The Catch Mechanism Live · Roadmap Pilots Executive Pilot → Sovereignty & IT Governance Compare SMB → Evaluator Q&A → IT Runbook → ← Back to AEGIS OS
Book a demo
Enterprise · The Vigilance Layer

Every operating business loses a few percent at every seam.

Some follow-ups never sent. Some contract sections signed without anyone noticing. Some obligations aging out without a clear owner. Some commitments drifting away from stated strategy. Each miss looks small. Compounded across a year, it translates to lost revenue, missed renewals, partner-relationship damage, or compliance exposure.

AEGIS is the vigilance layer that catches it — across CRM, mail, documents and calendar — and proves each catch with evidence before it costs you. A builder can't grade its own work, which is why AEGIS watches beside the systems you already run, not inside them.

The record you hold is the Catch Ledger: what we caught, with evidence, before it bled out.

Watches seams Catches misses Asks before acting Remembers approved decisions Live on production tenants

What a vigilance run actually looks like.

AEGIS runs continuously on its own operating tenant — what you see below is the loop catching real follow-ups, partner openings, and strategic postures that would otherwise have aged out silently. Strategic Memoria nodes accepted on the support tenant stand as live evidence today.

01

Multi-signal catch from operating context

"Follow up with an enterprise prospect regarding an AI solution discussion routed through a senior executive in the same group." Surfaced from call notes, accepted Memoria strategy, and dormant correspondence. Signals across multiple systems point to one un-owned follow-up.

02

Time-sensitive opening before it closes

"A partner candidate indicated sponsorship interest — schedule outreach before the window closes." Caught from cross-system signals: partner correspondence, calendar gaps, and accepted strategy about partner posture. The window would have closed silently.

03

Durable strategic posture, reusable as context

"Strategic posture: engage personal and family network for organizational access into target accounts." A partner_strategy node — a durable operating posture extracted as memory, reusable as context for the next conversation. Without this layer, that posture lived only in someone's head.

None of these needed AI to invent them. They needed a vigilance layer to notice them. The catch was the product. Every accepted catch is now durable organizational memory — provenanced, auditable, reusable. The running record you hold is the Catch Ledger: what we caught, with evidence, before it bled out.

What AEGIS watches, what it refuses to do.

The vigilance loop runs continuously across the seams modern enterprise tools don't watch. It distinguishes evidence from accepted memory, asks for human approval on consequential writes, and never autonomously executes.

WATCHES

The seams between your systems

Across CRM, email, documents, calendar, tasks, notes. Notices when commitments go unclosed, when handoffs drop, when behavior drifts from stated strategy, when silent damage accumulates against a healthy baseline.

DISTINGUISHES

Evidence from accepted memory

Anything retrievable in your knowledge base, vault, or drive is evidence. What your company has approved as true — with provenance, confidence, and supersession trail — is accepted memory. The two are never confused.

PROPOSES

Surfaces misses as proposed actions

AEGIS detects, analyzes, drafts, and proposes. It never autonomously sends an email, updates a CRM stage, amends a contract, or books a calendar slot. The accept gate is the trust boundary.

REMEMBERS

Turns approval into durable memory

Each accepted catch becomes a Memoria node — tenant-scoped application data with provenance, trust labels, and source references. Not model memory. Not fine-tuning. Reusable as context for the next workflow.

Permanent refusal: AEGIS never autonomously executes a consequential write — no email, no CRM update, no contract amendment, no calendar booking — without explicit human approval. This is a Founding Contract clause, not a roadmap item.

A builder cannot grade its own work. The platform selling an agent — and the vendor deploying it — are structurally disqualified from being the independent check. AEGIS is a fabric of governed agents built to be that check: each does scoped work under a contract, sees only what it needs, cannot quietly overspend, never writes memory alone, and leaves a trace for everything. That is precisely what lets AEGIS stand beside the systems you already run, not inside them.

CONTRACT

Scoped by an explicit standard

Each agent runs under a contract with least-privilege over the layers and sources it may touch — never broader than its job.

SPEND · LIVE

Cannot quietly overspend

A per-agent monthly budget hard-gates that agent's tasks once reached; per-tenant spend is metered, attributed, and alerted.

HUMAN GATE · AUDIT

Nothing durable without approval

No conclusion becomes action or memory until a human approves it, and every action is logged for the record.

SKILL-HARDENING

Cheaper and more reliable over time

Recurring work becomes a reusable skill, so agents call the model less as they mature — lower cost, higher reliability.

How a catch moves through AEGIS.

A public schematic for IT review: inputs stay tenant-scoped, agents operate under policy, and only approved catches become durable memory.

