Stage 01 · The intent

The CFO built a budget app.

It works. It uses real company data. Finance wants the rest of the company to use it.

CClaude Code/ budget-compassLocal workspace
Budget compassBuilding
CFO
Dana · CFO

Add the department view and make sure each leader sees only their own forecast.

C
Claude

Done. The final tests pass. The department scope, forecast filters and variance alerts are working in the local preview.

28 tests passed12 filespreview ready
Build complete · running only on Dana’s desktop

Budget Compass

FY26 · Live actuals

Local preview
Plan$42.8mon target
Actual$31.4m73% elapsed
Variance+$1.2m3 teams above
Plan vs. actualJUL 2026
DepartmentPlanVariance
Product$8.4m+2.1%
Sales$11.6m-0.8%
CClaude Code/ budget-compassBuild complete
Budget compassComplete
CFO
Dana · CFO

This looks great. Put it somewhere the finance team can use it.

C
Claude

The app is ready, but this desktop session has no production identity, cloud project or company route. I cannot safely publish it from here.

Production access required
The app is finished. The path is not.

Claude can build and test the app locally. It cannot grant itself access to company infrastructure or decide which production risks the company will accept.

MissingProduction identityNo persistent cloud credentials should be created here.
MissingApproved environmentNo GCP project, network policy or company route is available.
MissingEnterprise decisionThe app has not been reviewed against company policy.
CClaude Code/ budget-compassNext step
Budget compassNeeds access
C
Claude

Reach out to Marcus and ask for a production GCP project with access to the finance warehouse. I drafted the request below.

Message for your CTO

“Budget Compass is ready. Can you give me access to a GCP project so I can deploy it for the finance team?”

Waiting for a human path to production

Budget Compass

Final local build

Not deployed
Tests28/28passed
Users1Dana only
Company URLNoneblocked
Useful value, stranded.

Everyone in Finance could use the app. Nobody else can reach it.

Stage 02 · The old path

Then the company gets involved.

The CFO needs production access. The CTO sees the risk immediately. Both of them are right.

Acme
Dana Weiss · CFO
# finance-aiFinance automation and internal tools
Production request
Today
CFO
Dana Weiss

The budget app is ready. Can you give me access to a GCP project so I can deploy it for the team?

BC
Budget CompassPrivate preview · FY26 plan + live actuals
CTO
Marcus Webb

No way I can give an unreviewed app production access. I’ll ask someone from DevOps to look after the product launch. Probably a few weeks.

CFO
Dana Weiss

So for now it stays on my laptop?

◷ Awaiting DevOps review · estimated in 3 weeks
Message #finance-ai

Stage 03 · The third way

Mithran takes responsibility for the path.

The CFO does not receive cloud credentials. The CTO does not inherit another manual review queue.

CClaude Code/ budget-compassMithran connectedForge available

Budget Compass

CFO
Dana · CFO

The app is ready. Deploy it to production for the finance team.

C
Claude

I’ll work with Mithran Forge to run the build through the company’s deployment process. Forge will check the app against company context and production policy before anything ships.

MHandoff to Mithran Forgestarted
Packaging build, dependencies and requested permissions
Sending intended users, data sources and production goal
Starting independent adversarial review
Claude is waiting for Forge…
MAegis/ deploy review / budget-compassAdversarial review

Independent review

method v2.3.1 · policy set acme-prod

changes required
Identity
Context
Policy
Challenge
Persistent cloud key

Replace the generated GCP key with a short-lived, brokered workload identity.

Required
Compensation data overexposed

Apply row-level scope so department leads see only their own teams.

Required
Unrestricted outbound traffic

Allow only approved finance APIs and block every other destination.

Required
!
Deployment paused · 3 changes requiredReport returned to Claude with evidence
CClaude Code/ budget-compassFixing Forge report3 changes

Budget Compass

C
Claude

Forge found three production issues. I can fix all three without changing what the app does. I’m applying the required controls now.

