Skip to content

The question is not whether it works. It is what happens when it is wrong.

Every serious buyer of an autonomous system asks that, and it is the right question. OnDuty is the context layer your AI reads from, and the thing that decides before any of it acts. This page is the mechanism that answers the question, what we can and cannot promise about your data today, and the shape of a pilot.

One seam, and nothing gets past it

  1. Built and tested

    Whatever proposes holds nothing

    An agent here has read-only retrieval and one tool that proposes. An assistant your team connected has strictly less: it reads, it can add a memory carrying its evidence, and it can propose. Neither holds a credential, a connector, or a path to the outside world.

  2. Built and tested

    The gate is not ours to argue with

    Selah evaluates against your tenant's policies and returns a decision, a reason and a trace id. OnDuty executes; it does not decide.

  3. By design

    Fail-closed is the default path

    No clean permit, no execution. A timeout, an error or an unclear answer kills the action, and nothing configures that away.

  4. Built and tested

    Holds go to a person

    A held action waits in a review queue with the proposal, the reason and the context. Nothing expires into being sent.

Built and tested By design
Propose / evaluate / execute / record
Proposal
Your rule · example rule
The engine
Propose / evaluate / execute / record
  1. 01Agentproposes · holds no credentials
  2. 02Decision enginepermit · hold · deny · your rules, not the model
  3. 03Executepermit → Connector
  4. 04A personhold
  5. 05Nothing happensdeny
Record: 0 rows

Each row carries the hash of the row before it. The real trail is kept and verified by the decision engine.

Checked against backend/app/agents/executor.pyRuns in your browser on the illustration's data. Nothing is sent and no engine is called.

The interesting question about an autonomous system is what it does when it is uncertain, when the network is slow, and when nobody is looking. All three answers here are the same: nothing happens.

What isolation means today, precisely

At the level of detail somebody doing diligence needs, including where it is weaker than an enterprise buyer would like.

  1. Tenant separation

    Today
    Every query scoped by tenant. A workspace you do not belong to answers 404.
    On the enterprise tier
    Same, plus a dedicated database on request.
  2. Connector credentials

    Today
    Encrypted at rest with a key held outside the database.
    On the enterprise tier
    Same, with the key in your own key management.
  3. Conversation content

    Today
    Processed by a model vendor on our account.
    On the enterprise tier
    Runners on your machines register today. Running agents there, so content stays on your network, is not built yet.
  4. Data residency

    Today
    Not offered.
    On the enterprise tier
    Through Selah jurisdictions, scoped during the pilot.
  5. Audit

    Today
    Every decision, permitted or refused, in a hash-chained trail with a verify endpoint.
    On the enterprise tier
    Same, exportable.
  6. Model training

    Today
    Your data is not used to train shared models.
    On the enterprise tier
    Same, in writing.
  7. Third-party audit

    Today
    None. No SOC 2 report.
    On the enterprise tier
    None yet. We will not write otherwise.

What a pilot actually looks like

Six weeks, one workflow, one team. Scoped narrowly on purpose: an evaluation that touches everything proves nothing about anything.

Scrub the six weeks

Week 1

Scope. The one workflow, the actions an agent may propose in it, and the guardrails over them.

This needs your operation in the room. It is the input we cannot supply.

A reply the example rule holds

decision
none yet
shadow
none yet
the reply
none yet

Week 1 · SCOPE · nothing is connected and no rule runs yet

Checked against docs/selah-integration-addendum.mdRuns in your browser on the illustration's data. Nothing is sent and no engine is called.

Shadow mode is set on the Selah side and OnDuty honours the flag the gate returns. In shadow a rule's verdict is recorded and not enforced, so nobody here can claim a tenant is governed in production while its shadow is still on.

Three ways to start

Explore

No commitment

A non-binding letter of intent, a quarterly conversation about the roadmap, and first refusal on a pilot slot.

Book a call

Pilot

Six weeks

One workflow, one team, dedicated setup and a weekly review, with the success criteria written down before week 1.

Book a call

Design partner

Co-build

We build against your edge cases, you get preferential pricing over twenty-four months and a quarterly say in what gets built.

Book a call

Where we are looking for design partners

Named because it is where the founders have operated, not because there are deployments to point at. There are none yet.

  1. Vehicle retail

    The shape of the mess
    Long cycles, quotes that go quiet, and a customer history spread across a CRM, a chat channel and an inbox.
  2. Hospitality

    The shape of the mess
    High message volume against a small desk, where the same guest asks three people the same question.
  3. Multi-location food service

    The shape of the mess
    One brand, many locations, and complaints that only look like a pattern read together.
  4. Venues and events

    The shape of the mess
    Enormous demand in a short window, and context that has to be right the first time.

The questions that come up

What happens when the model is uncertain?
Uncertainty is not the mechanism that protects you, and a confidence score is not a permission. The action is permitted, held or denied on your policy, and a held action goes to a person with the full proposal attached.
Can it integrate with our stack?
Connectors are built for Google (Gmail, Drive, Calendar, Ads, Business Profile), Microsoft 365, Meta, HubSpot, Salesforce and QuickBooks. Your own systems can come in through a REST API, a CSV, a read-only Postgres or a push endpoint. Channels are WhatsApp, Telegram, webchat and the workspace chat. Some providers still have to pass their own app review before a production account can connect, and the integrations page says which. Anything else is work, and we will say how much during scoping.
Can our own AI read it?
Yes, and that is the point rather than a concession. The Brain serves the same assembled context to an agent here, to a person in the product, and over the Model Context Protocol to Claude, ChatGPT, Cursor or a runtime you run yourself, on a key issued in your workspace by somebody whose role still allows it. Such a key can read and propose and nothing else: no permission anywhere accepts a decision, answers a hold or executes. Signing in from Claude or ChatGPT is built and has not yet been exercised against a live connection. There is no developer API and there will not be one.
Who owns the data?
You do. It is processed to run your agents and is not used to train shared models. Logs, history and the decision trail can be exported.
What does it cost?
Enterprise has no published price on purpose. Everything below it has a price on the pricing page, read from the same place your card is charged from.
How much of this is built?
The seam, the executor, the review queue, the audit trail, the Brain, the source connectors and billing are built and running. Residency is scoped per deal. Runners on your machines register, but running agents there is not built. There is no SOC 2 report and Google verification has not been submitted yet.

Thirty minutes, and a real answer about scope.

We will walk one of your workflows, show you what the gate does with it, and tell you plainly whether a pilot makes sense.

On duty ·