Guarded Automation: Agents That Run Operations
MU-AI-011 - Meridian's proposed crew-dispatch agent - left AI Assurance with an addendum and NEEDS-OWNER in every cell. This training fills the rows the addendum left blank: an assigned owner, an envelope enforced where the agent cannot reach, approvals that expire and bind to one action, a kill switch outside the agent's own reach, and a receipt for every attempt it makes. The thesis stays exact throughout: the envelope can stand, but the authorization cannot - every action is decided fresh, against a plan the approver actually saw, and receipted where the agent cannot write. Every lesson drives an AI CLI against a non-production lab that runs with no account; the release decision itself stays Training 07's gate.
6 modules · 22 lessons · ~6.1 hours · Platform and SRE teams, security engineers, operations leaders, and the leaders who fund the gateway and the drills
Chapter 9 in the Meridian sequence · 9 live so far · builds on Operating in Production: On-Call, Incident Command, and Reporting Clocks and AI Assurance: System Risk and Release Decisions and Zero Trust Implementation · the last chapter so far
MU-AI-011 is Meridian's proposed crew-dispatch agent — it reads the feeder outage predictor's ranking and drafts crew pre-positioning work orders; it can send the dispatch notice too. AI Assurance wrote its deployment addendum and left NEEDS-OWNER in every cell: nobody has said which of its actions it may take on its own, inside what limits, approved by whom for how long, reversible how, receipted where, and stopped by whom. This training fills those rows in a non-production lab. You will assign an owner and classify every action by impact and reversibility before the first run; enforce the envelope — parameter bounds, budgets, and a fail-closed policy test — outside the agent, never in the prompt; capture the pre-state and verify the outcome with a check the agent did not write; require an expiring, single-use approval for anything it cannot do alone, and two people for anything irreversible; build a kill switch the agent cannot reach and measure how long it takes to halt; and leave behind one receipt for every action attempted, in a chain the agent cannot edit. The thesis stays exact throughout: the envelope can stand, but the authorization cannot — every action is decided fresh, against a plan the approver actually saw, and receipted where the agent cannot write. Every lesson drives an AI CLI against a substrate that runs with no account, ending in a capstone that runs MU-AI-011 through its first guarded night end to end. No prior Meridian knowledge needed.
The Curriculum
One Action, One Moment
Classify before the first run
The thesis for the whole training set against MU-AI-011's first storm night, the labelled autonomy rungs, the four-class action register a named owner signs, and the receipt every attempted action leaves behind
The Envelope
A place, not a sentence
Where a rule is actually enforced, the parameter and budget bounds that make blast radius a number, tests that prove the policy fails closed, and the sandbox floor an agent can still widen from inside
Before and After
Capture before, verify after
Capture the pre-state and the plan before approval, verify the outcome with a check the agent did not write, compensate or stop by the word that names the action, and require two people for anything irreversible
Approval and Revocation
An expiry and a halt
Approvals that expire, bound to one request and consumed once; the fatigue that turns rubber-stamped approvals into a control failure; a kill switch the agent cannot reach; and which oversight rules actually reach Meridian by contract, not by guidance alone
The Record of Every Action
The receipt is the unit of audit
A hash-chained receipt for every attempted action, the query that turns receipts into an incident timeline, and five dated agent incidents read in the vendors' own words
Own It
Earned on receipts, not granted
Cost the incremental bill of guarding one agent, earn the next autonomy level on receipts instead of a config flag, and run MU-AI-011 through one guarded night end to end
New to AI CLI tools?
This training assumes you can drive an AI CLI (Claude Code, Codex CLI, Antigravity CLI, or Copilot CLI). If that's new, these modules from our AI-Powered Development training are the fastest preparation — most students need only the first one: