surehand

Built to pass the review. Not to skip it.

Security, change control and audit sign first. Then the agent works.

AI agents that clear your security review, change control and internal audit before they touch a queue. Signed rules. An approver from your own team. Your cloud if you want it. A record your auditors can replay.

  1. 01rules you sign
  2. 02checked before it acts
  3. 03your approver on hard calls
  4. 04a record that shows any edit
[ what changes ]

Your review board signs once. Every change, again.

The shared-services queue. The pilot a business unit already runs. The policy desk. All under one signed file of rules your CISO can read, the manifest. Every action is checked against it before it runs. Hard calls wait for a person you name. The manifest is your change-control artefact. The record is your audit artefact.

[ the queues ]

Four queues. One set of rules.

Pick a queue. What the agent reads and touches, what it may do, where it must stop, and what goes on the record. Then one run of it, simulated.

01 / 04 · Enterprise

The pilot a business unit already runs

Written scope · Gate in front · Record behind

A team built an agent that works. Nobody in security will sign for it. We find what it does, write it down and put Gatehouse in front. The agent stays. The gate is new.

Reads
  • The pilot's tools
  • Its credentials
  • Its logs
  • Its prompts
Touches
  • Whatever the pilot touches today, named one by one in the manifest
May do
Exactly what the manifest lists, and nothing else
Stops for
The approver the business unit and security agree on, for every action outside the list
On the record
Every action, the manifest line it passed or hit, who approved, hash-sealed
fig. 01 · SimulatedRUN-9E1A4 · manifest v1 · pilot under gate
  1. SIGNEDmanifest v1 signed by business unit lead and security
  2. PASSrun opened, policy check
  3. PASSread ticket queue, classify, draft reply
  4. REFUSEDattempted: send external mail, no mail scope in manifest

    refused · not in manifest

    • action · send external mail
    • manifest v1 · scopes: ticketing, knowledge base
    • mail · no scope, no credential
    • refusal recorded · 10:04:16

    anything the manifest does not name is refused

  5. HELDproposed: close ticket with refund 320.00, limit 250.00
  6. DECLINEDdeclined by approver, refund routed to finance
  7. SEALEDrecord sealed

THE AGENT STAYS · THE GATE IS NEWAn existing pilot's first run under a manifest: one action refused, one held.

[ your first agent ]

Bring the pilot security won't sign.

Or the shared-services exception queue. Or the policy desk. Business owner and security in the same room. We write rules both can sign, then run the agent. NDA and DPA first, before any business material moves.

  1. 01

    Study

    Business owner and security, one session. The queue, the systems, the controls, who signs today. You keep the write-up.

  2. 02

    Deploy

    The manifest goes through your change control like any other change. Then the agent runs under it. Your cloud or ours. You decide, and the manifest records it.

  3. 03

    Run

    Your approvers clear the first stopped actions. Every run exports to your archive. We review the record with internal audit when you say.

[ what security, audit and shared-services leaders bring first ]

Bring the question nobody can answer fast.

  1. 01

    What does the pilot actually do, and who signs for it today?

    Queue: The pilot a business unit already runs
  2. 02

    Which actions did the agent attempt that the manifest refused?

    Queue: The pilot a business unit already runs
  3. 03

    Which exceptions across entities waited longest for a controller?

    Queue: Shared-services AP and procurement
  4. 04

    Which vendor onboardings this quarter had an unverified bank detail?

    Queue: Shared-services AP and procurement
  5. 05

    Which policy questions did the agent answer, and which did it escalate?

    Queue: Employee policy and help-desk answers
  6. 06

    Who changed the manifest, when, and who signed the change?

    Queue: Change control and audit export
[ Gatehouse ]

Controls before the action. Evidence after it.

Four controls. Your technical team gets the detail on the Gatehouse page.

manifest

A written scope your CISO can read.

Systems, actions, limits and approvers on one signed document. It is the change-control artefact: every change is a new version, re-signed.

policy check

Control before the action, not review after.

Every action is checked against the signed version as it happens. Anything the manifest does not name is refused, and the refusal is recorded.

approver

A name from your organisation on every hard call.

Held actions go to one named person with the evidence gathered. Overriding a block takes two names, and both are saved.

sealed record

The audit artefact, in open formats.

Each run is chained by SHA-256 and exports as JSON and CSV your archive, SIEM or GRC tooling can ingest. Internal audit reads it without Gatehouse installed.

[ security ]

What your security team can check today.

01

NDA and DPA first

Signed before any business material moves. Security questionnaires answered in writing, with a person's name on the answers.

02

Checked before every action

Every action is checked against your rules as it happens. Not named means refused. The refusal goes on the record.

03

One approver for hard calls

Hard calls wait for one person you name, evidence attached. Overruling a refusal takes two names. Both are saved.

04

Your cloud, if you want it

Your cloud or ours. You decide, and the manifest records it. Encrypted in transit, and at rest in the stores we control. Least-privilege access, and every access logged.

Your cloud or ours. You decide, and the manifest records it.

No SOC 2 report or ISO 27001 certificate today. Your security team gets a walkthrough of the four controls and where the deployment runs. We answer your questionnaire in writing and tell you where certification stands.

Read the security answers
[ composite case ]

One deployment, from queue to record.

Built from more than one engagement. Names and figures changed. No performance figures, because none were measured on a single engagement.

W/01Composite caseInsurance

Every claim checked before a handler opens it.

The problem

Every file had to be checked for completeness before a handler could start.

What changed

The first pass runs around the clock. Every routing decision carries its reason.

[ read before you start ]

The questions security, audit and shared-services leaders ask us first.

Each one answered in full, with its sources. No sign-up to read them.

[ faq ]

Asked before every start.

Not here? Write to support@surehand.io. A person replies, usually inside two business days.

Talk to the people who run it
What do you need from procurement to start?

An NDA and a DPA, signed before any business material moves. Then a teardown of one queue with the business owner and your security team. The teardown document is yours whether or not we go further.

Can we deploy in our own VPC?

Your cloud or ours. You decide, and the manifest records it. The manifest names the systems the agent may read and write, and the sub-processor list on the security answers page names everything else.

How are changes to what the agent may do controlled?

Every change is a new manifest version, signed again by the accountable person. Every version is kept. Anything the current version does not name is refused. The refusal is recorded.

Who can override a block?

Two named people, and both names are saved in the record with the reason. One person cannot do it alone, and the agent cannot do it at all.

Does it work with our SSO?

The approver is a named person in your organisation. How that person signs in is agreed in the security review with your identity team and written into the deployment record. We will not claim an integration on this page that your review has not seen.

Are you SOC 2 certified?

Not today. Your security team gets a walkthrough of the controls and where the deployment runs. We answer your questionnaire in writing. You hear it from us first when this changes.

What happens if we stop working with Surehand?

You keep the rules, the records and the corrections, in open formats that read without Gatehouse. What happens to the agent itself is in the contract.

Start here

Bring us the queue nobody wants.

Tell us what comes in, who handles it and where it waits. We study it with your team and tell you straight if an agent belongs there. A person replies, usually inside two business days.

support@surehand.io