Mithran Forge report3 required changes
!
Persistent cloud keyUse brokered workload identity
fixing
!
Overbroad compensation accessAdd viewer-scoped row filter
fixing
!
Unrestricted egressAttach finance API allowlist
fixing
identityReplaced GCP key with brokered tokendone
dataAdded management-tree row filterdone
networkRestricted outbound destinationsdone
Claude is sending the revised build back to Forge…
CClaude Code/ budget-compassForge response

Budget Compass

C
Claude

The revised build passed Forge. Mithran approved it for protected production and attached the controls it will enforce while the app runs.

Mithran green light

deployment decision dec_7a9c24 · signed

Findings3 resolved
Policy checks14 passed
Production riskWithin policy
Human authority remainsBlock · approve exception · revoke

Any override requires an owner, reason, scope, expiry, and a signed record. The agent cannot approve its own exception.

MForge is ready to deployapproved
Brokered production identity attached
Data and egress controls attached
Audit and runtime intervention enabled
Ready to continue to protected production

Stage 04 · Protected production

The app ships with the controls attached.

Mithran changes what must change, deploys the result, and keeps protecting it after approval.

MForge/ production / budget-compassProtected deployment

Deploying budget-compass

release 7a9c24 · acme-prod

Healthy
Build
Identity
Network
Compute
Live
Application image built and signeddone
Workload identity bound to finance readerdone
Row-level policy injected at data boundarydone
Egress allowlist attached to runtimedone
Isolated compute started with kernel enforcementdone
Health checks passed · company route assignedlive
budget.acme.internalProtected production · deployed in 00:42
MProtected appbudget.acme.internalLive production + auditHealthy

Budget Compass

Signed in as Amir · Sales VP · live actuals

Production
Sales plan$11.6mviewer scoped
Actual$8.9m76% elapsed
Variance+$0.3mwatch
Sales plan vs. actualJUL 2026
TeamPlanActualVariance
Enterprise$4.8m$3.7m+1.2%
Mid-market$3.6m$2.9m-0.4%
MFlight Recorder/ budget-compass / ev_144209Runtime intervention

Overbroad export intercepted

14:42:09 · budget-compass · production

App requested detailed forecast export for all departments
Aegis detected 321 rows outside the viewer’s management scope
Export rewritten to include Sales rows only
Scoped export delivered. Original request preserved as evidence.
APPExport detailed forecast for all company departments
AEGISViewer is Sales VP. Export Sales only and remove compensation fields.
APPAccepted. Useful export delivered within policy.

Stage 05 · Company-wide impact

Now the company can build on it.

The app is no longer trapped on one laptop. It becomes a governed company capability.

MMithran
acme.com · company realm

The trust contract

No decision disappears inside the AI.

This illustrative walkthrough resolves the request the same way Mithran is designed to resolve real work: with an independent verdict, cited evidence, preserved human authority, and a record that survives the session.

01 · Request

Ship Budget Compass.

Dana asks her harness to publish an app that reads live finance data for department leaders.

02 · Independent review

Changes required.

The reviewer is separate from the builder and has no incentive to wave the app through.

03 · Evidence

Three findings, each cited.

Persistent credentials, broad data access, and unrestricted egress are tied to named policies and evidence.

04 · Repair

The goal stays. The risk changes.

Claude fixes the build without changing the business outcome, then submits it again.

05 · Human authority

People can still say no.

Security can block, approve a scoped exception, change policy, or revoke the release. Every override is attributed and expires.

06 · Record

The verdict becomes evidence.

The request, review, changes, approval, deployment, and runtime interventions stay connected in one signed trail.

Approved after repair. Protected in production.

The app reached the company. The original unsafe build did not.

dec_7a9c24 · signed

That is the shift

One useful build no longer has to choose between risk and irrelevance.

Mithran gives people a path to production and gives the enterprise control over what happens there.