Skip to main content
NexITC
B14 · AI · 8–12 WEEKS · BUILD

Agents that act.
Under governance.

B14 · Agentic Workflow Agent Build™ delivers an enterprise workflow agent that executes real business actions safely — approval gates, least-privilege tool access, full audit logs, and a kill-switch. Not a chatbot. Not autonomous. A workflow performer with mandatory human oversight where it matters.

DURATION
8–12 wks
DELIVERABLES
6 named
COMMERCIAL
Fixed fee
B14·PROJECTION / TASK SUCCESS RATE
B14
BEFORE
40%
SUCCESS · MANUAL BASELINE
B14
AFTER
92%
SUCCESS · GOVERNED AGENT
WK 00
WK 03
WK 07
WK 10
STEADY
STREAMS
6
ROUTING ACCURACY
97%
SUCCESS RATE ↑
52pts
SCENARIO · UAE GOVERNMENT PROCUREMENT · N=1
ILLUSTRATIVE
§ 00 · THESIS
01
WHY AGENTIC
SAFETY MATTERS.

Every enterprise conversation about agentic AI arrives at the same fork. One path treats the agent like a smarter chatbot — bolted onto existing tools, given broad access, trusted because the demo looked convincing. The other path treats the agent like what it actually is: software that takes real actions against real systems, and therefore needs the same governance discipline as any privileged operator.

The instinct to move fast on agents is right. The instinct to skip the control plane to get there faster is where engagements fail publicly. B14 pairs a narrowly-scoped, structured workflow with a control plane built once and reused: registry, gateway, least privilege, approval gates, action logs, kill-switch, evaluation harness. The agent acts. The governance is what makes that acceptable.

STATE · BEFORE
Manual triage, hardcoded scripts, shared credentials. No audit trail. No kill-switch.
STATE · STEADY
Governed agent executes structured decisions. Approval gates on high-stakes actions. Every step logged.
§ 01 · WORK STREAMS

Six streams,
ending in one safe agent.

The engagement runs in parallel streams. Mapping and control-plane setup front-load weeks 1–4. Integration, approvals, and safety testing overlap through weeks 4–10. Handover runs weeks 11–12.

STREAM 01
WK 01–03

Workflow mapping

The target workflow decomposed into decision points. Action-vs-approval boundaries agreed with the business owner before a line of integration code is written.

STREAM 02
WK 02–04

Control plane setup

Agent registry, tool gateway, least-privilege enforcement. The scaffolding every subsequent action runs through — built once, reused across future agents.

OUTCOME
1
GOVERNED AGENT AT HANDOVER
+ REUSABLE CONTROL PLANE
STREAM 03
WK 04–07

Tool integration

Read connectors first. Write connectors gated behind approval flows from day one — never bolted on after the fact.

STREAM 04
WK 06–09

Approval workflows

Approval routing rules, escalation paths, timeout handling. The mechanism that keeps a human accountable for every consequential action.

STREAM 05
WK 08–10

Safety testing

Adversarial red-team exercises, an evaluation harness run against edge cases, and kill-switch drills — proving the off-switch works before go-live, not after.

STREAM 06
WK 11–12

Handover

Operator training, an action-log audit walkthrough, and 30/60/90-day post-handover check-ins.

EXPLICITLY NOT COVERED
Continuous monitoring and tuning
after handover. That's Managed Agent Operations, our Run-tier retainer.
A second or third agent
beyond the one governed workflow in scope. Scaling a portfolio is C2 CoE-as-a-Service™.
§ 02 · TIMELINE

Twelve weeks maximum.
Eight minimum. Four phases.

Phase count is fixed. Duration flexes with workflow complexity and the number of tool integrations. Milestones are signed gates — not aspirations.

WK 0102030405060708091011 · 12Phase 1 · Mapping & control planePhase 2 · Tool integrationPhase 3 · Approvals & safety testingPhase 4 · HandoverWorkflow mapped & control plane setEND WK 04 · GATE 01Tools integratedEND WK 07 · GATE 02Safety tests passedEND WK 10 · GATE 03Handover completeEND WK 12 · GATE 04OPERATING RHYTHMDaily standup · Weekly sponsor check-in · Bi-weekly Practice Lead reviewNAMED ACCOUNTABILITYPractice Lead — AI (CEO escalation available)
§ 03 · APPROACH

Agent frameworks scored,
not on conference-stage demos.