01 · Sources

Business systems

CRM, mailbox, documents, calendar, tasks, Teams and M365 history enter as evidence.

02 · Isolation

Tenant boundary

Schema-per-tenant PostgreSQL, RBAC, audit logs and per-source permissions hold the data line.

03 · Channel ledger

Reliable intake

Channel events are recorded with source identifiers before work begins, so retries do not become duplicate actions or silent loss.

04 · Router

Governed agents

Omni routes work to the specialist roster under tier-aware model policy and least privilege.

05 · Vigilance

Radar + evidence

AEGIS surfaces the missed follow-up, clause risk or stalled commitment with source evidence.

06 · Gate

Human approval

Consequential writes and durable memory wait for a person. No silent autonomous execution.

07 · Reuse

Memoria + skills

Accepted catches become trusted context; recurring patterns harden into reusable skills.

For deeper IT diligence, use the Evaluator Q&A, Enterprise IT runbook and Tech Stack. The private schematic can be reviewed under NDA.

Built, not a slide.

AEGIS is live in production today. Each item is tagged so diligence can separate shipped product, configured/pilot-gated capability, and the next build priorities.

LIVE

What you can see today

/os workspace, Omni command surface, governed agent roles, Skills Engine and approval-gated execution.
Opportunity Radar → Catch → source evidence → approve/reject → Memoria, with Catch Ledger on desktop and mobile.
Operate AEGIS from Telegram: deterministic pipeline / tasks / schedules / calendar / contacts reads, lead capture, vigilance approvals — no web UI required.
3i-audited stale-outbound mailbox catch path: M365 read-only pilot ingestion, thread-aware selection, one catch per thread, and inline evidence drawer.
Knowledge Base ingestion, Memoria graph, native CRM, Document Intelligence, Strategic Memory Extractor, and CRM source-settings polish.
Tier-aware model resolver, premium quota controls, OpenRouter provider budgets, per-agent direct-task budget gate, and per-tenant spend soft-stop alerts.
GDPR account + tenant active-data erasure, audit trail, RBAC, and schema-per-tenant PostgreSQL isolation.
HARDENING

Built, needs configuration or polish

!M365 is secure for the controlled 3i pilot, but customer/admin self-service is still being productized.
!External CRM source surface: native CRM is live; HubSpot lookup/write-back is live; full HubSpot/Salesforce/Dynamics workspace sync is roadmap.
!Subject-level erasure inside a live tenant is built and reviewed; live dry-run and scoped erase verification remain before stronger DSR claims.
!Private/sovereign deployment has Docker and licensing foundations, but still needs claim-grade lab verification.
!Post-call spend attribution, resolver-failure UI, and remaining legacy model call-site migration are still hardening work.
!Microsoft Teams and SAML are implemented paths that still require per-customer Azure/IdP configuration.
NEXT

Roadmap priorities

First real Catch Ledger readout from the 3i M365 pilot, with bounded scope widening only after review.
M365 connector admin surface: Entra credential verification, Graph permission display, mailbox scope, health, backfill, revoke and audit.
Source-aware pipeline across connected CRMs (HubSpot).
External CRM source model: provider records, sync health, read/write policy, and Catch Ledger evidence links back to systems of record.
Omni as an installable control plane (desktop / browser extension) with rich rendering.
Claim-grade sovereign verification: deployment env, migrations, backup/restore, BYO keys, LiteLLM routes and optional local model path.
Catch Ledger export and operator-readable proof pack: what was caught, source evidence, decision, owner and memory impact.
Shadow Replay after real catches: compare against an honestly labelled flat-context baseline, not competitor-specific claims.

What AEGIS will not become: a universal enterprise agent mesh, autonomous executor, or system that fine-tunes on tenant data. These refusals are permanent.

Three pilots. Each sized for evidence.

A pilot is narrow, measurable, and governed. No step obligates the next. Commitment grows only as evidence accumulates.

Opportunity Radar Accelerator LOWEST DATA RISK

Load public themes and product context. Run Opportunity Radar against CRM, email, Memoria, tasks, calendar. Save useful catches to Memoria. Re-run context-aware output. Evaluate quality through dogfood scoring. Turn the pattern into a repeatable Skill. Directly demonstrates the Intelligence Loop on a workflow the buying team already runs.

Governed Document Intelligence MATURE WORKFLOW

Controlled layer for contract, policy, or transformation document review. Select source. Choose or skip policy comparison. Run analysis. Draft corrections. Approve selected outputs. Save to Memoria. Export approved artifact. Run prior-review or delta path on a later version. Simple to understand for legal, compliance, IT, and business audiences.

