Start an evaluation
Genie
An AI that runs your operations as a colleague — with tools, boundaries and an evidence standard. Not a chat box over a knowledge base.
How an answer is assembled
The tools he chose, and the ones he did not. The rows each one returned, and every figure in the answer joined to the evidence it came from. Two sequences end in something he could not determine, and one ends in a refusal. Those are the ones worth watching.
Every other vendor bolted a chat box onto a knowledge base
You type a question, it finds a document, it summarises the document. It cannot see your estate, cannot act on it, and cannot tell you whether the thing it just described is actually true of your network.
Genie has tools. He reads your monitoring, your tickets, your patch state, your backups, your Microsoft tenants and your packet captures — and he can act on them, within limits you set and can see.
“This policy claims MFA is enforced, I verified it 40 minutes ago, and Entra was unreachable for eleven minutes at 09:20 so I am not reporting that window as compliant.”
No knowledge base produces that sentence. It requires having checked, knowing when, and being willing to say what you could not see.
He diagnoses. He does not answer.
An answer that cites a source is defensible whatever happens next. A diagnosis that names the wrong layer sends somebody to spend an afternoon on the wrong thing — and they will not ask twice.
“Your collector reaches 10.4.2.11 at the IP layer — ICMP replies at 1ms. UDP/161 gets nothing back, and the same collector polls four other devices on that subnet successfully. That is an ACL or an SNMP view on the device, not the network and not the collector. Here is the one command that distinguishes them.”
And where two causes remain, he names both and gives the check that separates them — rather than picking the likelier one and being wrong half the time.
He cannot state a number he did not compute
Not should not. Cannot. Every figure in anything he writes must appear character-for-character in a number the deterministic layer produced, or the output is refused before you see it.
That is enforced in code, not in a prompt. A language model is very good at producing a plausible figure, and a plausible figure in a report to a client is the most expensive thing this product could do.
So he narrates. He never calculates. The sentences are his; every number in them came from somewhere you can click.
A refusal is a feature, and you can read it
Genie sits on an autonomy ladder you set. Some things he does alone. Some he proposes and you approve. Some he will never do at any setting, and no configuration exists that changes it.
| He does alone | He proposes | He never does |
|---|---|---|
| Investigate, correlate, verify | Anything that changes a client system | Approve billable time |
| Draft a reply, a note, a report | Anything with a blast radius | Commit to a client |
| Raise a finding with its evidence | Anything irreversible | Attest compliance |
And when he refuses, he says which rule refused and why. Not “I can't help with that” — the named boundary, so you know whether to change a setting or whether you have found the edge of what he is allowed to be.
A refusal is never recorded as a failure. It is the product working, and confusing the two is how a platform teaches its operators to route around its own controls.
He says what he could not see
This is the sentence that separates him from every dashboard you have ever been shown.
- A device that did not answer is unreachable, never “compliant”
- A backup nobody restore-tested is reported, never verified
- A vendor API that timed out is silent, and silence is not success
- A capture that missed half the conversation gets no verdict, with the reason stated
- And a question he cannot ground in something he read is escalated, not guessed at
Absence is never rendered as confirmation. Every green tick in this industry that turned out to be a fiction was a system reporting “nothing found” when it meant “nothing looked”.
Where he actually earns his keep
He notices before anybody calls. There is an analyst resident on every workstation, judging each machine against its own history — and a ticket arrives with the diagnosis attached rather than a threshold alert. “This disk will be full in nine days, and here is what is filling it.”
Triage before the ticket exists. Autoreplies, newsletters, delivery receipts and the eleven bounces from one bad send never become work — and nothing is silently discarded.
Client onboarding, autonomously. Discover the estate, build the asset model, propose the monitoring, and tell you what it could not reach.
Documentation that maintains itself from what is actually there rather than from what somebody wrote down eighteen months ago.
Reconciliation, continuously. What you bill against what you manage, what a policy claims against what a system reports, what a backup job said against what a restore proved.
And the packet capture question — is it the network or the server — answered from the trace in seconds rather than argued about for a week.
On your hardware, answering to nobody
The model runs on your own machine. Your clients' data never crosses the internet to be reasoned about, there is no per-seat AI charge, and no rate limit somebody else sets.
There is no path from us into your estate and no code that could create one. Your deployment asks for updates when it chooses; nothing is ever pushed.
What we receive is ten fields and a signature. No client names, no hostnames, no ticket content — and a payload carrying anything else is rejected in full rather than stripped.
Nobody else can afford to let their AI think this hard
Every other AI in this market runs on a hosted model billed by the word. Their vendor pays for every sentence it produces — which is why those assistants summarise a ticket and stop. Anything speculative is a bill somebody has to justify at the end of the month.
What he does with the rest of the day — going back over old findings, retiring false positives, and reviewing his own wrong answers.
So their AI is rationed, and yours is not. Not because they built it badly — because the arithmetic forbids it. Doing this properly across every customer would cost them more than the subscription.
Genie runs on a card in your rack. The marginal cost of him thinking is electricity, so there is nothing to ration and no reason to stop him going over the same ground again when there is something new to compare it against.
And that shows up where you would notice it. A finding he raised three months ago has been looked at again since, against everything learned in between. A false positive gets retired rather than tuned around. The noise falls month over month instead of staying flat.
And he will tell you what he could not determine — a sentence that costs a metered assistant real money and produces no billable resolution. It is the cheapest thing in the world to say on hardware you already own, and the most expensive thing to say on somebody else’s.
What he will never be
- A replacement for your judgement. AI does the work; a person makes every commitment
- A reason to trust something unverified. He is the thing that checks, not another thing claiming it worked
- Silent about his limits. Where he is uncertain he says so, and where he is refusing he says which rule
- A person. Asked directly, in any phrasing, he says what he is
The endpoint agent carries forty-two declared verbs, remote control included, and a privacy boundary enforced in the database rather than promised in a policy. What it can and cannot do.
Try it on your own estate
Thirty days, read-only, on your own hardware. No card, no call, and nothing to uninstall if you walk away.