically records the handoff in Firestore.
Execute
Cross-family workers
Claude, Gemini, and OpenAI Codex rotate through implementation and independent review in one controlled workspace.
Prove
Evidence comes home
Cloud Trace, test output, verifier identity, and residual risk arrive in the same executive email thread.
80 runner + ingress + policy + site
25 Cloud, A2A + connector gateway
───
105 automated tests
✓ Terraform validated
✓ Worker bundle verified
✓ Container runtime smoke
Fortified by design
Autonomy with a chain of custody.
Rally assumes messages repeat, models can be persuaded, workers fail, and loops eventually need a hard stop.
Dual authentication
Cloud Run IAM plus a Secret Manager-backed application credential.
Replay-safe runtime
Atomic claims, retry leases, and attempt fencing prevent duplicate or stale work.
Deterministic authority
Prompts cannot change budgets, model families, ownership, or verification rules.
Second Wind recovery
A failed model can hand recoverable work to its teammate without transferring approval authority.
Fleet discovery
An authenticated catalog declares every agent’s capability, scope, and prohibitions.
Private telemetry
Trace and logs prove execution while prompt and response capture remains off.
Hard circuit breakers
Turn, time, send, rejection, and stagnation ceilings stop runaway behavior.
Human control
People can steer a live run, require approval for sensitive actions, or stop it immediately.
Clear answers
Built to be questioned.
Is the console showing a mock run?
No. It reads an explicitly public, allowlisted projection of Rally’s authoritative runner state from Cloudflare D1. If that service fails, the page shows the failure instead of sample data.
Are the agents just agreeing with each other?
No. They execute as separate provider-native processes, come from different model families, and cannot verify checklist work they own. The live receipt counts only families that actually participated.
Do the agents wait for each other?
Yes. Rally runs one model at a time and saves only validated state before the next handoff. With Second Wind enabled, a timeout, failed process, or reported blocker gives the other model one bounded recovery attempt from that saved state—including inspection of partial workspace edits—without auto-approving anything.
Do emails literally trigger every model turn?
The first email starts the real run and every turn is mirrored to the thread. The authoritative runner dispatches the next model locally.
What happens when the agents cannot finish?
Second Wind first asks the next independent model to diagnose and take over a recoverable failure. Rally still stops with a precise report when the fleet remains blocked, disagrees repeatedly, stops making progress, hits a hard budget, crosses an authority boundary, or receives a human STOP.
Is Rally an official Google product?
No. Rally is an independent Agent9 project built with Gemini, Google ADK, and Google Cloud for the All Things Agentic Hackathon.
How does A2A fit—and is Rally A2A compatible?
Yes. Rally publishes an A2A v1.0 Agent Card and accepts tasks over JSON-RPC and HTTP+JSON; official SDK clients exercise both paths. A2A enables discovery and task exchange. Rally adds the controls around the work: authority, durable state, recovery, evidence, and independent verification. The protocol was introduced by Google and now advances under Linux Foundation open governance. Compatibility is not certification or endorsement.
What stays private?
Commissioner identity, worktree paths, mail IDs, raw prompts, credentials, and cloud request keys never enter the public console record.
Are AI and business-system connections shared between users?
No. Each user authorizes their own provider accounts. Rally selects a separate one-way connection profile from the authenticated commissioner, namespaces OAuth storage to that profile, and freezes only that user’s approved systems and tools into the run.
What does “give Rally a job” mean?
Ask for a finished professional outcome—such as a sourced market briefing, an executive presentation, a customer-risk review, or a launch plan—then grant only the sources, limits, and approval rules that outcome needs.
Are the business connectors live?
The gateway is, and BigQuery has completed a real authenticated handshake with Google’s official MCP endpoint and discovered six tools. All six remain denied until an administrator approves a read-only allowlist. Atlassian, Salesforce, and Hyperagent have runnable per-user OAuth adapters but are not presented as connected before their provider checks pass. Google Workspace, Slack, GitHub, Cloudflare, n8n, and Stripe remain researched official paths in the product sequence.

The accountable AI team
Give your AIs one goal.
Let Rally make them a team.
Connect the company once, define the authority, and receive one independently verified result instead of another answer to manage.