owno.ai  ·  implementation · control plane · continuous improvement

Every agent has an owner.

We put one important workflow into production with AI, and keep it there: implementation inside your company, a control plane at the point of action, and a loop that makes the agent measurably better.

every action → owner · rule · cost · outcome  ·  written once

§01   what we do

01 / 09

Three things, sold as one.
One record under all of them.

owno implements one workflow, runs every action it takes through a control plane, and keeps improving it. Each part has a page of its own; this is the map.

01   implementation

One workflow, into production

One important, recurring workflow: order intake, refunds, account adjustments, collections. We implement it to run with AI inside your company, with adapters to your systems, acceptance tests written from your real cases, a runbook and a supervised launch. Eight to twelve weeks once access exists. If agents already run, we start from them.

How an implementation runs →

02   the platform

A control plane at the point of action

Every action the agent takes passes through owno. Owner, budget and rules are checked at the instant of the call, not in a report afterwards; the result is written once to a ledger you own, with the owner’s name on it. A stolen key opens nothing.

The product in full →

03   continuous improvement

Finished is not correct. The loop is how it gets better.

Every correction by your specialist becomes a test; every incident becomes a rule; a change ships only when the agent’s own tests pass and the owner signs. Results are measured on the original workload, in your systems, with the method stated in advance.

How improvement works →

for clients

What you buy, what you bring, what you decide

Four offers with a decision at the end of each: a readiness study, implement and launch, operate and improve, and the recovery of an agent you already run. The first step is a study you can inspect, useful even when the answer is “do not automate”.

For clients →

already have agents?

We start from them

A pilot that stalled, a platform that was bought, an automation that grew, a deployment that was rolled back. The hard cases arrive after the demo: incomplete context, rules that change, tools that fail. The problem is rarely the model. Failure map, acceptance set, tested correction, release evidence.

Recovering an existing agent →

§01.1

Implementation is how it starts. The loop is why it keeps working.

§02   the problem

02 / 09

A person gets a badge.
An agent gets nothing.

A new employee arrives with a badge, a manager, a budget, rules, a work log and a file for the auditor. A new agent arrives with a copied password.

scene 01   the stray flock

no owner · no rule · no record

Scene 1 · a flock of agents, nothing in the path. Every action counts as done; one key walks out of the building. Illustrative.owno.ai

01   no owner

Nobody’s name is on it

Ask who is responsible for an agent and the answer is a team or a service account. It is the first question an auditor, a regulator or an insurer asks.

02   shared keys

Real keys, copied by hand

Agents hold live API keys passed between laptops, projects and other agents. When one leaks, nothing says which agent held it or what it did with it.

03   no rule at the action

Written down, checked by nobody

“Never message more than 500 customers without approval” lives in a document. At the instant the agent sends, nothing evaluates it.

04   unattributed cost

The bill arrives whole

Finance sees one model invoice. Nothing says which agent spent it, on whose behalf, or what the money bought.

05   finished is not correct

Reversed work still counts as done

A ticket the agent closed and the customer reopened a week later reads as a success on every dashboard. It consumed the work twice.

06   no file for the auditor

Partial logs that never meet

Each tool keeps its own fragment. The answer to “what did your agents do, and who allowed it” is assembled by hand, months later.

Finished is not correct A support agent closes twenty-four tickets in a week. Every one of them finishes, and every dashboard counts twenty-four successes. Five are reopened by the customer within the week. Nothing in the company's stack connects the reopenings back to the closures that caused them, so the agent is recorded as having done twenty-four pieces of work when it did nineteen. ONE WEEK OF SUPPORT TICKETS 24 closed · every dashboard says 24 successes 19 stayed closed · 5 reopened within the week, linked to nothing

scroll →

Fig. 1 · finished is not correct. Illustrative week, demonstration workspace. owno.ai

§02.1

This is the difference between a security camera and a lock. Most tools today are cameras.

§03   before / after

03 / 09

Four actions, with and without owno.

