Contact

AgenticIntelligenceTeams.

Not a swarm of agents, but a well-rehearsed system. Workflow where possible. Agents where decisions are open. Humans where it matters.

Workflow before agent.

1/3

Most of it is workflow.

Classify, extract, route: most enterprise use cases work best as a fixed process with individual AI steps. Predictable, affordable, auditable.

2/3

Agentic only where it’s open.

An agent comes in where there is real freedom to decide: unstructured input, changing solution paths, research.

3/3

Multiple agents only with clear separation.

A team of agents only pays off when context and responsibility can be cleanly separated. Otherwise cost, latency and errors go up without better quality.

The agent is the easiest part.

Everything around it is the hard part. Eight layers we build minimal, but right.

01/08

Orchestration & runtime

Agent logic belongs in a persistent, resumable process, not in a chat session. For long-running flows with waits, approvals and retries we rely on durable execution.

  • Claude Agent SDK
  • OpenAI Agents SDK
  • Google ADK
  • LangGraph
  • Temporal
  • Inngest
02/08

Integration via MCP

We connect tools and data via the Model Context Protocol. An MCP gateway centrally controls which agent sees which tools, with authentication, rate limits and an audit log.

  • MCP
  • MCP gateway
  • A2A
03/08

Identity & permissions

Every agent has its own identity in the identity provider. It acts on behalf of a person with their permissions, or with narrowly scoped permissions of its own. Never through a shared superuser.

  • Entra ID
  • Okta
  • OAuth on-behalf-of
  • Human-in-the-loop
04/08

Security

No filter reliably stops prompt injection. We solve it in the architecture: separate capabilities, control outbound connections, allowlist tools, sandbox code execution.

  • Egress control
  • Tool allowlist
  • Sandbox
05/08

Context & knowledge

Retrieval inherits the permissions of the source systems. An agent only finds what the person it works for may see. For numbers we use defined metrics instead of free-form SQL on raw tables.

  • Permission-aware RAG
  • Semantic layer
  • Memory
06/08

Model layer

A gateway in front of the models enables multi-model operation, fallbacks and cost control per team. Large models plan, small ones handle routine. With EU data residency on request.

  • LiteLLM
  • Portkey
  • Bedrock
  • Vertex AI
  • Microsoft Foundry
07/08

Observability & evals

Every run is fully traced, including tool calls, context, cost and latency. Evals built from real cases run as regression tests on every change. Without evals, every model switch is flying blind.

  • OpenTelemetry
  • Langfuse
  • LangSmith
  • Arize
  • Cost per run
08/08

Governance & operations

An agent registry shows which agents exist, who owns them and what they may do. Plus audit logs, a kill switch, risk classification under the EU AI Act, GDPR and, where needed, the works council.

  • Agent registry
  • Audit log
  • Kill switch
  • EU AI Act
  • GDPR

Three capabilities. Never all together.

An agent that reads private data, processes untrusted content and can send data out is vulnerable. Simon Willison calls this the “lethal trifecta”. No guardrail model solves it reliably. That’s why we take at least one of these capabilities away from every agent.

What makes us different.

TypicalWith us
Build the AI platform first, value comes later.
Start with one use case with measurable success. Only as much platform as it needs.
As many agents as possible, as autonomous as possible.
As much fixed process as possible. Agents only where decisions are open.
One service account with every permission.
Its own identity per agent, narrow permissions, approvals enforced by the system.
A guardrail prompt against attacks.
Security by architecture: separate capabilities, control egress.
One vector index over all documents.
Retrieval that respects source-system permissions.
A dashboard nobody looks at.
Evals with real cases on every change.
A strategy paper at the end.
A running agent your team keeps building on.

Start small. Build it right.

01

Pick a use case

One or two tightly scoped cases with high volume and measurable success.

02

Lay the foundation

Identity, gateway, tracing and evals. Minimal, but right. No platform built on spec.

03

Raise autonomy

Suggestions first, then execution with approval, then autonomous execution at low risk.

Which process is impossible for you?