Replicate facts, not authority
Enterprise state enters a verifiable backup; AI reads only classified, transformed, version-pinned copies.
Dual-system enterprise AI safety · Open infrastructure · Verifiable demonstration
Agentobe is a dual-system enterprise AI safety research, open safety infrastructure, and verifiable demonstration project. It preserves enterprise facts, lets AI simulate autonomously in isolation, and places every real change behind evidence, human authorization, and deterministic execution controls.
01 / Why now
Connecting agents directly to enterprise systems binds reasoning capability and production authority inside one runtime. Agentobe separates them by architecture.
Enterprise state enters a verifiable backup; AI reads only classified, transformed, version-pinned copies.
Agents may branch strategies, use simulated tools, and form proposals without holding production credentials.
Every real change links to fact versions, alternatives, risk, permits, and execution receipts.
02 / How it works
One continuous loop. Two authority planes. One verified path to production.
Connectors continuously record materials, state, and events into source-faithful immutable backups.
Classify, mask, tokenize, and pin versions by contract; the raw vault stays hidden from agents.
AI compares branches, replays history, and returns alerts, findings, and proposals inside isolation.
Named accountable people review evidence, impact, risk, and alternatives before issuing a permit.
The gateway checks live state and runs allowlisted commands; outcomes return to calibrate the next simulation.
03 / Product architecture
Explains product value, safety boundaries, and the evidence loop, with customer-data-free demo and pilot entry points.
Boundary: reads no customer workspace dataPreserves enterprise facts, creates AI projections, receives AI results, and maintains cross-plane evidence lineage.
Boundary: facts and AI records have distinct authorityLets agents plan, branch, call simulated tools, and produce comparable evidence on governed copies.
Boundary: no production-write authorityBrings backup health, simulations, decision packages, approvals, outcomes, and full audit into one workspace.
Boundary: role, scope, and separation of dutiesTurns valid authority into typed, scoped, idempotent, verifiable, and compensatable real operations.
Boundary: independent identity and command allowlist04 / V1 use case
Agentobe V1 focuses only on customer-support ticket operations. A narrow scope makes the replication, simulation, approval, execution, and calibration loop testable.
05 / Security and trust
Agentobe does not rely on agent self-restraint to protect production. Separate identities, data partitions, human accountability, and a deterministic gateway form the hard boundary.
Raw backups, enterprise events, AI projections, AI results, and execution records carry distinct authority and access rules.
Agents, replication services, approval sessions, and production gateways use separate identities, keys, and execution accounts.
Permits bind package hash, resource scope, command, count, and expiry; free text is never an execution command.
The production gateway rechecks live versions, preconditions, impact limits, stop state, and compensation.
One trace_id connects facts, simulations, proposals, approvals, commands, receipts, and real outcomes.
Data can move in both directions.Agentobe Principle / Core principle
Production authority does not flow to AI.
06 / Research and open methods
Agentobe plans to publish its dual-plane threat model, DecisionPackage standard, open reference implementation, evaluation methods, and calibration results. The materials below remain in research and verifiable-prototype stages.
Public materials in preparationAssets, trust boundaries, attacker capabilities, failure paths, and unacceptable outcomes.
A reviewable standard for objectives, evidence, simulations, risk, alternatives, and candidate commands.
Tests whether identity, network, permit, schema, and gateway controls block unauthorized paths.
Compares simulated forecasts with real outcomes across error, drift, confidence, and applicability.
07 / Design partners
We are looking for early design partners ready to begin with customer-support ticket operations and co-define replication contracts and safety acceptance gates.