Skip to content

The design-partner pilot

One workflow, in production, with proof.

A fixed-fee pilot run self-hosted in your own environment on synthetic or minimized data. An agent does the routine work, your named person signs the actions that carry real consequence, and you walk away with a signed audit an outside inspector can recompute offline, with no access to your systems. Forward this page to your team; the sample evidence file below is real.

The offer, plainly.

  • A multi-week engagement, self-hosted in your environment, on synthetic or minimized data. Nothing leaves your infrastructure.
  • A fixed fee, US$25,000. Scope is set on a single scoping call: which agent, which irreversible action, and whether we run one gate or two. We quote the number up front. No per-seat licensing and no usage metering during the pilot.
  • The agent runs deny-by-default. It performs only the skills you grant, inside fail-closed limits. Your named person signs every action that carries real consequence, and the software refuses the agent as its own approver, a hard HTTP 403.
  • You keep a signed, offline-verifiable audit. Every action, agent and human, commits to an Ed25519-signed, SHA-256 hash-chained record your own auditor recomputes offline, with no access to your systems.

What you get, stage by stage

Phase one

Running in your environment

Deployed self-hosted on your infrastructure. Your decision logic encoded as the agent policy, skill grants and fail-closed limits configured and signed off by your workflow owner. First cases flowing through, your designated reviewer signing at the gate, and the first signed audit checked offline by your own team.

Phase two

The workflow at volume

Your full pilot case set processed on synthetic or minimized data you select. A side-by-side of the agent against your team's historical decisions, including every disagreement and how the gate caught it. Segregation-of-duties and limit-breach scenarios tested on purpose and shown failing closed.

Phase three

The evidence pack and the decision

A signed, offline-verifiable audit covering the whole pilot, plus a one-page summary you can put in front of your own reviewers or an outside inspector: what the agent was allowed to do, what it was denied, who signed each consequential action, and how to verify all of it. A production-readiness assessment and a joint go or no-go.

What we need from you

A workflow owner
One person with authority over the decision logic, available for a standing weekly check-in.
Work samples
Synthetic cases, or a minimized historical sample with identifiers stripped. No production records need to leave your environment.
Named approvers
One to three people authorized to approve the actions in scope. Depending on the domain that could be a finance approver, a clinical reviewer, or a safety officer.
An environment
A VM or container host inside your network. Your security team keeps the keys. Nothing leaves your infrastructure.

What it is not

Not a data-sharing deal
Self-hosted, in your environment, synthetic or minimized data. We never hold your records.
Not a system-of-record replacement
Your existing systems stay yours. We govern the agent and produce the evidence.
Not autonomous sign-off
The agent drafts and proposes. Your named person approves the actions that carry consequence. That is the design, not a setting.
Not a multi-year services deal
Fixed fee, fixed window, a defined exit. You keep the evidence either way.

Take these to your team

A real signed audit, to download and check yourself.

This is a real MakerChecker audit bundle from a governed run: an agent was blocked from approving its own work and a named human signed instead. Download it, then drop it into the verifier and watch it re-check itself. Change one row and it breaks. This is the kind of file your pilot produces.

Want the two-page pilot brief for your risk and security team, or the commercial terms? Email hello@makerchecker.ai. See also how we clear a security and procurement review.

See it for yourself

Pick one workflow. We will get it into production.

One command starts the demo: an agent stopped from signing off its own work, and the signed evidence file an inspector can check for themselves.

Designed against the rules your auditors already enforce.