AI Procurement Agent
○DesignedPrepares purchases for approval. It reads, compares and drafts, and it never approves or pays for anything itself. This is the worked example used across the platform pages.
Starts at: L2 Approve: a person approves each purchase it prepares.
No ready-made template ships yet. The shape is the one the platform pages describe.
What AI Procurement Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read approved supplier info
- Analyse contracts
- Compare pricing
- Prepare purchase recommendations
- Create draft POs
| - Access unrelated employee data
- Approve its own high-value transaction
- Make payments
- Modify restricted records
| - Purchases above threshold
- Contractual changes
- Sensitive external comms
| - Identity
- Data accessed
- Model used
- Output
- Tools called
- Policy applied
- Decision
- Approval
- Action
- Outcome
|
Customer Refund Agent
◐Starting pointReads a support ticket and the order history, and recommends whether a refund is warranted. A person or a payments system issues it.
Starts at: L1 Assist, moving to L2 Approve for refunds once the recommendations are reliable.
The agent wizard includes a customer-support sample, and workflows have a human-input step you can use as the approval gate. The refund policy and gate are yours to add.
What Customer Refund Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read the ticket and the related order history
- Draft a reply to the customer
- Recommend a refund, a partial refund or none, with the reason
| - Issue a refund or change an account
- Approve its own recommendation
- Promise an outcome to the customer before it is approved
| - Refunds above the threshold set by the process owner
- Goodwill exceptions outside the refund policy
- Any reply that admits liability
| - Ticket and order fields read
- Model used and the recommendation
- Policy applied
- Approver and decision
- Action taken by the human or the payments system
- Outcome
|
Access Review Agent
○DesignedPrepares periodic access reviews. It finds access that looks stale or too broad and puts a clear pack in front of each reviewer.
Starts at: L2 Approve.
What Access Review Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read an entitlements export for the review scope
- Flag access that is unused, stale or broader than the role needs
- Draft a review pack for each manager or resource owner
| - Grant or revoke access
- Edit the directory or any access record
- Review its own access or the access of the people who built it
| - Every revocation, by the resource owner
- Access kept as an exception, with the reason
- Sign-off of the completed review by the control owner
| - The export version it read
- Flags raised and why
- Reviewer and decision for each entitlement
- Sign-off
- Reference to the revocation ticket
|
Change Approval Agent
◐Starting pointPrepares a change request for its approver: what changes, what could break, and whether the evidence is complete.
Starts at: L1 Assist.
Studio has Worker templates for code review and DevOps. They produce assessments and recommendations only, with no approval flow, so the gate is yours to add.
What Change Approval Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read the change request, the diff summary, test results and deployment history
- Summarise the likely impact and flag missing evidence
- Draft the risk assessment for the approver
| - Approve, merge or deploy a change
- Edit the change record after it is approved
- Waive a missing test or a failed check
| - Every normal change, by the change approver
- Emergency changes, reviewed afterwards by a named person
- Any change that touches a restricted system
| - Change request and evidence read
- Risk assessment drafted
- Approver and decision
- Time of approval and of deployment
- Outcome and any rollback
|
Release Readiness Agent
◐Starting pointCompiles the evidence for a release decision and recommends go or no-go. A named person decides.
Starts at: L2 Approve.
A release-manager Worker template exists. It is advisory: it recommends, and nothing in it publishes or approves.
What Release Readiness Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read the release checklist, test results, open defects and gate evidence
- Compile a readiness report with gaps marked
- Recommend go or no-go with its reasons
| - Publish, tag or promote a release
- Waive a failed gate
- Mark a gate passed without recorded evidence
| - The release decision, by the release owner
- Any waived gate, with the reason recorded
- Release of anything signed with a restricted key
| - Evidence read for each gate
- Report and recommendation
- Decision and who took it
- Waivers and their reasons
- Release outcome
|
Incident Response Agent
◐Starting pointHelps the on-call team in the first minutes: correlates alerts, drafts a timeline and proposes first steps. People take the actions that change things.
Starts at: L1 Assist, with containment staying at L2 Approve.
Security analyst and production-support Worker templates exist, as does a paging integration. They triage and recommend. The approvals and the timeline record are yours to add.
What Incident Response Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read alerts, logs and the relevant runbook
- Correlate signals and draft a running timeline
- Page the on-call person and propose first-response steps
| - Isolate hosts, rotate credentials or change configuration without approval
- Delete or alter evidence
- Notify customers or authorities
| - Containment actions, by the incident lead
- External communications, by the communications owner
- Any notification to a regulator, by the accountable officer
- Closing the incident
| - Alerts and logs read
- Timeline as drafted and as corrected
- Actions proposed, approved and taken
- Drafts of communications
- Closure and review actions
|
Vendor Onboarding Agent
○DesignedChecks a new supplier file for completeness and summarises the risk answers for the person who decides.
Starts at: L2 Approve.
No template exists. The nearest shipped one is a contract-review workflow with named sign-offs.
What Vendor Onboarding Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read the supplier questionnaire and supporting documents
- Check the file for gaps and inconsistencies
- Summarise the risk answers and draft the onboarding checklist
| - Approve a vendor or create it in the payment system
- Share company data with the vendor
- Accept contract terms
| - Vendor approval, by the risk owner
- Any data-sharing agreement
- Exceptions to the standard terms
| - Documents read and their versions
- Gaps found and how they were closed
- Risk summary as presented
- Approver and decision
- Systems the vendor was added to, by whom
|
KYC Review Agent
○DesignedAssembles a know-your-customer case for a trained reviewer. It organises evidence and never decides.
Starts at: L1 Assist. Decisions stay with people.
No template exists. A KYC onboarding listing on this site is a sample listing, not a shipped template.
What KYC Review Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read submitted documents and the results returned by the screening provider
- Check the file for completeness and consistency
- Draft a case summary with the evidence cited
| - Approve, reject or onboard a customer
- Override or dismiss a screening hit
- Copy documents outside the permitted systems
| - Every decision, by the qualified reviewer
- Any adverse, unclear or escalated hit, by the compliance officer
| - Documents and checks read
- Summary and the evidence it cites
- Reviewer, decision and reason
- Escalations and their outcome
|
DPIA Intake Agent
○DesignedCollects what a data protection impact assessment needs and drafts the first version for the data protection officer.
Starts at: L1 Assist.
No template exists. DPIA appears in the platform only as a control and an attestation topic.
What DPIA Intake Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Read the project description and data-flow notes
- Draft assessment sections and list the questions still open
- Flag features that usually call for closer review
| - Conclude that an assessment is not needed
- Sign off an assessment
- Contact a supervisory authority
| - Sign-off, by the data protection officer
- Any decision to consult an authority
- Acceptance of residual risk, by the accountable owner
| - Inputs read and their versions
- Draft and every edit to it
- Reviewer, decision and reason
- Residual risk accepted, by whom
|
Policy Attestation Agent
◐Starting pointRuns a policy attestation round: asks the named people, chases, and reports who has and has not attested.
Starts at: L2 Approve.
The certification feature records human attestations against controls. The chasing and the report are yours to assemble.
What Policy Attestation Agent can do, cannot do, needs approval for, and records| Can | Cannot | Requires approval | Records |
|---|
- Send attestation requests to the named people
- Track and chase responses
- Compile the attestation report
| - Attest on anyone’s behalf
- Change the policy text
- Mark the round complete while responses are missing
| - Sign-off of the final report, by the policy owner
- Exemptions, by the policy owner
| - Requests sent and when
- Each response, with the person who gave it
- Reminders and escalations
- Final report and sign-off
|