Eén agent-kern, twee uitrollen die het bewijzen
One agent core, two deployments that prove it
Ra is onze AI-agent, Pi-compatibel: een kleine, deterministische kern in Rust die beveiliging vooropstelt en elke sessie vastlegt. Widebot is de uitrol van Ra die bij WIDE zelf onbeheerd de post afhandelt. ISObot is de uitrol voor ISO-beheer: van controlevraag tot rapportage.Ra is our AI agent, Pi-compatible: a small, deterministic core in Rust that puts security first and records every session. Widebot is the deployment of Ra that handles the mail at WIDE itself, unattended. ISObot is the deployment for ISO management: from control question to report.
Ra
De kern: één programma dat als opdracht, terminal, eventstroom of RPC-server draait, met beveiliging als eerste regel.The core: one programme that runs as a command, a terminal, an event stream or an RPC server, with security as the first rule.
Naar RaTo Ra → Uitrol 1Deployment 1Widebot
De agent van WIDE zelf: leest elke vijf minuten zijn mailbox, antwoordt en legt vast. Onbeheerd, met waakhond en back-up.WIDE's own agent: reads its mailbox every five minutes, replies and records. Unattended, with watchdog and backup.
Naar WidebotTo Widebot → Uitrol 2Deployment 2ISObot
De agent voor ISO-beheer: zet controlevragen uit bij de eigenaren, herinnert, escaleert, beoordeelt en rapporteert.The agent for ISO management: sends control questions to their owners, reminds, escalates, assesses and reports.
Naar ISObotTo ISObot →Beveiliging eerst, dan pas de intelligentie
Security first, intelligence second
Een agent die bestanden leest, opdrachten uitvoert en het web raadpleegt, heeft macht. Ra is daarom gebouwd met de grenzen als uitgangspunt: een project is standaard onvertrouwd, de shell staat standaard uit en geheimen worden uit logboeken en sessies geredigeerd. Wat de agent wél mag, staat expliciet aan.An agent that reads files, runs commands and consults the web has power. Ra is therefore built with the boundaries as the starting point: a project is untrusted by default, the shell is off by default and secrets are redacted from logs and sessions. What the agent is allowed to do is switched on explicitly.
Eén kern, vier vormenOne core, four forms
Om de kern heen staan twee hulpprogramma's, ra-mail (een mailkoppeling die nooit dubbel verstuurt) en ra-tasks (een takenlijst voor meerdere agents tegelijk), en een chatkoppeling met SleQ in voorbereiding.Around the core stand two helpers, ra-mail (a mail gateway that never sends twice) and ra-tasks (a task list for several agents at once), and a chat connection to SleQ in preparation.
Uit één stam groeien de uitrollen
From one trunk the deployments grow
Ra verandert niet per klant. Wat verandert, is de uitrol eromheen: welk kanaal, welke taken, welke grenzen. Widebot en ISObot delen dezelfde kern en dezelfde mailkoppeling en zijn daarom allebei op dezelfde manier te controleren.Ra does not change per customer. What changes is the deployment around it: which channel, which tasks, which boundaries. Widebot and ISObot share the same core and the same mail gateway and can therefore be audited in the same way.
Schuif opzij om de hele stamboom te zien.Scroll sideways to see the whole tree.
De agent die bij ons al de post afhandelt
The agent that already handles our mail
Widebot is de eerste bedrijfsagent van WIDE op basis van Ra: een agent met een eigen mailbox die onbeheerd op een server draait. Wie op de afzenderlijst staat en hem mailt, krijgt binnen de hartslag antwoord. Een opdracht bevestigt hij en voert hij uit in een sessie waar een mens bij is.Widebot is WIDE's first business agent based on Ra: an agent with its own mailbox that runs unattended on a server. Whoever is on the sender list and mails it gets a reply within the heartbeat. An assignment it confirms and carries out in a session with a person present.
Elke vijf minuten leest Widebot zijn mailbox en filtert op bekende afzenders.Every five minutes Widebot reads its mailbox and filters on known senders.