Four agents, four calls, one afternoon. Once with nothing in the path, once with owno in it.

scene 02   the point of action

allowed · held · refused

Scene 2 · the same stream of calls, evaluated as each one arrives: most pass, some wait for a human, one is turned back. Illustrative sequence.owno.ai

Without owno

nothing in the path

Four agent actions without owno Four calls — a CRM update, a message to four thousand two hundred customers, a vendor payment and a data export — travel from the agents straight into the company's systems. Nothing evaluates them and nothing is recorded. Two days later the complaints about the unapproved message arrive, with nothing linking them to the call that sent it. AGENT SYSTEMS crm.update · 96 rows email.send · 4,200 vendor.pay $1,880 export.run · 12k rows THE RECORD no rule evaluated · no owner · nothing written TWO DAYS LATER complaints arrive · nothing links them to the send

scroll →

Every call succeeds, so every dashboard reads four successes. The unapproved message to 4,200 customers is one of them.

With owno

evaluated at the action

The same four actions with owno The same four calls reach owno at the point of action. The CRM update and the data export are allowed and run. The vendor payment is held for a human because it crosses a spend cap. The message to four thousand two hundred customers is refused before it reaches the mail provider, because no human approved a send that size. Four lines are written to the ledger, each carrying the owner and the rule that decided it. AGENT POINT OF ACTION SYSTEMS crm.update · 96 rows email.send · 4,200 vendor.pay $1,880 export.run · 12k rows REFUSED · RULE R-22 HELD FOR ANA · SPEND CAP THE LEDGER allowed · crm.update · marc.oliva · support-L1 refused · email.send 4,200 · rule R-22 flagged · vendor.pay $1,880 · held for ana.duarte allowed · export.run 12k rows · iris.chen · data-L2

scroll →

The message never reaches the mail provider. Every line carries a name and a rule.

Fig. 2 · the same four calls, evaluated and unevaluated. Illustrative sequence, demonstration workspace. Target state of the first engagement. owno.ai

Everything a company does for people, done for agents

For a personFor an agent, todayFor an agent, with owno
A badge and a login A key copied from a colleague’s laptop, shared by several agents. Identity and keys. The agent holds a decoy. owno swaps in the real key at the moment of use, so a stolen key opens nothing.
A manager A team, a service account, or nobody. An owner. One named person, with a backup. When they leave, responsibility passes automatically.
A job description A prompt somebody edited last quarter. A mission. What the agent is for, and which tools it may use. owno checks that its work matches its mission.
A spending limit Discovered on the invoice, after the month closed. Budgets. Per day and per month, on models and on tools, with an alert before the limit and a stop at it.
Company rules A document nothing reads at the moment of the action. Policy at the action. Checked at the instant the agent tries to act, not in a report afterwards.
A work log Partial logs in six tools that never meet. The ledger. Every action, job and work item in one place: who, what, which rule allowed it, what it cost, what came of it.
A performance review Nothing. The agent is rewritten often and nobody checks. Tests and a scoreboard. Built from the agent’s own real cases, run before every prompt, tool or model change.
A promotion Either fully supervised or fully loose, chosen once. Earned autonomy. After enough approved decisions with no incidents, owno proposes acting alone and the owner signs.
Training after a mistake Someone edits the prompt. Nothing checks it. The improvement loop. Every incident becomes a test, and often a rule, with the change that would have prevented it named.
The file for the auditor Screenshots and a spreadsheet, assembled by hand. Evidence packets. A signed extract of the ledger, verifiable without an owno account.
Offboarding The agent is switched off. Its keys stay live. Retirement with proof. Keys revoked, data purged, a signed artefact that says so.

§04   the same incident, twice

04 / 09

A duplicate send, with and without owno.

One agent, one mistake, one calendar, read down both columns.

scene 03   the same mistake, once

incident → test → rule → refused

Scene 3 · two sends, one flag, one rule, and the third attempt refused where it happens.owno.ai

Without owno

as things are

With owno

in the path

Mon

The agent sends the same campaign twice to 4,200 customers. Both sends go out. No rule evaluated either one.

Mon

Both sends are recorded against the agent, its owner Marc, and the rule that allowed them.

Wed

The unsubscribes and the complaints land in the help desk. Nothing links them back to the two sends that caused them.

Wed

owno reads the unsubscribes from the help desk and links them to the two sends. Marc is alerted the day they land, not the month the report closes. flagged · finished, not correct

Thu

Every dashboard still reads two successful campaigns. The next duplicate is not prevented, because nothing was learned.

