Offer · Operate Early access

Work out what your nights cost you.
Then read what we refuse to promise.

Managed Run is the service layer over agents that already do the work: the catalogue of what is in scope and what deliberately is not, three service levels measured from sources that are not ours, the list of levels we will not commit to yet and the reason for each, and a named person who can stop the whole fleet at three in the morning.

Start with your own arithmetic

Not ours. Four numbers you already have, multiplied in the order below. Whatever comes out is the figure this offer is measured against — and it is the figure to check with your own finance team before you talk to anyone, including us.

Count

The positions you cover around the clock. Not people — positions. One seat that must be filled every hour of the year.

Multiply

By the people each position takes. Once you subtract leave, training, sickness and the legal working year, covering one seat continuously takes closer to five people than to four.

Multiply

By your fully loaded cost per person, for the country you actually staff it in. Use the onshore figure if you have already ruled out doing it elsewhere — most regulated buyers have, and comparing against a blended rate flatters the wrong option.

Then add

What you already pay for the out-of-hours premium on every managed line in your contracts. Moving a managed service from business hours to full cover is a consistent, published uplift — and where that uplift is a flat amount per unit rather than a percentage, it grows as a share of the total the larger your estate gets. Pull the figure off your own schedule; you will find the same line in every one.

Result

That is the seam. Agents cover the night at no marginal cost; people do not. What still needs people at night is the decision under ambiguity and the crisis — which is a much smaller rota than the one you staff today, and the only part of it this offer asks you to keep.

We publish no price on this page on purpose. The unit is per governed asset in the units your own schedule already uses, with full cover as a multiplier rather than an invented availability tier, volume tiers as your estate grows, and a capped outcome component on counters that can be verified from outside. Ask us for the schedule when you want it.

What we measure, and what we will not pretend to

Most run proposals hand you a page of percentages. Here is ours, in two halves, and the second half is the one worth reading — because a service level nobody can recompute is not evidence, it is a claim.

Committed, and how each is measured

  • Agent decision time — from the platform's own run records, stamped independently of the agent that acted. We report the distribution, never the average.
  • Out-of-scope attempts — from the record the permission check writes itself, not from the agent's account of its own behaviour. We publish which tools that check covers, and which it does not, beside the number.
  • Resolutions backed by a verdict — counted only where a deterministic check of your own monitoring or your own scanner said the service was back or the exposure was gone. Never from a ticket changing status. A job that finished is not a fix.
  • Time to restore, as a floor: the clock starts on a record we do not write, and stops on one we do. We tell you that in the same sentence as the number, which will make our figure look worse than a provider who counts a workaround as a fix.

Not committed, and why

  • Availability percentage — measured, not yet committed. When your monitoring pushes its alerts to us, we compute it for the services you declare, with the share of time your monitoring actually covered printed beside it. A failure your monitoring does not see counts as up, and planned maintenance is not yet excluded, so we report it rather than promise it.
  • Time to acknowledge — measured, not yet committed: from your monitoring tool's own start time to the first acknowledgement by a person, never by an agent. There is no standards definition of it, so the contract has to define it, and we commit to it only once there is a measured history behind the number.
  • Time to a human picking up after an agent escalates — the commitment we most want to make. We measure it from your own tooling where your process records it, and we will commit to it the moment we can prove it on ours.
  • Audit coverage of one hundred per cent — the trail proves a decision was not removed. It cannot prove one was never written. We commit to retention and to a timed test that reconstructs a randomly chosen action end to end.
  • Neutralising incidents before impact — it would mean charging you for something that did not happen. Excellent as an indicator, unusable as a promise.
  • Justified escalation rate — a judgement with no record. Sold as a reviewed sample with a published definition, not as an automatic number.
  • Rollback rate — self-reported, and two-sided: too low means we are not rolling back when we should.
  • "No agent acted on an out-of-date procedure" — nothing links a run to the version of the procedure it used. We report how fresh the documents are, and say plainly that it is a different claim.

