Every exchange your business has with a customer — support, CRM, content, follow-up — runs continuously on shared memory. You set which workflows run unattended, which escalate, and which wait for a person to approve.
Email, chat, SMS and voice land in the same place, against the same customer. The agent answers where they wrote, and the record behind it updates itself.
Your own address. Threads stay together, signatures are stripped, opens are counted.
A widget on your site. Answers straight away, escalates when it should.
Two-way SMS from your own number, in the same thread as everything else.
Calls become text in the same thread, with a summary and a follow-up.

The work that’s left.
The judgement, not the typing.
Every workflow is an MCP tool on one endpoint. Bring any model — Claude, ChatGPT, Cursor, your own — and shape it into whatever agent your business needs.
One Postgres schema, one identity model, an MIT licence. Your engineers can read all of it before you sign anything.
Munin does not automate a few tasks around the edges. Every exchange your business has with a customer — the answer, the record it updates, the follow-up it earns, the article that stops the question recurring — runs continuously against one shared memory. Four of them look like this.
These four are illustrations, not the boundary. Anything your team does across CRM, conversations, knowledge, content, and outreach composes the same way — you describe the job, the agents run it, and you decide where a person steps in.

Before it ships.
Someone still decides where the line falls.
Munin gives you more than one operating mode. Some workflows are autonomous. Some escalate to a teammate. Some create reviewable drafts for approval. The common thread is that access is scoped, actions are visible, and riskier AI work stays reviewable.
The agent gathers, drafts, and proposes. The human does the judgment. Edit a draft and the model learns the diff. Reject and the activity history records why.
winback-prospects-q2. Consent and compliance checks ran clean. Awaiting approval to schedule.Set up a chat widget, a CMS blog, and analytics in a single Lovable prompt. Lovable builds the frontend — Munin spins up the operations behind it.
One contact, one Tuesday. Every module wrote to the same record, so each step already knew what the step before it had learned.
No integration ran between those steps. There was nothing to integrate — it was one record the whole time.
Threll.ai runs the complete customer platform in production — the chat widget, email, voice, analytics, and the CMS behind their site, all on the same Munin every account gets.
Before, every question about a customer meant joining three systems by hand and hoping the email addresses matched. Now it’s one query. The agent answers from the whole record instead of whichever slice it happened to be pointed at.

Same code. Same MCP endpoint. Same Postgres schema. Pick the path that matches what your team can take on — switch any time, your data follows you.
Real OSS. The whole suite, running on your hardware, your cloud, your terms.
docker compose up — the whole stack on one hostReady in five minutes, EU-hosted, no card. The whole suite — for solo builders, small teams, and proofs-of-concept.
For teams running real customer work on Munin. Higher caps, priority support — metered overage instead of hard cliffs.
Same code, same protocol — you choose where it runs.

Help Scout is the best product in this category at not feeling like a ticket system, and its AI metering is the most honest I have read. Two things send people looking anyway: the per-seat bill as the team grows, and what the agent is allowed to do once it gets there. Here is the field.

At two seats almost everyone is cheap or free — Help Scout's free plan takes five users, Chatwoot's and Crisp's take exactly two. So the seat price decides nothing. What decides it is what the meter starts counting the day you turn the AI on, and whether the answer one of you writes ever reaches anywhere the other one can find it.

MCP's tool annotations are hints, and the specification says clients must treat them as untrusted. A hint asks the client to be careful. A required `ifVersion` in the input schema doesn't ask. Here is what a version row actually holds, what restore actually does, and why six CMS tools refuse to run without the number you last read.

Munin sells the tools and none of the intelligence. Point any MCP client at it and a frontier model you picked does the writing — a Claude subscription from $20 a month, with the model a field on the scheduled task. HubSpot Content Hub Professional is $450 a month with its AI metered in credits. Here is the rig, and the one decision it hands back to a human.
Stop running your customer operation.
Start supervising it.
Free tier, no card. Self-host instead if you would rather.