Overwing Tower
Clearance for agents on the systems that run the business.
The people who know the green screens are retiring. The agents that could replace the keystrokes get blocked for not identifying themselves, or trusted with writes nobody can audit. Tower sits between them: agents call typed operations, Tower decides whether each write runs on its own, needs a person, or is refused, and signs a receipt for every step.
First target: IBM i (AS/400) order entry at mid-market distributors. Ships with a template workflow and a mock adapter you can try today.
Four principles
Every design choice follows from these.
Machine-native
Typed operations with JSON Schema inputs, structured errors that name the field, dry runs, idempotency keys, and a capabilities endpoint. No prose in any agent-facing response.
Permissions
Every agent gets its own identity and key, scoped to the operations it may call. Policies gate writes: hard gates, weighted questions, and deterministic checks that never touch a model.
Recovery
Idempotent retries return the original result. Every write can declare a compensating operation. Anything uncertain lands in a human review queue with a plain-English summary.
Receipts
Every decision, action, review and compensation is a signed link in a per-organization hash chain. An auditor with the public key can verify the whole history offline.
Example
A purchase order arrives by email. What happens next.
The agent reads the PO, looks up the customer, and calls create_order with typed input: lines, total, ship-to, the customer’s credit limit and history.
Fixed rules run first, in code. Required fields present, total under the credit limit. A failure here is a rejection with a structured reason, and no model was involved.
Then the policy asks TypeSafe’s Jev four questions: does this match the customer’s normal pattern, is the ship-to consistent with their history, which intent is this, and how sure are we the lines map to real SKUs. Each answer comes back typed, with a probability and a confidence.
Tower combines them. A confident wrong intent is a hard gate and rejects. Otherwise the weighted score decides: above the auto threshold the order is entered and receipted; in the review band a person sees a plain-English summary and approves or rejects; below the floor it is refused.
If it later turns out wrong, the agent or a person calls compensate, and the defined compensating operation, here cancel_order, runs and is receipted too.
POST /api/v1/tower/actions
Authorization: Bearer ow_agent_…
{ "operation": "create_order",
"idempotency_key": "po-88213",
"input": { "customer_id": "C04471", "po_number": "PO-88213",
"lines": [{ "sku": "FLT-2040", "qty": 24, "unit_price": 12.5 }],
"total": 300, "source": { "channel": "email", "excerpt": "…" },
"customer": { "credit_limit": 25000, "avg_order_total": 640 } } }
202 Accepted
{ "action_id": "…", "status": "pending", "review_id": "…",
"decision": {
"outcome": "review", "score": 0.71, "provider": "jev",
"results": [
{ "question_id": "normal_pattern", "answer": false, "confidence": 0.62, "passed": false },
{ "question_id": "ship_to_consistent","answer": true, "confidence": 0.91, "passed": true },
{ "question_id": "intent", "answer": "new_order", "confidence": 0.97, "passed": true },
{ "question_id": "sku_confidence", "answer": 3, "confidence": 0.88, "passed": true } ],
"checks": [ { "check": "credit_limit", "passed": true } ] } }Pricing
Pay per executed action. Deciding is free.
Separate from the guardrails and Atlas plans. One organization can hold any combination.
Pilots with a real IBM i or SAP system need an on-prem adapter that connects outbound to Tower; that is scoped per pilot. Book a pilot and we will walk through your first workflow together.