Blog
What we learn building covey: how the platform works, why it is built this way, and what proves itself in practice when AI agents are managed like employees.
Why does an agent never see its own credentials?
How covey brokers access to target systems at runtime: short-lived, scoped tokens that never sit in the sandbox as long-lived secrets.
How do you control what an AI agent can reach on the network?
How covey uses a proxy allowlist and hard network isolation to control what an agent sandbox can reach.
The website and the product are two things now
Why publishing a blog post used to mean deploying the platform, what that had to do with self-hosters, and what we built instead.
Where an agent works: sandbox, workplace and server
Every agent gets an isolated working environment of its own. How it is built, what survives a restart, and how it is spread across servers you run yourself.
How an agent gets access to a target system
An agent is meant to work in Zammad, GitLab or Kubernetes. How it gets in, who holds the credentials, and why they never sit in its working environment.
An agent that proposes and changes nothing
Covey Doctor reviews the other agents and the platform itself. Why it may not change anything, and why an approval records the exact values a person read.
How we measure what an agent has delivered
No model awards a grade here. We count verifiable events instead. Why we chose that, and why an agent never gets to see the rule it is measured by.