Cates Works
All work
Platform/2026

Helmsman

Fleetworks suite

A control plane for managing deployments and agentic AI workloads under one org-scoped RBAC, audit, and search model.

Helmsman — A control plane for managing deployments and agentic AI workloads under one org-scoped RBAC, audit, and search model.

The challenge

Teams managing deployments, CI/CD pipelines, cluster quotas — and increasingly AI agents and MCP tool servers — had no single place to see state and act on it. The critical question, “what needs my attention right now?”, took far too long to answer.

Answer “what’s the state of my org, and what needs my attention?” in seconds — then take the one action that matters without ceremony.
The north star

The approach

  1. 01

    Designed a deployment orchestration catalog where Applications own Pipelines, Pipelines produce runs and Deployments, and each Application carries its own per-cluster quotas, permissions, and ownership.

  2. 02

    Extended the same model from deployed applications to agentic workloads — agents, multi-agent processes, and MCP servers — under one framework-agnostic governance layer.

  3. 03

    Made every resource governed by unix-style ugo×rwx permissions on top of an org-scoped RBAC model, with human-in-the-loop approval gates for sensitive actions.

  4. 04

    Built cross-service sync with a sibling service catalog: registering agents, subscribing to webhooks, and mirroring a read-only shadow of the upstream catalog.

Design iteration

From generic dashboard to a purpose-built ops console

The product evolved through a clear lineage — an AI-config tool, forked into a deployment catalog codenamed “Coastguard,” then refined into Helmsman. The defining design pass moved it off a generic indigo admin look into a deliberate cyan “ops-console” identity: a grid-lit deeper-dark shell, glowing metric and chart cards, and calm cyan accents. The hard constraint was discipline — restyle through design tokens and layout only, never rewrite the design system, and keep dense data tables perfectly legible. Dark is the star.

What we built

Highlights of the work

Unified control plane

Applications, pipelines, deployments, quotas, and agents governed under one model.

Attention-first UX

Surfaces approvals, drift, and moderation so the next action is always obvious.

Fine-grained permissions

Per-resource ACLs plus org RBAC make “can’t touch another team’s data” a guarantee.

Multi-console reach

A shared REST API powers web, mobile, and desktop clients from one source of truth.

Let’s talk

Have a project, or a product that could work harder?

Most projects begin with a short, no-pressure discovery call.