Not a chat box bolted onto a dashboard — a real agent runtime. Claude Code runs in a sandboxed terminal inside your workspace, wired to your data over MCP, and everything it ships waits at the same review gate as your team.
The agent can build — but only inside the walls. Each terminal session gets a fresh machine with bubblewrap isolation: your repo mounted, your scopes enforced, torn down when you're done.
The terminal doesn't guess — it calls. Tenant-scoped MCP servers expose your SEO context and the DataForSEO index as typed tools, so every claim in a session traces back to a real call with a real schema.
Servers mount per workspace. The terminal for one client can read that client — and nothing else. No global keys, no shared context.
The same typed-tool discipline powers the ads workbenches — propose, approve, apply. See it in Growth →
Long jobs go headless — claude -p, an isolated clone, a context pack attached. What comes back is a draft at a gate, not a surprise in production. And headless publish is fenced to Claude only: the budget model can’t ship unsupervised.
Drop a pin on the live draft and type the note. The agent turns it into a bounded JSON edit — scoped to the element you touched, diffable, and gated like everything else.
Claude by default. Kimi K3 where budget wins. Hard fences wherever money or publishing moves.
The runtime isn't one page — it's underneath the platform.