For most of my career, the work I get hired for has had one shape. A company running on ten or fifteen systems that don't talk to each other. The CRM over here, billing over there, compliance in a spreadsheet, the same customer in four databases with four schemas. I map it, then I build the connective tissue.
AI hasn't fixed that. It's added a layer on top of it. Walk through almost any office now and you'll see the same thing: a chatbot in one tab, the CRM in another. Someone copies a customer's history out of one, pastes it into the other, asks for a summary, and pastes the answer into an email. The model is brilliant. It just can't see anything. Every employee has quietly become the integration layer between the AI and the business.
The usual responses are both bad. Lock AI down, and people use personal accounts anyway, and your customer data leaves through a door you'll never see. Open it up, connect everything to everything, and let the agents auto-approve, and you've handed a very confident intern the keys to every system you own.
There's a better option, and it's the reason I'm adding a new service: give the company its own AI operating system.
What an AI Operating System Is
Not an operating system in the Windows sense. An operating system for a company to be productive with AI: one place where your people and their agents work, connected to the systems you already run, with the rules about who can touch what built in. Three pieces matter:
- A workspace that knows how your company works. Your people ask it to research, write, analyze, or build, and it starts from your context, your vocabulary, and your playbooks instead of a blank page.
- Apps your team builds for itself. A dashboard, a tracker, a client report, a deck. The agent builds it on request, each one runs in its own sandbox with its own storage, and it can be shared like a document or turned into a template for the rest of the team.
- Gatekeepers. The layer between agents and your systems. Every agent and app starts with access to nothing. A Gatekeeper sits in front of one system, handles sign-in, narrows access to the specific resource someone intended, logs every action, and puts anything with side effects in front of a human.
The goal isn't a product your company uses. It's your company's OS.
Why the Gatekeepers Are the Part That Matters
These days I spend a lot of time auditing apps people built with AI. The findings are rarely about clever code. They're about access. A key with too much power. A database anyone can query. An integration that can write when it only ever needed to read. Builders get security wrong because every builder has to get it right, individually, every single time.
Gatekeepers move that problem from the app to the platform. Security stops being something each person building an app or running an agent has to remember, and becomes a property of the system they're working in. An agent asked to fix the typos in one Google Doc gets that one doc. Not your Drive.
They also solve the approval problem. Most human-in-the-loop setups make the agent stop and wait for each approval. You give it a task, get a coffee, and come back to find it stuck on step one. Eventually someone gets tired of that and switches it to auto-approve. A Gatekeeper takes a different approach: it simulates the outcome of a side-effecting action, lets the agent keep working, and queues the real action. When you're ready, you approve the queue in bulk or one item at a time. You get the speed of auto-approve with the safety of review.
A sandbox around every app and a gate in front of every system is also the first setup where I'd be comfortable telling a non-technical team to go vibe-code their own tools. The thing I audit for is the thing the platform enforces.
Where the Platform Comes From
I didn't start from a blank page either. My platform began as a fork of Cloudflare OS, the agent workspace Cloudflare open-sourced this summer after rolling it out to its own staff. Their security model, especially the Gatekeepers, was the right foundation. Since then I've customized it heavily, and it's considerably more mature than the early-access project it came from. It runs on Cloudflare's global network, so there are no servers for you to patch.
What matters for you isn't the lineage. It's that the platform is already built, and the engagement goes into the part that's actually yours.
What I Build for You
A platform, however good, doesn't know your company. That part is the actual work, and it's the work I've been doing for twenty-five years under other names:
- Map. Every data source, every recurring process, who needs what, and which data is regulated. It's the same systems map I start every engagement with, now pointed at a sharper question: what should an agent be allowed to see and touch?
- Connect. Gatekeepers for the everyday tools: Google, Slack, GitHub, Notion, Confluence. But the systems that actually run your business usually aren't SaaS tools. They're the policy admin system, the billing platform with the odd API, the SQL Server database from 2009 that three month-end reports depend on. Each one gets its own Gatekeeper with the narrowest access that does the job.
- Encode. Your vocabulary, your playbooks, how a quote gets approved, what "active customer" means in your shop. Then templates for the work your team repeats every week: the client report, the month-end package, new-hire onboarding.
- Automate. The processes that should run without anyone opening a chat window, with approvals placed exactly where a person should still decide.
- Hand over. One place to decide which AI models are available and see what each team is spending. Logs your security team can read. A system running in your own account that your team can operate without me.
Who It's For
Companies where most of the work is information work: reading, reconciling, writing, deciding. Insurance agencies and MGAs, financial services firms, professional services, healthcare operations, and any ops-heavy business whose people spend the day moving information from one system to another. If your team already pays for AI seats and still copy-pastes all day, you're who I built this for.
One caution if your data is regulated. Scoped access and a full action log help a great deal, but they don't make you compliant on their own. That's a design conversation we have before anything gets connected, not after.
If you want your company to have its own AI operating system, with your data, your processes, and your guardrails, book a call. And if your team has already vibe-coded a few internal tools, start with the free Vibe Reality Check. Those tools are often the first things worth moving inside.