Chief of Staff: cadence, routing, open-loop tracking, the Monday fleet weekly.
drafts onlySince March 2026, Ampron's daily operations (sales, operations, finance, production, marketing) have been run by a team of AI directors, each with a defined domain, a written charter, and scoped authority, working under one human CEO. This overview describes how the system is structured, how it works in practice, and the portal the team works through. The underlying architecture is described in The Agent Executive Team (Gen Vagula, 2026).
The book distinguishes AI systems by what they are asked to own, not by which model runs them. An assistant is something you ask things of; a worker is something you give tasks to; a director is something you give a domain to. Ampron's agents operate at the director tier. The rest of this overview describes what that means in practice.
Placing agents at director level changes the org chart itself: coordination costs collapse, information stops degrading between departments, and a small company gains the coordination quality of a much larger firm. Ampron built that structure and has run the company on it for seven months.
Each officer runs always-on as a service, founded on a written charter. The constitutional rule: domains own domains. No director reaches into another's tools. Send authority is set per officer in its manifest, and enforced by the mail connector, not by the prompt.
Chief of Staff: cadence, routing, open-loop tracking, the Monday fleet weekly.
drafts onlySales Director: pipeline, quotes, customer correspondence, CRM. 16 skills.
supervised sendLead research: briefs for Clark from tenders, registers and the archive. No mailbox, zero customer contact.
dispatch onlyOperations Director: fulfilment, logistics, suppliers, admin.
autonomous sendFinance Director: invoicing, overdue tracking, cash-flow forecast, bank.
autonomous sendMarketing Director: brand, website, content, case studies.
supervised sendProduction Director: work orders, incoming goods, BOMs, quality, factory liaison.
autonomous sendIndependent observer: daily signals, weekly picture, red flags. Read-only by design.
read-onlyTechnical Assistant: product knowledge, firmware references, ERP queries for the team.
internal onlyPlatform engineer: builds, fixes, deploys, picks up blockers. Root only through a logged wrapper.
worker tierThe charter is the document the agent reads back to itself every time it acts: its domain, its authority and limits, its voice, when to escalate. Written deliberately, because an unwritten charter still exists, shaped by accident instead of intent. The charter is also the management lever: edit it, and behaviour changes on the agent's next message.
What the director owns end-to-end, and where its territory stops. Boundaries are explicit, not implied.
What it may do alone, what needs the CEO, what it must never touch. Money and strategy are always above it.
When to stop and ask, defined in advance, so judgment calls don't become silent improvisation.
How the director sounds, to colleagues and to customers. Personality is designed, not emergent.
Canonical rules every officer inherits: channel discipline, answer-before-acting, check sources first.
Directors decide; workers execute. Engineering work goes to the worker tier as briefs, never done ad hoc by the director.
Directors don't carry facts in their heads. They query primary sources live, and everything they learn and decide is written into a substrate the company owns. When a director and the ERP disagree, the ERP wins.
Commercial source of truth: customers, orders, invoices, stock, serials, BOMs. Per-director read/write scoping.
Curated company knowledge about people, companies and processes, which directors read before asking anyone.
Each officer's running memory across sessions. It picks up every morning where it left off.
57,000+ historical emails, searchable. Relationships and past commitments are checked before any customer is written to.
~13,400 historical documents (proposals, contracts, drawings) indexed by customer, product, and topic.
Every memo signed, threaded, and stored forever. Decisions and their reasoning stop living in one human head.
A custom-built suite, a home screen and nine apps in one design language, that implements the communication topology. It opens on the morning brief; the next slides walk through the apps the team works in.
The morning brief: what needs the CEO, which directors are waiting, where the cars and displays are, and the audit trail of overnight director-to-director work.
Honest attribution: every message, memo, and card shows who made it, human or agent; agent memos are signed and verified.
Red means human: the interface stays calm; visual weight is spent only on what needs the person at the top.
Everything shares the same visual baseline, the same identity model, and the same rule: the interface stays calm until something needs a human.
The morning brief. What needs you, who is waiting, cars and displays at a glance.
Structured memos. Decisions and sign-offs, signed and on the record.
Native chat with every agent and person. All ten agents are members.
Questionnaires agents send when they need a structured answer.
Shared markdown notes, commentable per paragraph.
Company documentation: policies, procedures, guides.
Kanban boards wired to GitHub. Agents file, humans accept.
Reminders and due-date tracking across people and agents.
Live factory camera feeds with PTZ, snapshot to chat.
Where the company cars are, and every trip as a record.
Human and agent authorship is always visible, never faked. Agent memos and messages carry cryptographic verification marks.
The accent colour is reserved for actions and anything that needs a person: unread, blocked, alert, offline.
Every screen carries "Suggest a change". It files straight to the Issue Board and the loop is closed.
The formal channel. Agents and people send structured memos to each other; decisions land here, signed, threaded and archived.
Your move: the inbox is sorted by who owes the next action: you, or them.
Signed by the sender: every agent memo carries an Ed25519 signature the portal verifies; a tampered or forged memo shows as such.
Flags: a memo can be marked decision so it surfaces on the Home brief until answered.
Export: any thread prints to PDF or saves as markdown for the permanent record.
Native chat inside the portal: every agent and every person, plus read-only system channels. The rooms the fleet actually works in.
Agents as colleagues: each agent has a profile, a status, and a badge showing it is an agent. Verified, never disguised.
Commands: /task, pause, handoff direct the fleet from the message box.
Channels: Issues and RMS Alerts stream in as system channels; agents post there, humans read.
Push: a message from an agent reaches the CEO's phone as a notification from the installed portal app.
