OpenAI Dots: Your AI Agent Works 24/7 Even When You're Offline — How to Deploy and What Are the Business Risks
I'm Denis Shokhirev, Agentic AI Systems Architect in Freiburg, running DennisCraft AI Studio. I deploy autonomous multi-agent systems for DACH B2B clients—logistics, fintech, industrial automation—using Claude, Supabase, n8n, Doppler, and self-hosted Postgres. In production, agents operate 24/7, even if no one is watching. That's where the real risks (and value) emerge. Why “24/7 Agents” Are Not Just Slack Bots Most demos run only on manual triggers or in sandboxes. In production, agents proc
I'm Denis Shokhirev, Agentic AI Systems Architect in Freiburg, running DennisCraft AI Studio. I deploy autonomous multi-agent systems for DACH B2B clients—logistics, fintech, industrial automation—using Claude, Supabase, n8n, Doppler, and self-hosted Postgres. In production, agents operate 24/7, even if no one is watching. That's where the real risks (and value) emerge.
Why “24/7 Agents” Are Not Just Slack Bots
Most demos run only on manual triggers or in sandboxes. In production, agents process real business events, interact with customer APIs, write directly to Postgres, and orchestrate flows via n8n—often autonomously. My live agent at live.gerdennisai.com is public; you can see its actions in real time.
- The agent doesn’t wait for a user—it monitors and reacts to events.
- Stability under error, data drift, and cloud outages is mandatory.
- The real question isn’t “does it demo well,” but “will it survive in prod?”
Architecture: How OpenAI Dots Work in Real Production
1. Event-driven Pipeline
Core pattern: events (order, anomaly, inbound email) go into a queue—Supabase Realtime or webhook into n8n. The agent picks up tasks and triggers workflows. All actions and context are logged to self-hosted Postgres for traceability—a must for audit trails.
import supabase_py
from n8n_python import N8NClient
supabase = supabase_py.create_client(url, key)
n8n = N8NClient(api_url, token)
# Fetch new events
events = supabase.table('events').select('*').execute()
for event in events.data:
if event['type'] == 'order_created':
n8n.trigger_workflow('process-order', payload=event)
2. Orchestration via n8n and Claude
n8n handles integration and workflow steps. Claude (via API) processes natural language, decision logic, and output. Doppler handles secrets to avoid token leakage—never hardcode secrets in source or logs. State and logs always go to Postgres for recovery and compliance.
- n8n: orchestrates external API calls and workflow steps.
- Claude: LLM-based processing, prompt-based actions.
- Supabase/Postgres: durable state, logs, audit trail.
3. Monitoring, Idempotency, Rollbacks
Idempotency is critical—agents must safely retry events without duplicate side effects. I log all intermediate outputs and prompts to a dedicated table. Rollbacks become possible, and incident forensics are straightforward.
CREATE TABLE agent_events (
id SERIAL PRIMARY KEY,
event_type TEXT,
payload JSONB,
status TEXT,
created_at TIMESTAMP DEFAULT now()
);
CREATE TABLE agent_prompts (
id SERIAL PRIMARY KEY,
event_id INT REFERENCES agent_events(id),
prompt TEXT,
response TEXT,
created_at TIMESTAMP DEFAULT now()
);
What Breaks in Production: Key Risks
| Risk | Description | Mitigation |
|---|---|---|
| SQL Injection | LLMs generate DB queries from user input. On three recent deployments, I found CWE-89 patterns in agent-generated code. | Static analysis (semgrep, bandit), strict prompt validation, runtime sandbox. |
| Data Leakage | LLMs or Claude pass sensitive client data in prompts without redaction. | Doppler for secrets, n8n filters, OWASP guidance. |
| Event Loops | Agents get stuck retrying bad events (e.g., invalid order status). | Idempotency checks, max retry limits, n8n alerting. |
| API Lockout | Excess requests—rate limits kick in, API blocks agent. | Rate limiting in n8n, throttling, error monitoring. |
Security & Audit: What Works in Practice
Static Analysis and Runtime Sandbox
Static analysis (bandit, semgrep) can’t catch all prompt-related injection risks. Bandit’s own docs (2024) warn of this. I add a runtime sandbox in n8n—every agent action is logged and suspicious cases are routed to manual review.
Prompt and Action Logging
All prompts and LLM responses go to a dedicated Postgres table. For banking and logistics clients, this is non-negotiable. If an incident occurs, you can reconstruct the full chain of events.
Input Validation
I validate all incoming data with pydantic (Python) or zod (TypeScript)—never pass raw webhook payloads to the agent.
from pydantic import BaseModel
class OrderEvent(BaseModel):
order_id: int
status: str
customer_email: str
# Validate before agent execution
event = OrderEvent.parse_obj(raw_data)
FAQ
What SLA can you expect from 24/7 agent setups?
In my projects: 99.7% uptime on integration layers (n8n + Supabase), but only with active monitoring and human review for edge cases.
Can you fully prevent LLM data leakage?
No. Even with Doppler and n8n filters, complex prompts can leak data. Only audit trails and human review reduce this risk to a minimum.
What LLMs actually ship in regulated EU sectors?
Claude (Anthropic), GPT-4 (Azure OpenAI), self-hosted models via API gateway. Always behind an API gateway with full log control.
How do you automate rollbacks of agent actions?
Persist every operation in Postgres with unique event_id—rollback only the chain that triggered the error.
What if the agent goes silent?
Have fallback logic in n8n (e.g., human notification) and heartbeat monitoring in a dedicated DB table.
Which part of your agent pipeline catches the most bugs in production: static analysis, runtime sandbox, or human review? I’d genuinely like to know. I run a free 30-min stack audit for DACH founders building AI in regulated markets. DM me on LinkedIn or write to @ger_dennis_ai.
Turn your process into an AI system
Production quality. DACH B2B focus.