Dual-system enterprise AI safety · Open infrastructure · Verifiable demonstration

Let AI explore freely.
Keep real action controlled.

Agentobe is a dual-system enterprise AI safety research, open safety infrastructure, and verifiable demonstration project. It preserves enterprise facts, lets AI simulate autonomously in isolation, and places every real change behind evidence, human authorization, and deterministic execution controls.

Request a demo
Bidirectional data Authority stays isolated Every outcome traced
Agentobe operating view Demo environment
01
Enterprise fact planeAuthoritative state · verifiable input
TicketsPoliciesEvents
Governed copy
Verified passage
Evidence & proposals
02
AI simulation planeAutonomous exploration · no production credential
Path A82% Path B67% Path C41%
Action requires explicit authorityThe deterministic gateway accepts signed, scoped, compensatable commands only
Boundary intact
Two planes. One trusted path.

01 / Why now

AI needs room to explore.
Enterprises need accountable boundaries.

Connecting agents directly to enterprise systems binds reasoning capability and production authority inside one runtime. Agentobe separates them by architecture.

01

Replicate facts, not authority

Enterprise state enters a verifiable backup; AI reads only classified, transformed, version-pinned copies.

02

Enable simulation, not default execution

Agents may branch strategies, use simulated tools, and form proposals without holding production credentials.

03

Build evidence before authorizing action

Every real change links to fact versions, alternatives, risk, permits, and execution receipts.

02 / How it works

From enterprise facts to controlled action,
every step has a boundary.

One continuous loop. Two authority planes. One verified path to production.

01

Preserve enterprise facts

Connectors continuously record materials, state, and events into source-faithful immutable backups.

02

Create a governed copy

Classify, mask, tokenize, and pin versions by contract; the raw vault stays hidden from agents.

03

Let AI simulate

AI compares branches, replays history, and returns alerts, findings, and proposals inside isolation.

04

Review and authorize

Named accountable people review evidence, impact, risk, and alternatives before issuing a permit.

05

Execute and calibrate

The gateway checks live state and runs allowlisted commands; outcomes return to calibrate the next simulation.

03 / Product architecture

Five product surfaces.
One accountable loop.

02

Backup & Simulation Middleware

Preserves enterprise facts, creates AI projections, receives AI results, and maintains cross-plane evidence lineage.

Boundary: facts and AI records have distinct authority
03

AI Simulation Space

Lets agents plan, branch, call simulated tools, and produce comparable evidence on governed copies.

Boundary: no production-write authority
04

Agentobe Console

Brings backup health, simulations, decision packages, approvals, outcomes, and full audit into one workspace.

Boundary: role, scope, and separation of duties
05

Guarded Execution Gateway

Turns valid authority into typed, scoped, idempotent, verifiable, and compensatable real operations.

Boundary: independent identity and command allowlist

04 / V1 use case

One support ticket.
A complete chain of accountability.

Agentobe V1 focuses only on customer-support ticket operations. A narrow scope makes the replication, simulation, approval, execution, and calibration loop testable.

3parallel strategy branches
1named approver
1replayable trace_id
TICKET · #CS-1842High priority

Regional queue backlog anomaly

Enterprise fact v184
  1. Facts sealedVerification complete · 12:04:18
    Done
  2. AI compared 3 strategiesProposal: reprioritize and assign a dedicated queue
    Done
  3. Awaiting domain approvalImpacts 12 tickets · reversible
    Pending
  4. Gateway execution and calibrationRuns only after a live version check
    Not started

05 / Security and trust

A boundary is not a prompt.
It is system structure.

Agentobe does not rely on agent self-restraint to protect production. Separate identities, data partitions, human accountability, and a deterministic gateway form the hard boundary.

Data partitioning

Raw backups, enterprise events, AI projections, AI results, and execution records carry distinct authority and access rules.

Identity isolation

Agents, replication services, approval sessions, and production gateways use separate identities, keys, and execution accounts.

Explicit authority

Permits bind package hash, resource scope, command, count, and expiry; free text is never an execution command.

Deterministic execution

The production gateway rechecks live versions, preconditions, impact limits, stop state, and compensation.

End-to-end traceability

One trace_id connects facts, simulations, proposals, approvals, commands, receipts, and real outcomes.

Data can move in both directions.
Production authority does not flow to AI.
Agentobe Principle / Core principle

06 / Research and open methods

Safety claims need
inspectable evidence.

Agentobe plans to publish its dual-plane threat model, DecisionPackage standard, open reference implementation, evaluation methods, and calibration results. The materials below remain in research and verifiable-prototype stages.

Public materials in preparation
01

Dual-plane threat model

Assets, trust boundaries, attacker capabilities, failure paths, and unacceptable outcomes.

Planned
02

DecisionPackage

A reviewable standard for objectives, evidence, simulations, risk, alternatives, and candidate commands.

Draft
03

Adversarial evaluation suite

Tests whether identity, network, permit, schema, and gateway controls block unauthorized paths.

In research
04

Outcome calibration reports

Compares simulated forecasts with real outcomes across error, drift, confidence, and applicability.

V1 target

07 / Design partners

Validate the boundary of AI autonomy
on one real, controlled workflow.

We are looking for early design partners ready to begin with customer-support ticket operations and co-define replication contracts and safety acceptance gates.

  • One narrow, reversible workflow
  • An isolated demo with no production credentials
  • Joint threat-model and evidence-quality review

During early access, the form validates locally and does not transmit or store any data.