The AI Cowboys

Rung one of three · No enforcement · No data egress

Run the passive dry-run scan

See where consequential actions are firing in your environment with no verified human behind them. Nothing is blocked. Nothing leaves your perimeter. Nothing changes in your IAM.

Most security teams cannot answer a simple question: of the consequential actions executed in our environment last week, how many can we prove a human was actually present for? The dry-run scan answers it. It observes, it scores, and it reports. It does not enforce, and it cannot lock anyone out, because in this mode it has no authority to.

What the scan does

  • Deploys inside your perimeter and observes behavioral signal on the services you nominate
  • Produces a continuous human confidence score across each session
  • Maps every consequential action against the score that was live when it executed
  • Returns a written report on where verified human presence is absent, weak, or assumed

What the scan does not do

  • It does not block, challenge, or interrupt anything. Enforcement is rung three.
  • It does not store biometric data. Signals are processed ephemerally into scores. There is no BIPA, GDPR or CCPA surface to inherit.
  • It does not send data outside your network perimeter. No egress.
  • It does not require changes to your existing IAM, SSO or compliance tooling.
  • It does not require anything in your operators' hands. No second device, no enrollment ceremony.

The three rungs

  1. Passive dry-run scanYou are here

    Observe and report.

  2. Shadow mode

    Decisions are generated and logged, but not enforced. You compare them against what your team would have done.

  3. Per-service enforcement

    You turn it on, one service at a time, on your schedule.

Why teams run this now

An agent can operate any interface a person can. A credential checked at the login screen proves nothing about who is acting ten minutes later. The scan tells you how large that gap already is in your own environment, before anyone asks you to buy anything.

What you get back

A written report within ten business days: the consequential action inventory, the confidence distribution across sessions, the specific gaps ranked by exposure, and a recommended shadow mode scope. Yours to keep whether or not you continue.

Request the dry-run scan

We agree the observation window with you before anything is deployed. Nothing is enforced at this rung.

Before you scope one

How long does the scan run?

Long enough to capture a representative window of normal operation. Two to four weeks is typical. We agree the window with you before anything is deployed.

Where does it run?

Inside your network perimeter. The runtime deploys on your infrastructure and the scoring happens locally.

What data leaves our environment?

None. The report is generated from what you hold.

Will our users notice?

No. In dry-run mode there is no challenge and no interruption. Nothing is added to the interface.

What is a consequential action?

Any action your organization would not want executed without a verified human behind it. Fund transfers, privilege changes, data exports, production deploys, configuration changes. You define the list and we help you scope it.

Do we have to continue after the scan?

No. The report is yours either way.