surehand

Keep your agent. Add the sign-off.

Same agent. A gate in front. A name on every hard call.

Your pilot works. Nobody will sign for it. We find what it really does, write it down for signature and run it under Gatehouse. Every action checked first. Every hard call approved by a person.

  1. 01rules you sign
  2. 02checked before it acts
  3. 03your approver on hard calls
  4. 04a record that shows any edit
[ what changes ]

Nothing is rebuilt. A gate goes in front.

Your agent stays as it is. What changes: its scope is written down and signed. Every action is checked against it before it runs. Hard calls wait for a person you name. Every run leaves a record you hold. Your security team can sign that. Your auditor can replay it.

[ the queues ]

Four queues. One set of rules.

Pick a queue. What the agent reads and touches, what it may do, where it must stop, and what goes on the record. Then one run of it, simulated.

01 / 04 · Govern the agent you already run

The pilot with no written scope

Teardown · Manifest · Signature

First, find what it actually does. Which systems. Whose credentials. What it has already sent. That becomes the rules, and someone signs them.

Reads
  • The pilot's prompts
  • Its tool list
  • Its credentials
  • Its logs, where they exist
Touches
  • Whatever it touches today, named one by one
May do
After signing: exactly what the manifest lists
Stops for
The approver the manifest names, on every action outside the list
On the record
The teardown document, the signed manifest, every run after it
fig. 01 · SimulatedMANIFEST v1 · agent support-triage · draft to signed
  1. FOUNDticketing · knowledge base
  2. FLAGGEDoutbound mail via a shared credential, not in any document
  3. AGREEDmail scope removed; replies drafted, sent by a person
  4. NAMEDsupport lead
  5. SETrefuse
  6. SIGNEDsupport lead · security · manifest v1

WRITTEN DOWN, THEN SIGNED · THE AGENT ITSELF IS UNCHANGEDA pilot's real behaviour written down as a manifest, then signed.

[ your first agent ]

Bring the agent nobody will sign for.

Bring the pilot, the person who built it and the person who should sign for it. We map what it does and write the rules with both. Then we run it. Nothing is rebuilt.

  1. 01

    Study

    One session to find what the agent really does. Systems, credentials, what it has sent, who signs today. You keep the write-up.

  2. 02

    Deploy

    The rules come from what we found. Your accountable person signs. The same agent runs under Gatehouse. Your cloud or ours.

  3. 03

    Run

    Your approver clears the first stopped actions. We read the record with you and tighten the rules as the queue changes.

[ what teams with a pilot bring first ]

Bring the question nobody can answer fast.

  1. 01

    What does the agent actually do, and with whose credentials?

    Queue: The pilot with no written scope
  2. 02

    What has it sent to a customer or a vendor that nobody reviewed?

    Queue: The chatbot that started sending
  3. 03

    Who else can use the credential it runs on?

    Queue: The script with a shared credential
  4. 04

    Where is the record of what the vendor's agent did last quarter?

    Queue: The vendor agent with its own dashboard
  5. 05

    Who would sign for this today if the auditor asked?

    Queue: The pilot with no written scope
  6. 06

    Which of its actions would the manifest refuse on day one?

    Queue: The pilot with no written scope
[ Gatehouse ]

Whoever built it, the gate is yours.

Four controls. Your technical team gets the detail on the Gatehouse page.

manifest

What it does, written down and signed.

Systems, actions, limits and approvers, drawn from the teardown of the real pilot. The document a security team can sign.

policy check

Checked at the gate, not in the agent.

The gate sits between the agent and your systems. Every action is checked against the manifest as it happens, whoever built the agent.

approver

A name on every call that matters.

Held actions go to one named person with the evidence gathered. Overriding a block takes two names, and both are saved.

sealed record

Your evidence, whoever built the agent.

Each run is chained by SHA-256 and exports in open formats. Your record, not the vendor's dashboard.

[ security ]

What your security team gets.

01

Rules your accountable person signs

Systems, actions, limits and approvers. Written down. Signed before the agent runs.

02

Checked before every action

Every action is checked against your rules as it happens. Not named means refused. The refusal goes on the record.

03

One approver for hard calls

Hard calls wait for one person you name, evidence attached. Overruling a refusal takes two names. Both are saved.

04

A record any edit breaks

Every run is chained by SHA-256. It exports in open formats. Your auditors read it without Gatehouse.

Your cloud or ours. You decide, and the manifest records it.

No SOC 2 report or ISO 27001 certificate today. Your security team gets a walkthrough of the four controls and where the deployment runs. We answer your questionnaire in writing and tell you where certification stands.

Read the security answers
[ composite case ]

One deployment, from queue to record.

Built from more than one engagement. Names and figures changed. No performance figures, because none were measured on a single engagement.

W/03Composite caseInternal operations

Every answer cites its clause. Or a person answers.

The problem

The same easy questions every day. The hard ones waited behind them.

What changed

People only get answers the library backs up. Every correction becomes a worked example.

[ read before you start ]

The questions teams with a pilot ask us first.

Each one answered in full, with its sources. No sign-up to read them.

[ faq ]

Asked before every start.

Not here? Write to support@surehand.io. A person replies, usually inside two business days.

Talk to the people who run it
Do we have to rebuild the agent?

No. The gate sits in front of it. Your rules say what it may do. Gatehouse checks every action against them. The code and prompts stay as they are.

What if the pilot was built by a vendor?

The vendor's agent is named as one system in the manifest and its actions cross the gate like any other. The record of what it did is yours, in open formats, not the vendor's dashboard.

Where does our data live?

Your cloud or ours. You decide, and the manifest records it. The gate adds no copy of your systems; the record holds what the agent did, not your data.

How long does the teardown take?

We quote it after the first conversation, not before. It covers one agent and the people who sign for it today.

Who decides what the agent may do?

You do. The rules are written with whoever built the pilot and whoever owns it. The owner signs. Every change is signed again.

What happens if we stop working with Surehand?

You keep the rules, the records and the corrections, in open formats that read without Gatehouse. What happens to the agent itself is in the contract.

Start here

Bring us the queue nobody wants.

Tell us what comes in, who handles it and where it waits. We study it with your team and tell you straight if an agent belongs there. A person replies, usually inside two business days.

support@surehand.io