pot/labs

We build and run agentic AI for enterprise. Then we try to break it.

// a South African firm. Named engagements, running systems, evidence trails. Every promise ends in a command you can run, not an adjective.

/01 practice areas

Four practice areas. Three we have built. One we propose, and label as proposed.

Each is a named engagement with a delivery shape, a stated dependency on you, and an exit criterion written as a command rather than an adjective.

/01 AI Agents custom-built · deployed in your environment

An agent that does a named job inside your system, on your infrastructure, under your credentials. You buy a running system with an evidence trail, not a capability.

/02 Managed Agents operated by us · on a clock · against a live system

A standing graph of scheduled runs, each with a named output, plus the evidence trail it produces. Not a support retainer and not a seat count.

/03 Agentic Workflows headless · intake to close · no person in the happy path

A commercial process that completes without a human on the success path. That property is machine-asserted, not observed. Most of the design work is deciding what the machine must prove.

/04 Adversarial Assurance proposed

Independent attack on agentic systems we did not build. Proposed on internal evidence. It has never been sold, and this site says so rather than implying otherwise.

/02 method

The same discipline on every build, because it is the product.

Plan into lanes.

The work is decomposed before anyone writes a line. Each lane carries a named output and an exit criterion. If the criterion cannot be written as a command, the lane is not ready.

Build in parallel.

Lanes run concurrently against the same contract. Speed comes from isolation, not from hurry. Nothing merges on a promise.

Converge on a verifier that did not write the code.

The check is independent of the author, executable, and it refuses rather than warns. A system that grades its own homework is marketing. Ours gets marked by something that wants it to fail.

/03 the gate

This page went through one before you saw it.

$ gate run --all --strict
reading shipped files at generation time, before deploy
 
no external resources ................ PASS
no client named without consent ...... PASS
every claim states a mechanism ....... PASS
proposed work labelled as proposed ... PASS
confidentiality scan ................. PASS
layout gate at deploy ................ PASS
 
6 gates. 0 warnings. gates refuse, they do not warn.

One honest footnote. This page is verified by its own maker, which is internal assurance, and we label it as such. Independent assurance is the fourth practice area, and it stays marked proposed until someone has bought it.

/04 boundary

What we do not sell.

Chatbots for their own sakea chat surface is an interface, not an outcome
Seat licenceswe sell running systems, not access to one
A model wrapper with a logoif the mechanism is a prompt, we will say so
Promises without an exit criterionevery engagement ends in a command you can run
Your datait stays in your environment, under your credentials

/05 start

Bring one process, and the person who actually runs it.

One conversation. We map the process, name the output, and write the exit criterion together. If agentic AI is the wrong tool for it, we say so in the same meeting.

labs@potstrategy.com

// code meets commerce