Colleagues in an operations room reviewing an assistant's proposed actions on wall displays, one approving on a tablet.

// Solutions · Agentic AI

AI that does the work — inside the rules you already have.

A chatbot answers questions. An agent prepares the work: it finds the record, drafts the response, assembles the requisition, and hands it to the person whose decision it actually is. Nothing it does exceeds the permissions of the person it acts for, and every retrieval and action it takes is recorded — so adopting it does not mean loosening your controls.

Retrieve · Prepare · Await approval · Record

// The trace

Everything it did, in the order it did it.

One question, followed all the way through. Note where it stops: the agent assembled the follow-up and then waited, because sending it was somebody's decision to make.

Agent interaction · audit view

Awaiting approval
  1. 01 Asked

    Which purchase orders are still waiting on goods receipt?

    Procurement officer

  2. 02 Retrieved

    14 purchase orders · 3 goods-receipt notes

    Scoped to Procurement

  3. 03 Checked

    2 records outside the division withheld

    Permission boundary

  4. 04 Prepared

    Draft follow-up to 3 suppliers · not sent

    Awaiting a person

  5. 05 Paused

    Approval required before anything leaves the building

    Procurement manager

  6. 06 Recorded

    Interaction logged with full retrieval trace

    Audit log

Illustrative interaction · example data, not a client system

// The three questions

Where it reads, who decides, what is kept.

A professional at a desk with a hand resting on printed company records beside a laptop, archive binders behind them. 01 · Retrieve

From your records, not the internet.

The agent reads your contracts, policies and transactions — and only the ones the person asking could already open. Where it cannot find an answer it says so instead of composing a plausible one.

A senior manager pausing with a stylus above a tablet, deciding whether to approve, while a colleague waits opposite. 02 · Approve

The decision stays a person's.

Consequential steps are prepared and held. A named approver reviews, edits if needed, and commits — so when someone asks who authorised it, the answer is a person, not a model.

A compliance professional at a dual-monitor workstation reviewing a long list of records with a notepad in hand. 03 · Record

Reviewable long after the fact.

Every question, retrieval and action is logged with who asked and what was reached — so an auditor who was not in the room can reconstruct what happened and why.

Layered translucent panels receding into darkness, one lit brighter than the rest.

An agent that can do anything is not a capability — it is an unowned risk. The useful question is not how much autonomy it has, but exactly where it stops.

Our position on agentic AI

// What you get

Agents that act, within limits you set.

Each capability below exists to answer the same objection: how do we get the leverage without handing an autonomous system the keys to the business.

Answers From Your Own Records

Agents answer from your documents, policies and transactional data rather than from general web knowledge — and only from the slice the person asking is allowed to see.

  • Grounded in your own data
  • Scoped to the asker's access
  • Cites the record it used
  • Says "not found" instead of guessing

Draft-Then-Approve Execution

The agent prepares the requisition, the reply, the journal or the schedule and stops. A person reviews and commits it, so accountability stays with a named human.

  • Prepared, not posted
  • Named approver on every action
  • Edit before committing
  • Nothing consequential auto-runs

Permission-Bound By Design

An agent inherits the rights of the person it is acting for — it cannot read a salary, approve above a limit or see another division's records just because it was asked nicely.

  • Inherits the user's own rights
  • No privilege escalation path
  • Authority limits still apply
  • Sensitive fields stay redacted

Work That Crosses Departments

Because the records sit on one platform, an agent can follow a question from a purchase order to the invoice to the payment without four integrations in between.

  • One data fabric underneath
  • Follows a record across modules
  • Triggers the next step for review
  • No per-department AI silo

A Trail You Can Audit

Every retrieval, tool call and outcome is logged with who asked, what was reached and what happened — reviewable after the fact by someone who was not in the room.

  • Per-interaction audit log
  • Retrieval & tool-call trace
  • Reviewable right/wrong marking
  • Evidence for ISO 27001 / 42001 work

Your Choice Of Model

Run on leading commercial models or on private self-hosted open-weight models. Capability, cost and where your data is processed stay your decision.

  • Commercial or self-hosted
  • Swappable model layer
  • Data-residency constraints honoured
  • No lock-in to one vendor

// How we get there

One use case, proven, then widened.

Agent programmes fail when they start as a platform rollout. We start with a single task that costs you real hours, and earn the next one.

  1. 1

    Qualify

    Pick a task with a measurable cost today — the report compiled by hand, the enquiry answered five times a day. Agree what "better" means before building.

  2. 2

    Ground

    Connect the records the agent must read, define the permission boundary it inherits, and decide explicitly which steps a human must always confirm.

  3. 3

    Pilot

    Run with one team in draft-then-approve mode. Their corrections are the evaluation set — where it was wrong matters more than where it was impressive.

  4. 4

    Widen

    Once accuracy holds on real volume, extend to adjacent tasks and relax confirmation only where the audit trail justifies it.

// FAQ

What leaders ask before saying yes.

Will it act without us knowing?

No. Anything consequential is prepared and left for a person to commit, and every retrieval and action is logged whether or not it was approved. If you later want a narrow, well-understood step to run unattended, that becomes a deliberate decision with the audit trail already in place — not the default.

Can it see things the person asking should not?

No. The agent inherits the permissions of the user it is acting for, so it cannot reach a record, a salary figure or another division's data that the person could not open themselves. Sensitive fields are redacted before anything reaches the model.

Does our data go to train someone else's model?

Not on our architecture. Where a commercial model is used it is called under terms that exclude training on your content, and where that is not acceptable to you the same agent can run on a self-hosted open-weight model instead.

Do we have to take the whole platform to use one solution?

No. Each solution is a configured slice of the same platform, so you can start with one department and add another later without a migration or a second integration to maintain. What you do get from the start is one data fabric underneath — so when the second solution arrives it already recognises your people, approvals and records.

Can this work alongside the systems we already run?

Yes. Most engagements leave existing line-of-business systems in place and integrate with them through APIs, scheduled syncs or event feeds. Where an existing system is genuinely the blocker we will say so, and that becomes an Application Modernization conversation rather than something we quietly work around.

// Get started

Bring one task, not a strategy.

Name the job somebody on your team does by hand every week. That is a better starting point than a shortlist of AI features.