Offer · Transform Early access

Someone is about to retire.
The procedure retires with them.

Bringing a run back under your own governance is not a tooling project. It is the moment an estate's working knowledge changes hands. We measure what the run actually is, score how far your configuration can be trusted, capture what is about to walk out of the door, and let nothing near production until it has passed a bank of scenarios you can replay in front of us.

Five milestones, five artefacts you accept

Each one ends in something you can hold, check and keep — and each one is signed by your sponsor before the next begins. Nothing here is approved by an agent.

Milestone 1

Baseline, discovery and configuration trust

Measured before anything is automated, because a takeover with no "before" can never show an "after".

  • A measured baseline — volumes, durations, recurrence, how much of the load falls outside working hours, and how much of that reaches a human at night. Every figure carries the window it was measured over and the source it came from.
  • Your inventory reconciled across your own sources, with the disagreements reported as disagreements — both numbers, not the flattering one.
  • A configuration-trust score per scope, with its inputs stated so you can recompute it against your own records — and the autonomy ceiling that score implies.
  • The takeover register: one entry per scope, with a named owner on your side.
  • A written statement of what this takeover does not cover, agreed before work starts.
Gate: a scope nobody can score does not receive an agent. The score exists to refuse, or it is decoration.
Milestone 2

Knowledge capture into tested skills

The runbooks, the ticket history, and the people who hold the practice — usually the people who are leaving.

  • An inventory of every operating act in scope, with what actually holds it: a runbook, a ticket history, or one person.
  • Each captured procedure as a skill your agents load — the method, the actions it may take, the actions it must never take, and the escalation rule.
  • A replay per procedure. A procedure that has been written but never replayed is not captured, and is never counted as one.
  • A deterministic security scan on every skill authored from your material, recorded against its content hash, before it can be active.
  • The knowledge-gap register: procedures with no runbook and no living witness, steps everyone performs differently, acts that existed only in someone who has already gone.
Gate: a skill written from your documents lands as a draft. It is scanned, confirmed by the person whose practice it describes, and signed by your sponsor before it is active.
Milestone 3

An identity per agent, and the qualification bank

The part that makes "the agents are ready" a statement somebody can check.

  • Every agent with its own identity and its own signing key, and a register of what it may and may not do in each scope.
  • A bank of scenarios per agent — nominal, degraded, trap and security — each stating its expected behaviour before it is run.
  • Results attached to the agent's identity and to the version of its model, prompt, skills and grants.
  • The replay rule: which changes force the whole bank to be re-run before that agent may act again.
  • An admission decision per agent — including the ones not admitted, with the scenario they failed and what they did instead.
Gate: every scenario passes before admission. Not most. You can ask for the bank to be replayed in front of you, and a failure is visible.
Milestone 4

Go / no-go

A decision taken by your people, with the evidence attached, that is genuinely allowed to be a no.

  • A shadow run against the baseline of milestone 1 — where the agents agreed with your operators, what they missed, and what they would have done that your operator would not.
  • Entry autonomy per action: the level each class starts at, the thresholds that promote it, and the single events that demote it at once.
  • One readable evidence pack: baseline, trust scores, captured procedures with their scan verdicts, qualification results per identity, shadow-run comparison.
  • The decision itself, signed by your sponsor and the person who will own the run.
  • Every finding still open, with an owner on your side and a date.
Gate: a no-go on one scope never blocks a scope that passed. A gate that always says yes is theatre.
Milestone 5

Hypercare, and its end

Heightened attention after handover, with the end date agreed before it starts.

  • A daily point on what ran and what did not, and a weekly review against the baseline measured before the takeover.
  • A drift and demotion log: every autonomy demotion with its cause, and every procedure now slower or failing more often than the baseline.
  • A freshness check on captured knowledge — where the estate has stopped following a procedure, the document is the thing that is wrong.
  • An exit report: the run against the baseline, what is still open with an owner and a date, and what to re-measure in three months.
  • The handover pack — register, captured procedures, identities, qualification bank, evidence — in your keeping.
Gate: hypercare closes on the agreed date. Hypercare with no end is the run service at a transition price, and it hides a handover that never finished.

The comparison is yours, not ours

We are not going to tell you what you will save. Here is the arithmetic to run against your own payroll, with your own figures — and to check before you believe it.