Transformation Memory Cockpit CONSULTING-GRADE

Use AEGIS around a transformation program where decisions, risks, and stakeholder communication must persist. Upload artifacts. Ask for current state and unresolved risks. Run executive weekly briefing Skill. Capture approved decisions into Memoria. Generate stakeholder-specific brief. Inspect provenance and prior decisions.

Typical pilot shape: 60 days, one domain, controlled data scope, 10–25 users, no autonomous external writes in v1, explicit approval gates, pre/post scoring against baseline, final report on value, governance, reuse, and roadmap.

View the executive vigilance pilot →

Deployable where your data already lives.

Vigilance is the product. Sovereignty is how it ships safely. The IT-side guarantees that make pilots viable in regulated, sovereign, or on-premise environments.

01

Data sovereignty by default

Your PostgreSQL. Your object store. Your audit log. AEGIS never writes to a shared cloud database. Every tenant runs in an isolated schema — and in Enterprise deployments, that schema lives on your own servers.

02

Identity that already exists

SAML 2.0 with Azure AD / Entra ID means employees can log in with credentials your IT team already manages. No new password universe. Provisioning and deprovisioning remain anchored in your IdP.

03

Where your people already work

Microsoft Teams connector path with Azure Bot setup. Employees can reach AEGIS agents from Teams while the portal remains the control plane for approvals, evidence, memory, and audit.

The enterprise primitives IT expects.

Identity, channel, access, audit, and hosting controls are implemented or configuration-ready. Each deployment walks through the exact customer environment, provider policy, and data boundary before go-live.

CHANNEL

Microsoft Teams Connector

Agents can appear as a bot inside Teams after Azure Bot setup. Employees message AEGIS from a channel or DM while agent intelligence, KB context, CRM data, and Memoria remain governed by the tenant's AEGIS backend.

Setup guide →
IDENTITY

SAML 2.0 SSO — Any major IdP

Configuration path for Azure AD / Entra ID, Okta, Google Workspace / Cloud Identity, OneLogin, Ping Identity, JumpCloud, Keycloak, and ADFS — any SAML 2.0-compliant provider. IT connects Federation Metadata XML and AEGIS joins the customer identity layer. Native OAuth/OIDC tiles for Okta and Google coming soon.

Setup guide →
ACCESS

RBAC — Role-Based Access Control

Assign Admin, Manager, or Member roles per user. Managers cannot touch billing or agent configuration. Members cannot see other teams' data. Roles enforced at the API layer — not just the UI.

Roles reference →
COMPLIANCE

Audit Log Export (CSV)

Agent actions, login events, config changes, and API calls are logged with timestamp, user, outcome, and token cost where available. Export to CSV from Settings → Security for GDPR, ISO 27001, and internal audit workflows.

Audit reference →
DEPLOYMENT

On-premise Docker

The AEGIS stack — PostgreSQL, LiteLLM, the web app, nginx — ships as a Docker Compose path for Linux hosts in a datacenter or private cloud. Customer-specific networking, identity, model routing, and backup policies are configured during deployment.

Deployment runbook →
AI INFRA

Local LLM via Ollama (air-gap)

For restricted or air-gapped environments, AEGIS can route inference through a local Ollama instance. Supported model families include Llama, Qwen, Mistral, and GGUF-compatible models the customer already operates.

LLM routing docs →

Your pipeline. Your agents. One loop.

AEGIS complements the CRM instead of replacing it: native AEGIS CRM is live, HubSpot is connected for OAuth-backed contact lookup and write-back, and full external CRM workspace sync is a roadmap item. Salesforce, Dynamics 365, Zoho, and Pipedrive are prioritised by pilot demand.

HubSpot CRM

OAuth connection for contact lookup and AEGIS lead write-back. Full CRM workspace sync is on the roadmap.

✓ Contact path live · Workspace sync roadmap
Coming Soon

Salesforce

Planned Sales Cloud adapter for leads, opportunities, accounts, and pilot-scoped custom objects.

Notify me when live →
Coming Soon

Microsoft Dynamics 365

Planned Dynamics adapter paired with Teams, with write actions gated by customer policy.

Notify me when live →
Coming Soon

Zoho CRM

Planned adapter for pipeline, contacts, and deals, sequenced by customer demand.

Notify me when live →
Coming Soon

Pipedrive

Planned adapter for deals, contacts, and activity logging with human-approved write-back.

Notify me when live →

Missing your CRM? Tell us — integrations are prioritised by demand.

Where AEGIS fits beside copilots.

Copilots are useful inside their suites. AEGIS is designed for the seams between systems: the missed follow-up, stale commitment, unowned obligation, approval trail, and accepted memory.

