The data room as an agent platform

Waafir Team3 min read
  • Product
  • AI

The data room has always been somewhere you put documents. The more interesting question now is what happens when the people reading those documents are no longer the only ones working in the room. AI agents are becoming first-class participants in deals — triaging diligence, drafting summaries, answering questions across hundreds of files. A data room that an agent can only stare at from the outside is a missed opportunity. The room itself has to become something an agent can act inside.

There is now an open standard for connecting AI agents to tools and data. We think a serious data room should speak it in both directions.

Expose the room as tools

In the first direction, the data room publishes its own capabilities as callable tools: read the structure of a room, retrieve a file, redact sensitive text, translate a document, inspect and apply permissions. An agent — yours, or one running inside the product — can invoke these the same way a person would click them, and crucially under the same controls. Every call is scoped to the caller's actual access, re-checked against their role at the moment it runs, and written to the same audit trail as any human action. The agent gains reach; the room keeps its guarantees. Reach without governance is how confidential documents leak — so the governance is not an add-on, it is the point.

Let the room reach out

In the other direction, the room is also a client. You can register your own external tools and let the data room's agents call them — pulling in a system of record, a research source, an internal service — without us pre-blessing every integration. The boundary is yours to extend. And because anything you connect can return adversarial content, untrusted tool output is fenced before it ever reaches a model, so a hostile document can't quietly redirect an agent.

Build what's core; compose the rest

This two-way posture reflects a deeper choice about how we build. A confidential-document platform has a small number of things it must own outright: how documents are stored and rendered, how access is decided, how every action is recorded, and how AI reasons over the corpus without the content ever leaving the perimeter. Those are the trust boundary, and the differentiators — so we build them in-house.

But the long tail of a deal touches capabilities that specialists have already solved superbly. Electronic signatures are the clearest example: reinventing a compliant signing stack would add risk and ship nothing new. So we integrate a best-in-class specialist for it and present it as one seamless surface inside the room. The principle scales — composed where someone else has earned it, built and owned where the trust boundary demands it.

An agent platform is exactly the architecture that lets both coexist: a stable, governed core that exposes itself cleanly, and an open edge that composes the rest of the world. A data room that only stores files asks your team — and their agents — to work around it. One built as an agent platform lets them work through it. That is the room we're building.