Y Combinator open-sourced QM, its production-tested internal AI system, giving organizations isolated workspaces, admin control, and a model-agnostic blueprint, despite documented security limitations.
Y Combinator has open-sourced QM, its actual internal AI system, with the full codebase on GitHub under an MIT license, so any organization can inspect, run, or fork it. Instead of a typical personal assistant, QM gives every employee and room an isolated workspace with its own memory, files, permissions, and sandboxed execution, all managed under a single company-wide admin control plane to avoid the tangled context and permission issues of scaling assistants. The system is model-agnostic, supports multiple swappable harnesses, and includes unified search and a company brain for retrieving institutional knowledge. Its security model enforces a hard baseline policy, uses the user’s own credentials, and logs all actions, while candidly documenting limitations such as the command policy being only a speed bump, plaintext credential exposure, and broad admin visibility with indefinite data retention. YC already runs QM internally across accounting, legal, events, and engineering, making it a real, production-tested blueprint for deploying organization-wide AI agents.
▶ 18:51 QM’s security model prevents unrecoverable actions by reusing proven patterns from local developer tools rather than inventing a novel permission system.
▶ 18:54 The agent operates with the actual user’s credentials and permissions, not a separate elevated account, so every action stays scoped to the human’s access level.
▶ 19:09 All agent actions are logged for audit, creating a clear chronological trail of what happened, on whose behalf, and when—mirroring Claude Code, Codex, and Open Code.
Load the full timestamped transcript on demand and click any time to jump in the video.