GOVERNED OPERATIONS AGENT-FIRST

Make office IT operable by agents.

Widerform is building one governed layer for endpoint support, network operations, and repeatable business workflows—so diagnosis, approval, execution, verification, and audit no longer live in separate tools and people's heads.

Currently a controlled lab program. Not a production RMM service.

01 / INTENTPeople + AgentsRequest · Diagnose · Plan
02 / CONTROLCloud Control PlanePolicy · Approval · Audit
03 / SITEEdge GatewayLocal queue · Evidence cache
WindowsNetworkWorkflow
Site autonomy preserved when the primary WAN is unavailable

One source of operational truth.

Every action attributable.

Every change reversible.

01 — OPERATING MODEL

From fragmented tools to one evidence chain.

01

Observe

Collect endpoint, network, and service evidence.

02

Reason

Turn signals into a bounded diagnostic plan.

03

Approve

Apply policy and explicit human authorization.

04

Execute

Use visible, removable agents and signed runbooks.

05

Verify

Compare before and after state.

06

Record

Preserve evidence, decisions, and outcomes.

02 — CAPABILITY MAP

Build the control path before expanding the promise.

We label what has been tested separately from what is being built. The public story follows the evidence—not the other way around.

LAB-VERIFIED

Endpoint execution foundation

  • Visible Windows service and explicit uninstall path
  • Structured diagnostic scripts and results
  • Task timeouts and bounded output
  • Local controller, CLI, and Codex tool surface
BUILDING NOW

Reliable operating loop

  • Leases, retries, durable result outbox
  • Organization, site, asset, and case model
  • Tiered approval and complete evidence chain
  • Read-only site and network diagnostics
PLANNED

Enterprise expansion

  • Out-of-band site recovery options
  • Controlled network configuration and rollback
  • Isolated workflow workers and secret references
  • Production identity, resilience, and compliance

03 — THE OFFLINE BOUNDARY

The cloud cannot repair a path it cannot reach.

A site Edge Gateway keeps a local view of topology, approved runbooks, pending work, and evidence. During a primary WAN outage it can continue bounded local diagnostics and report the full timeline after connectivity returns.

Real-time remote access during a WAN failure still requires an independent LTE, second-ISP, or other out-of-band channel. Total power and path loss remains a physical, not software, boundary.

CONDITIONLOCAL EDGEREMOTE
Cloud unavailableDiagnose + cacheWait
Primary WAN downDiagnose + act by policyOOB required
Site power lossUnavailableUPS / onsite

04 — TRUST MODEL

Authority belongs to policy, not the model.

R0

Observe automatically

Read-only collection runs within an approved site scope.

R1

Automate the reversible

Low-risk actions require an explicit, versioned policy.

R2

Approve consequential change

Core network, identity, and bulk operations require a person.

R3

Keep prohibitions hard

No stealth, credential theft, bypass, or unauthorized access.

VISIBLE AGENTSNO PLAINTEXT DEVICE CREDENTIALS IN MODEL CONTEXTSTRUCTURED RESULTSVERIFICATION BEFORE CLOSURE

05 — DELIVERY PATH

A narrow proof, then a real office.

Widerform is being developed in reviewable stages. Production access is a promotion decision backed by security and recovery evidence.

  1. NOW

    Controlled office lab

    Reliable Windows loop, test Portal, and read-only site Edge.

  2. NEXT

    Single-enterprise pilot

    One authorized site with measured support outcomes.

  3. LATER

    Network change + workflows

    Reversible configuration and isolated business automation.

中文摘要

让企业 IT 从分散的人工作业,变成可授权、可验证、可审计的统一运行系统。

Widerform 正在构建由云控制面、办公室边缘节点、终端与网络适配器组成的企业运维平台。当前处于受控实验阶段,不接受真实生产凭据,也不会把尚未验证的能力包装成已经上线。