ai · security · skills

Illustrative · orchestration · for the practitioner

We gave one helper the keys. The locked doors stayed locked.

Picture handing an assistant a key ring and letting it walk your whole building. It reads what it likes, checks what it likes, does real work in every room. Some doors have no key on that ring. Not because we asked it nicely to stay out. Because the building decides which keys exist, and it was never given those.

That is the whole story. The part people clap at — one assistant, working across four different systems, from a chat window — is the easy part. Plenty of tools do that. The part that matters is the doors it could not open, and being able to show you why it could not.

It works where you already are: Slack at your desk, Telegram on your phone, on our own machine rather than somebody else’s. Everything below happened in a chat window. Nothing was typed into a form.

The problem

An agent with broad keys is the newest insider risk, and most teams hand the keys over anyway.

What this demo proves

One agent runs this practice end to end through three narrow verbs, a kill switch, and no master key, and the locked doors stay locked.

The surface

Three things it can do. That’s the whole list.

Ask the rulebook a question, read a score, work out a new score. It can do those three things for every team in the company, which is a lot of reach. It cannot do a fourth thing, because there is no fourth thing on the list.

We didn’t tell it to behave. We built it so it can’t misbehave. Telling an AI “please don’t delete anything” is a wish. Never giving it a delete button is a rule. Anyone can hand you the first list below; every vendor has one. Ask for the second, and the room usually goes quiet.

Everything it can do

Ask the rulebook

You ask a rule in plain words. It finds the exact line in the official standard and shows you which line it was — or says “that isn’t in here” and stops.

It only ever sees the public rulebook. The private material is not in the room with it.

Read a score

It looks up a team’s score: how much AI they use, how well it’s watched, and whether that’s allowed yet.

Look, don’t touch. It cannot change a single thing with this one.

Work out a new score

You tell it what changed since last time. It redoes the sums and shows you the new score next to the old one.

It can add a new score. It cannot delete one, and it cannot touch who has access.

Everything it cannot

It cannot run commands on a computer.

We switched that off. It can think, and it can use the three things on its list. It does not get a machine to drive. Most of the scary AI stories start with someone leaving this on.

It cannot see the private material.

The valuable stuff — the full tool list, the mapping we sell, the paid rulebooks word-for-word — is simply not handed to it. Same as a stranger on the website. It roams widely because there is less to find than you would think.

It cannot delete anything, or add anyone.

Those buttons exist. They belong to a human. A helper with big reach is fine as long as the dangerous verbs were never on its list in the first place.

It is switched off until someone switches it on.

Out of the box the doors do not open at all, and one flag closes all three again instantly. Shipping it changes nothing until a person decides otherwise.

What the agent brings, capability by capability →

The run

One story, told six ways.

Six goes at proving the same one thing: the helper did real work everywhere, and never once stepped outside its list. Each stop opens the page with the actual numbers on it.

  1. 01 · 2 minTwo dials and a gate. Start here, before anything is switched on. One dial: how much of the work AI now does. Other dial: how well anyone is watching it. The gate says the first must never get ahead of the second. Every number after this is read against that one idea. How it works
  2. 02 · 8 minScoring a real team, from a chat message. It grades a security team against the real rulebook and says, out loud, “this team has gone further than its safety net — the gate is shut.” This is the only stop that teaches the idea rather than showing off a trick, so it goes first. The worked team
  3. 03 · 8 minChecking a thousand tools for booby traps. It lists what every tool can secretly reach, then looks for combinations. One tool that reads your files is fine. One that phones home is fine. The two together is not — and you only see that if you look at the whole pile at once. How the scan works
  4. 04 · 10 minTesting a real app made for children. A shipped app with a guard already on it. We measured the guard instead of trusting it, found it caught about half of the attacks, and improved the guard they had rather than selling them a new one. The guard
  5. 05 · 7 minAnswering “am I allowed to do this?”. Someone asks a rule in their own words, in their own language, and gets the actual line from the actual rulebook back. If the rulebook doesn’t say, it admits that and points at the person who decides. The question everyone has
  6. 06 · 5 minThe close. Not “look, one helper drove four systems.” One helper went everywhere, did real work, and never once opened a door it wasn’t given a key to — and we can show you why it couldn’t.

It can’t make the score up.

When the helper tells you a score, it isn’t remembering it and it isn’t guessing it. It can’t. We never save scores — we only save the answers people gave, and the score gets worked out fresh every single time anyone asks. Fix one thing in the real world, tell it, and watch the score go up and the gate swing open.

An AI that could just declareyou were secure would make this whole thing worthless. That is exactly why it can’t.

See the score it hands back →

The answer

Sometimes the answer is: don’t use AI.

Every reading lands on a list of everyday jobs — 17of them — each measured by a number your team already argues about on a Monday. And nearly half of the ways to move those numbers — 26 of 51— don’t involve AI at all. Write the runbook down properly. Script the boring half. Train someone. The other 25 reach for a model, and they have to earn it: the job names the exact controls you need before the AI is allowed to run it on its own.

We would rather tell you to rewrite a runbook than sell you a robot that guesses.

See the jobs and what each one costs →

We didn’t build a single one of these.

The tools that do the actual testing are not ours. They are free, they are famous, and your team can download every one this afternoon — Garak, PyRIT, Promptfoo, SkillGuard, and the rest. They come in three kinds: 14 that attack your AI, 3 piles of nasty examples to attack it with, and 5 that stand in the way.

So what do we do, if we didn’t build the tools? We answer the only question that is actually hard: which one of these answers which rule.

See which tool answers which rule →

And the honest bit.This helper is our own back-office tool. It isn’t for sale, and you would never depend on it. We show it because it is the same argument we make about the AI already loose in your own teams, just where we can prove it: let it do a lot, and make sure what it can do never gets ahead of what keeps it honest.