One narrow gateway for consequential action
An AI agent can never change a real system directly. Every change passes through a gateway that checks it against policy—the action’s exact shape, its limits, and its approvers are fixed by the company, and the agent cannot choose its own risk tier or its own approvers.
Stable identity and provenance
Company records preserve the entity, source, actor, causation, correlation, history, and confidence needed to reconstruct why work happened.
Verified effect
An accepted proposal is not proof of success. Idempotency, receipts, readback, and reconciliation establish what the owning system actually did.
Governed self-change
Prompts, models, skills, schemas, policy, rubrics, and governance change through proposal and approval. No agent silently expands its own powers.
Documents are read inside the installation
Scanned pages are read by text-recognition (OCR) software that ships inside your installation—a fixed, known version. Nothing is sent to an outside service and nothing is downloaded at run time. Every page records how it was read: embedded text, OCR, or explicitly unreadable.
Absence is never success
Missing effects or measurements remain not configured or need attention. Released minutes are not converted into money, and financial value is not inferred from activity or prose.
Customer-controlled runtime
The intended BYOC model isolates by deployment. The company record remains in infrastructure the customer controls, rather than a vendor multi-tenant data plane.
No vendor on the authority path
No licence check, vendor heartbeat, mandatory telemetry, vendor-held runtime credential, or inbound management endpoint is intended to block company operation.