| Run it |
| Deployment and environmentsCloud accounts, Kubernetes, CI/CD, environment promotion, rollback | Upgrades, cluster maintenance, release engineering |
| Scaling and performanceAutoscaling, queues, back-pressure, load and soak testing | Capacity planning, performance regressions |
| Reliability and SLAsRetries, failover, idempotency, incident response, status reporting | 24/7 on-call, incident reviews, SLA reporting |
| Orchestration and stateLong-running runs, scheduling, pause and resume, durable state | Stuck-run triage, migrations of in-flight state |
| Trust it |
| SecurityAuthentication, authorization, secrets, encryption, tenant isolation | Patching, penetration tests, vulnerability response |
| Governance and permissionsRoles, approvals, change control, applicability scopes | Access reviews, policy changes |
| Audit and replayDecision records, versioned rules, replay of past runs | Evidence requests, retention, auditor walkthroughs |
| ComplianceSOC 2, HIPAA, ISO 27001 controls and evidence | Annual audits, control testing, remediation |
| See it |
| Logging, metrics, and monitoringStructured logs, metrics, tracing, alerting, dashboards | Alert tuning, observability costs |
| Do the work |
| ConnectorsERPs, email, documents, databases, APIs | API changes on every connected system |
| Document understandingExtraction from invoices, emails, PDFs, scans | Model updates, new document types |
| Exception handling with peoplePause, ask, review queues, guidance, resume from the paused step | Workbench operations, reviewer tooling |
| Model management and evaluationsModel routing, prompt and model versions, regression and drift checks | Model upgrades, evaluation suites, inference cost control |
| Authoring, versioning, and the logic runtimeWriting logic in English, drafts, publish, rollback, the interpreter | Language and runtime evolution |