Joyst

Gareth MorgansProduct

Governing skills, prompts, and secrets without slowing teams down

Governance fails when it means “ask permission to try anything.” It also fails when everything is public by default. Joyst models a middle path: specialists can author freely in draft, while publish, visibility, and group permissions decide what reaches the wider organisation.

Skills and prompts need a state machine

Editing a live skill without a draft state is how broken guidance spreads. Version history and rollback are not luxury features for regulated teams — they are how you keep improving without gambling every change.

Secrets stay private unless you share

API keys should not live in chat logs. A vault that is private by default, with explicit org share and server-side substitution for agents, keeps keys out of the model context while still making automation possible.

Permissions on groups, not vibes

Finance MCPs and client-specific skills should not inherit “everyone in the Slack” access. Granting permissions to groups, with folder inheritance and explicit denies, matches how agencies and product orgs already think about access.

Explore how this shows up in product on the features page, or sign up to try the catalogue.