Skip to content

How it is designed to work · Private pilot

A job. A work area. A badge. A limit.

This is how companies give people room to work without giving everyone the master key. Dutch Door is testing the same idea for AI agents.

The model can come from anywhere. Dutch Door is designed to sit between the action an agent chooses and the real system that carries it out.

Pilot architecture being tested

Any AI agent

Proposes an action

Dutch Door execution boundary

Allow · hold · block

Your real systems

Run once · leave a receipt · recover when possible

The agent may change. The workplace pattern stays.

The workplace map

The same controls, built for an agent.

A handbook matters. But companies also use roles, rooms, badges, budgets, managers, and records. The pilot brings that operating model to AI work.

Company control

Job

The question

What are you here to do?

Agent version

One task, a done point, and a stop point.

Technical layer

Task contract

Company control

Work area

The question

Where may you work?

Agent version

A bounded place for this run, away from live systems when possible.

Technical layer

Isolated workspace

Company control

Badge

The question

Which doors open?

Agent version

Short-lived access to named systems. No master key.

Technical layer

Scoped credentials

Company control

Tools and data

The question

What may you see or change?

Agent version

Only what the job needs. Read-only when writing is not needed.

Technical layer

Tool and data scopes

Company control

Authority limit

The question

What may you do alone?

Agent version

Caps on money, volume, people, and live changes.

Technical layer

Action policy

Company control

Manager

The question

When must you ask?

Agent version

Pause when the job, stakes, or risk changes.

Technical layer

Approval and stop point

Company control

Receipt and way back

The question

What happened? Can it be fixed?

Agent version

A clear action record, one-time effects, and recovery where possible.

Technical layer

Audit, idempotency, recovery

Instructions teach the job.

The workplace holds the limits.

The action path

What happens when an agent tries to act.

The agent still does the useful thinking. The execution layer narrows what the action can reach before it touches the outside world.

  1. 1

    Set the job, the finish line, and the stop point.

  2. 2

    Open a small work area and a small key.

  3. 3

    Let the agent propose an action.

  4. 4

    Check the job, access, and risk.

  5. 5

    Let safe work move. Hold or block the rest.

  6. 6

    Run an approved action once—not again on a retry.

  7. 7

    Save a receipt and a way back when one exists.

The execution layer

The model is the brain. Dutch Door guards the action path.

Dutch Door is not another AI model. It is being designed as the place where an action can be made smaller, allowed, held for a person, or blocked before it reaches a real system.

Small keys

Give short-lived access to named tools and data. Keep broad account keys out of the job.

Exact checks

Show the real amount, people, records, and change before a high-risk action runs.

One yes, one action

A one-use approval and stable request ID keep a retry from doing the same thing twice.

Hard stop points

Rate, cost, and retry limits stop one mistake from turning into a chain of mistakes.

A way back

Use drafts, staged changes, checkpoints, and recovery for work that can hurt.

Mistake-proof architecture

Change the shape of the workplace.

A workshop Dutch door lets valuable work pass through the open half while the closed half holds the work boundary. AI systems need the same shape: routine work moves; risky actions pause at the threshold.

A woman passes a valuable box to a blacksmith through the open top of a Dutch door while its closed lower half keeps a child, chicken, and goat outside.

Words for the agent

“Never touch production.”

A boundary in its workplace

Production keys stay out of test work.

Words for the agent

“Ask before sending.”

A boundary in its workplace

One approval opens one named send, once.

Words for the agent

“Do not delete everything.”

A boundary in its workplace

Bulk delete is blocked, delayed, or reversible.

Words for the agent

“Stop if it keeps failing.”

A boundary in its workplace

A retry limit stops the run.

Make the safe path easy. Add friction only where the stakes rise.

Across real work

The agent may change. The workplace pattern stays.

Email

Reading and drafting can move. A new list or a large delete can wait.

Money

Prepare the payment. Hold the transfer until the amount and payee are clear.

Customer data

Read the records the job needs. Hold bulk changes and deletion.

Code and cloud

Build and test in a safe place. Hold the live deploy or secret change.

Files and browsers

Edit a draft. Hold publishing, sharing, or an outside account change.

From debt to equity

Make every fix useful next time.

Another warning helps one run. A test, smaller key, hard limit, stop point, or recovery path helps every run after it.

Read why Dutch Door began

Why the boundary matters

Rules help. They do not lock the door.

Studies and real cases show policy drift, changing reruns, approval fatigue, and broad keys reaching live systems.

See the evidence

Start small

Start with one job, not the whole company.

Dutch Door is in private pilot. This page describes the model-independent architecture being tested. It does not mean every named agent platform is integrated today.

Bring a workflow to the pilot