product · the platform

part 02 of 03

One place every action passes through.

owno sits between an agent and the system it is about to act on, and decides there. Owner, policy and ledger, enforced at the point of action. One record underneath, nine windows onto it.

§01   the mechanism

01 / 05

One place to pass through. One record left behind.

Every action leaves with five things on its line: who, what, which rule allowed it, what it cost, what came of it.

scene 04   one place to pass through

one action · one line

Scene 4 · every action goes through the (o) and comes out the other side with a line in the ledger. The duplicate does not come out.owno.ai

a · secure

Keys the agent never holds

Decoy credentials swapped at the moment of use, a fingerprinted allowlist of tools, and refusal at the action.

b · govern

Rules where the call happens

Owner, budget, thresholds and approvals, evaluated at the action. Every rule is replayed against last month’s real traffic before it is switched on.

c · observe

One ledger, joined to the outcome

Action, job and work item, with cost counted once and attributed by purpose. The business result is read back from the systems that hold it.

d · improve

Incidents become tests

Failures turn into test cases and rules; approvals turn into training examples. A change ships when the agent’s own tests pass.

Improvement in full →

e · prove

Evidence a third party can check

Signed packets verifiable without an owno account. A company’s own log is a claim; a countersigned record is evidence.

f · pool

What other fleets already learned

Patterns, never content: a model version that got worse at a task, an attack circulating this week. No single company sees this alone.

The mechanism drawn step by step, and the same incident with and without owno, are on the home page. The point of action →

§02   how it plugs in

02 / 05

Three levels. Nothing to install on the first.

Each level is a decision you make after seeing what the previous one showed. In an implementation, the workflow we build starts at level 3; the rest of your fleet can start at level 1.

scene 09   three levels

connect → badge → rules

Scene 9 · level 1 walks around the flock and counts it. Level 2 gives each agent a badge. Level 3 stands at the gate.owno.ai

level 1

Connect

Read-only access to what already exists: the login system, the cloud and model bills, the logs your automation tools and coding assistants already produce.

You get the census, the agent pages, and cost by agent and by purpose, written into the warehouse and the spend tool your finance team already uses.

Two weeks. owno sits beside the agents, not between them. Reading coding-assistant sessions means reading code and prompts, so owno signs the same data terms as any processor.

level 2

Badge

Agents get their own identity and a decoy key. owno swaps in the real key at the moment of use, starting with the agents the census showed sharing one.

Real keys leave the agents. Cost stops being reconstructed from invoices: every call is attributed as it happens, which is what makes a budget enforceable.

Days per agent. You choose which agents go first, and whether an unreachable owno holds the request or lets it through.

level 3

Rules

The actions agents take in other systems pass through owno, and rules are enforced at the moment of action, with the approval inbox live.

Enforcement, approvals, earned autonomy, incidents that become tests, evidence packets. Every rule is simulated on past traffic before it is switched on.

Weeks of rollout. The workflow we implement runs here from the first day; other agents join after the first thing you wish had been refused.

§02.1

Level 1 is read-only and reversible. It is what earns permission for level 2.

§03   the screens

03 / 05

One ledger. Nine windows onto it.

There is one thing underneath, and every screen is a different question asked of it.

scene 07   the census

every agent · one row

Scene 7 · the flock becomes the ledger: agent, owner, policy. The one nobody claims stays flagged. Demonstration workspace.owno.ai
  • 01CensusEvery agent the company has, who owns it, what it costs, which keys it holds.
  • 02Agent pageOne agent’s file, read as a profit-and-loss statement: work items, cost per correct result, incidents, autonomy.
  • 03RulesWhat each agent may do, checked at the moment it acts, simulated on last month’s traffic before it is switched on.
  • 04Approval inboxWhere a human says yes or no, and every answer becomes a test case.
  • 05Tests & scoreboardIs this agent getting better or worse, per criterion and per model version.
  • 06IncidentsWhat went wrong, the actions that caused it, the test it became, the rule it became.
  • 07EvidenceThe signed packet for the auditor, the regulator and the insurer, verifiable without an account.
  • 08Coding agentsWhat the developers’ assistants did, by purpose, by product and by how each job ended.
  • 09Fleet feedWhat every other fleet already learned. Patterns, never content.

