Each offer is a packaged team of agents with a bounded job, a list of what it may never do, the moment it must stop and call a human, and the evidence it leaves behind. Your team runs it on MeetLoyd, on your premises if you need that. Autonomy is earned on measured results, never switched on by default.
Whoever built the agent — us, a platform vendor, your own developers.
One registry and one set of rules for every agent in the company. Autonomy earned on evidence, a stop that halts an agent or a whole fleet, one identity per agent, and an audit trail the agent cannot write.
Every model call metered as it happens and attributed to a business unit, a project and a use case — budgets checked before the call, not discovered on the invoice, cheaper models recommended only on measured evidence, and every saving proved on the same workload.
Evidence for DORA, NIS2 and the EU AI Act produced while the work happens, signed by the runtime, assembled into auditor-ready packs per regulation and entity — then exported as OSCAL and OCSF into the GRC and SIEM you already own.
They plug into the tools you already have — monitoring, ticketing, automation, backup — and never replace them.
The service layer over the offers below: one catalogue with an honest state per line — delivered, consumed but not administered, or out of scope — three service levels measured from sources that are not ours, the list of levels we refuse to commit to and the reason for each, autonomy that hands itself back when it misbehaves, and a named person who can stop the whole fleet at three in the morning.
The governed path every production change takes: risk-scored, authorised, executed through your own automation, verified, and rolled back if it did not work.
Proof that each business service comes back: what your CMDB says it is made of reconciled against every product that protects it, isolated restore drills across all of them, recovery time and data loss measured, and signed evidence.
Downstream of whatever already correlates your alerts: one ticket per root cause, specialists for Linux, Windows, virtualisation, storage and containers, remediation only from your own runbooks through your change process, and recovery proven from your monitoring — out of hours included.
From a scanner's finding to a verified fix: ranked across every scanner, repaired through the tool that owns the asset, and closed only when a new scan no longer sees it, with the evidence kept.
The accounts nobody owns: service accounts, keys, secrets, certificates and agent identities, in one list with a named person behind each, rotation kept on your policy, re-certification run on your cycle — and nothing disabled until every system holding it has proved, over your whole quiet period, that nothing uses it.
Projects with a fixed scope and a clear end.
Measure the baseline before anything is automated, score how far each scope's configuration can be trusted, turn your runbooks and your leaving experts' know-how into skills that have been replayed, give every agent an identity and a bank of scenarios it must pass before it touches production — then a go/no-go your own people sign and that is allowed to be a no, and hypercare with an end date.
Everything your agents are made of — the registry, the policies, the rules, the knowledge you gave them and the history of what they decided — exported in a documented format, with each year's exercise restoring it into a clean workspace and recording what came back and what did not.
Your agents attacked the way a real adversary would — injected instructions in tickets and e-mails, over-broad permissions, poisoned tools — before they are admitted and after every change.
Every offer is deployable by your own operations or security team. A partner can run it for you if you prefer; nothing depends on one.
Each action starts supervised and is promoted on measured results — corrections, out-of-scope attempts, rollbacks — and demoted when those drift.
Rules are checked before the action and the log is written outside the agent that acted. An agent cannot vouch for itself.
Agents consume your monitoring, ticketing, automation and backup in place. Nothing to migrate first.
The whole platform ships as a signed release you install in your data centre or sovereign cloud, with evidence kept where your data is.
Rules, knowledge and decision history export in a documented format. Reversibility is designed in, not negotiated at the end.