Contracts and delegated authority
The system begins with principals, entities, agreements, policies, budgets and named approval owners. No agent receives authority through implication.
Agentic operating architecture
Provider-neutral skills, deterministic workflows and evidence receipts survive model turnover. Existing ERP and business systems remain authoritative until a controlled write-back gate says otherwise.
System layers
The model is replaceable. The durable asset is the operating graph that binds organisations, contracts, identities, assets, workloads, approvals and evidence.
The system begins with principals, entities, agreements, policies, budgets and named approval owners. No agent receives authority through implication.
Separate organisations, service accounts, secrets, memory, budgets, repositories and queues. Shared infrastructure never means shared access.
ERP, shop, CRM, documents, email, finance preparation, facilities and energy enter through read-first, typed interfaces.
Parties, assets, contracts, workloads, orders, approvals, evidence and revenue streams receive stable identifiers and provenance.
Deterministic workflows handle repeatable state transitions; agents research, classify, draft and reason inside explicit boundaries.
Local inference, cloud frontier models and specialist providers are selected by sensitivity, quality, latency, resilience and measured cost.
Owners see decisions, economics, incidents, obligations and proof—rather than a stream of autonomous activity without accountability.
Existing IT estate
Initial access is read-only. The system learns the company's actual object model and exceptions before any agent can change prices, inventory, contracts, finance or customer commitments.
Catalogue systems, data owners, interfaces, identities, manual workarounds and contractual constraints.
Create read-only connectors and event capture. Establish baseline quality before changing production state.
Map source objects into typed canonical records with source references and freshness policies.
Run recommendations beside current human workflows. Record disagreement, exceptions and missing evidence.
Grant narrow write actions only after acceptance tests, rollback and a named authority owner.
Reusable skill estate
Each skill declares inputs, outputs, authority, stop conditions, proof obligations and handoff. The repository files are executable operating specifications—not loose prompts.
Decision. Is this counterparty, asset base and mandate worth entering?
Output. Partner score, red flags, data-room request and stop/go memo.
Recommend only. Legal, credit and investment approval remain human.Decision. Which workloads justify local, cloud or hybrid capacity?
Output. Demand baseline, data classification, latency profile and utilization envelope.
May classify and model; cannot buy capacity or promise savings.Decision. Which commercial structure separates value, control and risk cleanly?
Output. Deal memo, party graph, consideration map and stage gates.
Produces options; principals approve economics and control rights.Decision. Which agreements and schedules make the operating bargain explicit?
Output. Clause issue list, document matrix, dependencies and counsel brief.
Never issues legal advice or executable agreements without counsel review.Decision. How does the system attach to the existing estate without destabilising it?
Output. System inventory, trust boundaries, connector plan and write-back gates.
Read-only discovery by default; production writes require named approval.Decision. Which cost belongs to operating cash, lease, debt, subsidy review or equity?
Output. Sources-and-uses model, financing pack and covenant questions.
Planning support only; lenders, tax advisers and principals decide.Decision. What is purchased now, deferred or rented?
Output. Bill of materials, quote comparison, warranties, acceptance tests and asset register.
May prepare orders; cannot bind a company without delegated authority.Decision. Is the physical and digital estate healthy, secure and within its service envelope?
Output. Runbook, health state, incident record, capacity ledger and maintenance queue.
May execute reversible runbook actions; consequential actions escalate.Decision. Which verified capability becomes an internal saving, service or external offer?
Output. Offer design, pricing evidence, pipeline and contribution-margin view.
Drafts and analyses; pricing and customer commitments require approval.Decision. Can every material claim, action and payment be reconstructed?
Output. Evidence receipts, exceptions, missing approvals and audit-ready timeline.
Append and flag; never rewrites source records.Compute estate
Heterogeneous infrastructure is intentional: reliable workers, private high-memory inference, cloud quality and later CUDA throughput solve different constraints.
| Class | Reference form | Economic role | Purchase trigger |
|---|---|---|---|
| Always-on worker nodes | Mac mini-class or equivalent | Browser, repository, scheduling, observability, lightweight services and resilient orchestration. | Pilot-approved after workload baseline |
| Private-memory node | High-memory AMD / unified-memory class | Confidential retrieval, embeddings, document intelligence and larger quantised models without default cloud transfer. | Pilot-approved after workload baseline |
| Cloud burst | Frontier API and hosted accelerators | Irregular high-quality reasoning, coding, vision and peak throughput paid per use. | Metered from day one |
| CUDA production node | NVIDIA workstation or server | Purchased only when measured queues, media workloads, fine-tuning or cost crossover justify ownership. | Measured utilization or revenue crossover |
| Site foundation | UPS, encrypted storage, network, metering | The unglamorous layer that determines recoverability, evidence quality, insurability and total cost. | Measured utilization or revenue crossover |
The architecture aligns with resource-centric zero-trust principles and lifecycle AI risk management. See NIST SP 800-207 and the NIST AI RMF.