Skip to content

Trust & control

Powerful agents. Your rules.

An agent that can change production deserves the same care as a senior engineer with the keys: limited access, approvals, a complete record, and a stop button you can reach in one tap.

Trust & control

Agents act.You decide how far.

Set an autonomy level for every kind of decision, per environment and budget. Prompts never grant permission - only a human can raise a level.

L2

Act with approval

Go ahead once the right person says yes.

For example

Release a new version to production.

  • Scoped by environmentDev, staging and production each get their own level.
  • Scoped by money and timePer-action and monthly caps; business hours or always.
  • Irreversible waits for youDeleting data, IAM changes and contracts always need a named human.

Careful by default

Sensible defaults.Every one yours to change.

  • L5

    Write code and open a pull request

    Always fine - you review before it merges.

  • L3

    Roll back a bad release

    Done at once, you are told, you can undo.

  • L2

    Release to production

    Waits for a named approver.

  • L1

    Delete data, change access, sign contracts

    Only ever proposed. A person decides.

When you can't be reached

Emergencies have rules too.Strict ones.

Only in a real emergency

An outage, a breach or data at risk - and only after the people who could approve have been tried.

Only the smallest safe step

Contain the damage with a step that can be undone. Never delete, grant access or commit money.

Checked before it acts

Every emergency action is independently checked against your rules before anything runs.

Reported straight away

You get a clear account of what happened and how to undo it, and a person reviews every step.

Security model

Least privilege.By construction.

  • Least privilege

    Agents get only the access a task needs, only for as long as it needs it.

  • See it before it happens

    Changes to your infrastructure are shown to you before they run.

  • Can't be talked into more

    Permissions come from your settings - nothing an agent reads can raise them.

  • Isolated by default

    Code an agent writes runs in a locked-down space, away from everything else.

  • A complete record

    Every action and approval is kept and exportable for your auditors.

  • Your data stays yours

    Your code, data and logs are never used to train AI models.

Hire your AI IT company.Before your next hire.

Early access opens to a small group first. Tell us what you would hand over, and we will be in touch.