Catalog / Build a Safe AI Operator

Course
Build a Safe AI Operator
Build an AI agent that does real work for your business and can't move money, delete data or act without your OK.
Price not set yet
Delivered right after payment, on your own access page.
Refund terms for this title aren't published yet, so it isn't on sale. Refunds
Contents
- Format
- Written course: one PDF plus a Python starter agent
- Guide
- 93 pages, A4
- Lessons
- 28 lessons in 10 modules, plus a bonus chapter
- Starter agent
- Python 3.11 or newer, with tests
- You need
- Some Python, or the patience to learn it with Claude beside you
Counted from the files on 30 Sep 2026.
What you'll be able to do
A written course, by Miro, on the eight rules his own agent, ATLAS, runs on. You build a small operator that watches first, picks actions from a closed list, asks before it acts, and says "unknown" instead of guessing. Each lesson ends with one exercise on the starter agent.
- Write checks that only read, and that report UNKNOWN when they can't see, never "fine".
- Give the model a closed menu of actions, with every argument validated, so it can't write code or commands.
- Set tiers in code: runs by itself, asks you first, or never. Silence never counts as a yes.
- Keep emails and web pages from giving your agent orders, and keep keys out of the prompt.
- Put it to work: a receptionist, a content engine and laptop control, each with receipts.
What's inside
Module 0: Why AI agents burn people
- 0.1 The week-one failure
- 0.2 The eight rules
Module 1: Eyes before hands
- 1.1 Collectors only read
- 1.2 Unknown is not OK
- 1.3 Watch-only mode
Module 2: Never guess a number
- 2.1 Fresh reads
- 2.2 "I can't reach Stripe" beats a wrong number
Module 3: The closed catalog
- 3.1 The model picks names, not code
- 3.2 Closed arguments too
Module 4: Tiers
- 4.1 Auto, ask, never
- 4.2 Things that are never allowed
- 4.3 Dry run and undo
Module 5: Approvals that can't be faked
- 5.1 One approval card, one tap
- 5.2 Silence is never consent
- 5.3 Earning autonomy
Module 6: Everything it reads is untrusted
- 6.1 Prompt injection in the wild
- 6.2 Wrapping untrusted text
- 6.3 Security alerts are untrusted too
Module 7: Secrets and least privilege
- 7.1 Keys never touch the prompt
- 7.2 Restricted keys
- 7.3 Which devices may talk to it
Module 8: Watch the watcher
- 8.1 Guard the machine your agent lives on
- 8.2 The kill switch
- 8.3 Deploys that roll back
Module 9: Put it to work
- 9.1 An AI receptionist
- 9.2 A content engine, with receipts
- 9.3 Laptop control
- 9.4 Your weekly report
Bonus
- From course to client: selling a safe operator to a local business
Who it's for
- Founders, freelancers and technical small-business owners who want an agent that does real work.
- People who have seen "AI team runs my company" videos and want the version that can't burn them.
Who it isn't for
- Anyone looking for a no-code tool. The course builds in Python.
- Anyone hoping for an agent that acts on its own from day one. This course earns autonomy step by step.
Pairs well with
Claude + Obsidian Vault Kit
Keep your clients, projects and prompts in one vault your operator's Claude can read.
Questions
Is the starter agent the ATLAS code?
No. It was written fresh for the course, small on purpose so you can read all of it in an evening. Every pattern is shown on it with made-up names.
Does the course include videos?
No. This is the written edition: the PDF and the starter agent.
Will it scan or test other people's systems?
No. The material is defensive only: scan networks you own or have permission to scan.
Refunds and licence
Refunds
Not published yet. This title stays off sale until its refund terms are set.
Licence
Not published yet. Until it is, the terms of sale apply.