Every engagement runs a six-criteria scorecard in weeks 1–2. Each criterion scored 1–5 with documented evidence. Signed by your business owner before Phase 2 begins.

AGENT FRAMEWORK SELECTION SCORECARD · TEMPLATE
CRITERIA · 06 · WEIGHTED 1–5
ILLUSTRATIVE SAMPLE RENDERING — actual scores are engagement-specific and derived from evidence gathered during discovery.
01
Tool-calling reliability
Consistency of structured tool invocation under real workload, tested against your own APIs — not vendor benchmarks.
4/5
02
UAE data residency
In-country processing options for model calls and logs — PDPL, ADHICS v2, CBUAE cloud oversight.
4/5
03
Approval-gate support
Native human-in-the-loop primitives — not bolted-on webhooks that fail silently.
5/5
04
Audit-log fidelity
Completeness and immutability of action logs. Regulators read these; so should your incident team.
4/5
05
Kill-switch mechanics
Time-to-halt, and whether in-flight actions can be safely interrupted mid-execution.
3/5
06
Ecosystem & tool-gateway maturity
Depth of pre-built connectors versus custom integration effort required per tool.
4/5
!
DISCLOSURE · VENDOR-NEUTRALITY
NexITC maintains commercial arrangements with several agent framework and tool-gateway vendors — these are how specialist consultancies build sustainable practices. We do not disclose which arrangements exist publicly because we do not want them to influence platform choice by anyone reading this page. The scorecard exists precisely so selection happens on evidence, not on economics. In practice, we have recommended platforms with which we have no partnership when the scorecard result favoured them.
§ 04 · ARCHITECTURE

From autonomous risk
to gated execution.

A typical pre-engagement state has no agent control plane at all — hardcoded scripts, shared credentials, no audit trail, no kill-switch. The engagement builds a two-layer control plane before a single production action executes.

BEFORE · T=0
TYPICAL STATE
TOOL_01
Hardcoded scripts
AD HOC
TOOL_02
Shared service credentials
OVER-PRIVILEGED
TOOL_03
Manual triage queue
MANUAL
TOOL_04
Point-to-point API calls
UNGOVERNED
TOOL_05 · AUDIT
No centralised action log
OPERATIONAL REALITY
  • No agent registry or tool gateway
  • Credentials shared across scripts, not scoped
  • No audit trail of automated actions
  • No kill-switch if something goes wrong
B14 · GOVERN
AFTER · STEADY STATE
TARGET-STATE
PLATFORM_01
Agent Control Plane
Registry · Gateway · Least Privilege · Kill-Switch
PLATFORM_02
Approval-Gated Execution
Human-in-Loop · Action Logs · Evaluation
↓ GATED · LOGGED · REVERSIBLE ↓
TOOLS · RETAINED
Wrapped, not replaced
STEADY-STATE OUTCOME
  • Every action attributable to a logged approval
  • Least-privilege tool access, no shared credentials
  • Kill-switch tested via adversarial drills
  • Scope of autonomous actions expands deliberately

Reference pattern. Some engagements retain a lightweight orchestration layer where an existing workflow engine is already fit for purpose. What always gets built new is the control plane. Never the underlying business systems the agent calls into.

§ 05 · REPRESENTATIVE SCENARIO

A procurement triage
agent, measured.

Representative pattern for a UAE government entity processing 500+ procurement requests a month. Ranges reflect target outcomes NexITC underwrites in scope for this class of engagement. N=1 — illustrative composite, not a specific client.

SCENARIO / B14 / UAE GOVERNMENT · 500+ REQUESTS/MO
DURATION · 10 WKS
TRIAGE CYCLE TIME
65%
Reduction vs. manual baseline
ROUTING ACCURACY
97%
Correct category on first pass
HUMAN EFFORT
40%
Reduction in reviewer hours
SITUATION

UAE government entity processing 500+ procurement requests monthly. Triage handled entirely by hand — category, urgency, and approver assignment decided by a small team working from an inbox.

