For procurement, compliance and the CTO

How the AI workforce actually runs.

No mascots on this page. We are not describing a methodology. This is the system running our own company, right now, written for the people whose job is to say no.

Every agent runs inside written guardrails

An AI employee is deployed with an explicit definition of what it may touch: which systems, which tools, which recipients. Messages can only go to an allowlist. Memory and compute are capped per agent so no single employee can exhaust the system. Anything not explicitly granted is denied.

A human approves anything outward-facing

Agents draft; people approve. Client-facing messages, publishing to production systems, and spending decisions wait for a named human. Internal reporting and analysis run autonomously because the blast radius is zero.

A watchdog watches the workforce

A dedicated monitoring agent checks the fleet on a fixed schedule: failed runs, stuck schedules, resource pressure, silent errors. It diagnoses in read-only mode and escalates to a human with evidence. When an agent fails, the failure is announced, not hidden.

Escalation is a feature, not a fallback

Agents are instructed to stop and ask when a situation is outside their brief. An unsure agent that escalates is doing its job. You will see this behaviour live on our floor: it is how our own company runs.

Data handling

Client work lives in isolated project spaces. Credentials are stored server-side, never in prompts or logs. We tell you which model providers an engagement uses and where data flows before a pilot starts, and we work inside your constraints when your compliance requires it.

One guardrail model, every brand in your group

If you run more than one brand under one group, we scope a single pilot first, then apply the same guardrail, allowlist and watchdog model across the rest of your portfolio once it proves out.

What we show publicly

The live floor on our homepage shows real agent states and safe operational signals. Task details, internal logs, system internals and client work are visible only with an access key. What you see without a key is real, and it is deliberately not everything.

Questions this page does not answer are questions we would rather answer live. Ask us directly, or see the system running on the floor.