Capability 07 / Bounded intelligence

The old way is optional.

Give AI a real job.
Keep the keys.

Build a specialist assistant with a clear task, approved knowledge, limited tools, and a human escalation path. Start with what success looks like—not the word “agent.”

Talk about this workflow

The bad clause

Here’s where
work gets stuck.

An agent that can do everything is hard to evaluate and harder to trust. We narrow the job to a repeatable outcome, then define the information it can access and the actions it can propose or take.

An illustrative workflow

An operations assistant reads a structured request, retrieves approved internal guidance, proposes the next step, and asks for approval before changing a record.

The rewrite

Make the next step
the useful one.

01 /

Interpret messy inputs

Turn an email or free-text request into structured fields while preserving the original and flagging uncertainty.

02 /

Find relevant internal knowledge

Retrieve from approved documents within the user’s access boundary, and show the source behind the answer.

03 /

Prepare a controlled next action

Draft an update, task, or reply with the required approval instead of independently making an open-ended commitment.

What changes

Before

The task lives in memory.

Progress depends on somebody remembering to check, copy, chase, or update the next tool.

After

The routine path moves itself.

The agreed event triggers a visible next step with the right context and a clear owner.

Control

The odd case reaches a person.

Missing data, uncertainty, failures, and high-consequence decisions leave the automatic path.

From idea to operating process

How we
make it work.

01

Specify

Name one job, the expected output, the failure cases, and the evidence required for success.

02

Restrict

Choose the available tools, data boundaries, action permissions, and review points.

03

Evaluate

Test normal requests, ambiguous input, malicious instructions, and unavailable tools.

04

Monitor

Track outcomes, costs, failures, and model changes; keep a fallback and stop control.

In the scope

Clear deliverables.
No mystery box.

  • Task specification and permitted actions
  • Approved knowledge and tool connections
  • Structured outputs and review gates
  • Evaluation scenarios and acceptance criteria
  • Usage visibility, escalation, and operating guide

Operating terms

A workflow still needs
adult supervision.

Ownership stays visible.

Accounts, permissions, documentation, and the person responsible for exceptions are agreed before launch.

Running cost is recorded.

Model usage, messaging, hosting, subscriptions, and support effort stay separate from the headline time saving.

Changes get reviewed.

New rules, messages, integrations, and decision boundaries do not quietly drift into production.

The questions
worth asking.

What makes this different from a chatbot?

The scope may include approved tools and structured actions, not just replies. Those actions require their own controls and evaluation.

Which AI model will you use?

We choose during scoping based on the task, data handling requirements, evaluation results, and cost. The brand of model is not the offer.

Can we use our own accounts?

Where supported, client-owned accounts make ownership and running costs clearer. The proposal documents the arrangement and handover.

Connected capabilities

Fix the next
bad habit.

Custom AI agent implementation

An agent is a permission system
with a model inside it.

A business AI agent combines a language model with approved knowledge, instructions, memory or state, and limited tools it can use to retrieve information or perform actions. That power makes boundaries more important, not less.

The starting question is not which model to use. It is which task requires judgment, what evidence the system may rely on, what actions it may take, and when it must stop for human review.

01

Task and decision boundary

Define the exact outcome, permitted inputs, forbidden decisions, stopping conditions, and escalation path. A specialist agent with a narrow responsibility is easier to evaluate and operate than a general assistant expected to understand the entire company.

02

Knowledge, memory, and privacy

Separate approved reference material from conversation history and operational records. Decide what can be stored, for how long, who may access it, how updates are approved, and which information must never enter the model context.

03

Tools and permissions

Each tool should expose the minimum actions and data needed. Read access, draft creation, record updates, communication, and financial or contractual actions carry different consequences. High-impact actions should require explicit confirmation or remain unavailable.

04

Evaluation and runtime control

Test representative, incomplete, misleading, and adversarial inputs. Monitor accuracy, unsupported claims, tool selection, escalation, latency, model usage, and cost. Model updates and prompt changes require regression checks because behaviour can shift.

Choose a workflow when rules are enough

If the process can be expressed as stable conditions and actions, deterministic automation is easier to test, explain, and maintain. Add an AI step only where language or judgment creates material value.

Choose an agent only when action is justified

Retrieval or drafting may solve the problem without autonomous tool use. An agent earns its complexity when multi-step judgment and controlled action improve a measurable workflow enough to justify the additional risk and operating cost.

Enough circling back.

Let’s scope something useful.

We’ll map the workflow, check the constraints, and agree what the first version should do.

Let’s kill the busywork