Fail-closed credential broker
Stores credential key names only. The MIT Agent Vault is live on a private host when attested; CRM stays fail-closed until then.
ManifestoAuto Agent OS · rooftop HITL control room
Agent OS is the in-app control room on Sales OS: operator overview, dealership packs, a tenant model registry, monthly token caps, runtime policies, and a white-label overlay. Dealer-owned credentials go through a MIT Agent Vault that stays fail-closed until an operator attests smoke. Session tokens never return to the browser.
What the solution covers
Stores credential key names only. The MIT Agent Vault is live on a private host when attested; CRM stays fail-closed until then.
Operator monthly token cap. Held completions fall back to rules. Never auto-send when a budget is held.
Catalogued cloud hosts or private-IP local runtimes. SSRF-safe URLs. Credential key names only.
Private-IP model URLs when the rooftop owns the hardware. Public default route for workers stays blocked.
Floor, listing, intel, and ingest packs. Disable stops that pack’s cron. HITL, autoSend, and autoPublish cannot be switched off.
Vault readiness, models, usage, packs, brand, and policies on one page. No secrets. Floor queue stays on Monitor and Approvals.
How deployment works
We document the current workflow, decide what people and systems remain authoritative, then configure and verify the solution before expanding it.
Identify providers, accounts, models, costs, data exposure, users, workflows, and unmanaged tools.
Define approved models, secrets, roles, knowledge boundaries, budgets, tools, and human approval requirements.
Connect one valuable workflow to the minimum required systems, then test permissions, evidence, refusal, and audit.
Review usage, cost, quality, safety, and adoption before enabling additional agents or local models.
Designed outcomes
Good fit
Not the promise
Questions & operational facts
Verified operating constraints, human-in-the-loop policies, and technical boundaries.
Sales OS is the transactional system of record for leads, units, and approvals. Agent OS is the AI control plane that governs agent packs (floor, listing, intel, ingest), model routing, and token budgets on top of that same HITL queue.
API credentials are brokered through the MIT Agent Vault on private infrastructure. Credentials fail closed until attested, and raw keys or session tokens are never stored in the CRM or returned to client browsers.
Yes. Agent OS supports tenant-configured local runtimes (such as Ollama or vLLM on private LAN hosts) alongside vetted cloud models.
No. HITL is a hard invariant across all agent packs. Agents can only generate drafts and queue tasks; they cannot autonomously execute customer-facing actions.
Scoped discovery
Tell us which models and tools you use today, where your API keys live, what you need to monitor, and which agents or local-model options you want to evaluate.