Thu

The incident becomes a test from the real cases. owno proposes a rule and replays it against last month: it would have refused both of Monday’s sends. Marc switches it on.

Fri

The agent tries a duplicate again. Nothing is in the path. The campaign goes out.

Fri

The agent tries a duplicate again. The action is refused at the instant it is attempted, with the rule and the owner on the record. refused at the action

Weeks

Someone in marketing notices the pattern weeks later. The fix is a paragraph added to the prompt. It is not tested.

3 months

Marc has decided 200 send requests above 500 recipients: 196 approved, four rejected. The agent agreed with him on all 196 approvals, so owno proposes letting it act alone on that class. Marc signs. autonomy earned, not assumed

At the audit

The evidence is assembled by hand from six tools. Who owned the agent, and which rule allowed the send, cannot be answered.

At the audit

One click produces a signed packet: the agent’s history, its owner, its rules, its tests, the incident and its remediation. The auditor verifies the signature without logging in. owned · recorded · proven

Illustrative sequence. Figures are from a demonstration workspace, not a customer.

Autonomy is earned Twenty customer-data exports above ten thousand rows go to Iris for approval; she approves eighteen and rejects two, and every answer becomes a test case. Once the agent has agreed with her on a long enough run, owno proposes letting it act alone on exports under fifty thousand rows and the owner signs. From that point the same exports are run with no human in the loop, at the same incident rate. EVERY EXPORT ABOVE 10K ROWS GOES TO IRIS THE SAME EXPORTS, NO HUMAN IN THE LOOP H H H H H H H H H H H H H H H H H H H H 18 approved · 2 rejected · every answer became a test case autonomy earned at a measured incident rate, not assumed

scroll →

Fig. 3 · autonomy is earned, decision by decision. Illustrative run, demonstration workspace. owno.ai

§04.1

A vendor who only records could not have written the test.

§05   the mechanism

05 / 09

One place to pass through. One record left behind.

owno sits between an agent and the system it is about to act on, and decides there.

scene 04   one place to pass through

one action · one line

Scene 4 · every action goes through the (o) and comes out the other side with a line in the ledger. The duplicate does not come out.owno.ai
The point of action A refund agent holding only a decoy key calls the payment system. The call travels into owno, which checks who owns the agent, which rule applies, and substitutes the real key before allowing it through to payments. A second, identical refund travels the same path and is refused inside owno under rule R-14, so it never reaches the payment system. One line is then written to the ledger for the action that ran: owner ana.duarte, action payments.refund, rule finance-L2 revision 14, cost $412, and the outcome read back from the accounting system two days later — reversed. 01 · AGENT 02 · OWNO 03 · SYSTEM OF RECORD 04 · THE LEDGER refund agent owner · ana.duarte key · decoy the point of action 1 · who owns this agent 2 · which rule applies 3 · the real key, held here 4 · allow · flag · refuse ALLOWED payments the money moves here reversal read back · wed refund $412 refund $412 REFUSED · R-14 OUTCOME ONE ACTION, ONE LINE WHOWHATWHICH RULE WHAT IT COSTWHAT CAME OF IT ana.duarte payments.refund finance-L2 · rev 14 $412 reversed · wed

scroll →

Fig. 4 · the point of action. The rule is evaluated where the call happens; the ledger is written once. Illustrative, demonstration workspace. owno.ai
The loop closes An incident — the same campaign sent twice to four thousand two hundred customers — becomes a test case written from the real actions. The test becomes a rule, simulated against last month's traffic before it is switched on. At the point of action the rule refuses the next attempt, and three attempts since have been refused. The loop returns to the start: the same mistake cannot happen twice. 01 · INCIDENT duplicate send 4,200 customers, sent twice 02 · TEST case #88 written from the real actions 03 · RULE R-22 simulated on last month first 04 · AT THE ACTION refused 3 attempts since, none served the same mistake, now refused The loop closes The same four stages, stacked for a narrow screen: an incident becomes a test case, the test becomes a rule simulated on last month's traffic, and the rule refuses the next attempt at the point of action. A return path leads back to the start — the same mistake cannot happen twice. 01 · INCIDENT duplicate send 4,200 customers, sent twice 02 · TEST case #88 written from the real actions 03 · RULE R-22 simulated on last month first 04 · AT THE ACTION refused 3 attempts since, none served the same mistake, now refused

