Technology
One reference architecture behind every system we build.
AI systems that act need more than a model and an API key. They need orchestration, real context, and controls that live in the execution path.
Reference architecture
Five layers, spanned by trust.
The Trust Layer is drawn vertically on purpose: identity, policy, evidence and approval cut across every other layer rather than sitting beneath them.
- 01
Experience Layer
Role-adaptive interfaces, workflows and approval surfaces. What a person actually sees and signs.
- Role-adaptive UI
- Workflows
- Approvals
- Review queues
- 02
Orchestration Layer
Agents, routing, planning and policy-aware execution. The part that decides what happens next and whether it is allowed.
- Agents
- Routing
- Planning
- Policy-aware execution
- 03
Intelligence Layer
Foundation models, domain reasoning, retrieval, classifiers and evaluators, selected per task, not per vendor relationship.
- Foundation models
- Domain reasoning
- Retrieval
- Classifiers
- Evaluators
- 04
Context Layer
The organisation's real substrate: systems of record, communication and knowledge. Context is what separates a demo from a deployment.
- CRM / ERP
- Data stores
- Email & calendar
- Documents
- Knowledge
- 05
Measurement Layer
Evaluations, performance, cost, adoption and outcome feedback: the evidence that a system is worth its autonomy.
- Evaluations
- Performance
- Cost
- Adoption
- Outcomes
Trust Layer
Identity, permissions, policy engine, evidence, audit, human approval and rollback, spanning every other layer rather than sitting beneath them.
- Identity
- Permissions
- Policy engine
- Evidence
- Audit
- Approval
- Rollback
Trust Layer
Identity, permissions, policy engine, evidence, audit, human approval and rollback, spanning every other layer rather than sitting beneath them.
- Identity
- Permissions
- Policy engine
- Evidence
- Audit
- Approval
- Rollback
Autonomy model
Autonomy is allocated per action, not per product.
Consequence and reversibility set the level. A single system typically operates at several levels at once.
L3 · Act with approval
The system executes, but only after an explicit human approval on the specific action.
Different actions within the same system can run at different autonomy levels, based on risk, confidence and reversibility.
L3
Act with approval
Governance load
52
The system executes, but only after an explicit human approval on the specific action.
The system may
Executes the specific approved action.
A human still
Approves that exact action first.
Evidence written
Approver, policy matched, result.
Governance load is an illustrative index, not a measured figure. Autonomy is set per action, so one system usually runs at several levels at once.
Conceptual model
Value rises with autonomy, and so does the governance requirement.
Conceptual illustration of the relationship we design around. It is not derived from measured data.
More autonomy can unlock more operational value, but governance and evidence must rise with it. Autonomy is only defensible where the evidence layer is genuinely in place. Conceptual illustration of a design principle, not measured data.
Evidence
What a system writes when it acts for you.
Pick an action and read the receipt it produces. Sample artefacts, built to the shape our systems emit.
Every consequential action our systems take writes one of these as it happens, not afterwards.
RCPT-4F2A19
Renewal outreach sent
- Inputs read
- CRM account record, read 11:04 UTC
- Last 40 days of activity, 62 events
- Renewal date and contract value
- Actor
- Closos · revenue agent
- Policy matched
- OUTBOUND-03 · named accounts, business hours, one touch per week
- Approval
- Auto, inside boundary. Owner notified.
- Result
- 1 email queued to the economic buyer, CRM task created.
- Reversal
- Recall window 15 minutes. Task deletable. Full input snapshot kept.
If it cannot be proved and undone, it should not be automatic.
Technical principles
Non-negotiables.
01
Model-agnostic by design
Models are components, not architecture. Task, cost, latency and risk decide which model runs, and the choice can change without rebuilding the system.
02
Human control where consequence demands it
Autonomy is allocated per action, calibrated to consequence and reversibility rather than applied as a single global setting.
03
Least-privilege tool access
An agent receives the narrowest possible access to the smallest necessary set of tools, scoped to the task in front of it.
04
Traceable actions and evidence
Every consequential action carries its inputs, the policy it matched, the approver and the result. Traceability is produced by execution, not bolted on.
05
Reversible automation where technically possible
Where an action can be undone, the reversal path is designed before the action is permitted.
06
Evaluation before and after deployment
Systems are evaluated before release and monitored after it. Regression is treated as a first-class risk.
07
Context over generic prompting
Performance in production comes from grounded organisational context and retrieval design, not from cleverer instructions.
08
Security and governance in the workflow
Controls live inside the execution path rather than in a parallel review process that runs after the fact.
The thesis
The next generation of software will not wait to be asked. It will understand, decide, act, and prove what it did.
We’re building that generation from Dubai’s DIFC, for organisations that have to answer for what their systems do.