Can we trust AI to act on its own?→Governance and guardrails
Who allowed the AI to do that?→Identity travels with every request
Can someone talk the AI into something risky?→Risk-graded autonomy
Can we see who did what, and why?→One thread from request to result
Where are the keys kept?→One vault, no shared secrets
Why did the AI bill jump, and who spent it?→One counted doorway
Is every task getting the right model?→Right model, right task
What if our AI vendor goes down or raises its price?→No single point of supply
Are we paying for tools that do the same job?→One tool per job
Does the AI forget everything between conversations?→Governed shared memory
Is this producing real work, or just answers?→The digital factory
Which work should run itself?→Managed, not scripted
Can we get more from the Copilot licences we already pay for?→Copilot proposes, the platform verifies
Will people actually use it?→Meet people where they work
How much time do people lose sorting inbound information?→Intake to insight, untouched
Can the same platform run a real business?→One governed foundation for every product
What happens when it breaks at night?→Detect, fix, escalate
Where is the list of what is open, and who owns it?→One list, closed with evidence
Could we recover if we lost everything?→Proven by restoring
Can you prove it to an auditor?→Challenge before acceptance
Does it get better over time, or just older?→Every lesson becomes a rule
Will this still work after the next upgrade?→Clean Core for AI
Do our documents match what is actually running?→Documentation as a by-product
Portfolio / Governance and guardrails
Governance and guardrails
AI that knows its limits, and proves it.
The question every board asks before AI is allowed to act: what stops it going wrong? Here, every agent works inside written rules: what it may do alone, what waits for a person, what it may never do, and how every decision is recorded.
See it workingAI that knows its limitsAnimation
The guardrails
The limits on every agent action.
Known problems are fixed automatically from a short list of standard fixes, and every run is recorded.
Detect, fix, escalate →Waits for a yesRisky steps need the ownerA risky action posts an approval card in Teams. Only the owner can approve, and the decision is kept with who, what and why.
Risk-graded autonomy →Stops at a limitCaps and retry limitsEach agent has a spend cap, a quota guard moves work before a limit is reached, and retries stop and alert a person.
One counted doorway →Never allowedDestructive or protectedDestructive actions are blocked for automated fixers, critical services sit on a protected list, and a guest never sees owner tools.
Risk-graded autonomy →The governance
How decisions are made, and kept honest.
Governance was added only where a real failure showed it was needed, so it stays small and useful.
Every agent's instructions point to one set of written rules, and a check flags any drift from them.
Every lesson becomes a rule →Decisions on recordDecisions are written down with the options considered and their consequences.
Challenge before acceptance →Challenge before acceptanceReviews run in independent lanes, and a challenger tries to break each finding first.
Challenge before acceptance →One change procedureBack up first, recheck the impact at the moment of change, and verify by real proof.
Challenge before acceptance →One task list, closed with evidenceAll open work lives on one board, and nothing closes without evidence of what was made to happen.
One list, closed with evidence →One thread from request to resultEvery model call, approval and change is linked, so any result can be traced back to a person.
One thread from request to result →Standard firstProven products before custom code, and every change labelled standard or custom.
Clean Core for AI →Keep-guardNothing is removed while it is the only copy or something still depends on it.
One tool per job →Data protectionPersonal details are redacted from what agents store, and keys never travel through code or chat.
One vault, no shared secrets →Why it matters
Say yes to more automation
Leaders approve more when the limits are written down, enforced and visible.
Why it matters
Pass an audit without a project
Every decision, approval and change is already on record, linked to the request.
Why it matters
Fewer surprises
Runaway costs, risky changes and silent failures are stopped, or raised the same day.
The case studies behind it
Each guardrail, case by case.
Approvals and guardrails
“Can someone talk the AI into something risky?”
The conceptRisk-graded autonomy
Read the case studyAgent and user authentication
“Who allowed the AI to do that?”
The conceptIdentity travels with every request
Read the case studySelf-healing operations
“What happens when it breaks at night?”
The conceptDetect, fix, escalate
Read the case studyCost control
“Why did the AI bill jump, and who spent it?”
The conceptOne counted doorway
Read the case studyGovernance and assurance
“Can you prove it to an auditor?”
The conceptChallenge before acceptance
Read the case studyAudit trail
“Can we see who did what, and why?”
The conceptOne thread from request to result
Read the case studyIncident and task management
“Where is the list of what is open, and who owns it?”
The conceptOne list, closed with evidence
Read the case studyStandard first: Clean Core for AI
“Will this still work after the next upgrade?”
The conceptClean Core for AI
Read the case studyLessons that shaped these rules: Too much access in one account · An audit that agreed with itself
Contact
Looking for someone to lead AI from pilot to production?
I would be glad to walk you through any part of this live and talk about the role you have in mind.
j.walters@erpaiintegration.com
Go deeper: Lessons · The journey · How it’s built · Live health