I Run My Company From My Phone. A Mac mini Does the Work, and Every Action Is Audited.
Tuesday, 7:40 in the morning. A client emails me: their contact form stopped sending enquiries. I read it on my phone in a coffee shop queue. I do not open a laptop, and I do not reply yet.
By the time I sit down at my desk, there is a proposal in my inbox. It names the client, describes the fault in plain language, lays out the fix, estimates the hours, and classifies the risk. Two links: Approve, Reject. I tap Approve.
Forty minutes later the fix is live. It went out as a pull request on GitHub, passed the required checks, was merged, and was deployed by a script that refused to run until the code on the server matched exactly what had been merged. The hours were booked to that client with a line-by-line breakdown. A short "it's fixed" note to the client, written in their words and not mine, is sitting in my drafts waiting for my eyes.
I did one thing. I tapped a link. Everything else was done by a machine in my office, and every step of it is on the record.
What this actually is
I call it Dembe OS. It is one always-on Mac mini, an AI agent built on Claude, and a layer of engineering controls I designed around it. I talk to it from my phone or my laptop over an encrypted channel. Nothing sensitive lives on the phone. The phone is a remote control. The mini does the work.
Functionally, it is a new employee. Not a chatbot, and not an "assistant" that writes a paragraph and hands it back. It carries work from the moment it arrives to the moment it is done, billed and reported. Here is what it handles today, without me in the loop except to approve:
- Proposals. Every client ask, whether it arrives by email, text or a forwarded screenshot, becomes a written proposal before anything happens. What, why, how long, what could go wrong.
- Fixes and features. Code changes across more than twenty production systems, shipped through the same pull request flow a strong engineering team would use.
- Billing. Finished work is booked as tracked time with a breakdown, filed against the right client, ready to become an invoice line.
- Email. Inbox triage, drafted replies in each client's own terms, and the follow-up note once their problem is solved.
- Audits. Scheduled SEO, accessibility, performance and security sweeps across every site I am responsible for, with findings opened as work and not buried in a PDF.
- Monitoring. Round-the-clock health checks on the whole fleet, with self-healing for the failure modes I have seen before and an alert for the ones I have not.
It works a full business day on a schedule, picks up the next approved item when it finishes one, and stops at the end of the day. It also records its own hours. If I ask what it did on Thursday, I get a list.
The difference is the controls
Most companies "adding AI" have bolted a chat window onto something. That is not what enterprise-grade means. Enterprise-grade means permissions, approvals, audit trails, and the ability to undo. It means a new hire cannot push to production on their first day, and neither can this.
I run a software company. I spend my days building systems that other businesses depend on. So I built this the way I would build anything that touches a client's money and reputation: least privilege, separation of duties, and a paper trail for everything. Here is how I keep it honest.
1. Nothing starts without approval
The agent proposes. I decide. Every piece of client work is written up first, with scope, estimated hours and a risk class, and it waits for me. Approvals are recorded with who approved and when, and the record is visible to the agent only after a real logged-in human has decided. There is no path where it approves its own work.
2. Every change is a pull request
No change reaches a live system without a branch, a pull request, a required automated check and a merge on GitHub. The trunk is protected on GitHub's side, which means even I cannot push straight to it from my own terminal. The history of every change, and the reasoning behind it, lives in the repository forever.
3. Deploys are gated on merged code
The deploy scripts refuse to ship anything unless the exact commit on the machine is the exact commit that was merged. No half-finished work, no uncommitted hotfix. Each deploy snapshots what it is replacing so a rollback is one command.
4. Secrets never leave the vault
The agent is engineered so it cannot print a credential, even to prove it works. It confirms a key with a status code, never the key. Guards sit in front of its tools and block destructive database operations, direct edits to production, and any command shaped like a leak. It has to earn each of those with an explicit, logged override, and most of them have none.
5. Drafts, never sends
Client-facing email is always a draft. I read every one before it goes. This is the rule I would give any new employee in their first week, and I see no reason a machine should get more latitude than a person.
6. Everything is logged, billed and visible
Every action lands in an audit log. Every finished item is booked to the client's time with a breakdown that adds up. A live status page shows what the agent is doing right now, what is queued, what it did today and what it booked. And there is a kill switch. One file, one flag, and the whole thing stands down until I say otherwise.
Why I call it enterprise grade
Ask a compliance officer what they want from any system that acts on a company's behalf and you get the same list every time. Who authorised this? Who did it? What exactly changed? Can we prove it? Can we undo it?
Dembe OS answers each of those with a record, not a reassurance. Authorisation is the approval. Identity is the GitHub account and the audit log. The change is the pull request diff. The proof is the merged commit and the deploy snapshot. The undo is the rollback. That is change management, the same discipline large engineering organisations have used for decades, applied to an AI worker from day one.
Separation of duties is built into the shape of it: the agent proposes, a human approves, and the machinery verifies. None of the three can skip the other two.
What it feels like to run a business this way
I used to come back from a meeting to a wall of email and a day already gone. Now I come back to a short list of decisions. Approve this. Reject that. Reword this reply. The work has already been scoped, and the moment I say yes it is moving.
It has also made me a better operator. Every piece of work has a written proposal, so I quote more accurately. Every hour is booked with a breakdown, so my invoices hold up months later. Every change has a diff, so when a client asks what happened in March, I can show them rather than remember.
And because the whole thing runs on hardware I own, in my office, my clients' data does not get scattered across a dozen SaaS tools to make this possible. One machine, under my roof, under my rules.
I can build this for your business
This is not a product I downloaded. I engineered it, I run my company on it every day, and I know exactly where the sharp edges are because I have hit most of them. That is the experience I bring when I set it up for someone else.
If you run a firm that drowns in email, carries a backlog of small technical work that never gets scheduled, or bills by the hour and loses time to the admin of proving it, this is for you. You get your own always-on machine, your own approvals, your own audit trail, and your own data staying on your own hardware. You get a new employee that writes everything down and never ships a change you have not approved.
Most companies are still asking whether AI is safe enough to trust with real work. I stopped asking. I made it safe, and then I put it to work.
Talk to me about setting this up See AI agent operations at Champlin Enterprises