The question is not whether it works. It is what happens when it is wrong.
Every serious buyer of an autonomous system asks that, and it is the right question. OnDuty is the context layer your AI reads from, and the thing that decides before any of it acts. This page is the mechanism that answers the question, what we can and cannot promise about your data today, and the shape of a pilot.
One seam, and nothing gets past it
- Built and tested
Whatever proposes holds nothing
An agent here has read-only retrieval and one tool that proposes. An assistant your team connected has strictly less: it reads, it can add a memory carrying its evidence, and it can propose. Neither holds a credential, a connector, or a path to the outside world.
- Built and tested
The gate is not ours to argue with
Selah evaluates against your tenant's policies and returns a decision, a reason and a trace id. OnDuty executes; it does not decide.
- By design
Fail-closed is the default path
No clean permit, no execution. A timeout, an error or an unclear answer kills the action, and nothing configures that away.
- Built and tested
Holds go to a person
A held action waits in a review queue with the proposal, the reason and the context. Nothing expires into being sent.
- 01Agentproposes · holds no credentials
- 02Decision enginepermit · hold · deny · your rules, not the model
- 03Executepermit → Connector
- 04A personhold
- 05Nothing happensdeny
Record: 0 rows
Each row carries the hash of the row before it. The real trail is kept and verified by the decision engine.
The interesting question about an autonomous system is what it does when it is uncertain, when the network is slow, and when nobody is looking. All three answers here are the same: nothing happens.
What isolation means today, precisely
At the level of detail somebody doing diligence needs, including where it is weaker than an enterprise buyer would like.
Tenant separation
- Today
- Every query scoped by tenant. A workspace you do not belong to answers 404.
- On the enterprise tier
- Same, plus a dedicated database on request.
Connector credentials
- Today
- Encrypted at rest with a key held outside the database.
- On the enterprise tier
- Same, with the key in your own key management.
Conversation content
- Today
- Processed by a model vendor on our account.
- On the enterprise tier
- Runners on your machines register today. Running agents there, so content stays on your network, is not built yet.
Data residency
- Today
- Not offered.
- On the enterprise tier
- Through Selah jurisdictions, scoped during the pilot.
Audit
- Today
- Every decision, permitted or refused, in a hash-chained trail with a verify endpoint.
- On the enterprise tier
- Same, exportable.
Model training
- Today
- Your data is not used to train shared models.
- On the enterprise tier
- Same, in writing.
Third-party audit
- Today
- None. No SOC 2 report.
- On the enterprise tier
- None yet. We will not write otherwise.
What a pilot actually looks like
Six weeks, one workflow, one team. Scoped narrowly on purpose: an evaluation that touches everything proves nothing about anything.
Week 1
Scope. The one workflow, the actions an agent may propose in it, and the guardrails over them.
This needs your operation in the room. It is the input we cannot supply.
A reply the example rule holds
- decision
- none yet
- shadow
- none yet
- the reply
- none yet
Week 1 · SCOPE · nothing is connected and no rule runs yet
Shadow mode is set on the Selah side and OnDuty honours the flag the gate returns. In shadow a rule's verdict is recorded and not enforced, so nobody here can claim a tenant is governed in production while its shadow is still on.
Three ways to start
Explore
No commitment
A non-binding letter of intent, a quarterly conversation about the roadmap, and first refusal on a pilot slot.
Book a call →Pilot
Six weeks
One workflow, one team, dedicated setup and a weekly review, with the success criteria written down before week 1.
Book a call →Design partner
Co-build
We build against your edge cases, you get preferential pricing over twenty-four months and a quarterly say in what gets built.
Book a call →Where we are looking for design partners
Named because it is where the founders have operated, not because there are deployments to point at. There are none yet.
Vehicle retail
- The shape of the mess
- Long cycles, quotes that go quiet, and a customer history spread across a CRM, a chat channel and an inbox.
Hospitality
- The shape of the mess
- High message volume against a small desk, where the same guest asks three people the same question.
Multi-location food service
- The shape of the mess
- One brand, many locations, and complaints that only look like a pattern read together.
Venues and events
- The shape of the mess
- Enormous demand in a short window, and context that has to be right the first time.
The questions that come up
- What happens when the model is uncertain?
- Uncertainty is not the mechanism that protects you, and a confidence score is not a permission. The action is permitted, held or denied on your policy, and a held action goes to a person with the full proposal attached.
- Can it integrate with our stack?
- Connectors are built for Google (Gmail, Drive, Calendar, Ads, Business Profile), Microsoft 365, Meta, HubSpot, Salesforce and QuickBooks. Your own systems can come in through a REST API, a CSV, a read-only Postgres or a push endpoint. Channels are WhatsApp, Telegram, webchat and the workspace chat. Some providers still have to pass their own app review before a production account can connect, and the integrations page says which. Anything else is work, and we will say how much during scoping.
- Can our own AI read it?
- Yes, and that is the point rather than a concession. The Brain serves the same assembled context to an agent here, to a person in the product, and over the Model Context Protocol to Claude, ChatGPT, Cursor or a runtime you run yourself, on a key issued in your workspace by somebody whose role still allows it. Such a key can read and propose and nothing else: no permission anywhere accepts a decision, answers a hold or executes. Signing in from Claude or ChatGPT is built and has not yet been exercised against a live connection. There is no developer API and there will not be one.
- Who owns the data?
- You do. It is processed to run your agents and is not used to train shared models. Logs, history and the decision trail can be exported.
- What does it cost?
- Enterprise has no published price on purpose. Everything below it has a price on the pricing page, read from the same place your card is charged from.
- How much of this is built?
- The seam, the executor, the review queue, the audit trail, the Brain, the source connectors and billing are built and running. Residency is scoped per deal. Runners on your machines register, but running agents there is not built. There is no SOC 2 report and Google verification has not been submitted yet.
Thirty minutes, and a real answer about scope.
We will walk one of your workflows, show you what the gate does with it, and tell you plainly whether a pilot makes sense.
On duty ·