Every figure we publish carries four things beside it: the window it was measured over, the system it came from, how much of that window that system actually covered, and whether the source is independent of us. Below the agreed sample size we print insufficient evidence rather than a percentage. Where the record that would tell us how something was handled is incomplete, it counts against us, never for us.

The catalogue is the contract

One sheet per service, and beside each one its state. A service with no sheet is not in the service, and an exclusion written down in advance is cheaper than the same exclusion discovered during an incident.

Delivered

Agents read and act, through a team that owns the action, with a path to act that actually exists.

Incidents and remediation on standardised infrastructure · production change · patch compliance and exposure closure · storage · backup, restore and proven recovery · non-human identity hygiene · governance of the agent fleet · the service reporting itself.

Consumed, not administered

We read your tool continuously and act on what it raises. We do not administer the tool, so we refuse any unit that prices administration we do not perform.

Your monitoring and its probes · your log platform · your configuration database · cloud provisioning, where plans are prepared and verified and a person applies them.

Out of scope

Written into the catalogue as an exclusion, naming who keeps it. We say this before you ask, not after you sign.

Network device administration · the user-facing service desk · database administration beyond observation and recommendation · disaster-recovery failover orchestration · cloud cost optimisation.

Each sheet also carries the part nobody writes down: your coverage hours and ours stated separately, the dependencies and what happens when one is unavailable, your own obligations, a named owner per agent, how each level is measured and whether you can recompute it, the volume envelope, and what counts as a change to the sheet — including a change of model, prompt or autonomy level, because that changes how a production system behaves.

Autonomy is earned per action, and handed back automatically

Every class of action holds a level and a budget over a rolling window. The budget is spent by a failed autonomous action, by a rollback, and entirely by a single action taken outside its declared scope.

Within budget

The class keeps its level and keeps accruing the evidence for the next one — decisions accepted without correction, attempts that stayed inside their bounds, the scope's configuration quality, and every qualification scenario passed on the version actually running.

Budget spent

The class drops back to supervised at once, with no meeting and no notice. That is not a penalty and not a failure of the service — it is the retreat both sides signed for in advance. Failing to carry it out is the breach.

One bad event

A single event that eats more than a fifth of the budget forces a review with named corrective actions before the class can earn its level back.

Twice in a quarter

The same kind of failure twice sends the class back to recommending only, and its qualification scenarios are extended before anyone discusses promoting it again.

Going back up

Never automatic. Promotion is decided in the monthly review on a prepared record, and the decision is written down and signed. Stopping is always allowed; restarting is a person's decision.

An action taken outside its scope that actually took effect is a governance breach, and its remedy is control rather than money — the class is suspended, the cause is written up at our cost, and it is re-promoted only after a re-qualification you witness. An attempt that a guardrail blocked is not a breach: we report the count and the cause, and we expect it to be greater than zero, because a period reporting no attempts at all is either a period nobody looked at or a period nobody tested.

Acknowledgement is not pickup

A receipt is something a tool can produce. A handover is a named person taking ownership of the record in your own system and saying what happens next.

So no agent in this service holds a tool that can acknowledge an alert, and none can change a ticket's owner or its state. Not as a policy — as a missing capability. It is the difference between measuring a handover and manufacturing one.

Every escalation carries an action

  • What happened, what the agent already did, and what it refused to do and why
  • The decision or action the person must take, and by when
  • What happens if nobody acts
  • An escalation whose only possible answer is "seen" is a notification, and is counted separately

And a ceiling, in both directions

  • A volume ceiling per scope, agreed from the baseline measured before anything ran
  • Above it, the excess is reported as a flood with its cause and a review is convened — you see it, and we are not penalised for an estate degrading
  • Without a ceiling the arrangement is gameable twice over: escalate less to look autonomous, or flood your rota and blame your staffing
  • A ceiling rising month after month is the honest signal that the fleet is not improving, and we report it that way

Wave 0 is a measurement, not an agent

The first deliverable is not an agent. It is a measurement of the run as it is today — frozen, signed, with the queries recorded so you can recompute every figure, and with what it does not contain stated. Without a before, nobody can argue about the after.

