PlatformDelivery BoardAutomation & RunbooksOutcome ReceiptsJust-in-Time ElevationCredential VaultGoverned SessionsDevices & DiscoveryPatch ManagementReporting & ExportsRoles & Multi-Tenancy
Verified AI OperationsThe Operation LoopCommanded AutonomyCompare the operating modelThe Verified Operation Spec
SolutionsFor MSPsFor Enterprise & Internal ITHealthcareLegalFinancial servicesMunicipal & Education
ProofOperation walkthroughSecurity & architectureVerified Operation SpecFive questions for your RMM's AIChangelog
CompanyAboutFounder's noteContact
PricingBuy 1–20 technician licenses onlinePlans — from $499 per monthCustom requirementsFoundation Circle
Log in

Home/Proof/The operation record

From request to result and recovery review

Follow an operation. Inspect what stays on record.

OP-000217 is the worked example: Dana cannot print at the front desk, Marcus authorizes from his board, the print spooler on SRV-ACCT-02 is restarted under an eight-minute lease, and the server supplies the result. The recording is still being captured; until it is published, use the live run to inspect each stage and its evidence.

OP-000217 · ticket to rollback

Where the player goes being recorded

There is no recording here yet.

We are not going to stage this one. It is being captured off a live system, on a real operation, and it is not finished. When it is, it will sit in this frame with the chapter marks below it.

Until then the fifteen-minute live version does more anyway — you pick the claim, we run it, and you get to interrupt.

OP-000217 · service recovery
lease 8m · the machine confirmed it
locked · chain 9f3a…c47e

The shape of it

Four actors. The humans are on screen twice.

Read the timeline first and the chapter notes second. The reason to watch a whole operation rather than a highlight is that the shape is the argument: the work is continuous, the human attention is not, and exactly one line in the whole thing comes from the machine that was changed.

The three minutes, chaptered — and who is on screen whenOP-000217
THE RECORDING · 00:00 → 03:00 OP-000217 00:00 00:20 00:35 00:50 01:20 02:00 02:20 02:40 02:55 the ticket arrives the authorization the work you're fixed the rollback the plan the lease the machine answers the record DANA reports it you're fixed MARCUS reviews · authorizes SERAPH plans leases 8 min · runs blind seals SRV-ACCT-02 the job runs ANSWERS: SERVICE RUNNING TWO SHORT MOMENTS OF HUMAN ATTENTION · ONE ANSWER FROM THE MACHINE · EVERYTHING ELSE RUNS ITSELF
Marcus is on screen for about fifteen seconds and Dana never leaves her desk. The green mark at 02:00 is the only place in the whole recording where something other than our own software asserts anything — and it is the line the receipt carries into the client's evidence pack.

Chapter by chapter

What each stretch contains, and the one thing to watch for.

If you only have a minute, the chapters that matter are 00:35, 02:00 and 02:55 — the human's say-so, the machine's answer, and the undo. The rest is context for those three.

  1. 00:00 · The ticket arrives

    Dana, on the front desk at a medical practice, writes in Teams that she can't print scripts and there are patients waiting. That is the whole intake — no form, no portal, no category dropdown. The message becomes a request with a typed outcome attached to it.

    WATCH FOR · nobody remotes into her screen. She keeps checking patients in for the rest of the recording.

  2. 00:20 · The plan

    A certified procedure is selected — not written. You see the outcome it claims, the target it will touch, the verification that will decide whether it worked, and the reversal, all before anything is authorized.

    WATCH FOR · the undo is already on screen. It came with the procedure. See Automation & Runbooks.

  3. 00:35 · The authorization

    Marcus reads the plan on his delivery board and authorizes it. One click, about fifteen seconds of his attention, and his name and the time are written into the operation — not into a separate approval system that someone will have to line up later.

    WATCH FOR · the authorization becomes a field, not a notification. See the delivery board.

  4. 00:50 · The lease

    Admin rights are minted for this operation on this target, for eight minutes. The amber band on the screen is a countdown, and it is the only privilege anywhere in the recording. No shared administrator account is used at any point.

    WATCH FOR · the expiry lands on the clock, not on the work finishing. See Just-in-Time Elevation.

