Marmon/Keystone OS

What are we working on?

Build governed apps, documents, and workflows with your organization's context.
Starter workspaces
Manufacturing Exposure & Resilience CenterReview synthetic exposure, identity, supplier-access, and recovery evidence across digital, warehouse, and processing environments.
Live App
Ransomware & Recovery Readiness BriefDraft a practical readiness plan for identity, IT and operational boundaries, supplier access, recovery, and communications.
Document
Governed Security Automation ReviewEvaluate security-assistance candidates through quality, access, cost, and human-action controls.
Slide Deck
Illustrative prototype. Uses public company context and simulated data; no connection to Marmon/Keystone systems.Marmon/Keystone publicly identifies as a Marmon Metal Services/Berkshire Hathaway company; this prototype is independent and illustrative.Open the Marmon Holdings OS demo
Manufacturing Exposure & Resilience Center
Illustrative
Build a manufacturing exposure and resilience center for Marmon/Keystone using synthetic data. Cover online quoting and customer accounts, warehouses and distribution, processing environments, supplier access, and recovery evidence. Require human approval before containment or access changes.
AI
I start with no access. I'll request only the evidence needed for this workspace.
Gatekeeper: Synthetic Exposure + Recovery Evidence
Read-only access to synthetic external-asset, identity, facility, supplier-access, vulnerability, and recovery records. No Marmon/Keystone system, credential, customer, employee, supplier, or operational record is connected.
Approve read-only access.
AI
Executed deterministic query
const exposure = await env.SYNTHETIC_ATTACK_SURFACE.list({ scope: ["digital", "warehouse", "processing"] }); const access = await env.SYNTHETIC_SUPPLIER_ACCESS.listReviews(); const recovery = await env.SYNTHETIC_RECOVERY.getEvidenceSummary(); app.render(ExposureResilience, { exposure, access, recovery });
The center is ready. Containment, account changes, production actions, supplier decisions, and readiness attestations remain human-approved.
Create a 90-day ransomware and recovery readiness brief for Marmon/Keystone. Address identity and remote access, warehouse and processing asset ownership, IT and operational boundaries, backup and restore evidence, and incident communications.
AI
I'll use curated company context and request only the resources needed for this workspace.
Gatekeeper: Asset Inventory + Recovery Evidence
Read-only access to simulated asset ownership, service dependencies, remote-access reviews, recovery tests, and decision records. No production telemetry or personal information is included.
AI
The brief turns recovery objectives into company-owned evidence, deterministic checks, explicit exceptions, and reviewable human decisions.
Create a governed security automation review for alert and incident evidence triage, vulnerability remediation evidence packs, and supplier access reviews. Use code for deterministic steps and models only where judgment adds value.
AI
I'll use curated company context and request only the resources needed for this workspace.
Gatekeeper: Synthetic Security Data + AI Gateway
Read-only access to simulated alert, vulnerability, supplier-access, evaluation, and aggregate spend metadata. No prompts, credentials, personal information, or production records are exposed.
AI
Executed deterministic query
const candidates = await env.SYNTHETIC_MODEL_REGISTRY.list({ domain: "security-operations", include: ["owner", "evals", "risk-tier"] }); const spend = await env.SYNTHETIC_AI_GATEWAY.aggregate({ by: "candidate", include: ["budget", "rate-limit"] }); deck.render(SecurityAutomationReview, { candidates, spend });
The review is ready. AI may classify, summarize, or draft; accountable people retain every containment, access, supplier, and remediation decision.
Manufacturing Exposure & Resilience Center
Live App
Illustrative data. Every exposure, finding, score, status, and event is synthetic. Public operating facts do not describe Marmon/Keystone systems, security posture, incidents, or performance.
27+
Publicly stated locations
4
Synthetic exposure queues
6
Governed demo resources
3
Illustrative approvals
Attention queue
Review: A synthetic vendor access path needs owner verification before any disable action.
Monitor: Illustrative restore evidence requires operations review before changing the readiness status.
Synthetic readiness by operating surface
Online quoting and customer accounts
92%
Complete
Warehouse and distribution systems
84%
Monitor
Processing and fabrication environments
75%
Monitor
Supplier and remote access
68%
Review
Ransomware & Recovery Readiness Brief
Document
Illustrative planning artifact. Illustrative planning based on public operations and synthetic scenarios, not Marmon/Keystone architecture, controls, incidents, service levels, or plans.

Marmon/Keystone - Ransomware & Recovery Readiness

Illustrative 90-day plan | Draft

Purpose

Protect material planning, quoting, inventory, processing, fulfillment, and customer support by making access ownership, service boundaries, recovery evidence, and escalation paths explicit.