scroll →

Fig. 5 · one incident, closed. Illustrative sequence, demonstration workspace. owno.ai

a · secure

Keys the agent never holds

Decoy credentials swapped at the moment of use, a fingerprinted allowlist of tools, and refusal at the action. Safety in full →

b · govern

Rules where the call happens

Owner, budget, thresholds and approvals, evaluated at the action. Every rule is replayed against last month’s real traffic before it is switched on.

c · observe

One ledger, joined to the outcome

Action, job and work item, with cost counted once and attributed by purpose. The business result is read back from the systems that hold it.

d · improve

Incidents become tests

Failures turn into test cases and rules; approvals turn into training examples. A change ships when the agent’s own tests pass. Improvement in full →

e · prove

Evidence a third party can check

Signed packets verifiable without an owno account. A company’s own log is a claim; a countersigned record is evidence.

f · pool

What other fleets already learned

Patterns, never content: a model version that got worse at a task, an attack circulating this week. No single company sees this alone.

Rules are not written once. They accumulate, and each one is signed.

A rule enters the book from one of four places. owno proposes it, replays it against last month’s real traffic so the owner sees exactly what it would have refused, and switches it on only when a named person signs. Nothing is enforced that nobody chose.

scene 05   the rulebook grows

proposed · replayed · signed · enforced

Scene 5 · three rules enter the book from three places: an incident of your own, a pattern from other fleets, and the owner’s own approvals. Each is replayed on last month’s traffic and signed before it is enforced.owno.ai

source 1   your own incidents

The mistake becomes the rule

A duplicate send, a refund reversed, an export nobody approved. The incident becomes a test written from the real actions; the test becomes a rule that would have refused it. The same mistake cannot happen twice.

source 2   the owner’s decisions

Every yes and no is a labelled example

The approval inbox is a training set. Two hundred consistent answers become a threshold: a rule that lets the agent act alone on that class, or one that holds it. The owner signs the rule they already wrote by hand.

source 3   other fleets

Suggested before the incident is yours

Patterns, never content: a prompt-injection wave circulating this week, a model version that got worse at a task, a tool definition that changed underneath everyone. owno proposes the rule; you decide whether it applies.

source 4   model and tool changes

A new version is a new agent

A model upgrade or a changed tool is replayed against the agent’s own tests before a single production call. What passed stays; what regressed is held, with the case that caught it attached.

§06   safety

06 / 09

A stolen key opens nothing.

An agent’s credentials are the shortest path into a company, and today agents carry them in plain text.

scene 06   the decoy

a copy leaves · a copy is worthless

Scene 6 · the agent holds a decoy; the real key stays inside owno. Using the copy is the alert.owno.ai

Without owno

the agent holds the key

A leaked key without owno The agent holds a live API key. A copy of that key travels out of the agent and comes to rest in a shared, untracked place. An unknown caller then walks that copy all the way to the model provider: the call is accepted and billed to the company, and nothing identifies which agent the key belonged to. AGENT PROVIDER support agent key · sk-live-4f2a models key · sk-live-4f2a COPIED · SHARED · UNTRACKED unknown caller accepted · billed to you · no agent to blame

scroll →

The provider sees a valid key. Nothing says which agent held it, or that it left.

With owno

the agent holds a decoy

The same leak with owno The agent holds only a decoy credential, and owno adds the real key at the point of action, where it stays. A copy of the decoy travels out of the agent to the same shared, untracked place, but a copy of it is worthless. When an unknown caller walks that copy toward the provider, the call is refused at the point of action and the agent's owner is alerted. AGENT OWNO PROVIDER support agent key · sk-decoy-0000 models key · sk-decoy-0000 A COPY IS WORTHLESS real key added here NEVER LEAVES OWNO unknown caller refused · unknown caller · owner alerted

scroll →

The decoy is the only thing that can leak. Using it is how you learn it leaked.

