Agents for company IT, under approval rules.
For regulated companies: an agent proposes a change, the owner approves it, and only approved changes are signed and run. Not available yet.
Attest is a planned managed service on Taifoon hosting, not available yet. Agents would make IT changes for a company (accounts, devices, business apps) through connectors with separate read and write rights. A change covered by a rule runs without a person; a change that needs a decision goes to its owner on one card; anything else goes to an expert. Only approved changes are signed and run, and every step is written to a log that cannot be edited and is sealed to the root, so anyone can check it later.
Observed, never trusted blindly: identity, device management, collaboration, business applications, the HR source, and, where relevant, the operator’s connectivity management.
Read scopes and write scopes separated from day one; tenant credentials held in the vault, never in an agent runtime.
Agent roles in isolated cells, EU region for EU clients, attested images published for enclaved workloads.
Four sensitivity levels. Each record carries blast radius, confidence, reversibility, expiry, approver identity and a record identifier. Auto stays off by default in production; enabling it per module is itself a logged decision.
Allowlisted operations, vault-signed, each signature bound to its approval record. No approval, no signature, no write.
The write-once log, sealed roots, scheduled evidence exports, and regulatory evidence packs a third party can recompute.
A person describes the problem where they already work. The route out is chosen by one question: whether a human judgement is required, and whose. Most requests do not need one, which is what separates completing work from routing it.
The policy already permits it. The system diagnoses, proposes the released plan, and asks only when it should happen. A person confirming what the rules already allow is theatre that trains them to click.
Clean up a device, a driver, a restart. Roll out released software. Activate a licence.
A business judgement is needed. The system finds who owns it and condenses the decision onto one card, carrying blast radius, reversibility and expiry. This is the approval ladder, and it is the route below.
Access to a collaboration site. Spend outside budget. Software off the standard list.
Outside the catalogue. The system escalates with the context, diagnosis and history it already gathered, rather than a ticket saying somebody is stuck. What the expert resolves becomes a candidate action.
Security incidents. Fault patterns nobody has seen. Cases with no registered action.
Attest does not replace the organisation’s governance. The policies, the owners and the approval chains stay the customer’s. What changes is that they are executed rather than looked up, remembered, or guessed at by whoever answers the ticket.
Language models are not deterministic, so they sit on the ingestion side and nowhere else. A model takes in the flow of information and hands on two things: structured facts, and a plan assembled from actions that already exist. It holds no permission and reaches no system, and its output is treated like any input from outside: untrusted.
The model may select from the catalogue of registered, tested, released actions. It may not compose a new one. An action nobody registered and tested cannot be reached from a prompt.
Not a system prompt and not a model instruction. Whether a plan is permitted, who must approve it, and what actually runs is never in the prompt.
The consequence is the point: the model is replaceable without the system’s behaviour changing, and a model that changes, hallucinates or fails cannot widen a permission, skip an approval, or reach a system. The execution engine is what holds that line, and the vault signs only what it permitted. The vault and the metal →
Off by default in production; enabling it per module is itself a logged decision.
Low blast radius, reversible: a person confirms with one tap, identity recorded.
High consequence: the approver types the confirmation; the record binds who, what, and until when.
The floor that never passes. Some operations are not automatable by policy.
The honest boundary ships with the product: sealing makes records tamper-evident, it does not make decisions correct. The approval ladder is the human-oversight mechanism that covers what the cryptography does not.
Proves what agents did inside an estate. Governed: nothing executes without approval.
Releases payment on what agents provably delivered between parties. The product →
Neither replaces the other, and both inherit the same sealed roots: the evidence plane is the shared floor. On the OS floor, agents run autonomous by design; under Attest, nothing executes without approval. Autonomous there, governed here, never blurred.