Jobs to be done

PriorityJourney momentRequired review
Identity and remote accessEmployee and supplier connectionsSecurity + operations review
Asset ownership and environment boundariesWarehouse, machining, and fabricationSite leadership + engineering review
Recovery and communicationsRestore quoting, inventory, and fulfillmentContinuity + legal review

Operating principles

  • Start with a measurable job to be done, not a new tool.
  • Use curated company context before model knowledge.
  • The human owner remains accountable for every output.
  • An agent never receives more permission than the person using it.
Gatekeepers hold credentials, scope every resource, and preserve the observation trail when work is shared.

Delivery sequence

Days 1-30: Map critical services, accountable owners, remote paths, data boundaries, and recovery objectives.

Days 31-60: Exercise synthetic identity, segmentation, restore, and communications scenarios with explicit evidence.

Days 61-90: Close evidence gaps, record accepted exceptions, and schedule repeatable recovery validation.

Control alignment

Least privilege, supplier access expiry, IT and operational separation, immutable evidence, safe recovery testing, legal review, operational safety, and human approval remain mandatory.

Governed Security Automation Review
Slide Deck
Slide 1 of 4

Governed Security Automation Review

Marmon/Keystone OS | Illustrative prototype

Slide 2 of 4

Public-context opportunity areas

Use caseStageHuman ownerNext gate
Alert and incident evidence triageCandidateSecurity operationsAccuracy + escalation tests
Vulnerability remediation evidence packsCandidateTechnology + site ownersValidate source and closure
Supplier and remote-access reviewsExploreVendor risk + operationsConfirm human decision path

Illustrative candidates and synthetic evaluations only. This is not a statement of Marmon/Keystone initiatives, models, deployments, incidents, or performance.

Slide 3 of 4

Governance scorecard

3
Illustrative candidates
3
Evaluation suites
100%
Gateway routed
4
Human action gates

Illustrative target-state controls.

Slide 4 of 4

Next operating loops

Context: curate terminology, policies, and quality criteria.
Evaluation: define task-specific quality, safety, and fairness tests.
Access: bind every data resource through a Gatekeeper.
Efficiency: use code for deterministic work and models only for judgment.

Integrations

Organization-wide connections for Marmon/Keystone OS. Gatekeepers hold credentials, scope resources, and log each action.

Prototype catalog. Connections and authorization states are simulated.
Gatekeepers
1
Productivity suite
Mail, calendar, documents, spreadsheets, and files
2
Collaboration
Chat, channels, meetings, and workflow notifications
3
Project tracking
Programs, epics, issues, sprints, and delivery status
4
Knowledge base
Policies, procedures, standards, and team documentation
5
Service management
IT tickets, incidents, change requests, and asset data
6
HRIS
Employee directory, organization, benefits, and lifecycle workflows
7
ERP & procurement
Finance, planning, purchasing, supply chain, and billing
8
CRM
Customer, account, partner, and service relationship data
9
Code platform
Repositories, reviews, issues, and engineering standards
10
Data platform
Governed warehouse, catalog, analytics, and reporting
11
Security operations
Alerts, cases, exposure, audit, and control evidence
12
Business intelligence
Dashboards, semantic models, and executive reporting
MCP Server Portals

Illustrative remote services available to authorized workspaces.

Security Operations
https://security.mcp.demo.example/mcp
Auto
Enterprise Data Catalog
https://data.mcp.demo.example/mcp
Needs auth
Finance & Procurement
https://finance.mcp.demo.example/mcp
Auto
People Directory
https://people.mcp.demo.example/mcp
Needs auth
Cloudflare API
https://cloudflare.mcp.demo.example/mcp
Auto

Organization Context

Shared, curated knowledge that grounds every Marmon/Keystone OS workspace. Context is versioned and read-only to agents.

Public operating context: marmonkeystone.com · Internal-looking documents below are illustrative.
md
company-strategy.md
Mission, operating model, annual priorities, and outcome definitions
md
brand-and-communications.md
Terminology, voice, accessibility, and approved communication patterns
md
security-standards.md
Identity, data protection, secure development, and incident requirements
md
responsible-ai-standard.md
AI risk tiers, evaluations, human oversight, and acceptable use
md
data-classification.md
Data categories, handling rules, retention, and sharing restrictions
md
architecture-principles.md
Technology standards, decision records, review criteria, and ownership
md
vendor-risk.md
Due diligence, contract controls, monitoring, and exit requirements
md
customer-experience.md
Journey definitions, service standards, and quality measures
md
operations-playbook.md
Service ownership, runbooks, escalation, continuity, and recovery
md
finance-controls.md
Planning, purchasing, expense, audit, and reporting procedures
md
people-policies.md
Hiring, onboarding, performance, leave, and workplace guidance
md
legal-and-compliance.md
Review paths, records, privacy, accessibility, and regulatory obligations

Skills

Reusable workflows for every function. The human requester owns the result.

