surehand

Your rules, in one signed file.

Which systems, which role, which limits, who signs, and what is refused.

Written with your team. Signed by the person accountable. Versioned.

Only the signed version runs.

One worked example runs through these pages. The screens are simulated, the figures are invented, and each one says so.

/ fig. 01The rules one accounts-payable deployment runs under. Simulated.
[ the file ]

We call the file the manifest.

It is the one place your rules live. Five sections, one per gate every action clears.

Scope: which systems and data the agent may reach. Role: the job it does, and the jobs it never does. Limits: what it may spend or commit on its own. Review: what waits for a person, and which person. Seal: every run ends in a record that shows any edit.

Anything the manifest does not name is refused.

  • ScopeWhich systems and data the agent may reach.
  • RoleThe job it does, and the jobs it never does.
  • LimitsWhat it may spend or commit on its own.
  • ReviewWhat waits for a person, and which person.
  • SealEvery run ends in a record that shows any edit.
[ versions ]

A change is a new version. Finance signs it.

Say finance wants the autopay limit lower. The change goes into the rules as a new version, and finance signs it.

The next run uses the new version, because only the signed version runs. Every record names the version it ran under, so an old run still reads against the rules it had.

/ fig. 02A lower limit, as a new signed version. Composite scenario. Simulated.
[ the default ]

Anything the file does not name is refused.

The default line of every manifest is refuse. The agent does not get to guess what you meant.

A refusal is not a silent failure. It goes into the record with the rule that caused it and the time, the same as an action that ran.

[ questions ]

What reviewers ask about this part.

Not here? Write to support@surehand.io. A person replies, usually inside two business days.

Book a walkthrough
How does the check work?

Your team signs one file of rules per deployment. It sets five things: scope, role, limits, review and seal. Before each action runs, Gatehouse checks it against the signed version. Allowed actions go ahead. Anything the file does not name is refused, and the refusal is saved to the record.

Who signs the rules?

The person accountable for the work, on your side. We write the first version with your team. Nothing runs under a version nobody has signed.

What happens when the rules change?

A change is a new version, and it is signed like the first. The next run uses the new version. Every run's record names the version it ran under, so an old run still reads against the rules it had.

[ all seven parts ]

Everything between the agent and your systems.

Start here

Bring us the queue nobody wants.

A teardown measures one process, and you keep the document. A walkthrough is 30 minutes on Gatehouse, no slides. We bring the rules and the sealed record of one held payment. You bring one live process and your reviewers' questions.

support@surehand.io