PlatformDelivery BoardAutomation & RunbooksOutcome ReceiptsJust-in-Time ElevationCredential VaultGoverned SessionsDevices & DiscoveryPatch ManagementReporting & ExportsRoles & Multi-Tenancy
Verified AI OperationsThe Operation LoopCommanded AutonomyCompare the operating modelThe Verified Operation Spec
SolutionsFor MSPsFor Enterprise & Internal ITHealthcareLegalFinancial servicesMunicipal & Education
ProofOperation walkthroughSecurity & architectureVerified Operation SpecFive questions for your RMM's AIChangelog
CompanyAboutFounder's noteContact
PricingBuy 1–20 technician licenses onlinePlans — from $499 per monthCustom requirementsFoundation Circle
Log in

Home/Company/Founder's note

Founder's note

I got tired of automation that could not show its work.

This is the longer version of the line on the home page. It is about a specific kind of morning, an account nobody wants to talk about in an audit, and the moment it became obvious that the record — not the fix — is the thing worth selling.

“The receipt is not a feature of this product. It is the product. Everything else exists to make that one record true.”
Joseph · founder, Seraph · twenty years in infrastructure, identity, and endpoint management

I have spent about twenty years inside other people's infrastructure. Domain controllers, group policy, identity, endpoint management — the unglamorous middle of IT, where things are either quietly working or on fire. For most of that time I was the person who got asked what happened.

The question is never "did the automation run". Automation runs constantly. The question is: what did it actually do, on which machine, under whose authority, and how do you know? For twenty years I did not have a good answer, because the only answer available was written by the thing I was being asked about.

A morning I do not miss

A scheduled job reports success overnight. Every dashboard is green. At 8:40 the front desk cannot print, or a line-of-business application will not start, and you go looking. The job log says it completed. The server disagrees. Somewhere between those two statements is the truth, and finding it takes the whole morning.

It took the whole morning because the log was never a record of what happened to that server. It was a record of what a script believed about itself. Those are different documents, and we had spent a decade treating them as the same one.

And underneath it, always, an account

There is always an account. It holds domain admin because that is what made the automation work years ago, nobody remembers who created it, and the password is in three places including a spreadsheet. Every audit I have sat through eventually arrives at that account, and everyone in the room looks at the floor.

We knew it was wrong. We could not remove it, because removing it stopped the work. That is the trade the whole industry quietly made: permanent privilege in exchange for automation, and a log file standing in for evidence.

Then a client asks you to prove it

A practice manager wants to know what was done on her network last quarter. An insurer's renewal questionnaire asks what your automated tooling is permitted to do, and how you would know if it had done something else. An auditor arrives with a list.

So you export from the monitoring tool, and from the ticketing system, and from whichever privilege product got bolted on, and you stitch three exports together in a spreadsheet — and it still does not answer the question. None of those systems recorded who said it could. None of them asked the server whether it was true.

Then AI arrived and made it worse

When this wave of AI reached our industry, I watched vendors point it straight at that stack. Now the thing acting is non-deterministic. It holds the same standing rights the old scripts held. And it is dramatically better at producing a fluent, confident account of what it believes it did.

We took the one part of the problem that was already broken — the actor is also the witness — and handed it a better vocabulary.

I do not think the hard problem is whether AI can do the work. It can, and it can do more of it every month. The hard problem is that nobody can check it. And checking does not mean reading a transcript. It means an independent party, with no stake in the answer, confirming that the world changed the way the work claimed it did.

We already have that party. It is the machine that was changed.

The gap, drawn

The evidence and the actor were the same party.

This is the whole letter in one picture. Nothing about the top row was anyone's idea — it accumulated, one reasonable decision at a time, until it was the way the industry worked.

What was missingthe witness
WHAT WE HAD The automation ran …on a standing admin account. It wrote a line about its own work. That was the evidence The actor was the witness. THE ONLY WITNESS WAS THE THING BEING ASKED ABOUT WHAT WAS MISSING The automation runs …on a lease that expires. Something else asks the machine, afterwards. That is the evidence The witness is the target.
One arrow moved, and everything else in the platform follows from it. The answer is asked of the machine, after the work, by something that did not do the work — which is the only version of "verified" that survives a hostile question.

So that is what we built

Privilege is leased for one operation against one target, and it expires on a clock rather than when the work finishes. The model never receives a credential value — it emits a reference, and the executor resolves it after the connection is already authenticated. When the work is done, something other than the AI asks the target whether it is true, and that answer is what the record carries. The undo is written down before anything runs, because a rollback invented after a failure is a hope.

What comes out the other end is one record with a reference number on it. Who asked. Who authorized. What privilege existed, and for how long. What ran. What the machine said. How to reverse it.

People sometimes describe that record as a feature of the platform. It is not. It is what lets the work be reviewed. The fix is the part your client feels; the record is the part your client, insurer, auditor, or lawyer can inspect. Everything else here exists to make the work accountable.

  • Privilege is leased — scoped to one operation on one target, and revoked on the clock rather than on the work finishing.
  • The model never holds a credential value — it emits a reference, and the connection is authenticated before the first generated step exists.
  • The machine that changed answers the question — and its answer, not the AI's summary, is what the record carries.
  • The undo is declared before execution — written down while there is still time to think about it clearly.

One thing I will not build

I would rather say this here than be asked in a sales call. I will not ship a mode where nobody's name is on the work. The autonomy dial can move a long way — there are settings where a human authorizes a class of work once and rarely again — but what moves is when a person authorizes, never whether a person is accountable, and never whether the machine had to confirm.

If that costs us a deal against something that will promise a fully unattended fleet, it costs us a deal. I have been the person holding the spreadsheet in the audit meeting. I am not building the thing that makes that meeting worse.

An invitation, and a request

Bring the question you could not answer last quarter.

If you have sat in the meeting I have been describing, bring the hardest question from your last client review. We will inspect the relevant workflow and its record with you, then tell you what the system can and cannot show today.

And if you think I have this wrong I would genuinely rather hear it than not. If a claim on this site does not survive contact with your environment, or the architecture has a hole I have talked myself past, write to me through the contact page. It reaches me, and I answer it myself.

— Joseph, founder

Fifteen minutes, live

One supported operation, its record, and its recovery path.

No slides. A supported ticket arrives, the work runs under a lease, the machine can verify the result, and we open the correlated record. If that runbook has a recovery path, we review it with you.