Budget Compass new
Plan, actuals and forecast variance by department.
It works. It uses real company data. Finance wants the rest of the company to use it.
FY26 · Live actuals
Claude can build and test the app locally. It cannot grant itself access to company infrastructure or decide which production risks the company will accept.
“Budget Compass is ready. Can you give me access to a GCP project so I can deploy it for the finance team?”
Final local build
Everyone in Finance could use the app. Nobody else can reach it.
The CFO needs production access. The CTO sees the risk immediately. Both of them are right.
The CFO does not receive cloud credentials. The CTO does not inherit another manual review queue.
method v2.3.1 · policy set acme-prod
Replace the generated GCP key with a short-lived, brokered workload identity.
Apply row-level scope so department leads see only their own teams.
Allow only approved finance APIs and block every other destination.
deployment decision dec_7a9c24 · signed
Mithran changes what must change, deploys the result, and keeps protecting it after approval.
release 7a9c24 · acme-prod
Signed in as Amir · Sales VP · live actuals
14:42:09 · budget-compass · production
The app is no longer trapped on one laptop. It becomes a governed company capability.
Everything people at Acme have built on Mithran, in one place. Sign in with your acme.com email to unlock it.
Plan, actuals and forecast variance by department.
Flags renewal and liability risk across the contract vault.
Answers new-hire questions from the Acme handbook.
Vendor-spend anomalies, week over week.
Checks every asset against brand guidelines.
Replay what the agent tried, what Mithran changed, and what actually ran.
Observatory · Company overview
One evidence journal, read as a year: what exists now that didn’t, what it costs, what didn’t happen, and who your people are becoming.
Nobody rolled this out. Somebody opened an app a colleague had built, understood they could do the same, and did.
The trust contract
This illustrative walkthrough resolves the request the same way Mithran is designed to resolve real work: with an independent verdict, cited evidence, preserved human authority, and a record that survives the session.
Dana asks her harness to publish an app that reads live finance data for department leaders.
The reviewer is separate from the builder and has no incentive to wave the app through.
Persistent credentials, broad data access, and unrestricted egress are tied to named policies and evidence.
Claude fixes the build without changing the business outcome, then submits it again.
Security can block, approve a scoped exception, change policy, or revoke the release. Every override is attributed and expires.
The request, review, changes, approval, deployment, and runtime interventions stay connected in one signed trail.
The app reached the company. The original unsafe build did not.
That is the shift
Mithran gives people a path to production and gives the enterprise control over what happens there.