WAVE 0

Measure

Volumes by category, severity, scope and hour. The spread of your delays, not the average. Recurrence. Effort agreed by both sides before. Out-of-hours callouts and what came of them.

WAVE 1

Volume, low criticality

Backup conformance, event triage, catalogued standard work, patch compliance, configuration hygiene. High volume, low unit risk, procedures already written.

WAVE 2

Core operations

Systems, virtualisation, storage, containers. Autonomous on a known cause with a runbook your team wrote; supervised otherwise.

WAVE 3

Sensitive, watched

Production databases, core network security, continuity. Observation and recommendation only — and one of them is watched from wave 1, so the record exists long before anyone asks for action there.

Two more things we ask for, and neither costs money. Keep a hold-out scope: two comparable scopes over the same period, one with agents and one unchanged, because it is the only way to tell the fleet's effect from a quiet quarter. And agree the success criteria in writing before go-live — the metric, the denominator, the source, who adjudicates, and what happens commercially if the answer is no. A gate that cannot fail is not a gate. Headcount is not the criterion: it is computed from the baseline at the end and reported, because a pilot optimised on removing people produces agents nobody dares put into production.

Your obligations, and what they suspend

The service depends on things you own. When one of them slips, the honest consequence is not that we failed — it is that the affected class drops back to supervised and that level is suspended, with the date, the measurement and the owner recorded. It resumes when the obligation is met.

What we depend on

  • The freshness of your configuration data, and whether your sources agree with each other
  • How current the procedures and runbooks the agents load actually are
  • Access and credentials provisioned — verified technically, never on a declaration
  • The quality of your ticket data, because the denominators come from it
  • How quickly your people answer the approvals supervised actions wait on

How exclusions work

  • An exclusion is a claim with a deadline and a burden of proof, never a checkbox
  • Planned maintenance is declared before it starts. A window filed after the outage is refused by the clock, whoever asks
  • Planned maintenance has an allowance; the excess goes back into the measured figure. Emergency maintenance is never excluded
  • An exclusion we attribute to you is a two-party record — if you have not accepted it, it is reported separately and never applied
  • Every figure states what was taken out, on whose decision, and how many exclusions we proposed that you did not accept

What is live, what early access adds

Live on the platform today

  • The execution teams this service holds: incidents and remediation, the governed change path, exposure closure, proven recovery, identity hygiene
  • Read connectors into the monitoring, ticketing, automation, backup and scanning tools you already run — consumed in place, never replaced
  • One registry and one set of rules for every agent, with a stop that halts an agent or a whole fleet and leaves a record
  • Autonomy that moves on measured results, and an audit trail the acting agent cannot write
  • An export of the agents, their rules, their knowledge and their decision history, usable without us
  • Installation on your premises

Built with early-access customers

  • Service levels computed continuously against your contract, with the money at risk separated into what is already incurred and what is only projected
  • The record of a person taking an escalation — the one missing piece between measuring time-to-pickup and committing to it
  • A measured audit-completeness figure, to replace the retention commitment and the timed reconstruction test
  • Pre-authorised change and runbook classes, which is what stops a weekly human board becoming the bottleneck again
  • Every agent action refused unless it is attached to an authorised record, enforced rather than disciplined
  • Supervision as an administered service, and a route into network devices — both absent today, and both stated as absent

Priced per governed asset in the units your own schedule already uses, with full cover as a multiplier, volume tiers as the estate grows, and a capped outcome component only on counters that can be checked from outside. We take a share of savings only where somebody else issues the number — a cloud provider's invoice qualifies; "incidents avoided" does not.

Managed Run holds the service. The work is done by Incident Neutralisation, Change Guard, Fix Squad, Recovery Proof and Identity Hygiene. Coming in is Run Takeover; leaving is Reversibility Dossier.

See every offer · Agent Fleet Guardian