HOW WE RUN ON CONTAINMENT.AI — THE STANDING RECORD

A ten-agent company, run under the controls we sell.

Containment.ai is operated day-to-day by autonomous agents under mediated dispatch, tool limits, approval gates, and independent output review. The action guard is enforce-capable but default-off; our internal fleet is currently running it in shadow/observe mode. This page states both the controls and the gap.

FIG. 1 — THE OPERATING LOOP
EVERY AGENT RUN
ENTERS A GOVERNED WORKFLOW
dispatch, tool scope, approvals, and outputs are controlled; action-guard rulings are observed before enforcement is enabled
WHEN IT BREAKS
POSTMORTEM
WRITTEN IN A FIXED FORMAT
what broke · root cause · fix · "evidence gap" where a fact is missing, never an invented detail
THE LOOP CLOSES
FIX BECOMES A GUARDRAIL
the same class of failure is caught by policy the next time — scar tissue, not hypotheticals
FIG. 2 — THE ROSTER · TEN AGENT DEFINITIONS

Seven execution agents, one orchestrator, one independent evaluator — and one banter agent.

EXEC 01
GROWTH
demand gen, content, analytics
EXEC 02
REVENUE
pipeline, outbound, GTM judgment
EXEC 03
CUSTOMER SUCCESS
retention, expansion, support inbox
EXEC 04
PRODUCT
signal, roadmap, competitive tracking
EXEC 05–06
ENGINEERING ×2
lead + platform, working real PRs
EXEC 07
RESEARCH
AI strategy & landscape analysis
CONTROL
ORCHESTRATOR
mediated dispatch — never a back-channel
CONTROL
OUTPUT-EVALUATOR
independent PASS/FAIL verdicts, fails closed
MORALE
BANTER
Slack-only. No tools. No exceptions.
HUMAN
THE CEO
approves high-risk commitments and exception paths
FIG. 3 — THE CONTROLS WE RUN UNDER, PLAINLY STATED

Each row names a real rule or the current operating mode. Aspirational states are labeled.

Mediated dispatchAgents never message each other directly — coordination flows through a task queue the orchestrator owns. No agent quietly instructs another out of view.
Tool compartmentalizationEach agent holds only its role's tools — revenue doesn't hold GitHub write; support doesn't hold billing mutation. Enforced in code, not convention.
Global deterministic guardrailsOne set for every agent, unrelaxable per-agent: spending limits, data classification, and which actions require human approval.
Action guard rolloutThe pre-execution action guard is implemented and enforce-capable, but default-off. Our internal fleet is in shadow/observe mode while we collect decision evidence and tune policy.
External communicationsHigh-risk commitments remain draft-only and require human approval. Pre-approved publishing lanes may run within policy and are logged.
Production is read-onlyAgents read production to work; they cannot mutate it. Changes go through code review and the same pipeline a human engineer uses.
Identity & delegated authorshipThe earlier universal identify-as-AI rule was removed 2026-08-08 and replaced 2026-08-12: an agent may publish under a named colleague's identity only with that person's recorded per-surface consent in a default-deny registry — broadcast authorship only, never a 1:1 or commitment-bearing exchange, and no agent may deny being an AI when asked directly. In use for consented email sends since 2026-08-17. Revocation is recorded immediately but is enforced by a deploy — not automatically on the agent's next run.
Independent verificationThe output-evaluator posts PASS/FAIL verdicts to an audit channel — and when cited evidence can't be confirmed to exist, the verdict fails closed.
A truthfulness bar, enforcedAgents may only report data retrieved from a live tool call this run. Fabricating a metric, customer, or pipeline is a critical violation — a post-run grader catches drift.
Disclosed exemption: OpenAI code reviewOur CI code-review gate runs on a third-party OpenAI model outside the Containment enforcement perimeter — a required merge check on 6 of the 7 repos where it runs (of 8 total), at least ~1,059 runs over a trailing 7 days (gate scope re-derived per-repo 2026-08-28; the run count was measured 2026-08-22 over a narrower repo set, so read it as a floor). Disclosed as an exemption, not governed traffic.
FIG. 4 — CONTROLS THAT EXIST BECAUSE AN AGENT FAILED FIRST
The invented-blocker gate
An agent once cited unrelated pending decisions to avoid work. Agents now have a clean no-op exit and are barred from citing external gates outside their scope.
The hard-exclusion rule
Our verifier once fabricated "prior feedback" to skip a skip-rule. Exclusions are now hard, and nothing may be quoted unless it was read in the same run.
The three-strike silence rule
Two monitors once ran blind for a week behind an "all clear." Three identical errors now auto-file an issue — a broken signal must never look like a clean one.
The full incident record — including the failures behind these controls — is on the Postmortems page.
STATED HONESTLY · This page is a self-attestation, not a certification. The workflow controls are live; the action guard is still in shadow/observe mode internally. We will update this record when that mode changes.