Agentic process automation
AIMY Agents
Multi-step work, executed inside boundaries you can defend.
AIMY Agents carries out real operational work — assembling the pack, filing the record, reconciling the exception, chasing the missing document — reading your systems under the requester's own permissions, stopping for approval wherever an action cannot be undone, and recording every step for review.
- Acts only through tools and scopes you have granted
- Human approval on anything that writes, sends or spends
- Every run replayable months later, step by step
What deployments look like
- Read-only
- is the default — every write is a permission you grant
- starting posture
- Every step
- logged with its inputs, tool call and result
- by design
- One gate
- before anything irreversible happens
- configurable per tool
The process is fully documented. It is still done by hand.
Every organisation has work that is entirely rule-governed and entirely manual: pulling figures from three systems into one form, checking an exception against a policy, chasing the document that is missing before a file can close. It is too variable for a rigid workflow engine and too routine to deserve a person — so it stays with the person.
- Screen-scraping automation breaks the moment a field or a layout moves.
- Workflow engines handle the happy path; every exception returns to a human anyway.
- General-purpose agents are handed broad credentials because scoping them properly is work.
- When an agent does the wrong thing, nobody can reconstruct why it decided to.
- Automation that cannot be reversed does not get approved, however good the demo.
What AIMY Agents actually does.
Scoped tools only
An agent can call the tools you register for it, with the arguments you allow. There is no general shell and no ambient credential to borrow.
Approval gates
Any step that writes, sends, spends or deletes stops and asks. The reviewer sees exactly what is about to happen, described in plain language.
Dry run first
Every task can be executed in simulation, producing the full plan and the exact calls it would make, before anything touches a real system.
Grounded in your own rules
Agents read the policies, procedures and records that govern the task through the same governed retrieval as the rest of the platform — so a decision can be traced back to the rule it applied.
Built for the exception
The cases a workflow engine hands back are the ones worth automating. An agent that cannot resolve one stops and explains why, rather than guessing.
Bounded blast radius
Rate limits, value ceilings and per-tool scopes are enforced configuration, not conventions. They are checked before the call is made, not after.
From a request to a recorded, reversible action.
-
01
Define the task
One job with a clear beginning and end — "assemble the renewal pack", not "handle renewals". Narrow tasks are the ones that survive review.
-
02
Register the tools
Each system the task may touch is registered explicitly, with the operations and argument ranges it is permitted to use.
-
03
Simulate
The task runs against your real data in dry-run mode, producing the plan and the calls it would have made. This is where scoping mistakes surface.
-
04
Gate
You decide which steps proceed automatically and which stop for a person. Irreversible actions default to stopping.
-
05
Run and record
Live runs produce the same trace as the simulation, so a review compares what was expected against what actually happened.
Technical profile
- Deployment
- Managed cloud · Customer VPC · On-premise on GB10
- Tools
- REST APIs, databases, ticketing, email and file systems, registered per task
- Execution
- Dry-run, gated, or autonomous within an explicitly declared scope
- Grounding
- The same governed retrieval and permission model as the rest of AIMY
- Triggers
- On request, on a schedule, or via API
- Audit
- Full per-run trace with inputs, evidence, calls and results, exportable
Security & data handling
- No standing credentials — tools are granted per task, not per agent
- Retrieval and actions run under the requesting user's permissions, never a service account
- Irreversible operations require human approval by default
- Rate limits and value ceilings enforced before a call is dispatched
- Complete, exportable trace of every run for audit and incident review
- Runs air-gapped on GB10 where the systems it touches are not externally reachable
The ones procurement always asks.
Something not covered here? Ask directly — you will get a straight answer, including when the answer is that we are not the right fit.
Ask usHow is this different from RPA?
Robotic process automation replays a recorded path through a user interface, so it breaks when the interface changes and it cannot handle a case it has not seen. AIMY Agents works from the rule rather than the recording: it reads the policy that governs the task, calls systems through registered tools rather than screens, and stops when a case falls outside its scope.
Do we need AIMY Expert to use it?
No. AIMY Agents is deployed on its own. It shares the platform — the same index, the same permission model, the same audit trail — so running both is one deployment rather than two, but neither requires the other.
What stops an agent doing something destructive?
It has no route to. Tools are registered per task with permitted operations and argument ranges, writes are gated by default, and limits are enforced before dispatch. An agent cannot exceed a scope it was never given.
How do we review what it did?
Every run is a trace: the request, the evidence retrieved, each tool call with its arguments, and each result. It is designed to be read by someone who was not there at the time.
Where do you recommend starting?
A task that is high-volume, low-variance and reversible — document assembly or record filing. Prove the trace is genuinely reviewable before granting anything that spends money or contacts a customer.
Sectors where AIMY Agents is deployed
Also on the AIMY Platform
Put AIMY Agents against your own documents.
We evaluate on a sample of your own corpus, never a canned dataset. That is the only way to tell whether retrieval will hold up on your content.