02 · working software, not workflow slides
AI systems & consulting
Agents, retrieval, MCP servers, automation that survives contact with production. I build AI that does a job — scoped tight, instrumented, and cheap to run — and I'll tell you plainly when you don't need it.
the concierge answering below and the mcp server agents call are both running on this page's own stack · scroll — the instrument is live ↓
the instrument — the concierge — ask this site about the work
live — same stack this service sells
concierge — preview
> can an agent book a discovery call with you?
tool · calendar.check
next opening surfaced from the live calendar
tool · scope.draft
three-line brief drafted from your message
tool · call.book
booked — invite issued to both sides
that was the canned preview — the live seat is below
● live — the concierge holds this seat
the work — manifest
w-01
Custom agents and assistants wired to your real systems — bookings, catalogues, support, operations.
w-02
MCP servers that make your product usable by the agents your customers already run. This site is one — four live tools.
w-03
Retrieval and content pipelines: your data, structured, queryable, and fresh.
w-04
Guardrails as a first-class feature: grounding, rate buckets, spend caps, injection resistance — tested adversarially before launch.
w-05
Sober consulting: model choice, cost ceilings, evals, failure modes — decided before the build, not after the bill.
how it's different
The concierge on this page is the demo — live model, real spend caps, hard rules that hold under injection.
Everything ships with an off switch, a budget, and a log.
No platform lock-in theatre — the repo is yours, the keys are yours, the costs are visible.
method — how it runs
01
name the job
one week of discovery ending in a working prototype or a written 'don't build this'. The second outcome is cheaper and delivered just as proudly.
02
ground it
the system answers from your data and refuses beyond it. Facts documents, retrieval, and tool access are scoped before a single prompt is written.
03
cage it
rate buckets, spend ceilings, kill switches, adversarial testing. The failure modes are rehearsed before customers find them.
04
hand it over running
deployed, documented, instrumented — with the logs and budgets visible to you, not just to me.
manifest — what lands on your desk
jm/ai·02
- 01
a working system in production, not a proof-of-concept in a folder
- 02
an MCP surface where it earns one — your product, callable by agents
- 03
guardrail suite: caps, buckets, kill switch, injection tests
- 04
cost model + logs you can read without me
- 05
a written 'don't build this' when that's the honest answer
signed — one operator, no handoffs
05 items
engagement — the terms
Discovery sprint first — one week, working prototype or a written 'don't build this'. Then fixed-scope builds.
proof — on the record
the concierge — live on this page
livegrounded in site facts, sealed identities held under direct injection, pricing routed to a human. Ask it something.
this site's mcp server
livefour tools live over streamable HTTP — grade_site, site_map, ask_concierge, contact_channel.
the bench →agent-ready grader
on recordthe scoring instrument at /lab — engine, verdict model, and abuse guards all part of the exhibit.
run it →asked straight — answered straight
01What is an MCP server, and why would a business site run one?
MCP is the protocol that lets AI agents call tools instead of scraping pages. This site runs one: agents can grade a site, read the site map, or ask the concierge directly. For a business it turns your site from something machines read into something machines can act through — bookings, lookups, quotes — under rules you set.
02What does agent-ready mean in practice?
An agent can find you, parse you, and act: stable machine surfaces, clean structure, llms.txt, sane endpoints, and no accidental blocks on the readers that matter. It's scored live at /lab — run your site through the grader and you'll have the practical checklist in about thirty seconds.
03Can you build an AI feature that isn't a gimmick?
The discipline is scoping it to the smallest system that's genuinely useful, then hardening it: grounded in your real content, hard rules for what it may never say, resistant to prompt injection. The concierge on this site is the working pattern — it answers from a sealed fact file and refuses everything else.
04Do you work alongside an existing development team?
Constantly — that's the embedded-lead shape. I land the system in your stack, write the documentation and decision records as I go, and leave your team holding instruments they can run without me.