Every answer cites its clause. Or a person answers.
The same easy questions every day. The hard ones waited behind them.
People only get answers the library backs up. Every correction becomes a worked example.
Same agent. A gate in front. A name on every hard call.
Your pilot works. Nobody will sign for it. We find what it really does, write it down for signature and run it under Gatehouse. Every action checked first. Every hard call approved by a person.
Your agent stays as it is. What changes: its scope is written down and signed. Every action is checked against it before it runs. Hard calls wait for a person you name. Every run leaves a record you hold. Your security team can sign that. Your auditor can replay it.
Pick a queue. What the agent reads and touches, what it may do, where it must stop, and what goes on the record. Then one run of it, simulated.
Teardown · Manifest · Signature
First, find what it actually does. Which systems. Whose credentials. What it has already sent. That becomes the rules, and someone signs them.
WRITTEN DOWN, THEN SIGNED · THE AGENT ITSELF IS UNCHANGEDA pilot's real behaviour written down as a manifest, then signed.
Answers to actions · Named approver · Draft, not send
Your bot answered questions. Then someone gave it a send button. The gate keeps answers flowing and turns every send into a draft for a person, unless your rules say otherwise.
ANSWERS CONTINUE · SENDING WAITS · CREDIT IS REFUSEDThe same bot, first run under a gate: one answer, one draft held, one refusal.
Least privilege · Credentials outside the agent · Logged access
An automation runs on a credential four people know. The gate holds the credential the agent needs and no other, hands it over per action, and logs each use with the action it served.
THE AGENT HOLDS NO STANDING CREDENTIAL · EACH USE IS LOGGEDOne run, three credential uses, each tied to the action it served.
Your record, not theirs · Export · Replay
Right now the only record of your vendor's agent is the vendor's dashboard. The gate gives you your own record, in open formats. The evidence stays yours, whoever you work with next.
YOUR RECORD, IN OPEN FORMATS · READS WITHOUT THE VENDORA vendor agent's actions, recorded on your side of the gate and exported.
Bring the pilot, the person who built it and the person who should sign for it. We map what it does and write the rules with both. Then we run it. Nothing is rebuilt.
One session to find what the agent really does. Systems, credentials, what it has sent, who signs today. You keep the write-up.
The rules come from what we found. Your accountable person signs. The same agent runs under Gatehouse. Your cloud or ours.
Your approver clears the first stopped actions. We read the record with you and tighten the rules as the queue changes.
What does the agent actually do, and with whose credentials?
Queue: The pilot with no written scopeWhat has it sent to a customer or a vendor that nobody reviewed?
Queue: The chatbot that started sendingWho else can use the credential it runs on?
Queue: The script with a shared credentialWhere is the record of what the vendor's agent did last quarter?
Queue: The vendor agent with its own dashboardWho would sign for this today if the auditor asked?
Queue: The pilot with no written scopeWhich of its actions would the manifest refuse on day one?
Queue: The pilot with no written scopeFour controls. Your technical team gets the detail on the Gatehouse page.
Systems, actions, limits and approvers, drawn from the teardown of the real pilot. The document a security team can sign.
The gate sits between the agent and your systems. Every action is checked against the manifest as it happens, whoever built the agent.
Held actions go to one named person with the evidence gathered. Overriding a block takes two names, and both are saved.
Each run is chained by SHA-256 and exports in open formats. Your record, not the vendor's dashboard.
Systems, actions, limits and approvers. Written down. Signed before the agent runs.
Every action is checked against your rules as it happens. Not named means refused. The refusal goes on the record.
Hard calls wait for one person you name, evidence attached. Overruling a refusal takes two names. Both are saved.
Every run is chained by SHA-256. It exports in open formats. Your auditors read it without Gatehouse.
Your cloud or ours. You decide, and the manifest records it.
No SOC 2 report or ISO 27001 certificate today. Your security team gets a walkthrough of the four controls and where the deployment runs. We answer your questionnaire in writing and tell you where certification stands.
Built from more than one engagement. Names and figures changed. No performance figures, because none were measured on a single engagement.
The same easy questions every day. The hard ones waited behind them.
People only get answers the library backs up. Every correction becomes a worked example.
Each one answered in full, with its sources. No sign-up to read them.
Not here? Write to support@surehand.io. A person replies, usually inside two business days.
No. The gate sits in front of it. Your rules say what it may do. Gatehouse checks every action against them. The code and prompts stay as they are.
The vendor's agent is named as one system in the manifest and its actions cross the gate like any other. The record of what it did is yours, in open formats, not the vendor's dashboard.
Your cloud or ours. You decide, and the manifest records it. The gate adds no copy of your systems; the record holds what the agent did, not your data.
We quote it after the first conversation, not before. It covers one agent and the people who sign for it today.
You do. The rules are written with whoever built the pilot and whoever owns it. The owner signs. Every change is signed again.
You keep the rules, the records and the corrections, in open formats that read without Gatehouse. What happens to the agent itself is in the contract.
Tell us what comes in, who handles it and where it waits. We study it with your team and tell you straight if an agent belongs there. A person replies, usually inside two business days.
support@surehand.io