The work is routine. Handing it to an agent is not.

Every business has work an agent could carry: the inbox triaged every morning, the numbers moved between systems by hand, the checks somebody runs every week. We build that agent, and we build it like the auditors we are: scoped, logged, and tested before it is trusted.

The build sheet

ScopeOne workflow, chosen with you. The agent does that and nothing else.
PermissionsDecided before the agent exists, enforced outside the model.
LogsEvery action recorded, so you can answer what it did and when.
AccountabilityThe agent carries the work. An engineer answers for what ships.

How an engagement runs.

1. The map

You pick the workflow. Before anything is built, we draw the agent’s map: what it may read, write, spend, and send, and where a person must approve. The price is fixed and agreed before we start.

2. The build

Built to that map, the agent runs alongside the person who does the work today, on real cases. Nothing is handed over until it has done the job in front of you.

3. The attack

Before the agent runs alone, we attack it: hostile inputs, attempts to exceed its authority, every path that could move data somewhere it should not go. The same failure classes we use as auditors. You see every result.

4. The run

Weekly from there. The agent takes on more as the map allows, the logs stay complete, and every change that ships has an engineer’s name on it.

Built by the people who attack agents.

We run an audit practice that attacks AI agents before they go live. The failure classes it publishes are the same ones every agent we build is designed against, from the first line.

The audit practice

What you receive.

  • The agent and its source, with the IP assigned to you.
  • The permission map, in writing.
  • The log of every action it has taken.
  • The pre-live test results, class by class.
  • A runbook: how to run it, and how to stop it.

Hand over one workflow.

The people on the call are the engineers who would build it.