where it stands

September 2026

The gateway with the kill switch and budget caps exists. The census has run on demonstration sources. The case record and the executor, the parts an implementation depends on, are built in the first engagements on that base. The Agents screen on the home page is drawn to the interface specification, not a screenshot of a customer.

what the first engagement uses

The thin core

Discover, connect, observe, control, teach: what one workflow needs to run under supervision and be measured. Screens beyond that arrive when a customer’s workflow needs them, not before.

§04   safety

04 / 05

A stolen key opens nothing.

An agent’s credentials are the shortest path into a company, and today agents carry them in plain text.

scene 06   the decoy

a copy leaves · a copy is worthless

Scene 6 · the agent holds a decoy; the real key stays inside owno. Using the copy is the alert.owno.ai

s1   credential broker

One identity per agent

Each agent gets its own identity, tied to its owner, and a decoy credential. The real key lives in owno and is substituted at the call. Revoking an agent is one action, with proof.

s2   llmjacking

Model calls that are not yours

Stolen model credentials are resold and burned within hours. owno reads every model call in the request path. A call from an unknown caller, an unexpected region or an unusual pattern is refused, not reconciled on the invoice.

s3   honeytokens

Keys that exist to be stolen

The decoy is a canary. Any use of it comes from a copy that left, so the first use is the alert. The alert names the agent, the surface it leaked from and the caller.

s4   tool integrity

A tool that changed is not the tool you approved

Every tool and MCP server an agent may call is fingerprinted at approval. When a definition changes underneath, the change is diffed and the call is held until a human accepts it.

s5   injection & exfiltration

Instructions from the data are not orders

Content that tries to steer an agent is a signal, not a verdict. What owno enforces is the action it produces: an unusual destination, a first-time recipient, a bulk read followed by a send.

s6   refusal

Stopped, not reported

A refusal happens at the instant of the call, before the money moves or the record changes. It is written with the rule and the owner on it. A detector that only reports is a camera.

The two safety figures, a credential leaving the company and a hijacked key, with and without a broker in the path, are on the home page. Safety →

§04.1

Detection tells you afterwards. A broker in the path decides at the call.

§05   what owno does not do

05 / 05

The systems stay. The record is yours.

owno works inside the access you grant and leaves a record you own. It does not replace the things below.

  • Replace your systemsThe ERP, the CRM and the automation tool stay. owno works inside the access you grant.
  • Replace your login systemPeople stay in Okta, Microsoft or Google. owno ties agents to those people.
  • Sell content filteringThose detectors exist and are mostly free. owno reads their signals; it does not sell them.
  • Move money or carry riskIt produces the evidence that rails, insurers and auditors ask for.
  • Replace your spend platformYour card and ERP know what AI cost to the cent. owno says what the money was for.
  • Train modelsWhen you want to train on your agents’ history, owno exports it.
  • Monitor servers or laptopsThat is Datadog’s and Zscaler’s work. owno feeds them and reads from them.
  • Surveil employeesFor coding assistants, managers see purposes and flags, never the conversations.

the record is yours

Evidence you hold, not a claim we make

The result is measured in the systems that hold it, by a method stated before the work starts, and the record lives in your warehouse. owno does not grade its own work: the outcome is read back from your systems, nulls included.

inference

On your keys, at cost

Model calls run on your own provider accounts, through the broker, and are shown at cost. No markup on tokens, and no invoice that has to be reconciled to find out which agent spent it.

the first step

OWNO-WEB-1.2 · 2026-09-09

Start with one decision you can inspect.

A readiness study of two to three weeks: baseline, concrete scope, access map, costed plan, and a go or no-go with the numbers on the table. Already running agents? Recovery starts from a failure map of their own cases.

owno.ai  ·  São Paulo