Skip to content
warpbeam

AI with guardrails

The AI weaves. Your hand stays on the lever.

The AI is meant to find loose ends and tears in the fabric: orphaned accounts and attack paths. An AI that may change identities and systems needs limits before it writes its first line. Those limits are set. Now the building starts.

StatusThe rules on this page are decided. The AI control centre and the built-in AI runtime are planned; Warpbeam contains no AI function yet.

Autonomy

Six levels, set per task.

You decide how far the AI may go: separately for each kind of task, such as “revoke access” or “restart a service”, and separately by how critical the affected systems are.

Pick a level to see what the AI does there

Level 0: Off

The AI does nothing. Warpbeam works fully without it.

Level 1: Explain

The AI explains findings and context. It proposes nothing and triggers nothing.

Level 2: Recommend

The AI proposes an action. One person adopts it, a second approves it. Default for every task.

Level 3: Act with approval

The AI prepares the job itself. It runs only once someone other than the requester approves; for the most critical systems, two people.

Level 4: Autonomous within limits

The AI acts on its own, inside fixed limits on scope, budget and duration. Only after a passed dry run, and only for a limited time.

Level 5: Fully autonomous

The AI acts on its own, approvals included. Only if you explicitly switch it on, with a second person and an explicit acceptance of risk.

At every level

What always applies.

  • Audit trailEvery AI step is recorded in full.
  • Emergency stopStopping is immediate, no approval needed.
  • BudgetThe AI works with limited resources and calls.
  • ReachEvery action has a cap on how much it may touch at once.
  • UndoEvery action comes with a plan to reverse it.
  • Dry runBefore level 4 or 5, a trial shows how often the AI would have been right.

Your most critical systems get their own switch, which only two people together can turn on, and only for a limited time. For critical infrastructure, the AI stays at level 3 in IT operations unless management explicitly accepts the risk. On top of that, a local switch on every server decides whether the AI may act there on its own at all; it ships switched off.

Principles

What can never be switched off.

These knots stay tied, even when everything else is switched on.

  • The AI never changes its own rules or its own level.
  • The audit trail can't be disabled or altered. Every AI decision stays marked as one.
  • The emergency stop is always there.
  • There's no way around the single checkpoint every AI action has to pass.
  • Secrets never go to a model.
  • Break-glass accounts are never the target of an AI action.
  • No language model decides whether someone may sign in.

You can switch everything on. Eyes open.

You can let the AI approve requests, confirm access reviews or lift an emergency stop. All of this is off by default.

Switching it on takes a second person and an explicit acceptance of risk, and first shows you which requirements of your applicable frameworks you would no longer meet.

Learning mode

Learn first. Act later.

In learning mode, Warpbeam watches your environment and the decisions your people make, decides in shadow mode and measures how often it would have been right. It doesn't act. Learning mode already exists in the sign-in guard today; we're extending it to the whole fabric.

  1. WatchThe environment and human decisions, without stepping in.
  2. Decide in shadow modeThe AI decides along, on paper only.
  3. MeasureHow often would it have been right, how often wrong?
  4. Open level 4Only this record allows autonomy within limits, for a limited time.

Every AI agent is an identity.

Your own AI agents and those of external tools get an identity in Warpbeam, a human who answers for them, and never more access than that human. An agent can never count as lower-risk than the person it acts for.

The model is meant to run inside Warpbeam.

Warpbeam is meant to bring its own AI runtime. The language model is meant to be an open model, delivered as a signed data package and running with no connection to the internet. For each tenant you choose: the built-in runtime, a model you run or contract yourself, or no AI at all. Before every call, names, identifiers and secrets are redacted; the model sees pseudonyms.

Your data never trains a model, and no model is fine-tuned on it.

Without a model, every function falls back to its non-AI version, and nothing stops.