The workbench

The console one senior team runs an engagement from.

Specialized agents and fine-tuned models give an engagement machine scale. A senior operator carries the judgment on every finding. The workbench is where the two meet.

// what it is

The operator console for adversarial engagements.

Serpio runs its adversarial engagements from one internal console. Specialized agents and fine-tuned models put the known attack classes to a target at machine scale. Senior operators scope the work, clear every high-impact gate by hand, and rate every finding against a fixed rubric. The workbench stays with Serpio: clients read results, they do not operate it.

// the console

One engagement, in view.

A crew of agents runs in dependency order against the agreed scope and stops the moment it reaches a step that would act with real authority. What follows is an illustrative run: client identity is sealed, the codes and packs are placeholders.

Run

run_8f3c1a · crew track_a · blocked on gate · 3 of 7 steps done

StepAgent and packStatus
scopescope.ingestdone
reconrecon.surface, read-only surface mapdone
attack_promptattack.prompt, pack llm.indirect_injection.v1done
attack_agentattack.agent, pack agent.tool_exfil.v1, high-impactawaiting human gate
judgejudge.evalpending
evidenceevidence.packpending
reportreport.draftpending
FIG. · the operator console
Runs

A crew of agents executes in dependency order against the agreed scope. Each step records what ran and against which asset.

Human gates

Every high-impact step stops at a gate. A named operator approves it before anything acts with real authority, and no agent can clear its own gate.

Findings

Each finding is rated on three axes: impact, exploitability, and authority, with impact weighted double. Severity follows from the score, not from feel, and a finding with no demonstrated exploit stays Info.

Coverage over time

Attack classes exercised by a pack and classes demonstrated by a recorded finding, tracked across cadences as an auditable number rather than an adjective.

Audit trail

Run starts, steps, gate requests, and gate decisions append to the engagement log. The record is append-only: a decision cannot be edited after the fact, and a denial cannot be flipped to an approval.

The workbench, its attack packs, and the models under it stay with Serpio. They are not shipped, licensed, or run on client infrastructure. What the client receives is a read-only record of one engagement: the report, the findings, and the evidence bundle.

// how it powers every engagement

Authored once, run for many.

Operators author an attack pack once, versioned and mapped to a named coverage class, and the workbench runs it against many targets. That is what lets one senior team hold depth and scale at the same time: the machine carries the repeatable work, the operator carries the judgment. The client reads the results in the engagement record and never touches the console.

// the subscriptions it enables

Standing coverage, two ways.

The same console backs two recurring offers, one operator-driven and one automated.

Continuous Assurance

Senior-led, on a cadence

The retainer. Standing adversarial coverage against a fixed set of named assets, re-run on a cadence, with findings tracked to closure and re-tested as your systems change. A senior operator drives every attack, rates every finding, and clears every gate.

It is the premium tier. You receive a read-only engagement record on every cadence: runs, findings, coverage over time, and the evidence bundle for every finding, replayable by your own team.

Continuous Red Team · early access

Automated packs on a cadence

Versioned attack packs run against your staging or model endpoint on a schedule. It exercises the known, published attack classes, reports coverage over time, and raises a regression alert when a class that was closed reopens. Lower marginal cost, because it runs on compute rather than senior-operator weeks.

It is not the deep human red team: it runs the published classes, it does not discover new ones or judge novel findings. That depth stays with Continuous Assurance.

Ask about early access

Bring us a system to break.

The workbench runs behind every Serpio engagement. Start with a scoped adversarial test, or ask about continuous coverage.

Scope an engagement