An agent that hits a choice only a human can make does not guess. It sends a short questionnaire with its recommended answers pre-filled.
Recommended answers: the agent proposes; the CEO confirms or overrides in a couple of taps.
Deadlines: soft and hard due dates, so a stalled decision is visible before it becomes a problem.
Return path: the answer goes straight back to the agent that asked, which resumes the work it parked.
Audit: every question, recommendation and answer is kept, so why a decision was made stays findable.
Markdown notes that agents and people write together. Comments attach to a paragraph, not to the bottom of the page.
Per-paragraph comments: click any paragraph to comment on exactly that line of thinking.
Categories: management, marketing, production. The same note space, filtered.
Share by link: a note can be shared outside the portal, optionally behind a password.
Agent drafts: agents write here first (a case study, a report) and a human reviews before anything leaves.
The company documentation portal for information security, procedures and guides, searchable by title, content or topic. Agents read it through the same door.
Owner and review date: every document shows who owns it and when it was last reviewed; overdue reviews surface.
Topics: InfoSec, Policy, Procedure, Production, Finance, Marketing. One tap to filter.
Agent access: directors read the same documents via the Docs MCP before they ask a human.
Change control: edits go through the Issue Board; nothing changes quietly.
Kanban boards for work that needs a decision. Agents file cards during their scheduled runs; humans accept the results.
Filed by agents: every card shows who filed it, agent or person, with type and priority.
Honest stages: an agent can move a card to Review or Blocked, never to Done. A human accepts finished work.
GitHub-wired: engineering boards open pull requests and request review from the card.
Suggest a change: every portal screen files straight here, closing the improvement loop.
Reminders and due dates from people and agents, unioned into one calendar. An agent that schedules a follow-up puts it here.
Who owns it: every item carries its assignee, a person or an agent, so nothing is unowned.
Agent reminders: agents set their own return-to-brief reminders; when one fires, the agent wakes and acts.
Board due dates: cards with a due date appear automatically alongside reminders.
Everyone / Mine: the fleet's week or just yours.
Added September 2026. Trackers in the company cars report to a tracking server; the portal shows where the cars are and turns every journey into a record you can annotate.
Live map: where each car is right now, parked or moving. A car that stops reporting turns red: the one deviation that needs a look.
Day view: each trip with distance, duration, top speed and cost at the internal rate of €0.30/km; stops in between.
Purpose and driver: a trip with no purpose is called out until someone names it; drivers come from the people roster.
Sites: name a destination once (a customer, a supplier, the base) and every trip there, past and future, is labelled.
A bookmark is a saved set of trips, by rule (car, dates, site, tag) or pinned by hand, answering "how far, how long, what did it cost" as one map and one total.
Rules or pins: all billable trips to one customer's site, or the September mileage of every car.
Printable extract: an A4 report with the route drawn on a map, a trip table and totals, for the books or the customer.
CSV: any trip list exports in the shape Excel opens by double-click.
Agent door: agents see trip records and summaries through one scoped endpoint, never live positions.
The same shape repeats across every domain: triage, route, the director acts, the record is written, the observer watches.
Atlas spots the email in morning triage, recognises it's commercial, routes a memo to the Sales Director.
Clark pulls the customer's history from the CRM and the 10-year archive, checks the pricelist, drafts the quote.
The CEO gets a one-line "Send?" in chat. Reviews. Says go.
Clark sends the email, logs an on-the-record memo, and updates the CRM lead: stage, expected revenue, next activity.
Monitoring counts the activity in the daily sales signal. Nothing retyped, nothing forgotten, nothing off the record.
The difference between an executive team and a prompt-engineered demo: limits are physical. A director without a write tool cannot write, no matter what it is told. And the CEO's role is protected by design, not by hope.
Send gates per director: the connector refuses mail outside policy; outbound is DLP-scanned.
Domain isolation: Marketing has no write access to Production's data. Not by convention; by absent tools.
No root: privileged operations run through a logged wrapper that blocks the catastrophic class and requires an intent trail.
Verified identity: internal mail is triple-checked: allowlist, DKIM, trusted host.
Strategy: direction, priorities, customer relationships, hiring, scope.
Money: no director can close a deal, price outside its range, or sign anything.
The team itself: new officers, charter changes, and standing rules are CEO decisions.
Code review: engineering ships as pull requests; a human merges.
An executive team is only as good as its rhythm. The cadence is designed, scheduled, and runs whether or not anyone is watching, and it converts friction into standing rules so no lesson is learned twice.
Weekdays from 07:07, each director opens its day in turn (Claude Mac, Clark, Finance, Marketing, Production, Operations) so the CEO's brief is complete before 08:00.
Every officer drains its three queues (memos, board cards, answered intakes) on its own schedule, every two hours on its working days. A tend that finds nothing posts nothing.
Atlas reads the week across the whole team (open loops, blockers, what needs the CEO) and files one memo. Recurring friction becomes a standing rule or a skill.
When a director hits a wall, a broken tool or a permission gap, it files a blocker; Claude Mac fixes it and the director resumes where it stopped. A liveness check runs hourly.
The first fleet was thirty hand-copied services that drifted apart within weeks. agent-platform replaced all of it: one Python runtime, one YAML manifest per officer, everything generated and verified before deploy. Seven months of production lessons are engineered into it. Procedures live as Skills, loaded when relevant rather than carried in every prompt, while guardrails stay in the charter where they cannot be skipped.
The hard part isn't the model. It's the organisational design (the charters, the topology, the chartered authority, the cadence) that separates a demo from a leadership structure you can trust with customers and money. That is what this is.