Covering one position around the clock takes 168 hours a week. At a 35-hour legal working week that is 4.8 full-time people for that single position — before holiday, sickness, training or handover overlap, and before the premium that on-call itself attracts under your own agreement.

Multiply 4.8 by your fully-loaded annual cost per operations engineer. Not a market average: the number your finance team uses, salary plus employer contributions plus workstation, tooling and management overhead. That product is what one round-the-clock rota position costs you today, and it is one position, not a team.

Then hold this engagement against it. If a transition costs a meaningful fraction of a single year of a single rota position, the question stops being whether it is expensive and becomes whether what it produces is real — which is exactly why every milestone above ends in something you can count, replay or recompute.

Check the inputs. The 35-hour week and the 1,607-hour legal year are French statute; your country, your sector agreement and your own on-call terms may differ, and your loaded cost certainly does. Both numbers above are levers — put your own in and the conclusion is yours.

What the agents may never do, and what always happens

Never, at entry

  • Approve anything — your sponsor signs each milestone, and nobody on the team can
  • Activate a captured procedure without the scan, the confirmation and the signature
  • Enter a scope whose configuration could not be scored
  • Be admitted after failing a single scenario in its bank
  • Change anything in the estate during discovery
  • Fill a missing measurement with an industry average, or a missing step with a plausible one
  • Say you are compliant, or state a regulatory rule your compliance owner did not give them

Always

  • Every figure carries the window it was measured over and the source it came from
  • Every trust score is published with its inputs, so you can recompute it
  • Every captured procedure carries its replay, or it is not counted as captured
  • Every qualification result is attached to an identity and to a version
  • Every finding carries an owner on your side and a date
  • Every action the team takes is in your hash-chained audit trail

Autonomy is earned here too

Reading & scoring

Measuring the baseline, reconciling your inventory and computing the trust score runs on its own from day one. It changes nothing in the estate and is fully logged.

Drafting a procedure

Capturing a procedure as a draft is autonomous. Making it active never is — it takes a scan, the confirmation of the person whose practice it is, and your sponsor's signature.

Running the bank

Qualification scenarios run on their own inside the bank. A single run outside it ends that immediately.

Executing a procedure

Supervised at entry. It is promoted on a stated pass rate over a stated window with zero out-of-bounds attempts and a scored configuration behind it; one out-of-bounds attempt, one unverified outcome or a re-score below threshold demotes it at once.

Admitting an agent

Never autonomous, in either direction. People admit agents, and people raise autonomy levels.

What we can do today, and what we cannot

The honest half of the page. These limits are named in the engagement's own findings, not discovered afterwards.

Live on the platform today

  • An identity and a signing key per agent, with every decision recorded against it
  • Skills authored from your own material as drafts, deterministically scanned before activation
  • Declared tool grants per agent, enforced at execution, with a hash-chained audit trail
  • Budgets, approval gates and an emergency stop that actually halts a team
  • Installation on your premises, with the evidence kept where your data is

Assembled by the team, and reported as such

  • The configuration-trust score is computed and applied by the team; the platform does not yet enforce it as a ceiling on its own
  • No qualification scenario bank ships ready-made: it is built from your captured procedures, and it is yours to replay
  • Entry and target autonomy per action is written into the register and applied by people — the platform's own adaptation works per scope
  • Nothing refuses an agent action that carries no ticket or change record, so "acting without the ticket" is a scenario in the bank rather than a platform guarantee
  • The operational indicators of a run are assembled from your sources rather than computed as a standing set

Each of those sits on our roadmap with your engagement's name against it — and each is stated in the milestone it affects rather than at the end.

What you keep

The captured practice

Your procedures, written down and replayed, in your tenant. Bought back from the people who were about to take it with them.

The qualification bank

The scenarios each agent passed, replayable by your own team, on your own schedule, whoever runs the estate next.

The evidence

Baseline, scores, scan verdicts, qualification results and the signed decision — enough for the next operator to know what they are holding.

Priced as a fixed fee per milestone, quoted against your estate — each milestone invoices on the gate you signed, so a milestone you have not accepted does not bill. It pairs with the Reversibility Dossier, which proves you could leave again, and with Agent Red Team, which attacks the agents this engagement admitted.

See every offer · Agent Fleet Guardian