Constraints we worked within.
- AI must not act
- The AI has no dispatch rights, and a deterministic rule layer runs under it. The gateway refuses any command without a recorded human approval.
- No production impact
- Simulation only: no DNS change, no real failover, and one read-only query on production for the baseline.
- Every command approved in advance
- Each command marked read-only, state-changing or data-overwriting and signed off before its first run. No ad-hoc commands.
- Privileged access through the client only
- The client exposed only the execution agents. Least-privilege accounts brokered by its own access management, and no database or backup clients installed by us.
- The backup stack stays as it is
- The database edition has no native standby, so restoring from backup media is the DR path. We orchestrate Oracle RMAN and the enterprise backup already in place.
- Evidence kept, personal data removed
- An evidence store designed for write-once retention, and personal data redacted from logs before the AI reads them, under a data processing agreement.