Secure automation

A secure place for automations to run, and a consultant who never holds your keys

The real risk in outside help is not the model. It is a laptop somewhere with broad credentials to the back of your business. I am provisioned like a member of your team, keys live in accounts you control, every run is logged, and your admin can revoke me in a minute.

What the environment looks like

Provisioned like staff

An ordinary user in your tenant, created by your admin, no more rights than a new starter. My machines never hold a system credential.

Keys never leave your accounts

Created in your cloud project and GitHub organisation, stored in their secret stores, readable by nothing but the job.

A desk in your repo

Development happens in a remote environment attached to your repository. My laptop is a window onto it.

Every run logged

One database you own: each run, each step, what it read and wrote, and the exact version of the code. One page to watch it.

Draft by default

Anything aimed at the outside world waits for a named person’s yes. Nothing is retried automatically.

Two switches, both yours

Remove me from GitHub and the desk, runner and repo are gone. Deactivate the user and mail, Drive and the AI seat are gone. A minute each.

Tell me what you're dealing with

Three lines is plenty. I reply personally, usually within a day, and the first call is free.

Frequently asked questions

Why does this matter for a business our size?

Because the usual alternative is a consultant with a spreadsheet of your API keys on a laptop, or an agency login that outlives the engagement. This design costs nothing extra and makes “what if their machine is stolen” a boring question.

What do you actually need?

A staff login, a seat on your AI plan, membership of a GitHub organisation you own, a role in a cloud project you own, and read-only views of the systems in scope. Nothing with “admin” in it.

We don’t have a GitHub organisation or a cloud project.

Creating them, in your name with your billing, is the first hour of the first project. Handover done at the start.

Who can see what the automations did?

You, on one page, by role. If you want, the same page shows what Claude has been doing across company mail and Drive, from your Workspace audit logs.

What happens when the engagement ends?

Your admin flips the two switches. Everything keeps running, because none of it depended on my accounts.

Worried about what an outside consultant could reach?

Good. Send me your current setup, even if it is “the agency has a login and we don’t know what it does”. I will tell you what to change first.

Back to the form