Capability AEGIS Enterprise Microsoft Copilot / Suite Agents Generic AI Tools
Primary job Independent vigilance layer across operating seams Productivity and task assistance inside Microsoft ecosystem Prompted generation, search, summarisation
Cross-system seam watching CRM + mailbox + documents + calendar + tasks + memory Strongest inside M365/D365 and connected Microsoft Graph sources Manual context assembly
Catch ledger Proposed catch → evidence → approve/reject → accepted memory Activity and audit surfaces inside suite workflows Usually none
Human approval before durable memory Explicit gate for consequential writes and Memoria promotion Depends on app, workflow, and tenant configuration Prompt-level only
Data residency Managed EU / BYOC / customer DB path Microsoft tenant and regional controls Vendor cloud
Private or self-hosted deployment Private deployment path; self-hosted annual license for customer-funded inference Cloud service inside Microsoft estate Rare
SAML / Entra / Teams SAML path + Teams connector via Azure Bot setup Native first-party strength Often capped
Cost model Plan + soft task notifications + premium-AI caps; self-hosted annual SKU Seat/licence plus credits or suite consumption Token/message based, often variable
Audit export Audit trail + CSV export path; model-policy records live Purview and Microsoft admin/audit surfaces Varies
CRM integration Native CRM live · HubSpot contact path live · broader CRM sync roadmap Dynamics 365 native Varies
Architecture transparency Public tech stack + IT runbook + evaluator Q&A + NDA schematic Vendor documentation and tenant admin center Usually limited

Three modes. Same product.

Pick the model that matches your security posture. You can migrate between modes without data loss.

Managed Cloud FASTEST

We host on EU-based infrastructure. Your data is isolated in a dedicated PostgreSQL schema — never shared, never used for training. Up in 24 hours.

Your Cloud — BYOC POPULAR

We ship the Docker Compose stack. Your team runs it on AWS, Azure, GCP, or Hetzner. We handle updates; you control the perimeter and the data.

Air-gapped On-prem MAX CONTROL

Full local stack with local model routing. Designed for restricted outbound environments in regulated industries: banking, defence, healthcare, government.

All three modes use the same 8 agents, the same UI, the same APIs, and the same audit trail. You're not choosing a different product — you're choosing where it runs.

Bound to every tenant, every plan.

Beyond the refusals AEGIS has made permanent (no autonomous consequential writes, no fine-tuning on tenant data, no universal-mesh pretensions), these commitments hold for partner-mediated and regulated-customer deployments.

RESIDENCY

Data residency declared at deployment

Tenants declare region. Cross-region processing requires explicit per-occurrence approval and is logged. Regulated plans receive a per-region deployment guarantee.

PROVIDERS

Sub-processor + model provider veto

Publicly listed registry of every sub-processor and model provider. Tenants notified before changes. Regulated plans may veto specific providers; the model gateway routes around them without service interruption.

EXIT

Data export as a first-class capability

Evidence, Memoria graph with edges and provenance, entity graph, audit log, tenant configuration — extractable in standard formats at any time. No lock-in by design.

LEGAL HOLD

Configurable retention, scoped legal hold

Per-tenant retention windows. Legal hold suspends all deletion paths — including Guardian retention sweeps — until released. Scope by entity, time window, or memory branch.

MODELS

No silent model deprecation

When an upstream provider deprecates a model AEGIS depends on, tenants are notified at least 30 days before AEGIS-side end-of-life with a documented migration path. Tenants may pin specific model versions for compliance-sensitive Skills.

PARTNER ACCESS

Delegated partner access, revocable

When a tenant grants delegated access to a partner during a transformation engagement, the scope of partner authority, the audit trail of partner actions, and the provenance of partner-introduced memory are all explicit, exportable, and revocable.

These commitments are part of the AEGIS Founding Contract §IVA and bind every deployment, demo, and pilot.

GDPR-aligned controls Multi-tenant schema isolation TLS in transit Encryption at rest supported Append-only audit trail No model training on your data Security overview →

Bring the vigilance layer to your organisation.

A 30-minute call is enough to walk one live catch on AEGIS's own operating tenant and scope a controlled pilot for yours.

Or email directly: [email protected]

AEGIS
AEGIS Enterprise AI
● Live · Ask anything
Hi — I'm the AEGIS enterprise assistant. Ask me how the vigilance layer works, what a catch looks like, how pilots are scoped, or any IT question your team has. 👋
What does AEGIS catch? How does Memoria work? What's the pilot shape? Can it run on-premise?
Powered by AEGIS AI · 10 questions/day