# AI Agents

> One operational job, owned end to end, inside your own systems.

We design and build AI agents that own one operational job end to end, inside the systems your team already runs on. Scoped credentials, approvals on anything you can’t take back, and every action on a record your security team can export.

## What this is

An AI agent decides and acts, not just answers. We take one named job, order-status replies, invoice matching, refund triage, and build the whole thing: integration, judgement, exceptions, and the escalation path to a person.

## Why it matters

- You hired people for judgement. They’re spending the day on work that repeats.
- Headcount scales in steps and takes months. An agent absorbs the Tuesday-night spike without a req.
- The risk isn’t the model, it’s the blast radius. Scope, approvals, and audit trails are design decisions.

## How we approach it

### Workflow teardown

Thirty minutes on one process. You leave with the job worth automating, the systems it touches, and an honest verdict, including “not this one, yet”.

### Shadow mode

It runs beside your team on real volume and decides nothing, so you watch accuracy on your own cases before a customer ever sees it.

### The gate

It goes live only when it clears the number we agreed up front. If it can’t clear it, you don’t pay the final milestone.

### Handover

The code, the prompts, the evaluation set, the runbook. Your engineers can maintain it without us, and you are never locked in.

## What we believe

### One job, owned

Not an assistant, not a copilot. A named job with a number attached, finished end to end or handed to a person.

### Show your work

An agent nobody can inspect is an agent nobody signs off. Every step, source, model version, and decision stays on the record.

### Least privilege, always

A badge for one job, never a master key. If a permission can’t be justified line by line, the agent doesn’t get it.

## Capabilities

- Support & Triage
- Back-office Automation
- Systems Integration
- Evaluation & Red-teaming
- Audit & Access Design
- In-product Agents

## FAQ

### Which models do you call, and do they train on our data?

You get the provider and pinned version in writing, on zero-retention terms, so nothing is kept or used for training. Prefer it entirely on your own contract? We build against your provider account, and the data never touches ours.

### What can it do without a human clicking approve?

Read and draft. Anything that moves money, changes a record, or leaves your systems waits for a named approver, and we agree that line with your team before we build.

### What if a ticket contains instructions telling it to leak data?

Content the agent reads is treated as data, never as orders, and its tools stay scoped so there’s nowhere to leak to. Hostile cases go into the evaluation set before go-live, not after an incident.

### Can we see the audit trail?

Every tool call is logged with its inputs, sources, model version, outcome, and approver, append-only and exportable to your SIEM. The agent gets no permission to edit its own record.

### Are you SOC 2 certified?

No. SOC 2 is an attestation, not a certification, and we don’t hold one. We’re a studio: we build inside your infrastructure, under your DPA and your controls, and usually never hold your data at all. We’ll answer your questionnaire line by line.

### What happens when it gets something wrong?

It stops and hands over with the context attached. Being wrong quietly is the one failure we design against absolutely, so uncertainty routes to a person instead of a guess.

### Who owns it once it’s live?

You do. Code, prompts, evaluation set, and runbook, handed over with a walkthrough. Keep us on retainer if it’s useful, but nothing stops working when the engagement ends.

### How long, and how is it priced?

A scoped pilot in weeks, not quarters, at a fixed price per phase agreed up front. Teardown first, then the build, then the gate. No usage surprises, no hourly meter.
