Containment is a design decision. Later, it is surgery.
When we build your agent, every tool call can pass a policy gate, every agent can carry its own identity, and every action can land in an audit log, while the code is still being written. The same architecture retrofitted afterwards costs three times as much.
Who it's for: Any client already commissioning an agent or LLM build from us. It is only available once, during the build.
- Outcome
- Policy layer, by designnot hours billed
- Engagement
- Add-on to a build
- Timeline
- Adds 0 weeks
- Investment
- +$9,000 on the build+ optional care retainer
- Handoff
- Full source + policy set
What the engagement covers.
- ✓A distinct identity per agent rather than one shared service account
- ✓Scoped, short-lived credentials in place of long-lived keys
- ✓A policy gate every tool call passes through, with the policy in version control
- ✓A blast-radius boundary per agent
- ✓An append-only audit log of every action taken
- ✓A kill switch and a documented rollback
- ✓Adversarial cases joined to the functional eval suite
What we would quote separately.
- –An independent red team, which this deliberately is not
- –A full IAM programme
- –Endpoint controls or device management
- –24/7 staffed monitoring
What lands at handoff.
- ✓The policy layer, running in production with the build
- ✓Policy-as-code in version control, reviewed like code
- ✓The append-only audit log, which doubles as controls evidence
- ✓A kill switch and rollback runbook
- ✓A starter adversarial eval suite in the same CI gate
Adds 0 weeks, problem to production.
- 01Build wks 1 to 2
Scope and evals
The agent's job gets pinned. The permission model is written into the same document.
- 02Build wks 3 to 5
Build
Every tool is wired behind the gate the first time, so there is nothing to unpick later.
- 03Build wks 6 to 7
Harden
Adversarial cases join the functional eval set. One suite, one gate, one CI run.
- 04Build wk 8
Ship and hand off
Audit log, policy set and kill switch ship with the runbook, with full source.
The SLA this service runs under.
During the build and through the warranty window after handoff. This engagement defaults to Priority.
| Commitment | Standard | Priority |
|---|---|---|
| First response | Next business day | Within 4 business hours |
| Critical issue triage | 1 business day | 2 hours |
| Production uptime target | 99.5% | 99.9% |
| Support hours | Mon to Fri, business hours | Extended, plus weekend on-call |
| Change requests / month | 2 included | Unlimited within retainer |
| Post-launch warranty | 30 days | 90 days |
| Named delivery lead | Shared | Dedicated |
ⓘStandard ships with every fixed-scope build. Priority comes with a care retainer. Pricing is a starting range; final terms are set in the statement of work.
Read the full Built-in Security capability page ↗