the part they skip
The problem nobody wants to own
Frameworks help you build an agent. What they don't help with is the part that matters the moment it touches the real world: running it for other people, spending their money, touching their data, taking consequential actions, without leaking data between customers or doing something wrong that can't be undone.
the four fronts
Tenancy
One customer's agent can't reach another's data, even through a shared tool.
Autonomy
Letting an agent act, not just chat, including one that acts on its own initiative, with a way to stop it doing something catastrophic.
Governance
Every consequential action passes an authorisation gate. Money and bookings always wait for a person; everything else runs only if the assistant's fixed policy allows it, and otherwise waits.
Economics
Each tenant's spend is capped, and value can move between tenants atomically: the meter is a throttle and a settlement layer, not just a bill.
one through six
The hard problems it solves
01 Isolation that survives composition
A tool owned by tenant A, called by tenant B, runs under B's scope, never A's. Proven: A can't read B, even through a tool A doesn't own.
02 Consequential action, safely
Capability envelopes, an approval queue (authorize-then-act), a kill switch, a soft-launch that graduates to autonomy only once trusted, and a crisis protocol, wired at every entry point.
03 Composition without mixing trust levels
Internal = in-process registry (fast, tenant-scoped). External = MCP, both directions, over an SSRF-guarded transport. MCP is never the internal bus.
04 Output that provably works
A quality gate: generate → verify → repair → ship. The model proposes; the backend enforces the schema.
05 Platform, not product
A new vertical means composing what's already there, not rebuilding it. Unrelated residents ride one spine, and the purity lint proves it on every commit.
06 Economics as a safety primitive
Credits decremented atomically; a turn deflected to crisis resources is refunded. you don't bill someone in distress. The same primitive moves value between tenants: a priced cross-tenant call charges the caller and pays the provider in one atomic, overdraft-proof step.
What happens when you send a message.
Each answer in the notebook on the home page prints the checks it passed. Each one is a guarantee, and each fails safe.
SET LOCAL app.current_tenant binds RLS for the turnno tenant context ⇒ zero rowsSafety properties you can read, not policies you have to trust, UPDATE … SET credits = credits - :n WHERE credits >= :n, an advisory-locked book_if_free. Watch two of them hold, live →
let's talk
Nobody wants to own this problem. I did.
If tenancy, governance and metering are what stand between your agents and production, that part is already built. Let's talk.
Ask what goes wrong when an AI can act, and what PANTHEON does about it.
- What goes wrong when an AI can act?
- What stops it leaking data?
- What still needs a person?