Operator runs the server work you'd rather not.
Ask in plain language: disk, logs, processes, a stuck service. Operator works on your servers over SSH, shows you what it found, and waits for your approval before anything destructive. Nothing is installed on the box.
$ journalctl -u app -n 3
connecting to postgres://app:[REDACTED:DB_PASSWORD]@10.0.0.4
error: connection pool exhaustedApprove destructive action
Nothing executes until you approve; your permission is re-checked, uncached, at that moment.Hand it the job, not the steps.
Operator's agent works through a fixed set of tools. It prefers safe, read-only commands first, and it never makes up command output.
Commands
Runs shell commands on the server you name, and pages through long output instead of losing it.
Files
Lists, reads and edits files, writes new ones and deletes old ones, over SFTP.
Restarts
Restarts a server with the restart command you configured for it, and only with your approval.
Memory
Keeps runbooks and durable facts about your environment. Anything in IMMEDIATE.md is in front of it in every session.
The model is yours: Operator uses the language model your project connects in Trusplex Console (OpenAI, OpenRouter or Ollama), chosen per environment. Operator never holds the key.
A terminal and your files, in the browser.
Terminal
A live shell on any registered server, over the same key. Output is scrubbed of your secrets as it streams, and every open and close is audited.
Files
Browse, upload, download, edit in place, rename and delete. Transfers go over SFTP on the same connection, up to 25 MB each, and downloads are scrubbed of your secrets.
Secrets
Store a value once and use it as @DB_PASSWORD@ in a command. It is filled in just before the command runs, and nobody can read it back: not you, not the API, not the agent.
One line in authorized_keys.
Register a server with its host, port and SSH user. Operator gives each environment its own Ed25519 key. Add the public half to ~/.ssh/authorized_keys for that user, press Verify, and you are connected.
To your server, Operator is just that user. Limit what the user can do, and you limit Operator. Password login can stay off.
# ~/.ssh/authorized_keys — the whole install ssh-ed25519 AAAAC3Nz… trusplex-operator:<environment-id>
Every connection updates the server's status, so when one won't connect you can see why:
- pending
- Registered. The key isn't confirmed on the server yet.
- reachable
- The last connection succeeded.
- key rejected
- The server answered but refused the key. It isn't in authorized_keys for that user yet.
- unreachable
- The port is closed, the host is down, or the name doesn't resolve.
It asks before anything it can't undo.
Approval for destructive actions
When the agent wants to restart a server or delete a file, it stops and shows you exactly what it will run. Nothing happens until you choose Approve & run, and your permission is checked again at that moment.
Checked twice, every time
Each tool call must pass your own permissions and the agent's fixed policy. The agent can never do more than the person who asked it.
Secrets come back redacted
Everything that leaves a server, from command output to downloads, is scanned for your secrets and your environment's private key. What you see is [REDACTED:NAME], even as an owner.
An answer to "what changed?"
Every command, tool call, file change, redaction, approval and denial is in the audit log, whether a person or the agent did it.
Operator is not monitoring, CI or a deploy pipeline. It is hands for the work those tools leave behind. Where you already have a tool for a job, keep it.
Your first server takes one paste.
Sign in, create a project, register a server and add the key. Then hand Operator the next ops task that comes up.