OperativeOps / Enterprise
Reading arc: 01 Mechanism02 Operation — this page03 Terms
Operation — written for the person on call
Installs from a compose file. Runs behind your firewall.
OperativeOps ships as containers you run — one host, a Kubernetes cluster, or fully air-gapped. This page is what you would be signing up to operate: install, sizing, upgrades, identity, and the code you can extend.
Nothing phones home · License check is offline
Fig. 01 — Topologies
Deployment options — as a spec, not a promise.
Three supported topologies. Sizing figures are the current reference configuration — your evaluation engineer validates them against your corpus before pilot.
| Specification | A — Docker Compose | B — Kubernetes | C — Air-gapped |
|---|---|---|---|
| Target | Evaluation to small-team production | Department to company-wide, HA | Classified or regulated networks |
| Install | docker compose up | helm install operativeops | Signed offline bundle, verified by hand |
| Nodes | 1 host | 3+ (control plane + workers) | 1 host or cluster |
| Reference sizing | 8 vCPU · 32 GB · 250 GB SSD | per worker: 8 vCPU · 32 GB | as A or B, + GPUs for local models |
| Network egress | Optional — gated model API only | Optional — gated model API only | None. Verified at the firewall. |
| Updates | compose pull · monthly | Rolling via Helm, zero-downtime | Signed bundle, applied offline |
| High availability | Not in this topology | Replicated services + Postgres | As deployed (A or B) |
| Backup | Volume snapshot + pg_dump | Velero + pg_dump, tested restore | Same, to offline media |
Fig. 02 — Model routing
Your models. Routed per agent.
The prompt goes where you decide — including to a model on your own GPUs. Routing is configuration, set per agent, changed without redeploying.
Local — Ollama · vLLMNothing leaves the network. Documents, embeddings, prompts and answers stay on your hardware. Required for air-gapped.
Hosted — OpenAI · Anthropic · Azure OpenAISomething does leave: the prompt and the retrieved passages inside it, over TLS, through the egress gate, every call logged. We say this plainly because a “zero data leakage” badge next to a cloud provider would be false.
Either wayYour keys, your endpoint, your choice per agent. Documents at rest, the vector store and the audit ledger never route anywhere.
Fig. 03 — Governance
Identity, roles, and access control.
SSO over SAML 2.0 or OIDC, provisioning via SCIM. Six roles, enforced everywhere — for this buyer the role matrix is a feature, so here it is in full.
| Capability | Admin | Auditor | Agent mgr | Editor | Member | Guest |
|---|---|---|---|---|---|---|
| Configure deployment | Granted | Not available | Not available | Not available | Not available | Not available |
| Grant agent scopes | Granted | Not available | Granted | Not available | Not available | Not available |
| Approve agent actions | Granted | Not available | Granted | Not available | Not available | Not available |
| Read audit ledger | Granted | Granted | Granted | Not available | Not available | Not available |
| Export ledger to SIEM | Granted | Granted | Not available | Not available | Not available | Not available |
| Manage connectors + sources | Granted | Not available | Not available | Granted | Not available | Not available |
| Ask, with cited answers | Granted | Granted | Granted | Granted | Granted | Read-only |
| Audited themselves | Granted | Granted | Granted | Granted | Granted | Granted |
■ = granted · — = not available to the role · every grant and every use is a ledger entry
Fig. 04 — The SDK
Your systems. Your connector.
The ERP nobody has heard of still counts. Custom MCP connectors are TypeScript against the SDK — a tool definition, a scope declaration, and the audit call you get for free. They run in your deployment, reviewed by your people.
packages/sdk · TypeScript · Apache-2.0
import { connector } from "@operativeops/sdk";
export default connector("warehouse-erp", {
scopes: ["erp.read"], // declared, not assumed
tools: {
"stock.lookup": async ({ sku }, ctx) => {
ctx.audit("erp.stock.lookup", { sku }); // ledger entry
return erp.query(
"SELECT qty, site FROM stock WHERE sku = ?", [sku]
);
},
},
});
A connector cannot exceed its declared scopes — the runtime enforces them, not the author.
Pointers
Threat model, cryptography, incident process and subprocessors live on the security page; the GDPR, EU AI Act, NIS2 and BSI C5 control mappings live in the compliance hub. We keep them there so your auditor reads one canonical version.
Fig. 05 — The path in
From here to running.
01 · Weeks 1–2
Technical evaluation
The compose bundle, a sample corpus, and two working sessions with an OperativeOps engineer. On your hardware from day one.
02 · Weeks 3–4
Security review
Architecture dossier, threat model, current pen-test summary, and the DPA draft — everything your security team asks for, unprompted.
03 · Weeks 5–10
Pilot
One department, agreed success criteria, weekly reviews. Real documents, real permissions, real ledger from the first question.
04 · From week 11
Rollout
SSO cutover, runbooks, admin training, and a named engineer you can reach — the same one from step 01.