AI engineering

Beyond the model.Into the business.

Agents, knowledge systems and automation connected to your information and applications. The work is in the permissions, integration, evaluation and operation.

Explore the technology
Engineering focus
01Understand the workflow
02Engineer the controls
03Validate the result
Reference architecture

A governed agent, layer by layer.

How we structure an AI agent that works inside the business. Every layer has a job, an owner and a limit.

  1. People and requests

    Every request carries the identity of the person who made it.

    • Teams
    • Email
    • Web
    • Voice
  2. Agent runtime

    Planning, memory and model routing, with one identity per agent.

    • Orchestration
    • Memory
    • Model routing
  3. Guardrails

    Policy is enforced outside the model. Consequential actions wait for a person.

    • Policy checks
    • Approvals
    • Evaluation
  4. Tools

    Each tool gets the narrowest credential that works.

    • MCP servers
    • APIs
    • Computer use
  5. Enterprise systems

    Existing permissions are respected, never widened.

    • Microsoft 365
    • Line of business apps
    • Databases
  6. Evidence

    Every step leaves a record you can inspect.

    • Audit trail
    • Traces
    • Cost and quality metrics
Reference architecture. The components change with each estate; the layers and their limits don't.

Read the note: Least privilege for AI agents