Fig. 6 · a credential leaving the company, with and without a broker in the path. owno.ai

s1   credential broker

One identity per agent

Each agent gets its own identity, tied to its owner, and a decoy credential. The real key lives in owno and is substituted at the call. Revoking an agent is one action, with proof.

s2   llmjacking

Model calls that are not yours

Stolen model credentials are resold and burned within hours. owno reads every model call in the request path. A call from an unknown caller, an unexpected region or an unusual pattern is refused, not reconciled on the invoice.

s3   honeytokens

Keys that exist to be stolen

The decoy is a canary. Any use of it comes from a copy that left, so the first use is the alert. The alert names the agent, the surface it leaked from and the caller.

s4   tool integrity

A tool that changed is not the tool you approved

Every tool and MCP server an agent may call is fingerprinted at approval. When a definition changes underneath, the change is diffed and the call is held until a human accepts it.

s5   injection & exfiltration

Instructions from the data are not orders

Content that tries to steer an agent is a signal, not a verdict. What owno enforces is the action it produces: an unusual destination, a first-time recipient, a bulk read followed by a send.

s6   refusal

Stopped, not reported

A refusal happens at the instant of the call, before the money moves or the record changes. It is written with the rule and the owner on it. A detector that only reports is a camera.

The bill is the first place most companies see it

A stolen model key is not used quietly. It is resold, and the buyer runs whatever they like on it: in another language, on another subject, at a volume your agents never reach.

Without owno

seen on the invoice

A hijacked key, spending Four calls in the agent's own subject matter — tickets, threads, churn scores — run on the key. Then the same key starts serving a different caller: a poem in Mandarin, a question about cryptocurrency, a roleplay, a forty-thousand-word translation, and 2,140 more calls in the same hour. Nothing stops them, and the hour's spend climbs to $1,847, which the company first sees on the invoice. PROMPTS ON YOUR KEY SPEND · THIS HOUR triage ticket #4471 summarise thread #8812 score churn risk · acct #2210 draft reply to #3320 SAME KEY · A CALLER YOU DO NOT KNOW · 3 REGIONS YOU DO NOT OPERATE IN 写一首关于月亮的诗 best crypto to buy in 2027 roleplay: pirate captain translate 40,000 words · ru … and 2,140 more this hour $1,847 nobody is watching this number

scroll →

The key works, so the calls are served. The month closes before anyone asks whose they were.

With owno

refused on the first one

The same hijack, refused The same four calls in the agent's own subject matter run normally. When the same key is presented by another caller with an unrelated prompt, owno refuses the call, alerts the owner and rotates the key, so no further calls are served and the hour's spend stays at $12. PROMPTS ON YOUR KEY SPEND · THIS HOUR triage ticket #4471 summarise thread #8812 score churn risk · acct #2210 draft reply to #3320 SAME KEY · A CALLER YOU DO NOT KNOW · 3 REGIONS YOU DO NOT OPERATE IN 写一首关于月亮的诗 refused · unknown caller · owner alerted key rotated · no further calls served $12 stopped at the first one

scroll →

The pattern is the signal: another caller, another subject, another volume. One refusal ends it.

Fig. 7 · a hijacked key, with and without a broker in the path. Illustrative figures, demonstration workspace. owno.ai

§06.1

Detection tells you afterwards. A broker in the path decides at the call.

§07   the product

07 / 09

One ledger. Nine windows onto it.

There is one thing underneath, and every screen is a different question asked of it. The product page collects the platform in one place, with a note on where it stands today.

scene 07   the census

every agent · one row

Scene 7 · the flock becomes the ledger: agent, owner, policy. The one nobody claims stays flagged. Demonstration workspace.owno.ai
AgentsOwnersPoliciesLedgerIncidentsSpend ws · acme-finance