ENGAGEMENT

10-week B14. Weeks 1–4 workflow mapping and control-plane setup. Weeks 4–7 read/write tool integration. Weeks 6–10 approval routing and safety testing running in parallel. Handover across weeks 9–10.

OUTCOME

Triage cycle time ↓ 65%. Routing accuracy at 97% on first pass, verified against a three-month held-out sample. Human review hours ↓ 40%, redirected to the exceptions the agent correctly escalates rather than the routine cases it now handles.

§ 06 · DELIVERABLES

Six artifacts,
each with signed acceptance.

Every deliverable has documented acceptance criteria signed at engagement kickoff. Nothing more, nothing less.

D_01

Workflow Blueprint

Decomposed workflow, decision map, action-vs-approval boundaries — signed by the business owner.

D_02

Integrated Tool Actions

Read and write connectors with least-privilege enforcement wired through the tool gateway.

D_03 · CORE

Approval Flow Engine

Approval routing, escalation paths, timeout handling. The mechanism keeping a human accountable for every consequential action.

D_04

Audit Dashboards

Action logs, approval history, exception tracking — one screen, always attributable.

D_05

Evaluation Harness

Safety-test suite and adversarial red-team results, re-runnable on every future change.

D_06 · OPERATOR-READY

Runbooks & Kill-Switch Playbook

Operator runbooks, kill-switch drill procedures, and an escalation matrix — the document the operator opens the moment something looks wrong, not after.

HANDOVER
WK 12
§ 07 · OUTCOMES

Six outcome metrics,
measured pre and post.

Success is not “the agent is deployed.” It is measured against six specific outcomes captured in a baseline report at engagement start and re-measured at steady state.

THE SUCCESS RATE JOURNEY · REPRESENTATIVE
Forty percent to ninety-two, across the four phases.
+52%SUCCESS RATE
100%75%50%25%040%BaselinePRE-ENGAGEMENT65%IntegratedEND WK 0782%Post-safety-testingEND WK 1092%Steady state30 DAYS POST
01 · SUCCESS
85+%
Task success rate, measured against acceptance criteria per workflow step.
02 · CYCLE TIME
40–65%
Approval cycle time reduction, end to end.
03 · EXCEPTIONS
<10%
Exception rate requiring manual override.
04 · COMPLIANCE
99+%
Policy compliance across logged actions.
05 · EFFORT
30–50%
Human effort reduction on the target workflow.
06 · SAFETY
100%
Safety-test pass rate at go-live, re-verified quarterly.
§ 08 · FIT

Honest scoping.

B14 is a fit when specific conditions are met. It is not a fit when other conditions are. We say so before the scope conversation, not after the commercial commitment.

PREREQUISITES
Move fast when these five conditions are in place at kickoff.
01
The target workflow is stable and documented

If the process itself changes week to week, there is nothing firm for the control plane to gate against.

02
Tool APIs are available

Read and write access to the systems the agent needs to act on — not screen-scraping, not manual handoffs.

03
Approval-authority mapping exists

Someone can name, today, who approves what. If that mapping doesn't exist, Phase 1 builds it — but this extends timeline.

04
A named business owner

Signs off the workflow blueprint and approval routing. Typically 25–30% time commitment through the engagement.

05
A change window agreed upfront

Go-live coincides with a period the business owner can actively monitor the agent's first live decisions.

NOT SUITABLE IF
Four patterns indicate a different engagement is a better fit.
The workflow isn't stable

Map it first. Start with A11 Agentic AI Readiness & Use-Case Discovery.

You want a chatbot, not an actor

B14 builds agents that take actions. For a knowledge-retrieval assistant, look at B2 GenAI Knowledge Assistant Build™.

You want a portfolio of agents at scale

B14 delivers one governed agent. For a governed pipeline of many, look at C2 CoE-as-a-Service™.

Regulatory deadline is under 6 weeks

Eight weeks is our minimum for a defensible control plane. We will not compress safety testing to hit a shorter deadline — the gate stays, or the timeline moves.