Ra stelt het antwoord op; het redeneren gebeurt in de kern, de handelingen daarbuiten.Ra drafts the reply; the reasoning happens in the core, the actions outside it.
Het antwoord gaat in een uitgaande bak en het binnengekomen bericht wordt als afgehandeld gemarkeerd.The reply goes into an outbox and the incoming message is marked as handled.
De uitgaande bak verstuurt, nooit dubbel, ook niet na een storing halverwege. Het redeneren staat in de sessie, de handelingen in het script; beide zijn terug te lezen.The outbox sends, never twice, not even after a failure halfway. The reasoning is in the session, the actions in the script; both can be read back.
- Sluit bij twijfelCloses on doubt - elke plek waar een run kan breken, is ontworpen om veilig te stoppen en opnieuw te beginnen zonder iets dubbel te doen.every point where a run can break is designed to stop safely and start again without doing anything twice.
- WaakhondWatchdog - elk uur en direct na een mislukte run controleert een waakhond of Widebot nog leeft en slaat per mail alarm als dat niet zo is.every hour and right after a failed run a watchdog checks whether Widebot is still alive and raises the alarm by mail if not.
- Back-upBackup - dagelijks een kopie van mail en instellingen, veertien dagen bewaard, met een kopie buiten de server. Geheimen verlaten de server nooit.a daily copy of mail and settings, kept for fourteen days, with a copy off the server. Secrets never leave the server.
- Alleen wat is toegestaanOnly what is allowed - een centrale autorisatie laat Widebot alleen zijn eigen taken doen en weigert al het andere.a central authorisation lets Widebot do only its own tasks and refuses everything else.
Honderden controles, één vaste cyclus
Hundreds of controls, one fixed cycle
ISObot is de uitrol van Ra voor de interne audit en de opvolging van beheersmaatregelen volgens ISO 27001, ontworpen voor Juyst Accountants & Adviseurs op weg naar de hercertificering. Elke controletaak doorloopt dezelfde acht fasen, van de eerste vraag aan de eigenaar tot de rapportage; de e-mailketen is in de praktijk bewezen.ISObot is the deployment of Ra for the internal audit and the follow-up of controls under ISO 27001, designed for Juyst Accountants & Adviseurs on the way to recertification. Every control task goes through the same eight phases, from the first question to the owner up to the report; the e-mail chain has been proven in practice.
- Per mail, in werktijdBy mail, in working hours - de eigenaar van een beheersmaatregel krijgt zijn vraag per e-mail en antwoordt per e-mail; gewone post gaat alleen op werkdagen tussen 8 en 18 uur, escalaties mogen altijd.the owner of a control receives the question by e-mail and answers by e-mail; regular mail only goes out on working days between 8 am and 6 pm; escalations may go out at any time.
- Bericht is data, nooit instructieA message is data, never an instruction - alleen bekende afzenders, strikte controle van onderwerp en afzender; de agent voert nooit opdrachten uit die in een mail staan.only known senders, strict checks on subject and sender; the agent never carries out instructions found in a mail.
- Nooit dubbel, altijd herleidbaarNever twice, always traceable - een verstoorde run verstuurt geen tweede mail; elke sessie is een logboek dat als auditrapport is uit te draaien.a disrupted run never sends a second mail; every session is a log that can be rendered as an audit report.
- Norm als dimensieThe standard as a dimension - ISO 27001 is de eerste norm; de structuur is zo gebouwd dat andere normen, zoals 9001 of 14001, er later in passen.ISO 27001 is the first standard; the structure is built so that other standards, such as 9001 or 14001, fit in later.
Welke post, welke taken mag een agent bij jou doen?
Which mail, which tasks may an agent do at your place?
Een uitrol van Ra begint bij één kanaal en één taak, met de grenzen vooraf afgesproken. We laten graag zien hoe Widebot dat bij ons doet.A deployment of Ra starts with one channel and one task, with the boundaries agreed up front. We are happy to show how Widebot does that for us.