Governed agents: real work without going rogue
Amolfi’s AI operators work under a Chair for each part of the business. Every seat carries a hard ceiling and a kill switch, and anything that spends money or leaves your workspace waits for an owner to say yes.
Every AI product built for a business arrives at the same screen eventually. It asks you to connect the bank account, or hand over the client list, or let it into the inbox. Everything before that screen is a demo. Everything after it is software holding things that can be spent, sent, or read by the wrong person, with nobody sitting behind it checking its work. Owners hesitate there for good reason.
There are two kinds of AI you can put inside a business. One of them only talks. It reads, summarizes, drafts, and hands the work back to a person to actually do. The other one acts. It can start a campaign, move a deal through the pipeline, send money. The first is safe because it is powerless. The second is useful for precisely the reason it is dangerous: the moment it gets something wrong, or the moment somebody talks it into getting something wrong, the damage is real.
Most products ship the one that only talks and call the problem solved. We wanted the one that does the work, minus the headline where a single bad prompt empties an account. A better model does not get you there. Architecture does.
A Chair for every part of the business
Amolfi does not run one all-powerful assistant with every key on its belt. It runs a workforce. The narrow jobs go to operators, and above them sits a Chair for each domain: a Finance Chair over money, a Marketing Chair that fans work out to a Social operator and a Newsletter operator. The Chair decides who does what. The operator does the one thing it exists to do, and nothing else.
The shape follows from the stakes. A question about your payables and a question about Thursday’s post are different jobs with different consequences, and no unbounded authority should be answering both. Give a seat a narrow remit and you can actually say what it is capable of, which is where trusting it starts.
Every seat has a ceiling and a switch
Two properties are wired into every seat. The first is a risk ceiling, a hard cap on how far that agent is allowed to go on its own. The second is a kill switch, so any seat can be stopped instantly.
Seats are also isolated from one another. The Social operator cannot decide to move money simply because the Finance Chair can. Authority does not leak sideways, and there is no path by which one operator inherits another’s reach.
That isolation is aimed at a specific kind of attack. A great many of the ways these systems get abused come down to persuading a low-privilege component to use a high-privilege one’s powers. Cutting the routes between seats takes away the thing that trick reaches for. An operator talked into overstepping is still an operator with one job and a ceiling on it.
The rule that never bends
Here is the rule everything else exists to protect. Anything that touches money or the outside world never acts on its own. It becomes an owner-approval card: a real decision, made by a person, before anything real happens.
The tiers are deliberately blunt, because blunt is what survives contact with a clever prompt.
- Low-risk work just runs. Reading your own data, assembling an analysis, preparing a draft. Nothing has left the building and nothing has been spent, so the cost of getting it wrong is a redo.
- High-risk work stops. Moving money, or anything headed outbound past your workspace, turns into a card that an owner approves or rejects. The agent can build the whole thing down to the last detail. It cannot be the one to release it.
An agent you can trust is one that can never do something the person asking couldn’t.
An operator’s reach is bounded by the authority of the person it is acting for. Irreversible steps route back to that person before they land. Which leaves the last call with a human: a bad instruction gets as far as a card, and a card gets read before it gets released.
Governance came first
The usual way to build an AI feature is to make it capable and then add safety at the end. A content filter. A confirmation dialog. A policy document nobody opens twice. That approach fails the first time it genuinely matters, because the dangerous paths were laid down before anyone drew a guardrail, and the guardrails end up guessing at where those paths run.
We built it the other way around. The Chairs and their operators, the per-seat ceilings, the isolation, the card standing between an agent and your bank account: all of it went in before the agent could do anything at all. It is what the agent is made of. Which is why you can connect the bank account, hand over the pipeline, and still know the exact shape of what this thing can do while nobody is looking.