<!-- Published by AIMasterz at https://aimasterz.com/docs/templates/05-os-fit-sheet.md . Part of the Company OS Method: https://aimasterz.com/docs/method -->

# OS Fit Sheet — <Digital Employee name>

Stage 5 of the [method](https://aimasterz.com/docs/method). For every requirement from the role design, name the native Company Workspace (Cloudflare OS) feature that delivers it. Native first; a requirement with no native fit is a gap with a decision.

## Native feature reference

| Native feature | What it gives a Digital Employee | Limits to check (verified at Cloudflare OS `6478a14`) |
| --- | --- | --- |
| Sign-in (Cloudflare Access or built-in accounts) | Human identity for the manager and operators | Admins are a fixed deployment list |
| Admin agent instructions | Rules that apply to every agent in the deployment | Global only; there are no per-agent instructions, so the role prompt travels with the agent spawn |
| Agent chat | Asking for work; conversational follow-up | The chat agent has `webFetch`; spawned agents do not |
| Gadgets | The role's home: server code with its own SQLite storage and a sandboxed UI for reports and decisions | No internet access; everything goes through bindings |
| Agent spawner binding | Starts the role's agent from Gadget code with a prompt, a fixed model and a fixed set of bindings | Spawned agents only inspect and call bindings in code (no web fetch, no file editing) |
| Scheduler Gatekeeper | Daily, weekly or one-time runs in a set time zone; runs Gadget code, which can spawn the agent; retries | Schedules start disabled and a person enables them once; no run history view |
| Context Gatekeeper | Curated knowledge collections, optionally backed by a Git repository | Agents can search and read only; people (or a Git push) write documents |
| Gatekeepers (connections) | Resource-scoped access; reads logged and allowed; writes queued for a person | Approval is per item in the UI; a Gatekeeper may mark specific action kinds auto-approvable, which a workspace can then allow |
| Supabase Gatekeeper | Read-only SQL runs directly; schema and table introspection | Grant is project-wide (no schema narrowing); every write waits for a person, with no auto-approval |
| MCP Gatekeeper | Any MCP server as typed tools; scope a grant to named tools | Writes wait for a person |
| Google, GitHub, Slack, Notion, Linear, Email Gatekeepers | Those systems, scoped per resource | Check each for read vs write behavior |
| Blueprints | A Gadget saved as a template others can instantiate with their own connections and model | Captures code, not data, chat or credentials |
| Sharing | Build / use roles and links for collaborators | — |
| Notifications | — | None built in: no email, push or in-app alert for finished runs or waiting approvals |
| Cost | Per chat and per workspace in the UI | Not readable from Gadget code |

## Fit table

| Requirement (from role design) | Native feature | Configuration | Limits found | Covered? | Gap → decision |
| --- | --- | --- | --- | --- | --- |

## Gaps

| Gap | Why native does not fit | Proposed build | Decision ID | Owner |
| --- | --- | --- | --- | --- |

## Gate

- [ ] Every requirement is covered natively or recorded as a gap with a decision and owner.
- [ ] Limits found while testing native features are written down.