Agents under management

2,140

+12 this week

Actions · 24 h

184,302

24 h window

Flagged

412

0.22 %

Refused at action

37

0.02 %

agentownerpolicylast actionamount
billing-reconcilerAna Duartefinance-L2allowed · payments.refund$412
support-triageMarc Olivasupport-L1allowed · crm.update96 rows
procure-botAna Duartespend-cap-2kflagged · vendor.pay$1,880
research-crawlerIris Chenread-onlyrefused · vendor.create
ledger-exporterunassignedno owner · export.run

scroll →

Fig. 8 · the Agents screen, drawn to the interface specification. Figures are from a demonstration workspace, not a customer. owno.ai
What the developers' assistants did A month of coding-assistant work: about two thousand nine hundred sessions are stitched into about two thousand three hundred jobs, because a request often fans out across several sessions and codebases. Each job is split into work items — one objective with one result — and the model spend is attributed by how each job ended: twenty-six thousand dollars on changes that merged, six thousand on investigations that answered a question, and nine thousand on jobs that produced neither. SESSIONS · 2,940 JOBS · 2,310 WORK ITEMS · 2,590 $41k · BY HOW THE JOB ENDED merged $26k answered a question $6k shipped nothing $9k one request, several sessions one objective, one result finance sees what the bill bought

scroll →

Fig. 9 · coding-assistant work, by purpose and by result. Illustrative month, demonstration workspace. owno.ai

The agent gets better, and you can show it.

Every real case the agent handled is a test it must keep passing. A prompt edit, a new tool or a new model version ships only when the agent’s own tests pass, and the scoreboard, per criterion and per version, shows whether it got better or worse.

scene 08   the agent gets better

tests · gate · autonomy

Scene 8 · every real case is a test. A prompt change that fails one never ships; the one that passes all of them does, and the agent earns more room.owno.ai

i   tests from real cases

No synthetic benchmark

The cases come from the ledger: what the agent actually did, what the owner said about it, and what came of it. Each incident adds one. The suite grows with the agent’s history, not with someone’s imagination.

ii   a gate before every change

Fails one case, does not ship

Prompt, tools, model: every change runs the suite first. A result compliance can co-sign replaces the review meeting, and the change that would have broken a real case never reaches production.

iii   autonomy that widens with evidence

Room is earned, not assumed

When the agent agrees with its owner on a long enough run and its tests keep passing, owno proposes a wider class it may handle alone. The owner signs. Incidents rise, and the room narrows again.

  • 01CensusEvery agent the company has, who owns it, what it costs, which keys it holds.
  • 02Agent pageOne agent’s file, read as a profit-and-loss statement: work items, cost per correct result, incidents, autonomy.
  • 03RulesWhat each agent may do, checked at the moment it acts, simulated on last month’s traffic before it is switched on.
  • 04Approval inboxWhere a human says yes or no, and every answer becomes a test case.
  • 05Tests & scoreboardIs this agent getting better or worse, per criterion and per model version.
  • 06IncidentsWhat went wrong, the actions that caused it, the test it became, the rule it became.
  • 07EvidenceThe signed packet for the auditor, the regulator and the insurer, verifiable without an account.
  • 08Coding agentsWhat the developers’ assistants did, by purpose, by product and by how each job ended.
  • 09Fleet feedWhat every other fleet already learned. Patterns, never content.

Where it stands, September 2026: the gateway with the kill switch and budget caps exists; the census has run on demonstration sources; the case record and the executor are built in the first engagements on that base. Screens beyond the thin core arrive when a customer’s workflow needs them.

§08   how it plugs in

08 / 09

Three levels. Nothing to install on the first.

Each level is a decision you make after seeing what the previous one showed.

scene 09   three levels

connect → badge → rules

Scene 9 · level 1 walks around the flock and counts it. Level 2 gives each agent a badge. Level 3 stands at the gate.owno.ai
What two weeks of read-only shows Sixty-three agents are found across the company's existing systems, with nothing installed. Forty-one of them have no named owner. Nine share a single API key. Four cost more than ten thousand dollars last month. This is the census: the first thing owno produces, and the reason the company grants the next level. EVERY AGENT THE COMPANY ALREADY HAS 63 agents found · nothing installed to find them 41 have no named owner 9 share one key 4 cost more than $10k last month

scroll →

Fig. 10 · the census, after two weeks of read-only access. Illustrative fleet, demonstration workspace. owno.ai

level 1

Connect

Read-only access to what already exists: the login system, the cloud and model bills, the logs your automation tools and coding assistants already produce.

You get the census, the agent pages, and cost by agent and by purpose, written into the warehouse and the spend tool your finance team already uses.

