---
title: "Built-in Security: containment designed into the build"
description: "A build add-on that gives every agent its own identity, every tool call a policy gate, and every action an audit trail, while the code is still being written."
source: "https://www.kensink.com/engagements/built-in-security/"
canonical: "https://www.kensink.com/engagements/built-in-security/"
---
SERVICE · BUILT-IN SECURITY · BUILD ADD-ON

# Containment is a design decision. Later, it is surgery.

When we build your agent, every tool call can pass a policy gate, every agent can carry its own identity, and every action can land in an audit log, while the code is still being written. The same architecture retrofitted afterwards costs three times as much.

Who it's for: Any client already commissioning an agent or LLM build from us. It is only available once, during the build.

THE OFFER

Outcome

Policy layer, by design not hours billed

Engagement

Add-on to a build

Timeline

Adds 0 weeks

Investment

+$9,000 on the build \+ optional care retainer

Handoff

Full source + policy set

[Request this service →](https://www.kensink.com/contact) [Book a scoping call](https://www.kensink.com/contact)

IN SCOPE

## What the engagement covers.

-   ✓A distinct identity per agent rather than one shared service account
-   ✓Scoped, short-lived credentials in place of long-lived keys
-   ✓A policy gate every tool call passes through, with the policy in version control
-   ✓A blast-radius boundary per agent
-   ✓An append-only audit log of every action taken
-   ✓A kill switch and a documented rollback
-   ✓Adversarial cases joined to the functional eval suite

OUT OF SCOPE

## What we would quote separately.

-   –An independent red team, which this deliberately is not
-   –A full IAM programme
-   –Endpoint controls or device management
-   –24/7 staffed monitoring

DELIVERABLES

## What lands at handoff.

-   ✓The policy layer, running in production with the build
-   ✓Policy-as-code in version control, reviewed like code
-   ✓The append-only audit log, which doubles as controls evidence
-   ✓A kill switch and rollback runbook
-   ✓A starter adversarial eval suite in the same CI gate

TIMELINE · 4 PHASES

## Adds 0 weeks, problem to production.

1.  01
    
    Build wks 1 to 2
    
    ### Scope and evals
    
    The agent's job gets pinned. The permission model is written into the same document.
    
2.  02
    
    Build wks 3 to 5
    
    ### Build
    
    Every tool is wired behind the gate the first time, so there is nothing to unpick later.
    
3.  03
    
    Build wks 6 to 7
    
    ### Harden
    
    Adversarial cases join the functional eval set. One suite, one gate, one CI run.
    
4.  04
    
    Build wk 8
    
    ### Ship and hand off
    
    Audit log, policy set and kill switch ship with the runbook, with full source.
    

SERVICE LEVELS

## The SLA this service runs under.

During the build and through the warranty window after handoff. This engagement defaults to Priority.

| Commitment | Standard | Priority |
| --- | --- | --- |
| First response | Next business day | Within 4 business hours |
| Critical issue triage | 1 business day | 2 hours |
| Production uptime target | 99.5% | 99.9% |
| Support hours | Mon to Fri, business hours | Extended, plus weekend on-call |
| Change requests / month | 2 included | Unlimited within retainer |
| Post-launch warranty | 30 days | 90 days |
| Named delivery lead | Shared | Dedicated |

ⓘ Standard ships with every fixed-scope build. Priority comes with a care retainer. Pricing is a starting range; final terms are set in the statement of work.

[Read the full Built-in Security capability page ↗](https://www.kensink.com/ai-security)

READY WHEN YOU ARE

## Bring one real problem.  
We'll bring the spec.

[Request this service →](https://www.kensink.com/contact) [All engagements](https://www.kensink.com/engagements)

[← All engagements](https://www.kensink.com/engagements) ENGAGEMENT · BUILT-IN-SECURITY
