LoadoutHQ is the private skills registry for enterprise AI agents. Publish versioned skills into governed folders. Let local agents — Claude Code, Cursor, anything MCP-native — consume only what your team allows.
No commitment. 30-minute intro call. 3 of 5 seats remaining.
Vendor-neutral. MCP-native. Shared-hosted or self-hosted. Built for teams that need governance without the weight of a full enterprise platform.
Skills, folders, tokens, and audit are scoped to your organization. Cross-tenant exposure isn't a configuration option — it isn't a code path.
Folder-based permissions. Direct users or groups, reader or writer. No skill-level ACL maze and no overrides to audit.
Local agents authenticate with a user-scoped token. They see exactly what their human is allowed to — no broker, no ticket queue.
A skill is a small directory with a SKILL.md at the root, optional scripts, references, and assets. The frontmatter is required and
minimal: name, description,
optional labels. Every reader can open every file before they decide to install.
Routes inbound support tickets to the correct team using the company policy graph and on-call rotations.
When a support ticket arrives without a clear owner or escalation path, or when the requester references a team that no longer exists in the directory.
references/policy-graph.md.support/responder).When a user lacks access, we don't show a blank 403 — we show an empty state that explains why, where the request lives, and who to ping. Authorization boundaries are a product feature, not a footnote.
Owners create groups inside one organization and assign them to folders with reader or writer permission. The same group can guard a private folder of skills and a public folder of references — one membership change, every surface updates.
A user can be a member of more than one organization, with membership tracked independently. Skills, folders, groups, members and tokens are scoped to a single org — there's nowhere a query can leak across tenants.
Whether the request comes from the web app, the download endpoint, an API token, or an MCP client, the platform resolves the same permission state. The UI is the contract users see first; it doesn't promise capabilities the other surfaces won't honor.
Pilot LoadoutHQ with a single team. Ship the same governance surface to the rest of the company once it lands. Self-host the moment you outgrow shared.
A loadout is a deliberate selection, not a pile of stuff. Curation is the feature.