ManifestoAuto Agent OS · rooftop HITL control room

Govern packs and models without turning HITL off.

Agent OS is the in-app control room on Sales OS: operator overview, dealership packs, a tenant model registry, monthly token caps, runtime policies, and a white-label overlay. Dealer-owned credentials go through a MIT Agent Vault that stays fail-closed until an operator attests smoke. Session tokens never return to the browser.

What the solution covers

One clear system, configured around the work.

Core

Fail-closed credential broker

Stores credential key names only. The MIT Agent Vault is live on a private host when attested; CRM stays fail-closed until then.

Core

Usage caps

Operator monthly token cap. Held completions fall back to rules. Never auto-send when a budget is held.

Configured

Tenant model registry

Catalogued cloud hosts or private-IP local runtimes. SSRF-safe URLs. Credential key names only.

Optional

Local runtimes

Private-IP model URLs when the rooftop owns the hardware. Public default route for workers stays blocked.

Core

Dealership packs

Floor, listing, intel, and ingest packs. Disable stops that pack’s cron. HITL, autoSend, and autoPublish cannot be switched off.

Core

Operator overview

Vault readiness, models, usage, packs, brand, and policies on one page. No secrets. Floor queue stays on Monitor and Approvals.

How deployment works

Start with the smallest useful scope.

We document the current workflow, decide what people and systems remain authoritative, then configure and verify the solution before expanding it.

  1. 01

    Inventory current AI use

    Identify providers, accounts, models, costs, data exposure, users, workflows, and unmanaged tools.

  2. 02

    Set the operating policy

    Define approved models, secrets, roles, knowledge boundaries, budgets, tools, and human approval requirements.

  3. 03

    Deploy one governed agent

    Connect one valuable workflow to the minimum required systems, then test permissions, evidence, refusal, and audit.

  4. 04

    Measure before expanding

    Review usage, cost, quality, safety, and adoption before enabling additional agents or local models.

Designed outcomes

What better looks like.

  • One operator overview for packs, models, usage, and brand.
  • Cron that only queues HITL drafts.
  • Dealer-owned keys stay out of the CRM database.
  • Listing photos never go through a generative redraw model.
  • A fail-closed vault until an operator attests smoke.

Good fit

  • A rooftop that wants governed agents on Sales OS
  • A group that needs the same HITL packs on every store
  • A store that will attest its own vault
  • A pilot that must refuse unsupervised send

Not the promise

  • A generic chatbot bundle
  • Unrestricted API keys in application data
  • Autonomous pricing or customer send
  • Generative listing photos that redraw the car

Questions & operational facts

Straight answers.

Verified operating constraints, human-in-the-loop policies, and technical boundaries.

What is the difference between Sales OS and Agent OS?+

Sales OS is the transactional system of record for leads, units, and approvals. Agent OS is the AI control plane that governs agent packs (floor, listing, intel, ingest), model routing, and token budgets on top of that same HITL queue.

How are dealership API credentials secured in Agent OS?+

API credentials are brokered through the MIT Agent Vault on private infrastructure. Credentials fail closed until attested, and raw keys or session tokens are never stored in the CRM or returned to client browsers.

Can Agent OS run local AI models on dealership hardware?+

Yes. Agent OS supports tenant-configured local runtimes (such as Ollama or vLLM on private LAN hosts) alongside vetted cloud models.

Can HITL or approval gates be disabled in Agent OS?+

No. HITL is a hard invariant across all agent packs. Agents can only generate drafts and queue tasks; they cannot autonomously execute customer-facing actions.

Scoped discovery

Map the dealership AI control plane.

Tell us which models and tools you use today, where your API keys live, what you need to monitor, and which agents or local-model options you want to evaluate.

Automotive only — salespeople & dealerships. Unsubscribe anytime.