NameDescriptionGroupSource
meeting-prepBuild an agenda and briefing from authorized calendar, CRM, and document contextGeneralShared library
weekly-operating-reviewCreate a cross-functional summary with decisions, owners, and open risksGeneralShared library
incident-responseAssemble evidence, draft updates, and preserve human approval for containmentSecurityShared library
vendor-risk-reviewCompare due-diligence evidence with security and privacy standardsSecurityShared library
control-evidence-packMap authorized evidence to control requirements and identify gapsSecurityShared library
architecture-reviewReview a proposal against architecture principles and decision criteriaIT & ArchitectureShared library
change-impactMap dependencies, affected services, stakeholders, and rollback requirementsIT & ArchitectureShared library
service-health-reviewSummarize service levels, incidents, changes, and capacity risksOperationsShared library
runbook-builderTurn a procedure into a deterministic workflow with approval gatesOperationsShared library
ai-model-reviewSummarize ownership, evaluations, drift, risk tier, and release readinessData & AIShared library
data-quality-reportAssess freshness, completeness, lineage, and policy complianceData & AIShared library
budget-varianceCompare actuals with plan and draft a finance-reviewed variance narrativeFinanceShared library
procurement-briefSummarize requirements, alternatives, risk, and approval statusFinanceShared library
job-descriptionDraft an accessible role description from approved job architectureHRShared library
onboarding-planCreate a role-based onboarding plan without expanding system permissionsHRShared library
contract-intakeExtract terms, route issues, and prepare a legal review checklistLegalShared library
privacy-assessmentMap a proposed workflow to data categories and privacy obligationsLegalShared library
account-briefCreate a customer briefing from authorized CRM and public informationSalesShared library
proposal-draftBuild a first draft using approved claims, pricing, and brand contextSalesShared library
executive-updateTurn project evidence into a concise decision-oriented updateGeneralShared library

Profile

Illustrative account information for this public prototype.

Demo User
No personal information is stored
Display name
Demo User
User ID
demo.user@example.com

AI Gateway

Illustrative demo data. Visibility and controls across every AI provider Marmon/Keystone uses — one console.

Requests
128,400
▲ 11% vs last mo
Tokens
342M
▲ 8% vs last mo
Est. spend
$9,120
76% of budget
Cache-hit
27%
▲ saves ~$2.4k
Error rate
0.6%
▼ 0.2 pts
p50 latency
480 ms
across providers

Models in Use

This month
ModelRouteTokensSpendSharep50 latency
Llama 3.3 70BWorkers AI156M$2,140310 ms
Claudevia AI Gateway98M$3,980720 ms
GPT-4ovia AI Gateway61M$2,510640 ms
Workers AI embeddings (bge)Workers AI27M$19040 ms

Spend vs. Budget

9 days remaining
$9,120spent of $12,000 cap
76%
On track · ~$2,880 left with 9 days
Top Users
Demo User 0142M tok $1,180
Demo User 0231M tok $960
Demo User 0328M tok $840
Demo User 0422M tok $610

Usage by Workspace / Team

342M tokens total
AI Enablement
121M tokens · $3,240
Platform Engineering
89M tokens · $2,460
Customer Experience
62M tokens · $1,510
Enterprise Operations
41M tokens · $1,020
Security & Compliance
29M tokens · $890
Model observability & controls powered by Cloudflare AI Gateway

Governance

Guardrails enforced by Gatekeepers + AI Gateway, with resource-scoped access, audit trails, and human approval.

Per-team allowed models

Restrict which providers each workspace can call.

Llama 3.3ClaudeGPT-4o+ embeddings

Monthly spend caps

Hard limits per team; agents stop before overrun.

Data & AI $4,000Platform $3,000

PII redaction

Strip sensitive fields from prompts before they leave.

Enabled

Prompt / response logging

Full request logs retained for audit & review.

Enabled · 90-day retention

Rate limits

Per-team request ceilings to protect budgets.

600 req / min|burst 1,000

Raise Data & AI cap to $6,000

Change queued by an agent — needs a human sign-off.

Requires approval

AI Gateway Explorer

Explore aggregate model traffic for This month.

4 models
ModelRouteTokensSpendSharep50
Llama 3.3 70BWorkers AI156M$2,14042%310 ms
ClaudeAI Gateway98M$3,98024%720 ms
GPT-4oAI Gateway61M$2,51018%640 ms
Workers AI embeddings (bge)Workers AI27M$19016%40 ms

Review spend cap change

AI Enablement · Monthly spend cap

Current cap$4,000
Requested cap$6,000

Change queued by an agent — needs a human sign-off. Approval updates this demo for the current session only.