At 2:34 on a Tuesday afternoon, a client emailed us a billing question. She had reactivated a returning member in the software we built for her, and the account went active without a bill ever going out. She wanted to know what she had done wrong.

She had not done anything wrong. By 2:37 an agent had read her email, traced the behavior through the code, and worked out that it was a genuine gap in the product: that particular path activated a membership with no invoicing step at all. It filed a tracked task and sent me a proposal with the issue, the evidence down to the file and line, the fix, the risk and an estimate. I read it and clicked Approve at 2:40. From there, the fix goes through the same pipeline as every other change we ship: its own branch, tests, a pull request, required checks, a guarded deploy, and then a short plain-English note to the client, saved as a draft for me to read before it goes anywhere.

Six minutes from her email to an approved fix, and I never opened the codebase. That is Dembe OS, the operating layer Champlin Enterprises runs on. This post explains what it is, how it works, and why the part that matters most is not the AI.

What Dembe OS is

Dembe OS connects AI agents to the three places a software business actually lives: the inbox, the servers, and the work tracker. Agents read incoming email and messages. Patrols check hosting, domains, security and account balances across every site we run. Anything they find becomes tracked work, filed against the right client, in plain words.

We built it for ourselves first, and it runs our business every day. It is built on Anthropic’s Claude models, with the model chosen per task: the most capable one for planning and hard problems, and faster, cheaper ones for routine work.

The loop: watch, notice, propose, approve, do, record

Every piece of work moves through the same six steps.

  1. Watch. Agents read the inbox and messages, and patrols sweep the fleet.
  2. Notice. A client request or a problem a patrol finds becomes a tracked task, even when the ask is buried in the fourth paragraph of a long thread.
  3. Propose. Anything that would change something real becomes a proposal: the issue, the evidence, the proposed fix, the risk and the estimated hours.
  4. Approve. A human reads it and clicks Approve or Reject. Nothing risky runs on its own.
  5. Do. An agent carries out the approved work on its own branch, writes and runs tests, and ships through a pull request.
  6. Record. The time is booked with an internal breakdown of where the hours went, and every step lands in one audit log.

The running job narrates itself as it goes: what it read, the backup it took, what it changed, the tests it ran. You never have to wonder whether an agent is still doing anything at all.

How it ships: enterprise engineering, not AI guesswork

Plenty of AI tools write code. Writing code was never the hard part. The hard part is getting a change into production without breaking something a customer depends on, and being able to explain afterwards exactly what changed and why.

So Dembe OS ships the way a disciplined engineering team does, and nothing reaches production any other way:

  • Its own branch. Every change starts isolated from live code and from any other agent working at the same time.
  • Tests, written and run. The agent writes tests for what it changed and runs the full suite. A red suite stops the job.
  • A pull request on GitHub. Every change has a plain summary and a reviewable history.
  • Required checks. Automated checks must pass before GitHub allows a merge. The main branch rejects direct pushes outright, including ours.
  • A guarded deploy. Deploy scripts refuse anything that is not exactly the merged code, and data changes get a backup first.
  • Verified live. The agent checks the live site after deploying and reports what it saw. Only then is the job marked shipped.

That is the difference between an AI demo and a production system. The model is impressive, but the process is what makes it trustworthy.

Guardrails that live in code

Agents that can act are only useful if you can trust what they will not do. These rules are enforced by the system, not left to good intentions.

  • Approval before action. Agents investigate freely. They change nothing that matters until a person has said yes.
  • Drafts, never sends. Client email is always written as a draft for a human to review. There is no path in the system that emails a client on its own.
  • One switch stops everything. A single off switch halts every agent at once. Autonomy you cannot turn off is not a feature.
  • It watches itself. The dangerous failure is the quiet one, a feed that stops while every log still looks fine. Self-checks raise the alarm once, not a hundred times.
  • Every action audited. Who proposed it, who approved it, what ran and when. The audit log is the record, not anyone’s memory.

What it changes for clients

Our clients never log into Dembe OS. They just notice the effects.

  • Requests do not get lost. An emailed ask becomes a tracked task within half an hour.
  • Problems get found before they call. Patrols catch expiring domains, exposed files and dry service balances while they are still small.
  • Billing they can read. Every invoice line is an outcome in plain English, backed by a breakdown of the hours behind it.
  • A small team with a big team’s reach. One principal engineer plus a disciplined set of agents covers work that used to need a department, without handing judgment to a machine.

Could your business run on something like this?

The pattern is not specific to software shops. Watch, notice, propose, approve, do, record fits any business that runs on email and recurring operational work: property management, healthcare administration, professional services, logistics. The agents change, the tools they plug into change, but the discipline stays the same.

We build this as a service, on top of the tools you already use, with the approvals, the audit trail and the off switch built in from day one. See how Dembe OS works, or tell us what yours would watch.