§ 09 · COMMERCIAL

Fixed fee.
Milestone-based.

Total engagement fee agreed in the scope statement. Not time-and-materials. Not day rate. Every engagement is preceded by a scope conversation to ensure fit before commitment.

STANDARD MODEL
ENGAGEMENT MODEL
Fixed fee
PAYMENT CADENCE
Milestone-based

Payment schedule aligned to engagement phases and defined delivery milestones agreed upfront.


INCLUDED IN SCOPE
  • All 6 named deliverables with acceptance criteria
  • Named Practice Lead throughout the engagement
  • Bi-weekly executive sponsor reviews
  • 30/60/90-day post-handover check-ins
  • Written scope amendment process for any changes
01

Signed scope statement

Every engagement begins with a signed scope statement fixing deliverables, timeline, milestones, and commercial terms. No verbal agreements. No moving targets.

02

No scope creep

Scope changes require a signed scope amendment. If scope changes, so does the commercial arrangement — always in writing, always signed by both parties.

03

Named accountability

The Practice Lead is accountable for commercial and delivery outcomes throughout the engagement, with escalation to the CEO within 24 hours if needed.

§ 10 · QUESTIONS

Five, most asked.

Q_01What's the difference between an agent and a chatbot?

A chatbot answers. An agent executes. That distinction carries real risk asymmetry — a chatbot giving a wrong answer is an inconvenience; an agent taking a wrong action against a live system is an incident.

B14 is scoped around that asymmetry: least-privilege tool access, approval gates on anything consequential, and full action logs so every step is attributable.

Q_02How do you keep the agent from doing something stupid?
Through a seven-part control plane, not a single safeguard: agent registry, tool gateway, least-privilege enforcement, approval gates, action logs, a kill-switch, and an evaluation harness that runs adversarial tests before and after deployment. Remove any one part and the control plane is incomplete — we build all seven, every engagement.
Q_03Which workflows are actually suitable for agents right now?
Structured workflows with clear steps and defined decision criteria — procurement triage, onboarding checks, ticket routing, compliance pre-checks. Open-ended workflows without decision boundaries are not suitable yet; the control plane has nothing firm to gate against. If you're not sure which category your workflow falls into, that's what A11 Agentic AI Readiness & Use-Case Discovery is for.
Q_04How long until we can trust the agent without approvals?

That's the wrong question. Full autonomy is not the goal of this engagement, and approval gates on high-stakes actions are permanent — not a training-wheels phase we remove later.

What changes over time is the scope of actions pre-approved for autonomous execution, not the existence of the gate itself.

Q_05What comes after one agent?
C2 CoE-as-a-Service™ scales additional agents in a governed pipeline once the first agent has proven out the control plane and the operating model. We don't recommend building a second agent from scratch outside that pipeline — the governance discipline is meant to be reused, not re-litigated.
§ 11 · NAMED ACCOUNTABILITY

One name
on the engagement letter.

A named Practice Lead is accountable for delivery, commercial outcomes, and the client relationship throughout the engagement. Not a project manager who disappears after kickoff. Not a partner who nods at the SOW and vanishes.

THE ROLE

Practice Lead — AI

Present at every phase gate, every scope decision, every difficult conversation. Available for 30/60/90-day post-handover check-ins as part of the engagement.

SIX ACCOUNTABILITIES
01
Commercial arrangement

Including scope amendments.

02
Deliverables acceptance

Signs off all 6 deliverables.

03
Bi-weekly reviews

With executive sponsor.

04
Change orders

Authorised to negotiate.

05
Escalation path

CEO within 24 hours.

06
Post-handover

30/60/90-day check-ins.

§ 13 · BOOK A CLINIC

Thirty minutes.
No slide deck.

A structured 30-minute scope conversation with the Practice Lead. You describe the target workflow, the tools it touches, and who currently approves what. We describe whether B14 is the right engagement — and if not, what is.

Book a clinic →Email directly
DURATION
30 minutes
PREPARATION
None required
FOLLOW-UP
Written scope, 5 business days