Two weeks. owno sits beside the agents, not between them. Reading coding-assistant sessions means reading code and prompts, so owno signs the same data terms as any processor.

level 2

Badge

Agents get their own identity and a decoy key. owno swaps in the real key at the moment of use, starting with the agents the census showed sharing one.

Real keys leave the agents. Cost stops being reconstructed from invoices: every call is attributed as it happens, which is what makes a budget enforceable.

Days per agent. You choose which agents go first, and whether an unreachable owno holds the request or lets it through.

level 3

Rules

The actions agents take in other systems pass through owno, and rules are enforced at the moment of action, with the approval inbox live.

Enforcement, approvals, earned autonomy, incidents that become tests, evidence packets. Every rule is simulated on past traffic before it is switched on.

Weeks of rollout. The workflow we implement runs here from the first day; other agents join after the first thing you wish had been refused.

§08.1

Level 1 is read-only and reversible. It is what earns permission for level 2.

§09   proof

09 / 09

Four numbers, measured per customer.

Every claim on this page reduces to four numbers, published with the method stated in advance, including when the result is no difference. The six numbers a deployment reports monthly are on the improvement page.

scene 10   two arms

random · by action · same instrument

Scene 10 · each action is assigned at random to one arm; both arms are recorded by the same instrument. Nulls count.owno.ai

§09.1   what is measured

  • Cost per correct resultFinished and right, not merely finished. The same agent with owno and without it, counted by the same instrument.
  • Incidents per thousand actionsEnforcement on versus off, split at random by action so the two arms are comparable.
  • Autonomy rateThe share of work items completed with no human in the loop, at a fixed incident rate.
  • Releases per agent per monthBefore and after tests with a gate. A test result that compliance can co-sign replaces the review meeting.

§09.2   how it is measured

Randomised assignment, action by action Actions arrive in one stream and each is sent, at random, into one of two arms: enforcement on, or enforcement off with the same instrument still recording. Over the cycle both arms fill, in no fixed order. What is compared afterwards is the incident rate of one arm against the other. ACTIONS · ASSIGNED AT RANDOM, PER ACTION ENFORCEMENT ON ENFORCEMENT OFF · RECORDED ANYWAY action action action action action action

scroll →

Fig. 11 · assignment. Nulls are published with the same weight as wins.

Randomised by action, not by agent or by week, so the two arms face the same traffic. The arm without enforcement is recorded by the same instrument, which is what makes the difference readable.

what you buy

A result, with a decision at the end

Four offers: a readiness study, implement and launch, operate and improve, and the recovery of an agent you already run. Setup is priced once; operation monthly; inference at cost on your own keys. Human review is priced, never implied. For clients →

who it is for

A recurring operation

Companies with a recurring, rule-bound workflow worth putting into production, and operators in regulated sectors who need the approval, the rule and the evidence on the record. With or without agents already running.

the record is yours

Evidence you hold, not a claim we make

The result is measured in the systems that hold it, by a method stated before the work starts, and the record lives in your warehouse. owno does not grade its own work: the outcome is read back from your systems, nulls included.

§09.3   what owno does not do

  • Replace your systemsThe ERP, the CRM and the automation tool stay. owno works inside the access you grant.
  • Replace your login systemPeople stay in Okta, Microsoft or Google. owno ties agents to those people.
  • Sell content filteringThose detectors exist and are mostly free. owno reads their signals; it does not sell them.
  • Move money or carry riskIt produces the evidence that rails, insurers and auditors ask for.
  • Replace your spend platformYour card and ERP know what AI cost to the cent. owno says what the money was for.
  • Train modelsWhen you want to train on your agents’ history, owno exports it.
  • Monitor servers or laptopsThat is Datadog’s and Zscaler’s work. owno feeds them and reads from them.
  • Surveil employeesFor coding assistants, managers see purposes and flags, never the conversations.

the first step

OWNO-WEB-1.2 · 2026-09-09

Start with one decision you can inspect.

A readiness study of two to three weeks: baseline, concrete scope, access map, costed plan, and a go or no-go with the numbers on the table. Already running agents? Recovery starts from a failure map of their own cases.

owno.ai  ·  São Paulo