I run several AI products as one person: Wakeworth (SME valuation, in production), AI Educator (structured AI-adoption learning, in production), Mindscast (product-grounded marketing content, in development), and the operating system underneath them, SA-OS with Hermes, which runs my own operations every day.
The honest answer to "how can one person build and operate multiple AI products" is not "use more agents". Agents are cheap. What is scarce, for a one-person company, is *attention that arrives at the right moment* — and the whole system is built around protecting that.
The shape of the system
Everything that runs on a schedule is declared once in a registry, and a verifier proves every entry is still alive: the executable still exists, the machine ran inside its tolerance, and the registry still matches the scheduler in both directions. I published this mechanism as [schedule-sentinel](https://github.com/yagebin79386/schedule-sentinel) after a security scan of mine died silently for 17 days — a crontab edit had left it pointing at a path that no longer existed, and nothing was responsible for noticing.
Every consequential action — publishing content, changing configuration, deploying an upgrade — stops at an approval gate. The gate is fail-closed: an unanswered request expires as *not approved*, and the expired record deliberately names no decider, so a timeout can never impersonate consent. Decisions land in an append-only daily ledger. I published this protocol as [fail-closed-gate](https://github.com/yagebin79386/fail-closed-gate), including the production bug that taught me its hardest rule: a revived approval card once silently bounced three fresh approvals against a stale archive before anyone noticed.
Code reaches the production box through GitOps reconciliation — a ten-minute loop that converges the runtime to the repository, gates on the test suite, and rolls back automatically when the gate fails. Hand-edits to the live box are overwritten by design.
What one person actually decides
The point of the machinery is that agents do the work while five kinds of decisions stay human: what gets published, what changes the frozen governance tier, what spends money, what touches credentials, and what alters this list itself. Everything else runs unattended — *because* the supervision and the gates exist, not despite them.
What broke, and what it taught
Every mechanism above is a scar. The 17 silent days produced the registry-and-verifier pattern. The three lost approvals produced the explicit supersede rule. A weekly probe job that timed out for weeks produced the principle that a checker that never fires is indistinguishable from a healthy system. I keep a curated map of tools that solve these same problems — approval gates, policy engines, durable execution, audit — at [awesome-governed-agents](https://github.com/yagebin79386/awesome-governed-agents).
Limits of this answer
This is one operator's system, documented from production but still a sample of one. It optimizes for governance and auditability over raw speed; a solo builder who ships one product may not need the registry or the ledger on day one. The mechanisms are published precisely so they can be judged against their code rather than against this description.