About Portfolio Cases Services Blog Contact 🎙 Talk to AI
EN DE RU
🎙 Talk to AI
October 1, 2026 · 3 min read

OpenAI Dots: Your AI Agent Works 24/7 Even When You're Offline — How to Deploy and What Are the Business Risks

I'm Denis Shokhirev, Agentic AI Systems Architect in Freiburg, running DennisCraft AI Studio. I deploy autonomous multi-agent systems for DACH B2B clients—logistics, fintech, industrial automation—using Claude, Supabase, n8n, Doppler, and self-hosted Postgres. In production, agents operate 24/7, even if no one is watching. That's where the real risks (and value) emerge. Why “24/7 Agents” Are Not Just Slack Bots Most demos run only on manual triggers or in sandboxes. In production, agents proc

Denis Shokhirev
Denis Shokhirev
Agentic AI Systems Architect
Telegram LinkedIn

I'm Denis Shokhirev, Agentic AI Systems Architect in Freiburg, running DennisCraft AI Studio. I deploy autonomous multi-agent systems for DACH B2B clients—logistics, fintech, industrial automation—using Claude, Supabase, n8n, Doppler, and self-hosted Postgres. In production, agents operate 24/7, even if no one is watching. That's where the real risks (and value) emerge.

Why “24/7 Agents” Are Not Just Slack Bots

Most demos run only on manual triggers or in sandboxes. In production, agents process real business events, interact with customer APIs, write directly to Postgres, and orchestrate flows via n8n—often autonomously. My live agent at live.gerdennisai.com is public; you can see its actions in real time.

  • The agent doesn’t wait for a user—it monitors and reacts to events.
  • Stability under error, data drift, and cloud outages is mandatory.
  • The real question isn’t “does it demo well,” but “will it survive in prod?”

Architecture: How OpenAI Dots Work in Real Production

1. Event-driven Pipeline

Core pattern: events (order, anomaly, inbound email) go into a queue—Supabase Realtime or webhook into n8n. The agent picks up tasks and triggers workflows. All actions and context are logged to self-hosted Postgres for traceability—a must for audit trails.


import supabase_py
from n8n_python import N8NClient

supabase = supabase_py.create_client(url, key)
n8n = N8NClient(api_url, token)

# Fetch new events
events = supabase.table('events').select('*').execute()
for event in events.data:
    if event['type'] == 'order_created':
        n8n.trigger_workflow('process-order', payload=event)

2. Orchestration via n8n and Claude

n8n handles integration and workflow steps. Claude (via API) processes natural language, decision logic, and output. Doppler handles secrets to avoid token leakage—never hardcode secrets in source or logs. State and logs always go to Postgres for recovery and compliance.

  • n8n: orchestrates external API calls and workflow steps.
  • Claude: LLM-based processing, prompt-based actions.
  • Supabase/Postgres: durable state, logs, audit trail.

3. Monitoring, Idempotency, Rollbacks

Idempotency is critical—agents must safely retry events without duplicate side effects. I log all intermediate outputs and prompts to a dedicated table. Rollbacks become possible, and incident forensics are straightforward.


CREATE TABLE agent_events (
  id SERIAL PRIMARY KEY,
  event_type TEXT,
  payload JSONB,
  status TEXT,
  created_at TIMESTAMP DEFAULT now()
);

CREATE TABLE agent_prompts (
  id SERIAL PRIMARY KEY,
  event_id INT REFERENCES agent_events(id),
  prompt TEXT,
  response TEXT,
  created_at TIMESTAMP DEFAULT now()
);

What Breaks in Production: Key Risks

Risk Description Mitigation
SQL Injection LLMs generate DB queries from user input. On three recent deployments, I found CWE-89 patterns in agent-generated code. Static analysis (semgrep, bandit), strict prompt validation, runtime sandbox.
Data Leakage LLMs or Claude pass sensitive client data in prompts without redaction. Doppler for secrets, n8n filters, OWASP guidance.
Event Loops Agents get stuck retrying bad events (e.g., invalid order status). Idempotency checks, max retry limits, n8n alerting.
API Lockout Excess requests—rate limits kick in, API blocks agent. Rate limiting in n8n, throttling, error monitoring.

Security & Audit: What Works in Practice

Static Analysis and Runtime Sandbox

Static analysis (bandit, semgrep) can’t catch all prompt-related injection risks. Bandit’s own docs (2024) warn of this. I add a runtime sandbox in n8n—every agent action is logged and suspicious cases are routed to manual review.

Prompt and Action Logging

All prompts and LLM responses go to a dedicated Postgres table. For banking and logistics clients, this is non-negotiable. If an incident occurs, you can reconstruct the full chain of events.

Input Validation

I validate all incoming data with pydantic (Python) or zod (TypeScript)—never pass raw webhook payloads to the agent.


from pydantic import BaseModel

class OrderEvent(BaseModel):
    order_id: int
    status: str
    customer_email: str

# Validate before agent execution
event = OrderEvent.parse_obj(raw_data)

FAQ

What SLA can you expect from 24/7 agent setups?

In my projects: 99.7% uptime on integration layers (n8n + Supabase), but only with active monitoring and human review for edge cases.

Can you fully prevent LLM data leakage?

No. Even with Doppler and n8n filters, complex prompts can leak data. Only audit trails and human review reduce this risk to a minimum.

What LLMs actually ship in regulated EU sectors?

Claude (Anthropic), GPT-4 (Azure OpenAI), self-hosted models via API gateway. Always behind an API gateway with full log control.

How do you automate rollbacks of agent actions?

Persist every operation in Postgres with unique event_id—rollback only the chain that triggered the error.

What if the agent goes silent?

Have fallback logic in n8n (e.g., human notification) and heartbeat monitoring in a dedicated DB table.

Which part of your agent pipeline catches the most bugs in production: static analysis, runtime sandbox, or human review? I’d genuinely like to know. I run a free 30-min stack audit for DACH founders building AI in regulated markets. DM me on LinkedIn or write to @ger_dennis_ai.

Continue reading
AI Agents Now Jailbreak Each Other: Real-World Self-Replicating Prompt Injection and How to Defend Production
Why Your AI Agents Go Dumb or Rogue in Production: Real Fails of Self-Learning and Evolution Loops
AI Coding Agents: 24 Plugins, 49 Agents, 44 Skills — How to Automate Everything
OpenAI AI Agents Leaked Private Data: How to Protect Your Production from Automated Breaches
All articles →
Where this is applied
Services — what we build
Talk to the voice agent
Case studies
Ready to build?

Turn your process into an AI system

Production quality. DACH B2B focus.

Start a project → ← All articles