From a good method
to a useful tool.
We are exploring product directions around recurring needs in secure AI workflows. There are no released products yet. Each direction needs evidence of usefulness, a defined user and a viable operating model.
Walk through the conceptSame task. Different responsibility.
Imagine a support assistant with access to one conversation. Choose an action to explore how its authority and decision record could change.
A concept illustration using a fictional example. It does not run an agent, send messages or test security controls.
One conversation. Read access.
Summarize the selected customer conversation.
Read only, within one case
Access covers one conversation. No changing records, browsing other cases or contacting the customer.
Being able to read something should not, by itself, confer permission to act on it.
What a record could include
- Source reference and version
- Scope of access at the time of reading
- System version and summary outcome
Less data. A clearer record.
References and versions may be enough instead of copies of entire conversations. Scope and retention would need a separate decision.
Ready for review. Not for sending.
Prepare a reply based on this conversation.
Prepare a draft
The assistant could prepare a draft. It could not send it or treat it as approved.
Preparing a proposal and taking an action are two different permissions.
What a record could include
- Sources used to prepare the draft
- Version of the proposed reply
- Status of human review
Less data. A clearer record.
References and versions may be enough instead of copies of entire conversations. Scope and retention would need a separate decision.
Sending needs its own approval.
Send the prepared reply to the customer.
An exact message and recipient
Sending would require approval for the exact message version and recipient. Without it, the action would stay a proposal.
Approval for an earlier draft should not authorize sending changed content.
What a record could include
- Approved version and recipient
- Approver and scope of approval
- Send outcome or reason for not proceeding
Less data. A clearer record.
References and versions may be enough instead of copies of entire conversations. Scope and retention would need a separate decision.
Two directions. A shared starting point.
Agent control tools
What should this agent be allowed to do, right now?
A possible tool layer for scoped permissions, action-bound approvals and explicit revocation. The starting point is a repeatable action contract that keeps a useful workflow within its authorized boundaries.
Explore the underlying researchDecision evidence tools
Could someone else reconstruct what happened?
A possible evidence layer connecting sources, system versions, permissions, approvals and outcomes. The aim is a reviewable record with a proportionate sensitive-data footprint.
Explore the underlying researchA product starts with a repeated need.
Consultancy reveals practical questions. Research tests whether an approach works. A product becomes worthwhile when that approach solves a recurring problem for a clearly identified user.
The next step is to test these directions against specific workflows and users before deciding what to build.
Explore the experience behind these questionsWhat we want to learn first.
We need to understand the workflow, the failure that matters and what a process owner would need to adopt a tool. Useful feedback can begin with a synthetic example.
- Which task recurs often enough to justify a dedicated tool?
- What evidence would demonstrate an improvement?
- Who owns access, operation and review?
- Can it be maintained within realistic cost and support limits?
Put a real workflow on the table.
A recurring task, a difficult decision, a missing record. That is enough to begin a conversation.