The client does not call the vendor. They call you.

You run agents inside other businesses. OwnCharter bounds authority per client, denies what was never granted, and puts every action on a hash-chained record you answer from.

An agent inside a client environment does something nobody sanctioned. It pulls a table it had no business touching, or it sends the renewal notice twice, or it writes to production on a Friday. The client does not call the model vendor and does not call the platform. They call you, because your technicians provisioned the credentials and your name is on the engagement.

What the channel sells against this governs on paper. A readiness assessment describes the risk. An acceptable use policy asks people to behave. A monitoring stack reports the damage once the damage is done. A contract can move blame after an incident. It cannot prevent the incident.

The liability sits with your shop either way. The only open question is whether anything was actually enforcing.

Blast radius, bounded per client

Every client environment runs behind its own gate. An agent holds exactly the capabilities you granted for that client, it cannot grant itself more, and anything unverified, unresolved, or errored is denied before it runs. Prevention, not detection.

So one hijacked goal, one bad afternoon, stays inside one client, because the authority to reach the rest of your book was never granted and cannot be self-granted. That is the difference between a boundary you enforce and a boundary you document.

Try it, live

One bad action. One client. Not your whole book.

You are the operator of a six-client book. The agent in Client 04 is about to try an action nobody granted it. Run it and watch where the deny lands.

Your book of business

Client 01governed
Client 02governed
Client 03governed
Client 04denied, contained
Client 05governed
Client 06governed

Denied, fail-closed. data.export was never granted in Client 04, so the gate stops it before it runs. The agent cannot grant itself the capability, and it holds no authority in any other client.

Five clients never saw it. The blast radius of a bad action is one tenant, and inside that tenant, nothing ran.

Trigger the action in one client and inspect where the deny lands. The test is whether a bad action can gain reach beyond the authority it was given.

One view across the whole book

Bounded authority per client is what makes a fleet safe to grow. The Control Information Center is what will make it a business you can see: order lifecycle, fleet health, hash-chained records, per-client visibility, in one place you own.

That view is being built in the open right now. The gate under every agent it will show you is already running.

Every action in every client environment lands on a hash-chained, tamper-evident record: authorized before it happens, recorded after. When the quarterly business review asks what the agents actually did, you answer from the record instead of recollection.

Follow the build.

The newsletter is where I publish what broke, what it revealed, and what it cost to fix. It is the record behind the claims on this page.

Subscribe to the newsletter