  5. 01:20 · The work

    The print spooler on SRV-ACCT-02 is restarted by a signed job. The credential that authenticated the connection was resolved from a reference the model cannot read, and it was resolved before any of this existed.

    WATCH FOR · what the model is holding: an operation, a target, a procedure. Never a value. See Credential Vault.

  6. 02:00 · The machine confirms

    An independent check runs on SRV-ACCT-02 and the server answers: service running, queue clear. That answer — not a status chip, not a summary — is what goes into the record. If it had come back wrong, the same field would say so.

    WATCH FOR · which line came from the target and which came from us. They are labelled differently on purpose.

  7. 02:20 · The user is told

    Dana gets a message in the same thread she started: you're fixed. From her side the entire event was three messages and a working printer, with no stranger driving her mouse and no scheduled call-back.

    WATCH FOR · the elapsed time on her side of the conversation, which is the number her practice manager will remember.

  8. 02:40 · The record

    The receipt opens: who asked, who authorized, what privilege was borrowed and when it expired, the job that ran, the machine's own answer, the declared undo, and a fingerprint of the record before it. One reference number covers all of it.

    WATCH FOR · the chain line at the bottom. That is what makes the export worth forwarding. See Outcome Receipts.

  9. 02:55 · The rollback

    The reversal that was declared at 00:20 is executed on the same target. It does not open a second ticket and it does not start a new operation — it lands in this one, and it is verified the same way the change was.

    WATCH FOR · the undo produces its own confirmed result, verified the same way, inside the same record.

Two clocks, and we will not blur them

The recording is three minutes. The operation was not.

Every vendor video is cut, and most of them quietly imply the elapsed time on screen is the elapsed time in the world. Ours is cut too, so here is the honest mapping between the recording's clock and the one written into the record.

Recording time against the operation's own clockOP-000217
THE OPERATION'S OWN CLOCK — WHAT THE RECORD SAYS 09:38 reported 09:40 authorized 09:47 expired · confirmed 09:50 ADMIN ACCESS · LEASED 8 MIN · EXPIRED 09:47 00:00 00:35 authorized 02:00 the machine answers 02:55 rollback THE RECORDING — SAME OPERATION, CUT TO THREE MINUTES
The recording compresses the waiting; it does not reorder anything and it does not re-shoot a step that went wrong. The timestamps that matter are the ones on the upper axis, because those are the ones in the record — and they are the ones a client's auditor will read, long after nobody can remember what the video showed.

To be plain about what this page is: the recording described here does not exist yet. Everything above is the walkthrough of what it will contain, written now so that when the file lands you can check it against this page rather than the other way round. If any chapter turns out not to show what this page says it shows, that is a defect on our side and we would like to hear about it.

The last twenty seconds

The part most demos leave out.

Anyone can record a fix. The interesting stretch is 02:40 to 02:55 — opening the record and then undoing the change while the record is still on screen.

  • The receipt is assembled by the platform, not written by the model. The confirmation row can only carry what the target answered.
  • A failed operation gets the same record. "No response captured" is a real recorded outcome, not a gap.
  • The rollback runs under a fresh lease and produces its own verified result inside the same operation.
  • One reference number resolves the whole thing, months later, for someone who was not there.

We are deliberately narrow about session capture. This page describes an operation record — the authorization, the privilege, the job, the machine's answer and the undo. It is not a claim of full multi-surface session replay; see Governed Sessions for what remote access does and does not cover today.

Outcome receiptOP-000217
operationservice recovery
requested byDana K · Teams #it-help
authorized byMarcus R · 09:40
admin accessleased 8 min · expired 09:47
ranrestart print spooler · signed job
the machine saidservice running · queue clear
undodeclared before execution
ticket#4821 · resolved
chain 9f3a…c47e DONE & LOCKED

Until the file lands

Three ways to check the same claims today.

Why we would rather leave the frame emptyWe could stage this in an afternoon on a clean machine with a scripted ticket, and it would look better than the real one. It would also be the exact thing this company exists to argue against. The recording gets published when it is a capture of a live operation on a live system, including whatever it shows that we would not have chosen. How an operation actually runs →

Better than a video

Watch it happen instead, and pick the ticket yourself.

Fifteen minutes: a real ticket resolved end to end, the record opened, the rollback executed. Bring the hardest question from your last client audit and we will answer it on the call.